Live data from Hacker News

Equifax Faces Multibillion-Dollar Lawsuit Over Hack

bloomberg.com

351–360 of 670 posts

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#351
post #260

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

No amount of governmental regulations can solve the current date breach trends. Even government's own intel agencies got hacked too. No organization is immune to data breaches. It's a matter of time and effort. A lot of us here are engineers and coders. It's our responsibility to design better architecture, security conscious protocols and write securer softwares. And it's up to all of us (regardless which country yo…

> No amount of governmental regulations can solve the current date breach trends.

I think there's a few things that could be done:

1. Invalidate all SSN numbers.

2. Force people to get a new ID card; make it like the smart-card passport card (or make people get such a card). That becomes your ID and number.

3. Getting that card requires you to be present physically for fingerprinting. Put the fingerprint data on the card, and no where else.

4. Make regulations that only allow for loans to be done in person - no more mailings, nothing online - if you want credit, you have to show up in person.

5. To prove who you are: Fingerprint, your card (with picture - and fingerprint data on the card), plus your pin number. Essentially chip and pin identification, with a fingerprint scan (and maybe a face scan too).

6. Make it so if you want to do online transactions - or any transaction for that matter - you must provide all of this. Basically, at home, a card reader that can read the chip, allow you to enter the pin, scan your fingerprint and face, and if all of that matches what's on the card, then an "acknowledgement" is sent.

Essentially the above would implement a 3-factor auth. I am not saying the above is perfect (I am absolutely certain I have screwed something up there - but the basic idea is what I am trying to convey), but we essentially have to do a clean break away from all current ID and credit/loan/payment systems - and move to a system that introduces a TON of friction.

Physical Presence (Something you are)

Physical Token (Something you have)

PIN (Something you know)

And all the data about "who you are" (face scan, fingerprint) stored on the card (hashed of course) only, no where else. Basically - the card, your presence, and your knowledge all have to be present, and the card's processor authenticates you.

And these factors need to be presented each and every time you do a transaction of any sort involving money or identification.

And no online or by-mail signup for credit. That should be done in physical form only.

Finally - allow for at-will changes of the PIN, and yearly a forced change of the PIN.

The problem with the above, though, is many-fold. It would be extremely costly - for everyone. It is also (seems in a way) draconian. But something of the above nature would need to be done, post haste, if we wanted this to go away.

And basically not allow any kind of storage of credit information or whatnot by -any- entity (and I am not sure how that would even work or if it could). Maybe all they have is a hash value and your name, and the card can generate that hash value as "authentication"/"identity" - but you have to have everything there (you, card, pin), and only the card holds the information, and only generates a hash.

I dunno - but again, this is the idea. I'll leave the details to people smarter than I on these things.

I don't expect something like this to be ever implemented, though. One would think this breach would do it, but it won't.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#352

With all the Equifax headlines today, I was wondering if there would be a few poor souls in the the Equifax Tech Department who feels atleast a bit responsible for the whole mess. ( I do understand it is a collective responsibility of the management as well ) edit: Was the analysis of the hack published?

The most frustrating place to be in these scenarios is the IT (especially security) department.

Go ask any security guy if they think their environment is secure. Very few of us will say yes. It frequently boils down to we ask for things, and there are budget/manpower/time limitations in getting them implemented.

So a breach occurs, execs say to IT staff "Why was this possible."

IT staff says "We requested back in to fix this, and its working through the slow process"

Execs say "Why didn't you scream louder, identifying it as a critical issue"

IT: "There are 1000's of other issues, just like this one. The attackers just managed to exploit this one, instead of one of the others. We can't identify all issues as critical, because then nothing is critical."

Both parties stay frustrated thinking the other isn't doing their job right.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#353

Earlier quoted context omitted.

Attorneys' fees in a class action have to be approved by the court, and for large class actions the percentage fee tends to be lower than what a privately-retained lawyer would receive. The privately-retained lawyers in NTP's lawsuit against Blackberry got an approximately 1/3 payout of a $600 million settlement. 20-33% is quite typical in a pure contingency situation. Most court-approved fee awards in class actions…

Is it weird to also observe that the opposition in a billion dollar case will be significantly more expensive to overcome than in a million dollar case? It seems obvious to me that billion-dollar cases would be more expensive to pursue.

