Live data from Hacker News

No matter what, Equifax may tell you you’ve been impacted by the hack

techcrunch.com

131–140 of 157 posts

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#131
post #67

Earlier quoted context omitted.

In the US, a combination of personal information is taken by most as proof that you are who you claim to be. If you know enough of someone else's information, you can steal money rather easily. We need a better identity solution, but it's what we have right now.

There is probably no way to make that work, without improving the security. Same thing with credit cards, is it so hard to ask for a PIN when trying to pay with them? Or use 2FA like in any internet banking? For what it's worth, here in Europe you could pretend to be someone else as well, if you have enough information, but what's the point when you can't touch their money?

What do you mean by, "you can't touch their money"?

You can spoof their identity, to instantly acquire material goods / lines of credit.

And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#132
post #42
post #26

Earlier quoted context omitted.

You don't need to worry. Equifax can say whatever they want in their BS terms, however no judge in their right mind would enforce such language barring you from joining a class action suit. If equifax sent out some sort of compensation check, and you cashed it, that's a different story.

I would not be so certain of the right-mindedness of judges if it were me.

With this many people affected, it'd be political suicide to enforce such a claim - ideally. The ideally bit is because we may just have reached a point where judges no longer have to worry about doing the right thing.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#133
post #114
post #21

Earlier quoted context omitted.

They're not lying, because the act of saying it made it true. A court would no longer permit them that argument because the counterparty would just present that highly public statement. (Maybe there's a tiny chance they could wiggle out of it, but they would have to find a human judge who would let them, and I imagine those are in short supply in a case like this.) See: http://legal-dictionary.thefreedictionary.com/P…

> they would have to find a human judge who would let them, and I imagine those are in short supply in a case like this.) Would it be possible to find any judge who can try this case, since the set of people affected by the breach is basically everyone?

I am not a lawyer, but I have taken a bunch of law classes.

IIRC, the judge doesn't need to recuse themselves of any/all cases where they are impacted, only that they must recuse themselves where they would be unable to be unbiased, or where there would be an appearance of being unbiased.

In the lower courts, when in doubt, that's decided by other judges. At the SCOTUS level, that's decided by the individual judge on an individual level.

So, yes... They will find a judge.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#134
post #116

Does anyone have any information about taking them to court yourself (small claims or otherwise)? This breach has affected me and as a cryptographic software engineer, I am exceptionally upset. I intend to go as far as my funds and personal knowledge will carry me.

I submitted this a few hours ago: https://news.ycombinator.com/item?id=15207727. Basically the steps to file a small claims lawsuit.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#135
post #57

In Sweden your social security number is public information. What's the reason for it being private in the US? Sounds like a horrible thing to rely on for security anyway.

ID == Authentication Error

When I got my first driver's license in Georgia USA, 1986, the license number was my SSN. Every system used it to identify you: banks, doctors...

But things started to get weird. As other have already commented, everyone got confused, and let "Identity" = "Authorization".

Perhaps in a world of paper records, this system would have been ok. But always more transactions from remote locations. Many stores required you to write the last four digits of SSN on checks, or credit card slips, because they had no way of authorizing the transaction with your bank. Large vendors had these little modems that could dial up and talk to your bank, but small shops only had paper.

Anyway, it was in the banks' interest to roll out Point-Of-Sale transaction tech, because USA banking laws committed the bank to pay the vendor.

But fraud increased as the tech got faster. Someone noted that Social Security, by explicit law, cannot be used as ID in any situation that is not directly involving a Social Security pension or insurance.

The banks and medical systems rolled a lot of the shift away from SSN under their huge Y2K projects.

Here we are. Now they all ask for other publicly-available personal information, and still confuse ID with Auth.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#136
post #130

Earlier quoted context omitted.

This is the thing that bites you. Someone opens a store credit card in your name, uses it enough to get the credit limit to a point where they can walk off with enough stuff to make it worthwhile. Guess who gets reported to the debt collectors? Not them, you do. And here is the really sad bit, when you tell the debt collector that its a bogus account and not you, by law they have to stop hassling you but instead of '…

It's also illegal to sell a debt when the owner has knowledge that it is fraudulent.

Yes it is, but that is much harder to prove, and not something I can do in small claims. Nor can I easily get the local AG to do it for me in the area where they operate (I've tried, they just laugh at me)

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#137
post #130

Earlier quoted context omitted.

It's also illegal to sell a debt when the owner has knowledge that it is fraudulent.

Yes it is, but that is much harder to prove, and not something I can do in small claims. Nor can I easily get the local AG to do it for me in the area where they operate (I've tried, they just laugh at me)

Too bad patio11 has a full time job now. Sounds like something he'd have fun with.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#138
post #44
post #37

Earlier quoted context omitted.

I have 5 and 7 yr old girls. To the degree that either exists with respect to the finance industry, they both exist. Neither has credit, obviously, or any interactions with a credit agency. The only people who have their SSNs are the federal government and our health care provider, which has some very strict laws about what they can do with _any_ data they have. Equifax says the 7-yr old "may" have been affected. The…

Sadly, "very strict laws" don't have much ability to prevent data breaches due to zero-days or simple incompetence.

Sure, but they didn't give data to a credit agency. That would require consent, and even if you assume they ignored HIPAA, if they'd done it for one daughter they'd have done it for both.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#139

Earlier quoted context omitted.

There is probably no way to make that work, without improving the security. Same thing with credit cards, is it so hard to ask for a PIN when trying to pay with them? Or use 2FA like in any internet banking? For what it's worth, here in Europe you could pretend to be someone else as well, if you have enough information, but what's the point when you can't touch their money?

What do you mean by, "you can't touch their money"? You can spoof their identity, to instantly acquire material goods / lines of credit. And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.

>What do you mean by, "you can't touch their money"?

If you had the number of my credit card, my account number, my social security number (or the local equivalent), my address or my name, or whatever else, short of my 2FA device and my internet banking credentials, you won't be able to steal anything. (And at that point, you might as well walk up to my house, break a window and steal whatever the hell you need while I'm somewhere else, why bother with hacking.)

If the 2FA device is just a phone, there's a few things you can do, otherwise not really. Are you going to deploy a fake cell tower to steal the code? Probably just conning the cell company support person would be good enough. Not sure whether they'd mail a new SIM to a different address (and they'd probably let me know). Maybe they'd give it to you if you presented an ID. You could have a fake one made, I guess. It would be a bit weird if you didn't speak the local language though. Quite a lot of effort compared to copy pasting a credit card number. Not something you'd do on a large scale.

>And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.

Yes, but against a determined attacker that singles you out, you are fucked regardless of what you do, especially if it's your bank or similar service provider that screws up even if you don't.

Post reply on HN