Live data from Hacker News

Equihax

krypt3ia.wordpress.com

91–100 of 209 posts

Re: Equihax

#91
post #80

Earlier quoted context omitted.

I wonder as well. I think we all forget how important credit reports are in giving banks comfort to lend (not that this is the only way to do it, but it seems that this is the current way). If people can default on a uncollateralized loan with no ramifications, no bank would lend and the credit engine would shut down.

People also forget about of rule of law. I defaulted on my loan? Sue me. Want to give me a loan? Search for me in public court records.

Economies of scale. Pulling a credit score costs about $.30 and takes two seconds. How long will it take to search public court records?

Besides, it's not only the bankruptcies that count. Good tradelines are also important, and those are not public.

Re: Equihax

#92

This really pisses me off. It's only a matter of time before some random person opens up a cellphone, utlity, or bank account... or worse. Completely messed up. Everyone American should be scared shitless at this incompetence. It's going to cost everyone thousands of dollars over their lives for credit fraud protection. Just another expense to add.

The thing is, up until now, there was a false sense of security that if someone didn't have your SSN, they couldn't open up financial accounts as you. And there was little being done to protect people whose SSNs are already disclosed in some way. With such a large percentage of our social security numbers being potentially outright public, financial institutions need to stop assuming that an account holder is legitim…

Agreed. If you used medical services in any significant way before 2010, your SS and birthdate was all over the place in insurance and medical records.

Re: Equihax

#93
post #80

Earlier quoted context omitted.

People also forget about of rule of law. I defaulted on my loan? Sue me. Want to give me a loan? Search for me in public court records.

If you think about it from the bank's perspective though, why would they lend you any money if you were likely to default and they would have to sue you to get money back. That would mean that the cost of your loan would go up for them and therefore, your borrowing rate goes up tremendously. Humans don't have an innate right to borrow money. It's a service provided by financial institutions for a fee. I don't think c…

>Humans don't have an innate right to borrow money. It's a service provided by financial institutions for a fee.

This would be fine, except those financial institutions get THEIR money from the fed discount window. If their service was entirely private, that would be one thing but having the government involved changes the concept of "rights", especially when the fed loans out money with the express reason that the banks will loan it out in turn.

Re: Equihax

#94
post #66

Earlier quoted context omitted.

I really hope that's the outcome here. I also think this should pave the way for real legal consequences for moronic data security. Individuals are banned from using computers when prosecuted, what about "no internet for companies who've proven they can't use it responsibly"

> Individuals are banned from using computers when prosecuted Who is banned from using computers? You mean, in prison?

It can be a punishment for certain crimes- or as an extended punishment after jail. Things like stalking where a computer was a primary method, valid threats made on a computer, etc.

Re: Equihax

#95
post #66

Earlier quoted context omitted.

I really hope that's the outcome here. I also think this should pave the way for real legal consequences for moronic data security. Individuals are banned from using computers when prosecuted, what about "no internet for companies who've proven they can't use it responsibly"

> Individuals are banned from using computers when prosecuted Who is banned from using computers? You mean, in prison?

Some convicted hackers have been banned from the internet, if ever caught using it they go back to prison.

There have been cases of people being banned from using any personal computer.

Re: Equihax

#96
post #66

Earlier quoted context omitted.

I really hope that's the outcome here. I also think this should pave the way for real legal consequences for moronic data security. Individuals are banned from using computers when prosecuted, what about "no internet for companies who've proven they can't use it responsibly"

> Individuals are banned from using computers when prosecuted Who is banned from using computers? You mean, in prison?

Kevin Mitnick, famously, ages ago. Not sure if anyone else has ever had that.

Re: Equihax

#97
This seems odd to say, but if they included a price for just a simple name+birth date query, there is probably a decent price point people would actually pay just to know if they are on there. Like if they have even just half of the names querying for their own identities for like $30 a pop, that'd be more than what they are asking for for the whole bulk.

Re: Equihax

#98
post #17

Earlier quoted context omitted.

I wouldn't be that surprised that she would miss lots of consecutive payments. Not because she didn't have the money, but because she doesn't care. 3 late payments in a row on a mortgage, credit card, etc, drags down your score a lot. Or perhaps she had little credit history. I could see a scenario where most of her stuff is financed through an LLC vs her personal credit. If your business is solely "being popular", a…

I doubt she's sitting down once a week or so and paying any bills. I imagine somebody else does that for her.

Plenty of celebs are late payers. Whether that's because they pay bills themselves, or just fail to route stuff to their accountants, I have no idea.

There's more than one embarrassing car repo celeb picture floating around.

Re: Equihax

#99

Earlier quoted context omitted.

If you think about it from the bank's perspective though, why would they lend you any money if you were likely to default and they would have to sue you to get money back. That would mean that the cost of your loan would go up for them and therefore, your borrowing rate goes up tremendously. Humans don't have an innate right to borrow money. It's a service provided by financial institutions for a fee. I don't think c…

>Humans don't have an innate right to borrow money. It's a service provided by financial institutions for a fee. This would be fine, except those financial institutions get THEIR money from the fed discount window. If their service was entirely private, that would be one thing but having the government involved changes the concept of "rights", especially when the fed loans out money with the express reason that the b…

Their usage of the discount window has to be miniscule compared to customer deposits, no?

Re: Equihax

#100
post #37

EDIT: see philipodonnell's reply to this post for an alternative explanation. I may have jumped the gun. As far as I know credit scores are not part of credit reports as they do not show up when you request your credit report. If they were storing "credit score" as part of your credit report but withholding that information when you request a copy that would seem to violate the Fair Credit Reporting Act. It wouldn't…

You're assuming this is a database dump. It looks more like logs from the service that creates PDF versions of reports for download. That would have a more simplistic data structure that might look like this.

If it's a service request log, why service would have field requestId and then set it to null? Of course, you can expect anything from people that have admin/admin security on their employee portal, but looks weird. Also, street data have no field for apartment number - does nobody live in multi-tenant buildings? Of course, there may be optional field for this, but given how many null fields there are, it doesn't look like this API does optional fields. In summary, API response format could be anything, as I said, especially from people who do admin/admin, but on the fact of it it looks questionable.

Also, why credit reports for Donald Trump and Kim Kardashian were created at the same second and then modified at the same second? Probability of this happening as a result of natural client activity - i.e. just watching the logs of the active service - is zero. If the attackers had access to this service and initiated the requests, then why not show the resulting PDFs, that they supposedly also must have had access to if they had access to the API?

Post reply on HN