Live data from Hacker News

The Equifax Breach Exposes America's Identity Crisis

wired.com

81–90 of 132 posts

Re: The Equifax Breach Exposes America's Identity Crisis

#81
post #60

Earlier quoted context omitted.

> were supposed to be kept secret It's especially laughable because you have to give it to -everybody-. Phone service, cable service, schools, employers, etc etc etc.

In a college class ~20 years ago the professor passed around a sign-in sheet expecting everyone to fill in their names and SSNs. I was astonished, to put it mildly, both at the professor's cluelessness and the willingness of my fellow students to do it.

My university in the 1980s used SSN as student ID number. It wasn't such a big deal then. People had their SSN pre-printed on personal checks.

Identity theft and online fraud didn't really exist at the time.

Re: The Equifax Breach Exposes America's Identity Crisis

#82

I don't know. I found the argument convincing that even naming the breach "identity theft" is beginning to push responsibility away from Equifax and make it seem a personal problem of those affected, or a general societal phenomenon. When in reality it's just Equifax's poor security practices. As you probably know, the exploit basically is using Java's ability to dynamically execute code from JVM bytecodes (supplied…

Before getting too deep in to this, how do we know it had anything to do with injecting bytecode? It's not clear that's what the Struts bug was about.

Re: The Equifax Breach Exposes America's Identity Crisis

#83

I don't know. I found the argument convincing that even naming the breach "identity theft" is beginning to push responsibility away from Equifax and make it seem a personal problem of those affected, or a general societal phenomenon. When in reality it's just Equifax's poor security practices. As you probably know, the exploit basically is using Java's ability to dynamically execute code from JVM bytecodes (supplied…

Ability to execute data as code is present in many languages. Almost all of them these days. I think you are saying that banks should only use C or C++ ??

Programs in C and C++ can still execute data as code with buffer overflows. They're not a panacea either.

Re: The Equifax Breach Exposes America's Identity Crisis

#84

I never realised till now that American's SSNs were supposed to be kept secret. That's absolutely ridiculous. The idea of trying to keep the UK equivalent (National Insurance Number) secret is laughable. How can anything function when an important id number is also supposed to be known by very few people?

Over the years, I am willing to bet that the average US adult over the age of 40 will have given their SSN to hundreds of organisations already... There is no realistic way to guarantee the secrecy of an SSN at this point - Equifax's breach notwithstanding.

For me, the takeway isn't that the supposedly private SSN has been leaked but that it's been leaked with so much other information that, all added together, give bad guys a fantastic haul with which to run amok.

This, combined with the timing of the notification and the dodgy answers coming back from the automated online systems telling you that you "may" have suffered shows a total lack of regard for your data! You are now purely a commodity that corporates can use to their own ends. This is so glaringly obvious now.

Why companies are allowed to hold so much info on us is the issue here: moreso, why are they not held to the highest of standards? Even a simple "each bit of personal data given to the wrong person will result in a $500 fine for the company" would soon add up.

The danger is that these companies (I mean all the credit agencies) push this onto the consumer to "manage". In fact, now that I read this back, it's pretty much a certainty at this point.

Unless someone goes to jail, or Equifax are shut down Arthur Anderson-style, then this will disappear!

Re: The Equifax Breach Exposes America's Identity Crisis

#85

I don't know. I found the argument convincing that even naming the breach "identity theft" is beginning to push responsibility away from Equifax and make it seem a personal problem of those affected, or a general societal phenomenon. When in reality it's just Equifax's poor security practices. As you probably know, the exploit basically is using Java's ability to dynamically execute code from JVM bytecodes (supplied…

Why is the top comment about the JVM? This has nothing to do with the article.

Re: The Equifax Breach Exposes America's Identity Crisis

#86
post #13

Earlier quoted context omitted.

These databases are there essentially to punish you. If you don't pay your utility bill, they report that to the credit agency, and reduces your chances of getting credit elsewhere. These credit information don't give much benefit to Americans, it gives benefits to businesses[1]. It's essentially just a global black list where business can communicate who not to do business with. This business is there for other busi…

> These [ sic ] credit information don't give much benefit to Americans, it gives benefits to businesses Americans own, work at and consume the products of businesses. If there is a class American law generally holds above investors, in terms of protection, it's consumers. I would also argue consumers benefit from our credit rating agency system, shitty as it is--it allows more people to get cheaper credit faster and…

I would suggest that getting credit faster and more easily is not a benefit for consumers but a benefit to business also.

Re: The Equifax Breach Exposes America's Identity Crisis

#87

Earlier quoted context omitted.

In a college class ~20 years ago the professor passed around a sign-in sheet expecting everyone to fill in their names and SSNs. I was astonished, to put it mildly, both at the professor's cluelessness and the willingness of my fellow students to do it.

The article linked at the top of this thread discusses the need for different identifiers in different information contexts (education, health, tax, etc.). Many education institutions 20 years ago used SSNs as a unique identifier for students. On the first day of class, the only way to determine if a body present in a class was actually enrolled was to confirm SSN. Confirming identity in an education context is cruci…

> Many education institutions 20 years ago used SSNs as a unique identifier for students

RIT university was still doing this only ten years ago, at the time I had to send a number of angry emails about publicly available lists of students with their SSNs indexed by Google.

Re: The Equifax Breach Exposes America's Identity Crisis

#88
post #81

Earlier quoted context omitted.

In a college class ~20 years ago the professor passed around a sign-in sheet expecting everyone to fill in their names and SSNs. I was astonished, to put it mildly, both at the professor's cluelessness and the willingness of my fellow students to do it.

My university in the 1980s used SSN as student ID number. It wasn't such a big deal then. People had their SSN pre-printed on personal checks. Identity theft and online fraud didn't really exist at the time.

The Oregon University System moved away from SSNs as identifier in the late 90's. I could punch in my SSN to charge my meal in a dining hall to my account in 98.

Re: The Equifax Breach Exposes America's Identity Crisis

#89
post #50
post #17

Earlier quoted context omitted.

The same holds for bank account numbers which seems just as ridiculous to us Europeans.

Bank account numbers are on cheques. How would anyone keep them secret? By never using cheques?

Anyone can make arbitrary withdrawals or transfers with only the info printed on the check (modulo fraud detection of course). People just don't know or don't think about the total lack of any technical security of their money.

Re: The Equifax Breach Exposes America's Identity Crisis

#90
post #35

I lived in the USA for long enough to get a SSN and a credit rating, but I left some time ago. I've now discovered that my details are in this leak. Does anyone have any advice for how a non-US citizen, not currently living in the USA, can secure their data and ensure that its not being used nefariously? I.e. is there a way to permanently retire a SSN and credit rating, remotely (which doesn't involve dying, lol)?

You can "freeze" your credit with each of the 3 rating agencies (Equifax, Experian, TransUnion) which will prevent anyone (including yourself) from applying for credit using your information.

[deleted]
Post reply on HN