Live data from Hacker News

Equifax Faces Multibillion-Dollar Lawsuit Over Hack

bloomberg.com

311–320 of 670 posts

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#311

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

"Then the executives sold their stock a day before they announced the hack to the public." Selling stock the day before the news makes these guys seem like absolute criminals, but (a) it's not what happened and (b) the soundbyte doesn't represent what is likely the case. The reality: - Breach happened between March - July 2017 - Breach detected July 29th (A Saturday) - Executives sold stock August 1 (A Tuesday) - Bre…

The sales were unplanned, meaning they weren't entered per the usual stock sale cycle. If that's not evidence enough of at least insider trading, coupled with your timeline, I don't know what is.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#312
With all the Equifax headlines today, I was wondering if there would be a few poor souls in the the Equifax Tech Department who feels atleast a bit responsible for the whole mess. ( I do understand it is a collective responsibility of the management as well )

edit: Was the analysis of the hack published?

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#313

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

"Then the executives sold their stock a day before they announced the hack to the public." Selling stock the day before the news makes these guys seem like absolute criminals, but (a) it's not what happened and (b) the soundbyte doesn't represent what is likely the case. The reality: - Breach happened between March - July 2017 - Breach detected July 29th (A Saturday) - Executives sold stock August 1 (A Tuesday) - Bre…

July 29 I don't see anything exonerating in the timeline you described. You are making assumptions here that could excuse the executives if they were true. These are nothing but assumptions though.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#314

Yeah, I would think so. So far, we've learned that they've exposed virtually everyone's data through their incompetence (thus exposing nearly every adult in the US to a high risk of identity fraud), sold stock to avoid personal financial losses before the news broke, and set up a scam site to trick people into giving up their right to sue. If this isn't criminal, then nothing is. If someone doesn't go to jail over th…

I am still unsure as to how any of the credit bureaus exist legally at all, I never consented to having all my eggs in those three vulnerable baskets. Why is this my problem all of a sudden? I get that consumer protections in the US are not very strong, but this just seems like a shady cartel in cahoots with the banks/insurance companies. Please tell me I'm grossly misunderstanding something here.

It's a historical fluke. Credit bureaus trace back to agencies that compiled third-party reports on the creditworthiness of business persons. So long as the information collected is accurate (and not defamatory), this type of activity is protected under the first amendment.

See the first segment of this episode of the Backstory podcast for a retelling of how these early agencies worked: http://backstoryradio.org/shows/keeping-tabs-2016/

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#315
post #269

Earlier quoted context omitted.

> If you where (sic) to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. What makes you think lack of investment in IT & security is the main reason they get hacked? Vice versa, NSA has virtually unlimited (let's just say unlimited means tens of billion dollars) budget invested in IT and security. They have the top resources there too. Do…

Certainly a lack of mental investment. The NSA and these credit agencies are not a comparison, as their jobs are quite different. If nothing else, the NSA has to be connected to public networks to do their covert operations. Not so with a "credit rating agency". They should not be on a public network at all. Before the Internet, they were not, they were on private leased lines.

Your argument that credit rating agencies shouldn't be on the internet is really terrible.

People pay credit rating agencies to retrieve their credit reports, get credit scores, and open disputes, and the best way to do all that is online.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#316

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

"Then the executives sold their stock a day before they announced the hack to the public." Selling stock the day before the news makes these guys seem like absolute criminals, but (a) it's not what happened and (b) the soundbyte doesn't represent what is likely the case. The reality: - Breach happened between March - July 2017 - Breach detected July 29th (A Saturday) - Executives sold stock August 1 (A Tuesday) - Bre…

I'm reading a book now call "Liquidated: an Ethnography of Wall Street" by Karen Ho from Princeton. There is this incredible part at the beginning of the book where the Vice Presidents of Goldman Sachs are training the incoming group of Junior Analysts who have all just graduated MBA school, telling them how to treat the executives of the companies they are going to be analyzing.

They make them shout over and over "MANAGEMENT ALWAYS LIES, MANAGEMENT ALWAYS LIES, MANAGEMENT ALWAYS LIES".

That scene took place in the early 90's, and I can't imagine anyone thinks it's gotten better in regards to the ethics of top management, their understanding of technology, or their desire to participate in insider training.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#317

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

"Then the executives sold their stock a day before they announced the hack to the public." Selling stock the day before the news makes these guys seem like absolute criminals, but (a) it's not what happened and (b) the soundbyte doesn't represent what is likely the case. The reality: - Breach happened between March - July 2017 - Breach detected July 29th (A Saturday) - Executives sold stock August 1 (A Tuesday) - Bre…

>What is much more likely reality is that they detect breaches on a regular basis, and until the forensic team came back with the bombshell - likely many weeks later - of the scope of the data loss, the executives were not even informed.

Your hypothesis is predicated on the fact that you trust their timeline, and make assumption that type of events could have occurred within each groups at Equifax on those days..

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#318
This is just pure crazy. There should not be any non-govt agencies that store such sensitive information. This is not like credit card where you end up getting a new card. You can't change your name and ssn. I wonder how we will tackle this problem.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#319
post #269

Earlier quoted context omitted.

> If you where (sic) to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. What makes you think lack of investment in IT & security is the main reason they get hacked? Vice versa, NSA has virtually unlimited (let's just say unlimited means tens of billion dollars) budget invested in IT and security. They have the top resources there too. Do…

Certainly a lack of mental investment. The NSA and these credit agencies are not a comparison, as their jobs are quite different. If nothing else, the NSA has to be connected to public networks to do their covert operations. Not so with a "credit rating agency". They should not be on a public network at all. Before the Internet, they were not, they were on private leased lines.

Yeah, but then they realised they could monetise it by selling your own data back to you with easy, constant, access to it via the web.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#320

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

"Then the executives sold their stock a day before they announced the hack to the public." Selling stock the day before the news makes these guys seem like absolute criminals, but (a) it's not what happened and (b) the soundbyte doesn't represent what is likely the case. The reality: - Breach happened between March - July 2017 - Breach detected July 29th (A Saturday) - Executives sold stock August 1 (A Tuesday) - Bre…

> I would bet, dollars to donuts, this is just terrible timing optically for the executives.

Difficult to prove, but I too suspect it’s just bad timing.

Note that the three executives sold relatively small portions of stock: 13%, 9%, 4% of their respective personal holdings.

Post reply on HN