Live data from Hacker News

Equifax security freeze PINs are the timestamp of when you request the freeze

twitter.com

141–150 of 193 posts

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#141
post #89
post #55

Earlier quoted context omitted.

How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?

You don't own your own data, unfortunately. At least not in the US.

I mean...you consent when you hand your details over to a financial institution. How credit reporting agencies end up with your information is very straight-forward. Save the alarmist rhetoric for the headlines.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#142

This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform. Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other…

And in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. A…

What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body.

You can't claim negligence of following industry standard practices when there ARE no industry standard practices. The closest we have in the software field is the work done by NASA on creating legitimately safe code. But companies don't want to follow those sorts of guidelines because they make software development slow and expensive. Sure software development is the primary driver of their businesses existence no matter what industry they are in, but they feel entitled to it being cheap and fast.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#143
post #103
post #55

Earlier quoted context omitted.

How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?

You do give your consent. Everytime you deal with a financial, or credit issuing institution.

Of course, effectively, you don't have a choice - you need those financial institutions to live a normal life. Equifax (and other bureaus) are coercive monopolies.

I hope that this story will bring down the hammer on their heads - not just Equifax, all of them.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#144
post #101

Earlier quoted context omitted.

>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one? One dude who everyone sorta thought handled security stuff? It's as clear as mud. Security team with people who do it full time. Betting your security on the one dude who sorta did everything should be criminal. Aka, not this: http://i.imgur.com/a7S95nG.jpg

What does professional even mean (from her past)? To me it means useless middle management that accomplishes nothing apart from moving numbers around to make them look good.

I always thought "professional" as the sole job description (i.e. not "professional X") was used as an euphemism for "prostitute", so I'm wondering why someone would put it on their resume like that. Did I just learn the word in the wrong context?

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#145

Earlier quoted context omitted.

And in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. A…

What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body. You can't claim neg…

>What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body.

Why there're standards for cars, but no standards for computer systems? I think it's possible to create them. If there're standards, it's easy to define malpractice.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#146
post #123

Earlier quoted context omitted.

>purge their PII from a credit authority I can't see that happening if they do any kind of offsite back up and archiving. They will purge you from the current master, say they purged you, and you'll be none-the-wiser.

The best solution for this would be to enable similar data protection laws like the ones that will become active in 2018 in the EU. A breach of this law would cost a company 2-4% of their revenue as a fine. Seeing how these big companies operate there would be a lot of breaches.

>The best solution for this would be to enable similar data protection laws like the ones that will become active in 2018 in the EU.

I like GDPR, but a lot of people claim it to be too draconian. We'll see how it works out in EU.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#147

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

We certainly can have such a thing, and exactly that has been discussed for well over a decade (probably much longer, but I'm only so old) in the ACM, among other organizations. It's a difficult issue. Creating a set of standards and a certification process has a lot of pitfalls. Failing to create such a process has a lot of pitfalls. Knowingly choosing to step into one set of pitfalls over another is never a comfortable choice and people are generally very bad at it until something really, really bad happens that gives a large number of people enough irrational fear of one option to push them toward the other (and they will rabidly and aggressively oppose any discussion of acknowledging or compensating for the pitfalls they're moving toward in that case - they feel entitled to a 'clean' option and they will demand you pretend the option they're going for is that).

Rather than compare it to doctors, lawyers, etc, I would compare it to structural and civil engineers. Those are the sorts of regulations we require. If a CEO of a construction company ignores warnings given by one of his structural engineers while building a bridge, that CEO is held responsible for criminal negligence and he is put in a prison for a long time. The same needs to happen for technology company management who cut the development timeline, deprive developers of adequate tools and work environment, and who hire inexperienced development staff simply because they're cheap.

Would you like to drive across a bridge if you knew the company operated the way tech companies operate? Viewing their engineers as a cost center to be reduced, as little more than spoiled typists whose technical concerns are always viewed as unimportant in the face of business goals, crammed into office spaces proven by over 1000 studies to damage productivity, and constantly pressured to rush through everything in defiance of basic biological fact that human beings are not capable of extended periods of mental exertion especially in the face of constant interruption? Would it make you more or less confident in that bridge if there were court precedent for companies resulting in peoples deaths being let off without punishment with such practices? That's the situation we're in.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#148
post #39

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

Structural engineers have to deal with these sorts of issues. They do not build a bridge and say "this bridge is safe." They build it and say "this bridge will function within X, Y, and Z parameters for A number of years if maintained in this way" and similar things. They're dealing with a system which is known to not be totally invulnerable. They do it through comprehensive testing, scientific methods, and, above all, through trusting those technical concerns to the total exclusion of business goals. If it is 90% cheaper to use a weaker concrete, they do not substitute it in and cross their fingers. And if the CEO goes behind their back and does the substitution, or he refuses to provide them with the expensive physical simulation software necessary to do their job, or he ignores safety concerns raised by his engineers, that CEO goes to prison and the company is usually destroyed. This is starkly different from technology companies where suggesting such practices is basically asking them to completely restructure their entire organization fundamentally.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#149
post #85

Earlier quoted context omitted.

Real engineers have a system in place for this. It's called "Professional Engineer" and it's managed by NCEES. There is no possible reason that practice cannot directly apply to software engineering, except for the cultural refusal of software engineers to take responsibility for anything.

I think one of the problems is that it's just not societally necessary for 95% of software. If a game is shitty or an order entry system crashes occasionally, nobody dies. Nobody really even cares. Normal social and market mechanisms mean most software at least approaches adequacy. In at least some of the areas where we really care about software quality (e.g., banking, medical devices) there are existing regulators…

That would be acceptable if we were talking about buildings, a blue collar job. But if you try to apply it to a white collar executive you're going to run into social resistance of a great magnitude. White collar crime is a social norm and only very rarely even lightly punished. It is, to a degree, expected. White collar crime kills more people and does much more economic damage every year compared to street crime, but our society has established as a norm treating street crime harshly while turning a blind eye to white collar crime. If the builders company gave the builder substandard materials to build with and refused to supply him with the tools needed or the time needed, few will get behind the idea of executing the executive who got his shareholders a 0.1% bump in profitability that quarter through those cuts, no matter who it killed.

Just look at Toyotas "unintended acceleration" case. If their firmware engineers had access to static analysis tools (a few grand for a license), the bug would have been pointed out to them immediately. Instead, Toyota hired inexperienced engineers, deprived them of appropriate tooling, and pushed the cars out to the marketplace where they killed people. The result? Toyota was cleared of any wrongdoing. They're computers. They're too complicated. No one can know how they work.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#150

True thing: until recently you could remove hard inquiries from your credit report merely by pulling your own credit so often in one month using an array of daily monitoring services that you would overflow the field and bump off legit inquiries. I did this in 2009-10, it had been going on for a while, and lasted for a while but sadly I hear they've solved it seemingly by nightly batch job to remove your own credit p…

I recently turned down a job offer at Experian; it (at least their San Diego office) was a shitshow.

I used to work for Experian. When I left, they paid me an extra month's wages before their payroll caught up to the fact that I was gone, then had to ask for it back. (I paid them back, FWIW.) If you can't run your own payroll, why should you be trusted with a credit bureau?
Post reply on HN