Whoa... one guy said on Twitter this was the case in 2007!!
9:38 PM - 8 Sep 2017
> Verified PIN format w/ several people who froze today. And I got my PIN in 2007—same exact format. Equifax has been doing this for A DECADE.
61–70 of 193 posts
Whoa... one guy said on Twitter this was the case in 2007!!
9:38 PM - 8 Sep 2017
> Verified PIN format w/ several people who froze today. And I got my PIN in 2007—same exact format. Equifax has been doing this for A DECADE.
OK, what is "Equifax security freeze"?
It also prevents them from selling your credit information to credit card companies (and, I'm sure, insurance agencies and many other businesses). These businesses want a list of people with good credit history to market their wares to.
Essentially, you're "taking yourself off their sales shelf", so they do not want you doing this, and will make it as hard as they legally can.
Also note that you pretty much cannot get a loan while your credit records at these firms are frozen, but it's actually easy to get them un-frozen and then frozen again once you get the loan.
In fact, you should find out which credit agency your bank (car dealer, whatever) uses and then only unfreeze that one.
Earlier quoted context omitted.
Or CEO/CTO's buddy's company
The CSO apparently graduated with a music major. Not that it should it disqualify them, many in tech didn't graduate with a CS degree but in light of the incident one has to wonder.
Earlier quoted context omitted.
I may agree, but Equifax is by no reasonable definition "a critical system".
I don't know what definition of "critical" we're going with, but the fact that they have the SSN of basically every American makes them an important weak point.
Serious question... if there are 3-5 attempt lock out, would this be any less secure than randomly generated number?
It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?
Earlier quoted context omitted.
Developers don't control budgets and deadlines at large companies, management does. So what does this "certified" individual do when he's given a project without resources allocated for proper security auditing? Does he intentionally get fired for refusing the assignment? That works if he has bountiful savings, no mortgage, no kids. Surely no unethical contracting company will pick up the job after he leaves...
How does it work with lawyers or engineers?
Earlier quoted context omitted.
Developers don't control budgets and deadlines at large companies, management does. So what does this "certified" individual do when he's given a project without resources allocated for proper security auditing? Does he intentionally get fired for refusing the assignment? That works if he has bountiful savings, no mortgage, no kids. Surely no unethical contracting company will pick up the job after he leaves...
How does it work with lawyers or engineers?
www.equifaxsecurity2017.com uses an invalid security certificate.
The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported.
Error code: SEC_ERROR_UNKNOWN_ISSUER