Live data from Hacker News

Equifax security freeze PINs are the timestamp of when you request the freeze

twitter.com

101–110 of 193 posts

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#101
post #39

Earlier quoted context omitted.

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one? One dude who everyone sorta thought handled security stuff? It's as clear as mud. Security team with people who do it full time. Betting your security on the one dude who sorta did everything should be criminal. Aka, not this: http://i.imgur.com/a7S95nG.jpg

What does professional even mean (from her past)? To me it means useless middle management that accomplishes nothing apart from moving numbers around to make them look good.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#102
post #55

Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.

How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?

The companies on the other side of your transactions.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#103
post #55

Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.

How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?

You do give your consent. Everytime you deal with a financial, or credit issuing institution.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#104
post #39

Earlier quoted context omitted.

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one? One dude who everyone sorta thought handled security stuff? It's as clear as mud. Security team with people who do it full time. Betting your security on the one dude who sorta did everything should be criminal. Aka, not this: http://i.imgur.com/a7S95nG.jpg

What if management doesn't hire a security team? What if management hires incompetent security team?

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#105

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

The sheer scale is incomparable. Comparing a doctor's mistake during a surgery doesn't quite compare to losing the data of 147 million.

"Critical systems" developers would need astronomically expensive insurance to even exist, and therefore prohibitively high salaries.

I personally believe there should be some measure of a corporate death penalty to emphasize the responsibility involved though.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#106

Earlier quoted context omitted.

Someone probably read an article about how RNGs aren't truly random, and so decided timestamp (which never repeats!) was the right alternative.

Of course, two people who happen to request at the same time will get the same key anyway, so it doesn't even solve that problem.

Right, of course not. They're idiots.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#107

This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform. Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other…

And in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. A…

Or Equifax became unresponsive while they investigated, but didn't reveal what was happening. Related, but not via inside info about the hacks.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#108
post #85
post #39

Earlier quoted context omitted.

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

Real engineers have a system in place for this. It's called "Professional Engineer" and it's managed by NCEES. There is no possible reason that practice cannot directly apply to software engineering, except for the cultural refusal of software engineers to take responsibility for anything.

While I agree, how do you apply software engineering practices in a field where a good chunk of the workforce doesn't have formal computer science education?

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#109
post #98
post #43

Earlier quoted context omitted.

This sounds like blockchain could have application. But honestly, other countries do fine without them, IMO they should just be abolished.

A blockchain is public. You want everybody's credit public?

No, blockchains are magic technology that makes money appear out of nowhere and hides all activity from evildoers.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#110
post #39

Earlier quoted context omitted.

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one? One dude who everyone sorta thought handled security stuff? It's as clear as mud. Security team with people who do it full time. Betting your security on the one dude who sorta did everything should be criminal. Aka, not this: http://i.imgur.com/a7S95nG.jpg

>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one?

Here's a quote from Equifax's early release on the breach [0]:

Equifax said that, it had hired a cybersecurity firm to conduct a review to determine the scale of the invasion.

So, to your question, I'm going with "no one", at least internally.

It's beyond belief (well, not really anymore); but, not only do they not have security covered internally (criminal in itself), but they don't even appear to have a regularly engaged cybersecurity firm. They had to go out and hire one post facto.

[0] https://investor.equifax.com/news-and-events/news/2017/09-07...

Post reply on HN