Definitely. E.g. for a $1 million case, the defense likely won't even hire an expert. For a $1 billion case, you'll be responding to thousands of pages of expert reports prepared by half a dozen PhDs in various specialties (and deposing them, fighting over the admissibility of their opinions and the reliability of their methods, etc.). Not to mention that you'll get buried in discovery, etc.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#354
post #340

Ok, so credit reporting agency collects sensitive personal and financial data on basically every adult American, loses it to a bunch of criminals and now I have to deal with the consequences? I looked into credit freezes yesterday. This is really a total scam. You have to _call_ each of the three agencies and pay a fee ($5 to $10) each time. If you need to unfreeze your report to make a legitimate credit application…

hmm i called the 3 mentioned here today and all were free. https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq... Equifax — 1-800-349-9960 Experian — 1‑888‑397‑3742 TransUnion — 1-888-909-8872

What state do you live in? Credit freeze rules vary from state to state.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#355

With all the Equifax headlines today, I was wondering if there would be a few poor souls in the the Equifax Tech Department who feels atleast a bit responsible for the whole mess. ( I do understand it is a collective responsibility of the management as well ) edit: Was the analysis of the hack published?

The H1B's are not going to sacrifice their chance at citizenship nor should they.

Why is H1B relevant here?

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#356
post #340

Ok, so credit reporting agency collects sensitive personal and financial data on basically every adult American, loses it to a bunch of criminals and now I have to deal with the consequences? I looked into credit freezes yesterday. This is really a total scam. You have to _call_ each of the three agencies and pay a fee ($5 to $10) each time. If you need to unfreeze your report to make a legitimate credit application…

hmm i called the 3 mentioned here today and all were free. https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq... Equifax — 1-800-349-9960 Experian — 1‑888‑397‑3742 TransUnion — 1-888-909-8872

I believe it depends on your state. I'm in California and I had to pay $10 for freezing on Experian and TransUnion, although it was free for Equifax.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#357

Yeah, I would think so. So far, we've learned that they've exposed virtually everyone's data through their incompetence (thus exposing nearly every adult in the US to a high risk of identity fraud), sold stock to avoid personal financial losses before the news broke, and set up a scam site to trick people into giving up their right to sue. If this isn't criminal, then nothing is. If someone doesn't go to jail over th…

I am still unsure as to how any of the credit bureaus exist legally at all, I never consented to having all my eggs in those three vulnerable baskets. Why is this my problem all of a sudden? I get that consumer protections in the US are not very strong, but this just seems like a shady cartel in cahoots with the banks/insurance companies. Please tell me I'm grossly misunderstanding something here.

> I never consented to having all my eggs in those three vulnerable baskets

Your information does not just magically make it into the database of a credit bureau. It gets there via public record or because you allowed a creditor to report it to them. You are more than welcome to find a creditor that does not ask for or report to credit bureaus.

Not trying to justify the existence of credit bureaus but let's not kid ourselves. They aren't sending spies to your house or tapping your phone lines to get this info. You personally authorize a large amount of it.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#358
post #17

I'd love to see the $70B number pan out (though $500 per person is less than the damages, I think) -- Equifax is a $17B company, and would presumably stop existing if that happened. On the other hand, these things always settle out of court, and Equifax certainly won't settle the suit for more than they're worth. I said it elsewhere, but I think the right response is to opt out of the class, and sue for $1000 in smal…

I love your idea. I would be game if something is happening in that direction.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#359
post #340

Ok, so credit reporting agency collects sensitive personal and financial data on basically every adult American, loses it to a bunch of criminals and now I have to deal with the consequences? I looked into credit freezes yesterday. This is really a total scam. You have to _call_ each of the three agencies and pay a fee ($5 to $10) each time. If you need to unfreeze your report to make a legitimate credit application…

>So why can't I have a mobile app (or three) for free

Yes, and I think it's a bigger question of why we have so little control over or access to our own data in the first place? It's a racket that they monetize our data by selling it to others, then charge us again to access and protect it. And, if you've ever had to go through the pain of having something corrected in a timely fashion, then you know it's doubly-maddening. They are purposely opaque and byzantine.

Yet, without our data, they'd have no business.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#360

From a security standpoint, it seems like there's a problem treating everyone's social security number as if it's some kind of secret key. Has there been any real discussion about alternatives to the present system? How else could authentication work for opening a bank account? I imagine that the present system survives (1) because of inertia, and (2) because it doesn't require much infrastructure and so it's relativ…

Soc sec. number is used as an immutable unique identifier for Americans since that's really the only piece of information that can be used in such a way. I'm not aware of anybody relying on it as a sole means of authentication... if it's used for authentication it's always combined with additional information such as "you had a revolving credit account with: a, b, c, or d".
Post reply on HN