Live data from Hacker News

Equifax security freeze PINs are the timestamp of when you request the freeze

twitter.com

81–90 of 193 posts

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#81
post #74
post #55

Earlier quoted context omitted.

How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?

Every financial institution you deal with gives them your info, and they do it so collectively they all have lower risk on loans. I suspect if this wasn't in place, we'd be paying significantly higher interest rates on loans.

[deleted]

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#82

Anyone else confirmed this? Don't know who Tony is, usually like more sources that a tweet.

I can confirm at least the first 6 digits are MMDDYY based on the date that I saved it into 1password. The last 4 digits seem like could very likely be hhmm.

Edit: Can confirm: The pin is the exact date/time stamp that my freeze was applied. I'm able to tell based on another note saved to 1password. It is within 1 minute :(

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#83
post #12
post #6

Earlier quoted context omitted.

If you have a 1 in 60*24 chance of guessing correctly then after 1000 guesses (potentially against different people) you have a 50 chance of being correct on one.

Could you explain your math here? Is there something you learn about the other digits when you make a wrong guess?

Your chance of being wrong in a guess is 1-1/(60* 24)

Your chance of being wrong in all 1000 guesses, assuming you guess randomly (not ensuring you never make the same guess twice) is (1-1/(60* 24))^1000

That's about .5

This is based on the assumption that you are guessing for a different person each time, so you can't increase your odds by eliminating any guesses you've already made. If you're guessing for the same person every time, you just need to guess half the possibilities. You can confirm this by realizing:

Your chance of being wrong in a guess is 1-1/(60* 24-x) where x is the number of guesses you have already made.

The product of 1-1/(60* 24-x) from x=0 to x=60* 24/2-1 is .5

Edit: hackernews formatting is weird

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#84

This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform. Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other…

And in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. An interesting aside, Mint announced on the 6th of September that they were updating their FICO score service to use TransUnion. They had previously used Equifax. That's either an incredible coincedence or they knew about the breach before anyone else and switched providers.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#85
post #39

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

Real engineers have a system in place for this. It's called "Professional Engineer" and it's managed by NCEES. There is no possible reason that practice cannot directly apply to software engineering, except for the cultural refusal of software engineers to take responsibility for anything.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#86
post #50

Earlier quoted context omitted.

Just try it out for yourself, like others did: https://news.ycombinator.com/item?id=15204573

I'm not using anything that Equifax set up in case it waives any of my rights. This is how bad it's gotten, people are afraid/untrusting of their security/protection measures. Thank you for linking to more accounts of this.

They can't waive your rights. See https://twitter.com/AGSchneiderman/status/906195350532304896

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#87

And the hits just keep on coming... www.equifaxsecurity2017.com uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. Error code: SEC_ERROR_UNKNOWN_ISSUER

This is such an awful domain to use in the first place. It's conditioning users in exactly the wrong way, aside from there being a security warning for some users.

How do you explain to your father/grandfather/whoever that equifaxsecurity2017.com is ok, but equifax-security-breach.com, checkyourequifaxaccount.com, equifaxsecurity-2017.com and equifaxsecurity2018.com are not legit?

Stick to your top level domain. Something like security2017.equifax.com or equifax.com/security2017 would be okay.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#88

True thing: until recently you could remove hard inquiries from your credit report merely by pulling your own credit so often in one month using an array of daily monitoring services that you would overflow the field and bump off legit inquiries. I did this in 2009-10, it had been going on for a while, and lasted for a while but sadly I hear they've solved it seemingly by nightly batch job to remove your own credit p…

How many requests, specifically, did you have to have to overflow the field?

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#89
post #55

Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.

How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?

You don't own your own data, unfortunately. At least not in the US.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#90

True thing: until recently you could remove hard inquiries from your credit report merely by pulling your own credit so often in one month using an array of daily monitoring services that you would overflow the field and bump off legit inquiries. I did this in 2009-10, it had been going on for a while, and lasted for a while but sadly I hear they've solved it seemingly by nightly batch job to remove your own credit p…

Ah, bumping.

The kids on flyertalk were all over this.

Post reply on HN