Live data from Hacker News

Equifax security freeze PINs are the timestamp of when you request the freeze

twitter.com

71–80 of 193 posts

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#71

True thing: until recently you could remove hard inquiries from your credit report merely by pulling your own credit so often in one month using an array of daily monitoring services that you would overflow the field and bump off legit inquiries. I did this in 2009-10, it had been going on for a while, and lasted for a while but sadly I hear they've solved it seemingly by nightly batch job to remove your own credit p…

I recently turned down a job offer at Experian; it (at least their San Diego office) was a shitshow.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#72
post #65
post #8

Serious question... if there are 3-5 attempt lock out, would this be any less secure than randomly generated number?

Very much so. If you can guess when someone froze their stuff to within a day, for example, then 5 tries gives you a 1 in 288 chance of getting in. A proper random number would be more like 1 in a trillion trillion trillion trillion trillion trillion trillion trillion.

But then you also have to guess their ssn and last name on top of guessing the correct day in order for it to be 1 in 288 chance, no?

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#74
post #55

Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.

How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?

Every financial institution you deal with gives them your info, and they do it so collectively they all have lower risk on loans. I suspect if this wasn't in place, we'd be paying significantly higher interest rates on loans.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#75

Earlier quoted context omitted.

>purge their PII from a credit authority I can't see that happening if they do any kind of offsite back up and archiving. They will purge you from the current master, say they purged you, and you'll be none-the-wiser.

I wish someone would go Mr Robot and corrupt their offsite tape backups with the HVAC system.

This is a unix system! I know this!

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#76
post #72
post #65

Earlier quoted context omitted.

Very much so. If you can guess when someone froze their stuff to within a day, for example, then 5 tries gives you a 1 in 288 chance of getting in. A proper random number would be more like 1 in a trillion trillion trillion trillion trillion trillion trillion trillion.

But then you also have to guess their ssn and last name on top of guessing the correct day in order for it to be 1 in 288 chance, no?

Or look it up in the breached info.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#78

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

Maybe it is, but that's also just a way of trying to push the costs onto the low-level employees. the attitudinal problem here is with the senior management and shareholders, who are the actual responsible parties. If they really cared they'd have established such a certification or announced an intention to adhere to some existing standard.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#79

And the hits just keep on coming... www.equifaxsecurity2017.com uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. Error code: SEC_ERROR_UNKNOWN_ISSUER

The cert is signed by GeoTrust and works perfectly fine on my Chrome on Windows 10.

[Edit: Ah, the chain is incomplete, see https://www.ssllabs.com/ssltest/analyze.html?d=www.equifaxse...]

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#80

And the hits just keep on coming... www.equifaxsecurity2017.com uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. Error code: SEC_ERROR_UNKNOWN_ISSUER

I was surprised they didn't even use a link on their main equifax domain, but set up a new one that could just as well been any phisher.
Post reply on HN