Live data from Hacker News

Equihax

krypt3ia.wordpress.com

131–140 of 209 posts

Re: Equihax

#132

This really pisses me off. It's only a matter of time before some random person opens up a cellphone, utlity, or bank account... or worse. Completely messed up. Everyone American should be scared shitless at this incompetence. It's going to cost everyone thousands of dollars over their lives for credit fraud protection. Just another expense to add.

It's also extortion. "Please pay us money to solve the massive problem we created." I don't know how it's legal.

The legal term is racketeering (https://en.wikipedia.org/wiki/Racketeer_Influenced_and_Corru...).

Re: Equihax

#133
post #57

Earlier quoted context omitted.

Yeah, at best, that tool from Equifax is unreliable. People have put in fake users and SSN and still it's told them they were affected. At worst, it's just another way to get customers to sign up for a new service.

It's asking for the last 6 digits of SSN and name. Considering that is 1 million unique numbers, out of 146 million potentially compromised accounts, you could probably put any number in there and be reasonably sure of getting a hit.

This is a very good point and may explain this phenomenon. However, I'm not 100% sure that those numbers are equally distributed. Still, it may well account for the fact that random numbers still resulted in a hit. Good point.

Re: Equihax

#137

600 BTC = ~2,111,994 USD

Note: The value of BTC dropped more than 10% in the past 8 hours, so the value of the ransom just became much more affordable than before, although it's still higher than the middle of May when Equifax claims the breach began.

Just an aside, "ransom" is probably not the right word, since I presume they are not taking money to destroy or not release the data. They're selling the data to anyone, and probably will be happy to sell the same data many times over.

Re: Equihax

#138
post #55
post #53

Earlier quoted context omitted.

"Who would store date of birth as a string?" Enterprise. "If we are stringifying dob why is address still seperated?" Enterprise. "Why are the credit report reasource Ids in the thousands not 1M +?" Enterprise. "Why is the file size null but the file is listed with it's mimeType?" Enterprise. Be grateful you are in a position to be horrified. I'm currently fighting my way through a system that is not currently "Enter…

Exactly. The data model, and particular data typing, being terrible is more indicative of it being legit. Not less.

Indeed. This is one of those cases where reality is worse than the fabrication.

Re: Equihax

#139

Earlier quoted context omitted.

> real legal consequences for moronic data security This could go really wrong if we let non-tech savvy regulators dictate tech stacks, specific hashing/encryption tools. Could work well, but just has a lot of potential to go very wrong. Given that risk, as much as I don't want to live in an overly litigious society, letting the risk of lawsuits drive good security may be preferable to putting security in the hands o…

"This could go really wrong if we let non-tech savvy regulators dictate tech stacks, specific hashing/encryption tools. Could work well, but just has a lot of potential to go very wrong." Engineers, capitalism, private business have utterly, completely, fully and in totality failed. This is not a little failure. Not a medium one. Not a large one. This is a foundational, cataclysmic failure of the most epic proportion…

I agree that we should work to determine if there was criminal negligence and prosecute to the highest degree possible, but I find it laughable that you talk about how engineers, capitalism, and private business have completely failed.

The DNC was hacked. The FBI and CIA have had their web sites hacked. The OPM had >22 million people's personal info stolen by Chinese hackers. The NSA itself has had major incidents where essentially cyber weapons were leaked. Those are just SOME of the ones we know about.

Let's stop pretending like government is any more capable, or even as capable, of protecting data than competent corporations. When was the last time Facebook or Google had massive data breach? It's not about 'the corporations maaan' it's about competency and the limited consequences of screwing up so bad.

Post reply on HN