Live data from Hacker News

Equifax security freeze PINs are the timestamp of when you request the freeze

twitter.com

151–160 of 193 posts

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#151

Earlier quoted context omitted.

And in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. A…

What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body. You can't claim neg…

Here're examples of things that could be included in such standards:

* Passwords should be stored only in salted and hashed form

* Code injection attacks shouldn't be possible

* Personal data should be stored in anonymized form with mapping between real and virtual id stored separately

* Only cryptographic algorithms from the approved list might be used (no MD5)

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#152

Earlier quoted context omitted.

What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body. You can't claim neg…

>What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body. Why there're stand…

I agree entirely. It's just a matter of there not being any standards yet. I would hope that eventually we can all agree that even though such standards will never be perfect, and their establishment will be contentious, we need to do it for the overall benefit of society. It will mean licensed software engineers are more expensive to companies, companies will be required to respect those engineers and treat them like competent experts rather than functionaries, and even give the engineers the ability to grind the business to a halt if they point out fundamental engineering problems with the system. Companies will hate that. Some of the practices made standard will seem boring, over-cautious, etc to some engineers and some will not be able to pass whatever tests are put in place and engineers will hate that. The licensing itself will probably end up being a way for some functionary body to enrich itself while providing dubious value as is the case with many of the existing engineering licensing bodies. But, despite all that, the overall social benefits would outweigh the negatives. And failure to accept those negatives will leave us in an even worse position.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#153
post #42

Earlier quoted context omitted.

The CSO apparently graduated with a music major. Not that it should it disqualify them, many in tech didn't graduate with a CS degree but in light of the incident one has to wonder.

I don't think that is relevant at all. There are plenty of incompetent CS graduates, and plenty of highly competent non-CS graduates.

In general it would not be, now that the personal data of 100+ millions of people have been stolen from these clowns, it seems relevant.

Leadership sets the priorities, and expectations. They get paid disproportionately more than other employees and I think they should be scrutinized and bear responsibility correspondingly.

But I have no doubt they probably found someone lower in the ranks as a scapegoat.

"Joe was in charge of patches. And we are all equally disturbed and horrified by his behavior. But we've reached out to him and let him go. Now give us more of your personal information so you can get free credit monitoring for 6 months [+]. -Sincerely and with deeper regrets, the Executive Team [++]"

[+] (fine print) then charged as $49.99 a month until cancelled. To cancel please visit one of the 3 Equifax location in person on the first Wednesday of the month. Accepting

[++] (even finer print) by accepting the free credit monitoring you agree to binding arbitration and forfeit your rights to participate in a class action suit against Equifax and its subsidiaries.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#154

Earlier quoted context omitted.

And in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. A…

What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body. You can't claim neg…

Except that there is precedence for these types of standards and laws in other industries:

PCI [0] is an industry standard which is mandated in order to maintain good standing in the payments industry and HIPAA [1] is US legislation which governs the handling of patient health data.

The issue we face is that there is no equivalent for either of these in relation to handling of PII and identity data.

[0] https://www.pcisecuritystandards.org/

[1] https://www.hhs.gov/hipaa/index.html

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#155

Earlier quoted context omitted.

And in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. A…

What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body. You can't claim neg…

What could be done? Pass a law that you can not store any data about a person without their explicit consent for each type of data. No blanket opt-in, no shady changes to TOS.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#156

Earlier quoted context omitted.

I am 100% certain that "tech" companies have an entirely different attitude towards engineering costs than non-tech companies. The former want the best people working on problems and will pay what it takes (within reason), the latter want problems solved for the lowest price. This is extraordinarily evident in the distribution of engineer salaries.

That's a massive reach! Have you been spending too long inside the bubble? Define a "tech" company.

Which part is a massive reach? The fact that certain companies (which I choose to classify as "tech" companies) are willing to invest 2-3x as much into their technical employees?

A "tech" company is a company for whom technology (ie. developers) is a profit center rather than a cost center.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#157
post #153

Earlier quoted context omitted.

I don't think that is relevant at all. There are plenty of incompetent CS graduates, and plenty of highly competent non-CS graduates.

In general it would not be, now that the personal data of 100+ millions of people have been stolen from these clowns, it seems relevant. Leadership sets the priorities, and expectations. They get paid disproportionately more than other employees and I think they should be scrutinized and bear responsibility correspondingly. But I have no doubt they probably found someone lower in the ranks as a scapegoat. "Joe was in…

I'm not saying we shouldn't have serious questions about his competence after this breach. Rather, my point is that we should be questioning his competence (and that of the rest of the executive team's) due to this breach, not his credentials.

If he had a CS degree, that wouldn't make him any less responsible for this massive data leak.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#158
post #87

And the hits just keep on coming... www.equifaxsecurity2017.com uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. Error code: SEC_ERROR_UNKNOWN_ISSUER

This is such an awful domain to use in the first place. It's conditioning users in exactly the wrong way, aside from there being a security warning for some users. How do you explain to your father/grandfather/whoever that equifaxsecurity2017.com is ok, but equifax-security-breach.com, checkyourequifaxaccount.com, equifaxsecurity-2017.com and equifaxsecurity2018.com are not legit? Stick to your top level domain. Some…

This is how every class action lawsuits do their websites too and it blows my mind! It looks so sketchy.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#159
post #87

Earlier quoted context omitted.

This is such an awful domain to use in the first place. It's conditioning users in exactly the wrong way, aside from there being a security warning for some users. How do you explain to your father/grandfather/whoever that equifaxsecurity2017.com is ok, but equifax-security-breach.com, checkyourequifaxaccount.com, equifaxsecurity-2017.com and equifaxsecurity2018.com are not legit? Stick to your top level domain. Some…

This is how every class action lawsuits do their websites too and it blows my mind! It looks so sketchy.

Bear in mind that in general, those class action settlement websites are run by the lawyers behind the class action, not by the company that was sued and has agreed to settle.

It is in the best interests of the settling company to keep distance between those sites and their primary domain.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#160
post #68
post #57

Earlier quoted context omitted.

How does it work with lawyers or engineers?

As licensed professionals, they work under the knowledge that there are practices and outcomes that can cause them to lose their licenses.

Once again, may be it is time for such a thing to exist for software engineers who aren't web devs.
Post reply on HN