Live data from Hacker News

Equifax Faces Multibillion-Dollar Lawsuit Over Hack

bloomberg.com

301–310 of 670 posts

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#301

Yeah, I would think so. So far, we've learned that they've exposed virtually everyone's data through their incompetence (thus exposing nearly every adult in the US to a high risk of identity fraud), sold stock to avoid personal financial losses before the news broke, and set up a scam site to trick people into giving up their right to sue. If this isn't criminal, then nothing is. If someone doesn't go to jail over th…

I am still unsure as to how any of the credit bureaus exist legally at all, I never consented to having all my eggs in those three vulnerable baskets. Why is this my problem all of a sudden?

I get that consumer protections in the US are not very strong, but this just seems like a shady cartel in cahoots with the banks/insurance companies. Please tell me I'm grossly misunderstanding something here.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#302
post #269

Earlier quoted context omitted.

> If you where (sic) to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. What makes you think lack of investment in IT & security is the main reason they get hacked? Vice versa, NSA has virtually unlimited (let's just say unlimited means tens of billion dollars) budget invested in IT and security. They have the top resources there too. Do…

Certainly a lack of mental investment. The NSA and these credit agencies are not a comparison, as their jobs are quite different. If nothing else, the NSA has to be connected to public networks to do their covert operations. Not so with a "credit rating agency". They should not be on a public network at all. Before the Internet, they were not, they were on private leased lines.

You missed the point. I am arguing that no amount of investment is big enough to make data breaches go away. Even the top intel agency with top budget and top resources can't avoid breaches, what else would you expect a corporation?

However this is not an excuse for Equifax to not put more focus and investment on their security.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#303
post #105

Earlier quoted context omitted.

The damage is not the cost of getting a new SSN, but the cost of verifying that your info is safe (still safe?). This is why companies routinely list the _cost_ of dealing with hacking incidents (scrub all the servers, pay people overtime, etc). I think it's fair to assign costs similarly for equifax.

Info monitoring is what, like $29.99 a month? Perhaps reasonably ask for 3 years of monitoring, so $980 But those aren't actual costs incurred yet.

That's retail and the pricing seems highly inflated. Does anyone actually buy these services at that price point?

Credit real time monitoring should be an entitlement for those whose data is being collected.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#305

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

"Then the executives sold their stock a day before they announced the hack to the public."

Selling stock the day before the news makes these guys seem like absolute criminals, but (a) it's not what happened and (b) the soundbyte doesn't represent what is likely the case.

The reality:

- Breach happened between March - July 2017

- Breach detected July 29th (A Saturday)

- Executives sold stock August 1 (A Tuesday)

- Breach announced September 9th (5 weeks later)

From the company's own statement, which you can BET was vetted by a lot of attorneys:

"Equifax discovered the unauthorized access on July 29 of this year and acted immediately to stop the intrusion. The company promptly engaged a leading, independent cybersecurity firm that has been conducting a comprehensive forensic review to determine the scope of the intrusion, including the specific data impacted."

I would bet, dollars to donuts, this is just terrible timing optically for the executives.

What is much more likely reality is that they detect breaches on a regular basis, and until the forensic team came back with the bombshell - likely many weeks later - of the scope of the data loss, the executives were not even informed.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#306
post #272

Is it time for a Federal Department of Verifying Whether People Are Who They Say They Are? Veryifying identity with SSN is broken. The right way is probably more or less how big webapps do it - MFA + a password that the user can reset by providing a bunch of info. The government has the necessary private info to do this in most cases (e.g. DL# plus your income from last year's taxes), and can fall back to "Show up at…

Won't work. Once companies start gathering private data stored in this DB, it can be compromised and government isn't that great at securing data either. MFA would required everyone having a smart phone or RSA key fobs. SMS/Phone based authentication isn't secure. Only real way to get true identity system is biometrics(Fingerprints,DNA, or Iris) taken at birth. But that will never happen for privacy reasons.

[deleted]

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#307
post #272

Is it time for a Federal Department of Verifying Whether People Are Who They Say They Are? Veryifying identity with SSN is broken. The right way is probably more or less how big webapps do it - MFA + a password that the user can reset by providing a bunch of info. The government has the necessary private info to do this in most cases (e.g. DL# plus your income from last year's taxes), and can fall back to "Show up at…

Won't work. Once companies start gathering private data stored in this DB, it can be compromised and government isn't that great at securing data either. MFA would required everyone having a smart phone or RSA key fobs. SMS/Phone based authentication isn't secure. Only real way to get true identity system is biometrics(Fingerprints,DNA, or Iris) taken at birth. But that will never happen for privacy reasons.

The whole point would be to move off of shared secrets, so data breached from one company's DB wouldn't be usable to impersonate the victims elsewhere. The idea is to abandon the idea that any data (which ever leaves the consumers's hands) is private or needs to be protected to prevent ID theft.

We have the technology, i.e. certificates, signatures, smart cards, identity federation like SAML.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#308
post #260

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

No amount of governmental regulations can solve the current date breach trends. Even government's own intel agencies got hacked too. No organization is immune to data breaches. It's a matter of time and effort. A lot of us here are engineers and coders. It's our responsibility to design better architecture, security conscious protocols and write securer softwares. And it's up to all of us (regardless which country yo…

Regulation is absolutely capable of reducing the damage done by these types of attacks and incentivizing companies to make the necessary investments. Nothing will ever be 100% secure but that is no reason to just give up on trying. We tried letting the free market do the right thing and it failed, this is the reason the government exists.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#309

Yeah, I would think so. So far, we've learned that they've exposed virtually everyone's data through their incompetence (thus exposing nearly every adult in the US to a high risk of identity fraud), sold stock to avoid personal financial losses before the news broke, and set up a scam site to trick people into giving up their right to sue. If this isn't criminal, then nothing is. If someone doesn't go to jail over th…

>> why the hell shouldn't I just go out and commit fraud on a daily basis myself? Because corporations are protected, individuals are not. This is what happens when business(profit) takes precedence over human rights. There will be no repercussions for those responsible. No changes will be implemented. At best we'll get a public apology, but even that seems far-fetched.

Should a sound approach, then, not be, to incorporate one-self at birth?

What if A Person were to be born into a corporation and all transactions made by thhem be the corporations actions - if things go south, dissolve the company.

(clearly this is simplistic, but you get the idea)

I want to re-form myself into one of these corporations which has little retribution for actions. I shall pledge 10% of SamStave INC LLC to any attorney on the ~~~prowl~~~ case...

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#310
post #286

Earlier quoted context omitted.

Correct me if I'm wrong, but the NSA leaks have all been the result of internal employees leaking outward, rather than outside people reaching inward where they shouldn't. That's a meaningful distinction, IMO. They call for two completely different types of defense.

You assume it's different for Equifax. Hacking humans is quite often the easiest point of entry.

From the Equifax webpage[1]: Criminals exploited a U.S. website application vulnerability to gain access to certain files.

[1]: https://www.equifaxsecurity2017.com/

This is inexcusable in 2017. Hacking humans may be easier but it's up to Equifax to figure out how to mitigate that risk. "It's hard" doesn't excuse their behavior.

Post reply on HN