Earlier quoted context omitted.
Common misconception. They actually do need your approval, it's just that that approval is buried in the mountains of legalese you sign whenever you sign up for a bank account, credit card or loan.
Is it really a choice if it's necessary to participate in our economy? No bank or loan will offer terms that don't involve the use of one of these credit reporting agencies.
Equifax’s Maddening Unaccountability
121–130 of 238 posts
Re: Equifax’s Maddening Unaccountability
#122PII is the nuclear waste of the internet. Incredibly expensive to store safely, and constantly vulnerable to a catastrophe.
And once it leaks, it's damn near impossible to clean up.
Credit agencies were about PII before the internet, but internet companies that collect all this PII toxify the internet.
Re: Equifax’s Maddening Unaccountability
#123There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?
Re: Equifax’s Maddening Unaccountability
#124Re: Equifax’s Maddening Unaccountability
#125Earlier quoted context omitted.
> Struts is maintained by one person. I see nowhere in the op-ed piece where Tufekci mentions Struts or implies that she holds Struts responsible for this. She is clearly laying this at Equifax's feet, and their responsibility in their choice of software and the industry as a whole for actively pushing against better software practices and responsibility. The section you quoted is followed by: > Some number of unexpe…
She's blaming the software industry and software failure. That's Apache, and Struts. If she wanted to lay it on Equifax, she might go into the fact that the Chief Information Security Officer at Equifax holds a masters in music, https://www.hollywoodlanews.com/equifax-chief-security-offic... The people that actually "do" are Chief Peon of Cube Farms, doing whatever the boss with a music degree tells them is priority.…
I interpret her differently:
> There are technical factors that explain why cybersecurity is so weak, but the underlying reason is political, and it’s pretty simple: Big corporations have poured large amounts of money into our political system, helping to create a regulatory environment in which consumers shoulder more and more of the risk, and companies less and less.
> This is a general feature of our lopsided world, but software businesses (and the technology sides of other companies) have acquired perhaps the greatest degree of impunity. Information technology arrived on the scene only recently, so it has faced fewer of the kinds of regulations that consumers and citizens, in more progressive eras, managed to impose on other industries.
To me, that reads as taking corporate interests and business motives to task, not software practices. Software development (like any other work) is a cost, and businesses need to balance those costs against business revenues. I'd argue who's chosen for C-level positions is a business decision, not a software practice one. If the costs of failure in production due to bugs were higher, businesses would make different decisions in hiring and how much time was dedicated to security and bug fixing. Do you disagree? Testing and quality control is expensive. If we can roll out a feature (or just continue business) spending as little as possible on testing and QA, it can certainly be an understandable decision (whether or not you agree) to do as little QA and testing as possible: you're not providing any new features (which may increase revenues): you're just increasing cost.
> It's never the leadership's fault when there's a failure in the US, but they happily take credit when there is success.
It's not clear to me which leadership you're referring to here. The government? The corporate leadership? Someone else? If the corporate leadership, I think that's entirely the point Tufekci is making.
Re: Equifax’s Maddening Unaccountability
#126Earlier quoted context omitted.
Equifax has an $18B market cap. Can you name one instance of a government imposed fine for improperly stored PII exceeding even $100M? Furthermore, do you have evidence that the PII was improperly stored, or that Equifax's security practices were lacking in any way? The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.
I wonder if the legal concept res ipsa loquitur (the thing speaks for itself) could apply here? It's one foundation of tort law. The argument would be that the very fact that PII security was breached demonstrates defendant's negligent data storage/security practices. If those practices had been adequate, the breach would not have occurred.
Re: Equifax’s Maddening Unaccountability
#127Earlier quoted context omitted.
Why would a dealership need to do a credit check if I showed up with a briefcase full of money to buy a car?
Can confirm. I bought a car last week in California with cash. Dealer did a credit check. The system is rotten and (short of moving country) impossible to avoid.
Re: Equifax’s Maddening Unaccountability
#128Earlier quoted context omitted.
I thought about that too but it could also be possible that they may get bankrupted by lawsuits. I don't see Equifax as victim. I hope they will go down and be warning for the rest of the financial industry.
Target lost tens of millions of credit card numbers and paid just over $18 million to settle every lawsuit against them. People seem to conflate the way they think things should be with the way things actually are .
If my SSN and financial history is stolen, someone can impersonate me. They can sign up for bank accounts, loans, credit cards, etc.
Re: Equifax’s Maddening Unaccountability
#129Earlier quoted context omitted.
I thought about that too but it could also be possible that they may get bankrupted by lawsuits. I don't see Equifax as victim. I hope they will go down and be warning for the rest of the financial industry.
Target lost tens of millions of credit card numbers and paid just over $18 million to settle every lawsuit against them. People seem to conflate the way they think things should be with the way things actually are .