Live data from Hacker News

No matter what, Equifax may tell you you’ve been impacted by the hack

techcrunch.com

121–130 of 157 posts

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#121
post #67
post #57

In Sweden your social security number is public information. What's the reason for it being private in the US? Sounds like a horrible thing to rely on for security anyway.

In the US, a combination of personal information is taken by most as proof that you are who you claim to be. If you know enough of someone else's information, you can steal money rather easily. We need a better identity solution, but it's what we have right now.

There is probably no way to make that work, without improving the security. Same thing with credit cards, is it so hard to ask for a PIN when trying to pay with them? Or use 2FA like in any internet banking?

For what it's worth, here in Europe you could pretend to be someone else as well, if you have enough information, but what's the point when you can't touch their money?

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#122
post #62
post #57

In Sweden your social security number is public information. What's the reason for it being private in the US? Sounds like a horrible thing to rely on for security anyway.

The banking industry decided to, in effect, use it as an authentication token. Even though it was stated that it should not be used for such.

And then, when their shitty "easy signups" authentication is exploited, they attempt to reframe the flaw as the individual's identity being stolen, rather than the bank being negligent.

Relevant comedy: https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#123
post #57

In Sweden your social security number is public information. What's the reason for it being private in the US? Sounds like a horrible thing to rely on for security anyway.

Well I mean, what it comes down to is you need someway of establing that it's actually you over a phone or Internet and you can assume that an equifax-equivalent would be storing that info regardless of exactly what it is in Sweden.

>Well I mean, what it comes down to is you need someway of establing that it's actually you over a phone or Internet

Why do you need that exactly? If you are selling something, it's quite simple: if you receive the money, you provide the service -- if not, you don't.

The payment processor can use 2FA (this is actually done by a number of banks in Europe, when you enter the payment information, you get a text message with a code from your bank to confirm the transaction).

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#124
post #12

Earlier quoted context omitted.

> Opting out of the waiver is a long winded process of mailing a form. I freaking hate tactics like this, so I am offering to go through the mailing process for anyone who fills out the form at https://unarbitrate.org/ . I'll pay to mail it, just because I hate this sort of thing. If you don't trust me with your data, the site also provides a way to print it and mail it yourself. But whatever it takes, I encourage ev…

Does everyone have an equifax username?

No, I don't have one either. Where do I find it?

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#125
post #57

In Sweden your social security number is public information. What's the reason for it being private in the US? Sounds like a horrible thing to rely on for security anyway.

Well I mean, what it comes down to is you need someway of establing that it's actually you over a phone or Internet and you can assume that an equifax-equivalent would be storing that info regardless of exactly what it is in Sweden.

In Sweden you use a special authentication method you install on your phone through your bank to prove your identity. It's basically a national 2FA. So when you for example declare your taxes you enter your social security number and authenticate the action with your phone each time.

So no, I don't think there's any Equifax equivalent where a data leakage would enable stuff like this.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#126

Earlier quoted context omitted.

Well I mean, what it comes down to is you need someway of establing that it's actually you over a phone or Internet and you can assume that an equifax-equivalent would be storing that info regardless of exactly what it is in Sweden.

>Well I mean, what it comes down to is you need someway of establing that it's actually you over a phone or Internet Why do you need that exactly? If you are selling something, it's quite simple: if you receive the money, you provide the service -- if not, you don't. The payment processor can use 2FA (this is actually done by a number of banks in Europe, when you enter the payment information, you get a text message…

> The payment processor can use 2FA (this is actually done by a number of banks in Europe, when you enter the payment information, you get a text message with a code from your bank to confirm the transaction).

I think 3-D Secure is the protocol they use.

https://en.wikipedia.org/wiki/3-D_Secure

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#127
post #125

Earlier quoted context omitted.

Well I mean, what it comes down to is you need someway of establing that it's actually you over a phone or Internet and you can assume that an equifax-equivalent would be storing that info regardless of exactly what it is in Sweden.

In Sweden you use a special authentication method you install on your phone through your bank to prove your identity. It's basically a national 2FA. So when you for example declare your taxes you enter your social security number and authenticate the action with your phone each time. So no, I don't think there's any Equifax equivalent where a data leakage would enable stuff like this.

How does the bank know it is you or your phone when you open an account?

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#128
post #20

I will be blunt, and I am very incensed by this. My comments ... https://twitter.com/hpcjoe/status/906549917509980160 This is an extinction level event for Equifax. They need to be disassembled, their stored data destroyed correctly and securely, their negligent officers charged. This isn't an accident. You don't surface 0.134 BILLION bits of PII without some sort of criminal level incompetence. Any organization that…

Just directing it at Equifax is much too narrow, though. At the very, very least some legislation should come out of this mandating that ALL credit bureaus should allow credit freezes, at any time, for free. The thing that really incenses me about this whole debacle is the system is designed to benefit from its own incompetence! All these "identity theft solutions" that the big credit bureaus provide are just a way t…

North Carolina already mandates free online security freezes with all credit bureaus. Now if only we can get this passed nationwide...

http://www.ncdoj.gov/freefreeze

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#129
post #19

Earlier quoted context omitted.

Let me know if you'd like a contribution to cover postage for people.

Thanks, I appreciate the support! I'll let you know if it comes to that; so far I have some money set aside and I should be able to keep costs under control by bundling them into one envelope.

It's going to take more than an envelope, if your site gains legs. There is also the expense of printing and shipping. Paper is heavy. You mentioned the idea of delivering them in person, you may wish to get some press and legal council.

Reach out, should you need financial assistance.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#130
post #97

Earlier quoted context omitted.

> If I ever saw an unusual charge on my credit cards, I’d just get it refunded. How much actual harm is going to come out of this? My suspicion is not that much. Fraudulent charges on an existing account is not the concern when someone has your SSN and other high-value information - it's the ability for someone else to open an account in your name that you have no knowledge of.

This is the thing that bites you. Someone opens a store credit card in your name, uses it enough to get the credit limit to a point where they can walk off with enough stuff to make it worthwhile. Guess who gets reported to the debt collectors? Not them, you do. And here is the really sad bit, when you tell the debt collector that its a bogus account and not you, by law they have to stop hassling you but instead of '…

It's also illegal to sell a debt when the owner has knowledge that it is fraudulent.
Post reply on HN