Live data from Hacker News

Equifax’s Maddening Unaccountability

nytimes.com

141–150 of 238 posts

Re: Equifax’s Maddening Unaccountability

#141

Earlier quoted context omitted.

Why would a dealership need to do a credit check if I showed up with a briefcase full of money to buy a car?

Can confirm. I bought a car last week in California with cash. Dealer did a credit check. The system is rotten and (short of moving country) impossible to avoid.

FYI dealers do this because they want to be able to offer you financing if your check bounces. It's also a way to ensure that you go through with the transaction because now your credit is worse and going somewhere else would lead to worse financing. Put a freeze on your accounts with the credit bureaus before you get serious about buying a car with cash. Tell them that they may not do a "hard pull" against your credit. If they try, complain to the appropriate government officials (not sure who this would be, some consumer protection agency) and take your cash elsewhere. It's a scam to lock you in to buying from them. I brought my own financing to a dealership and they wanted me to sign a thing which among other things authorized a credit check. I crossed that part out and signed it. This caused some back and forth with someone who was not in the room (basically my salesman had to go "get it approved") but they really wanted the sale because I drove a rental car down from 6 hours away just to buy this specific car (I had set the sale up ahead of time over email). I was very close to walking out and they probably knew it, and figured that they'd rather make the sale vs trying to sell me on their financing vs mine (I happened to get an extremely low rate from a credit union).

Re: Equifax’s Maddening Unaccountability

#142
post #75
post #58

Earlier quoted context omitted.

Since when does Uber ask for use of your camera or access to photos? And for what?

You can take a picture of your payment card instead of typing the digits in.

It should ask for permission if you try to do that, not when you install the app.

Re: Equifax’s Maddening Unaccountability

#143

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

> How can they not be liable? How is this not negligence?

The elements of negligence are:

1. Duty

2. Breach of Duty

3. Cause in Fact

4. Proximate Cause

5. Damages

You probably haven't suffered legally cognizable damages (yet). If and when you do, they might well be liable.

Re: Equifax’s Maddening Unaccountability

#144

Earlier quoted context omitted.

Yes, but you really have zero choice. Unless you decide that you can live without a cell phone, rental car, credit card, mortgage or bank account the rest of your life.

You can do only burner prepaid sims that don't require a name/personal info (which is a bit difficult to find) but your general point is still very valid. You cannot escape the data collection systems in our society without going all Henry David Thoreau.

> You cannot escape the data collection systems in our society without going all Henry David Thoreau.

Or living suspiciously like a drug dealer (without money laundering).

Re: Equifax’s Maddening Unaccountability

#146
post #75

Earlier quoted context omitted.

You can take a picture of your payment card instead of typing the digits in.

It should ask for permission if you try to do that, not when you install the app.

It might be an android thing. In iOS you can ask when you need it, and still use the app if you say no. I've gotten the impression that Android asks everything up front at installation time and doesn't install if you say no, but I'm not an android user/dev so I don't know for sure.

Re: Equifax’s Maddening Unaccountability

#147

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

Part of it is that even the name of the crime Identity Theft insidiously paints it as something purely between the thief and the end consumer, whose identity was "stolen". Alice stole Bill's identity! But where is the company she stole it from? Where is the bank where she fraudulently used this information? These corporations' lack of accountability is built directly into the name we use for the crime! It's as if they are bystanders, peripheral to the crime.

We need to bury this nebulous "Identity Theft" and call out more clearly the two specific crimes that happened: 1. negligence (the entity that gave up the info) and 2. bank fraud. When you use these terms, the companies don't get a free pass. Just change the words and they're part of the mess.

Re: Equifax’s Maddening Unaccountability

#148

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

> How can they not be liable? How is this not negligence? The elements of negligence are: 1. Duty 2. Breach of Duty 3. Cause in Fact 4. Proximate Cause 5. Damages You probably haven't suffered legally cognizable damages (yet). If and when you do, they might well be liable.

I'm not a lawyer, but I think it's pretty crappy that you have to show damages in order to nail someone for negligence. Shouldn't it be enough that they engaged in risky behavior? If I go out on the road and drive in a risky manner, I can end up guilty of all sorts of things without hurting anyone or damaging any property. But give up personally identifiable information (which we know leads to bank fraud) and somehow it's "show damages or GTFO".

Re: Equifax’s Maddening Unaccountability

#149

Earlier quoted context omitted.

Can confirm. I bought a car last week in California with cash. Dealer did a credit check. The system is rotten and (short of moving country) impossible to avoid.

FYI dealers do this because they want to be able to offer you financing if your check bounces. It's also a way to ensure that you go through with the transaction because now your credit is worse and going somewhere else would lead to worse financing. Put a freeze on your accounts with the credit bureaus before you get serious about buying a car with cash. Tell them that they may not do a "hard pull" against your cred…

> It's also a way to ensure that you go through with the transaction because now your credit is worse and going somewhere else would lead to worse financing.

There is no need to spread misinformation. While it is true that a hard inquiry will have a minor effect on your credit score (less than a 5 point hit), multiple hard credit inquiries from car dealerships or mortgage lenders within a period of 45 days only count as a single inquiry.

You're not at all disadvantaged by taking your business elsewhere, you're just making things up to furnish your dubious story.

Re: Equifax’s Maddening Unaccountability

#150
post #125
post #120

Earlier quoted context omitted.

She's blaming the software industry and software failure. That's Apache, and Struts. If she wanted to lay it on Equifax, she might go into the fact that the Chief Information Security Officer at Equifax holds a masters in music, https://www.hollywoodlanews.com/equifax-chief-security-offic... The people that actually "do" are Chief Peon of Cube Farms, doing whatever the boss with a music degree tells them is priority.…

> She's blaming the software industry and software failure. That's Apache, and Struts. I interpret her differently: > There are technical factors that explain why cybersecurity is so weak, but the underlying reason is political, and it’s pretty simple: Big corporations have poured large amounts of money into our political system, helping to create a regulatory environment in which consumers shoulder more and more of…

>software businesses (and the technology sides of other companies) have acquired perhaps the greatest degree of impunity.

TIL: No warranty == impunity.

Nobody MADE Equifax use Struts. The source is open to inspection. The bug existed there for 8 years. Let's see how many audits Equifax did on the source code with no warranty.

>If the costs of failure in production due to bugs were higher, businesses would make different decisions in hiring and how much time was dedicated to security and bug fixing. Do you disagree?

If the costs were higher, the one poor guy working on Struts would do a better job? No, I think that guy would probably not write the software. He'd find a different line of work. If he did write it, he would never release it for the world to use for free. Who would do that? "Here's this thing I worked on for over a decade. You can use it for free. Please sue me if you have any issues. Thanks."

Post reply on HN