Live data from Hacker News

Equifax’s Maddening Unaccountability

nytimes.com

161–170 of 238 posts

Re: Equifax’s Maddening Unaccountability

#161

Maybe this will finally be the "Three Mile Island Incident of Data" that Maciej Cegłowski talks about? If not, I don't know what will. http://idlewords.com/talks/haunted_by_data.htm

The 3-mile island of data leaks will happen when the ISP DNS lookups and browser history logs get matched up with the credit data and all the other datasets that are floating around.

Re: Equifax’s Maddening Unaccountability

#162
post #91

Earlier quoted context omitted.

Why would a dealership need to do a credit check if I showed up with a briefcase full of money to buy a car?

Because the patriot act. https://www.edmunds.com/car-buying/car-dealership-credit-rep... I was also very surprised to buy a car with cash, only to have a credit check required. It's a real thing. And according to this article, not required, but dealerships are confused by the language of the law and insist on running a credit check, anyway.

The link you posted shows the exact opposite of what you say. The Patriot Act doesn't mandate a credit check when purchasing a car.

Re: Equifax’s Maddening Unaccountability

#163

Earlier quoted context omitted.

I'm eagerly awaiting the technical details of the attack. If it turns out that their web server has 100% unfettered access to the database then I'll gladly pick up a pitchfork as well. I'm wondering if Equifax is using Struts-provided REST for its entire architecture. If that's the case, gaining access to the web server was only the first step. From there the attacker could perform RCE on sensitive services.

If it turns out that their web server has 100% unfettered access to the database then I'll gladly pick up a pitchfork as well. You may want to think twice. Try to design an architecture that doesn't have that. If you think it through, you'll realize the best you can do is not to deny access, but to monitor access so that any statistical deviation in requests-per-hour will trigger an alarm. Yet nobody does that, so wh…

I broadly agree with you, but disagree with your claim that Equifax has no duty to innovate in security. They have one of the biggest databases of PII in private industry. I believe that bestows on them the duty to keep it safe.

Re: Equifax’s Maddening Unaccountability

#164

Earlier quoted context omitted.

I still hold that this shouldn't matter to consumers. My priority of problems is * When fraud happens, banks can pass the pain and burden of proof onto consumers. * Banks use insecure SSNs for authorization; some data is used for validating eligibility, authenticating the application, and authorizing the loan. * There are minimal regulations on storing different classes of personal information (We need sarbanes-oxley…

I heard in US if somebody knows your SSN, he can take a loan accounted to you by phone. It is so strange. What gives banks right to do that?

There is a huge difference between taking a loan "on someone's behalf" (as their representative, eg by someone with power-of-attorney) versus via impersonating them. The former is rare but legitimate; the latter is fraud.

Re: Equifax’s Maddening Unaccountability

#165
"Most software failures and data breaches aren’t inevitable; they are a result of neglect and underinvestment in product reliability and security."

How do we know that Equifax fell into this category? That this was due to negligence? I see a lot of disdain towards Equifax but yet the breach details have not been out yet.

Re: Equifax’s Maddening Unaccountability

#166

Equifax played a slightly different version if this commercial during Monday Night Football a few times, it takes no accountability, but also doubles-down, claims your info might* be on the dark-web(*because they just negligently released it), and offers a "dark-web-scan" service to help find it... https://www.youtube.com/watch?v=vjrydnr_pvQ

So convenient to offer the problem AND the solution.

Re: Equifax’s Maddening Unaccountability

#167

Earlier quoted context omitted.

I heard in US if somebody knows your SSN, he can take a loan accounted to you by phone. It is so strange. What gives banks right to do that?

There is a huge difference between taking a loan "on someone's behalf" (as their representative, eg by someone with power-of-attorney) versus via impersonating them. The former is rare but legitimate; the latter is fraud.

I mean the latter. Changed "a loan on you behalf" to "a loan accouted to you"

Re: Equifax’s Maddening Unaccountability

#168

Equifax played a slightly different version if this commercial during Monday Night Football a few times, it takes no accountability, but also doubles-down, claims your info might* be on the dark-web(*because they just negligently released it), and offers a "dark-web-scan" service to help find it... https://www.youtube.com/watch?v=vjrydnr_pvQ

Experian != Equifax

Re: Equifax’s Maddening Unaccountability

#169

So how can I stop using Equifax? Or at the very least how can I find banks or other agencies that don't use Equifax? Is there any way to stop them from hoarding all my data without my explicit consent?

You might be able to find a credit Beaureu that does not report to equifax. Might be better off calling your representatives in Washington and telling them we need better consumer data protection regulations. Good luck.

Re: Equifax’s Maddening Unaccountability

#170

"Most software failures and data breaches aren’t inevitable; they are a result of neglect and underinvestment in product reliability and security." How do we know that Equifax fell into this category? That this was due to negligence? I see a lot of disdain towards Equifax but yet the breach details have not been out yet.

The 6.66 billion dollar question.
Post reply on HN