Live data from Hacker News

Equifax Faces Multibillion-Dollar Lawsuit Over Hack

bloomberg.com

271–280 of 670 posts

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#272

Is it time for a Federal Department of Verifying Whether People Are Who They Say They Are? Veryifying identity with SSN is broken. The right way is probably more or less how big webapps do it - MFA + a password that the user can reset by providing a bunch of info. The government has the necessary private info to do this in most cases (e.g. DL# plus your income from last year's taxes), and can fall back to "Show up at…

Won't work. Once companies start gathering private data stored in this DB, it can be compromised and government isn't that great at securing data either. MFA would required everyone having a smart phone or RSA key fobs. SMS/Phone based authentication isn't secure.

Only real way to get true identity system is biometrics(Fingerprints,DNA, or Iris) taken at birth. But that will never happen for privacy reasons.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#273

Earlier quoted context omitted.

>And while it's almost inevitable that discussions about class action suits will involve complaints about the lawyers fees, that's not really fair. Of course it's fair. It's not like the members of the class get to shop around for cheaper lawyers. The class gets shit either way, they just have to decide if they hate the company more than the lawyers that charge the obscene percentages. And you can't make any kind of…

Attorneys' fees in a class action have to be approved by the court, and for large class actions the percentage fee tends to be lower than what a privately-retained lawyer would receive. The privately-retained lawyers in NTP's lawsuit against Blackberry got an approximately 1/3 payout of a $600 million settlement. 20-33% is quite typical in a pure contingency situation. Most court-approved fee awards in class actions…

Is it weird to also observe that the opposition in a billion dollar case will be significantly more expensive to overcome than in a million dollar case? It seems obvious to me that billion-dollar cases would be more expensive to pursue.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#274

How likely is it that Equifax will face any real trouble from this breach? Will this be one of the first cases where security negligence causes real harm to a company? Or will it turn out to be another slap on the wrist?

I should hope something happens. This is a monumental fuckup.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#275
I like how people are encouraged to pay $5-10 to each reporting agency to have their file locked. Multiply that by the 140,000,000 people whose data leaked... should generate some nice revenue for all 3 of these companies holding your exploitable personal data hostage.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#276
post #254

Earlier quoted context omitted.

> Usually reserved for criminal cases Is this not? If that's the case I need to get out of this dumpster fire of a country.

IDK whether it has the potential to be, but that's how it currently stands. I can tell because criminal cases are prosecuted by the state; civil cases are prosecuted by private parties. (And class action is always civil.) But by all means, move to somewhere less dumpster-firey where large businesses and governments don't get hacked.

Just to make sure that we aren't all talking past each other...

1. I assume the FBI is investigating the hack itself (who did it, etc.). Citation?

2. I assume the SEC is investigating the suspicious timing the executives who were selling stock before the announcement. I'd also assume it could turn into a criminal investigation. Cite?

3. The class action suit is a civil action asserting that Equifax was negligent (that's what the Bloomberg article that these comments are currently pointing to is about).

4. There could be criminal negligence in securing their networks. It seems like that could be either of a Federal or state issue. Anyone know if this investigation would take place with the FBI, or if there is another federal agency which would take the lead on that?

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#277

Earlier quoted context omitted.

After you made the choice to allow them to.

A choice made under duress of not having access to a bank account or credit (which makes someone a de-facto persona non grata in the modern world). Monopolies aren't choices, and monopolies on essential services are coercive by definition.

Equifax isn't a monopoly. There are 3 major credit reporting agencies in stiff competition with each other. No doubt executives at TransUnion and Experian are cackling with glee at Equifax's stumble.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#278

Earlier quoted context omitted.

After you made the choice to allow them to.

The non-negotiable choice between allowing them to and being denied service entirely.

It doesn't seem crazy to me that if you ask for someone to loan you money they only do it under the condition that you agree to participate in a system that helps them track your creditworthiness.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#279

How likely is it that Equifax will face any real trouble from this breach? Will this be one of the first cases where security negligence causes real harm to a company? Or will it turn out to be another slap on the wrist?

Slap on the wrist, guaranteed:

- potentially every one of the 143M people are going to have some sort of trouble

- WORST CASE equifax shuts down, but that doesn't matter. too late.

- if everyone was to win a lawsuit for everything equifax is worth, they'd get maybe $100 minus lawyer fees.

And worse, now we have a financial system dependent on 2 companies. Making a 3rd isn't an easy matter.

::shrug::

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#280
post #260

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

No amount of governmental regulations can solve the current date breach trends. Even government's own intel agencies got hacked too. No organization is immune to data breaches. It's a matter of time and effort. A lot of us here are engineers and coders. It's our responsibility to design better architecture, security conscious protocols and write securer softwares. And it's up to all of us (regardless which country yo…

Sure it's our job to do that. The job still gets easier when you have the law backing you up.

An excellent example is how many companies are in panic mode right now to get GDPR compliant before next year. There's a lot of security engineers and developers that finally get the budgets and time they've asked for to improve customer privacy, because the potential fallout of non-compliance is too big to ignore.

Post reply on HN