Earlier quoted context omitted.
I did this about 8 years ago, and have only needed to temporally unfreeze it 3 times. Besides the big 3, I also froze reporting from Innovis. The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.
Can you call and it get it unfrozen immediately if it needs to be run?
Cybersecurity Incident Involving Consumer Information
541–550 of 551 posts
Re: Cybersecurity Incident Involving Consumer Information
#542Earlier quoted context omitted.
I did this about 8 years ago, and have only needed to temporally unfreeze it 3 times. Besides the big 3, I also froze reporting from Innovis. The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.
Do they refuse you rental? Here in UK they verify address via utility bills, cross-check with drivers license (verified by gov agency, DVLA). They maybe only take card payments too, no cash? I'd expect that to be enough, given they force you to take out expensive insurance, that must cover them, surely. What's the credit report going to get them at that point? (It may be even stricter now, don't know.)
Re: Cybersecurity Incident Involving Consumer Information
#543Fear not. You can check to see if you were affected by visiting their site and giving them more personal data: https://www.equifaxsecurity2017.com /s Maybe it doesn't matter much, since they've likely already got it. But, it feels a bit too soon. An interesting side-note: That domain was registered about two weeks ago on 8/22/2017. Whois reveals not a single pointer to Equifax (e.g. equifax.com email address, etc.).…
This comment should be nearer the top. Also, equifaxsecurity2017.com appears to be a stock Wordpress site. Equifax is a bunch of fucking amateurs. Their security culture is broken.
That sums it up perfectly. This is not a mistake here or there, but a fundamental lack of appreciation for even the most basic principles of online security. It's like no one there is even thinking about the consequences of their choices.
Elsewhere on this thread, I commented on their reliance on an outside security firm to post-mortem this incident. That is ridiculous. They don't seem to understand that they are in the security business as much as anything else. They can't outsource this stuff. Their internal teams should be unparalleled.
You're right. It's absolutely cultural.
Re: Cybersecurity Incident Involving Consumer Information
#544Earlier quoted context omitted.
By enrolling in the free "Identity Theft Protection" you waive your right to "PARTICIPATE IN A CLASS ACTION, CLASS ARBITRATION, OR OTHER REPRESENTATIVE ACTION" https://trustedidpremier.com/static/terms It is a scam to get people to sign away their rights to sue the bastards.
Shit. I already submitted and should've read the fine print. I need to un-enroll.
Re: Cybersecurity Incident Involving Consumer Information
#545Earlier quoted context omitted.
This is actually a major inconvenience. You won't be able to apply for credit cards or get a loan to buy a car if you have a credit freeze. You have to unfreeze and re-freeze each time you apply for a credit card, and this costs about $30.
How often do you apply for credit? In the last 5 years I’ve done it zero times...
Re: Cybersecurity Incident Involving Consumer Information
#546Earlier quoted context omitted.
What are they being replaced with? Yeah, as a young renter I went years without using a check. When buying a home last year I had various inspectors during the process. After buying, I've had electricians, plumbers, contractors, locksmiths, and other consultants. I think one gave me a bill and accepted credit card. The rest preferred checks (to be fair, I didn't seek other forms). I've tried all sorts of p2p methods…
> I've had electricians, plumbers, contractors, locksmiths, and other consultants. I think one gave me a bill and accepted credit card. The rest preferred checks Try cash? I use cash for almost all transactions like that and have never been turned down :-)
Re: Cybersecurity Incident Involving Consumer Information
#547Earlier quoted context omitted.
I would not doubt a class action lawsuit results from this, and I'd be very surprised if Elizabeth Warren didn't pursue congressional action against them (although not officers of the company unfortunately).
And? Who cares what a fake Indian says from a floor of the Senate?
Re: Cybersecurity Incident Involving Consumer Information
#548Earlier quoted context omitted.
This is very clearly what's going on. Fraud is uncommon enough and the cost of fraud to the banks is smaller than the cost of reducing the velocity of money and loan-making, so the problem will never get fixed so long as it depends on the banks to initiate the fix.
Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.
The solution is asymmetric cryptography, wherein identity is tied to a public/private keypair, and I can prove I have the corresponding private key without giving the other party the ability to impersonate me. Ideally, the government wouldn't know my private key, either, rather they would just give their own attestation that a given public key is owned by a person with a given name, DoB, SSN, and biometrics.
Along similar lines, any financial account would have its own keypair, with moving money out of the account requiring signing with the private key.
The state of cryptography today is way too obtuse for this to work right now, but I think it could be made more user friendly with specialized hardware to hold the keys and perform the encryption.
The idea that SSNs are secret, but we hand it out to half a dozen organizations is absolutely ludicrous.
Re: Cybersecurity Incident Involving Consumer Information
#549Earlier quoted context omitted.
There is strong evidence for it here: http://www.cl.cam.ac.uk/~sjm217/papers/oakland14chipandskim.... And regardless of whether you claim the evidence is inconclusive, it is simply not acceptable to dismiss a known vulnerability in something important by saying "I don't know of any case where it has been exploited yet."
That's explicitly not what I said. I know that flaws have and will continue to be discovered in those authentication systems, and also that a theoretical shift in liability occurs. Any bugs will need to be fixed, and that's important. But you can't ignore the situation in practice – liability is not being shifted, and all UK banks and credit card providers are pretty happy to refund fraudulent transactions regardless…
Re: Cybersecurity Incident Involving Consumer Information
#550Earlier quoted context omitted.
The point is that it is NOT "identity theft", even if that's what people call it. It is more aptly "authentication theft/fraud". The original point of this comment thread was that the credit reporting agencies want to keep it confusing so that it's not clear who exactly was the victim of the crime, so it's not obvious that the system sucks.
Yes, I agree, and I might have slightly misread what tripzilch wrote to mean that we should avoid the term here in this discussion, which I objected to. Towards the general public, it totally should be framed as an authentication failure, yes, I agree.
For the same reason I won't go into discussions about the finer moral points when stealing is wrong or not, if the topic is copyright. Especially not get carried into far-fetched analogies such that it is okay if a starving family steals the blueprint for a 3D printed load of bread or whatever.
In that sense, the term "intellectual property" is actually similarly problematic as "identity theft". While it evokes the connotation of "property", intellectual_property is actually just a legal term that stands on its own and derives nothing from the common concept of "property" except where explicitly defined as such.
Except that identity_theft is, afaik, not a legal term. I believe it stems from the idea of the loss of an interconnected number of (mostly electronic) credentials, an adversary could use to, in a sense "become you", and wreck one's life. This then became a serious fear, that was (in the public) not quite blamed on terrible security practices of powerful entities, but on the ever-growing interconnectedness and electronicification of all aspects of our life. In fact literally about the fear that the large amount of data about us in these computer databases, would some day mistaken to be us and identify, regardless of its truth in the real world. But identify_theft has always been painted as a sort of "curse of the modern age", our penance for living in an ever automated society, kind of typical Hollywood morality story.
Except these credit companies seem to be just focusing on the "wreck your life" part, twisting the definition around, that suddenly a security failure with their authentication/credential system gets to be blamed on the general societal menace of identity_theft, mainly because their error has the capability to wreck one's life.
I'm pretty sure Baudrillard or some other person in critical theory / semiotics has written some interesting stuff about this. Now that is a philosophical discussion on this topic that I would actually find worthwhile.