Live data from Hacker News

Equifax takes down web page after reports of new hack

reuters.com

61–70 of 143 posts

Re: Equifax takes down web page after reports of new hack

#62
post #38
post #31

Yes, this was discussed earlier today: https://news.ycombinator.com/item?id=15456221 And debunked...it wasn't a hack of the Equifax web site, but a malware package delivered by 3rd party analytics company, Fireclick.

Not exactly. Equifax has hardcoded references to an akamai cache of a domain (hints.netflame.cc) in their own pages[1]. That domain was owned by Fireclick (né Digital River) at one time, but changed ownership on November 15, 2016. The current owner is a Thai national using a personal Gmail address as the registration info. Equifax should be responsible for what 3rd party domains it is referencing in their pages. [1]…

That script was provided by Fireclick, so they're the ones that hardcoded it. It even specifically says "Please do not modify this code".

Re: Equifax takes down web page after reports of new hack

#63

Earlier quoted context omitted.

freeze your credit report with Equifax, and then if any company requests it, they'll be denied (because you have to request it be unfrozen for them to receive it). If any company uses Equifax, you'll then be denied credit or they'll ask you to unfreeze it.. either way, you can complain to them, and make it clear you won't work with Equifax. Of course, in practice, this will mean you'll get denied credit from any comp…

I submitted a complaint to the CFPB requiring [1] Equifax to remove my credit record, due to their proven incompetence at protecting that data (citing their breech, several congresspeople grilling their CEO on CSPAN, etc). Its been 9 days and I haven't heard back from the CFPB yet (Equifax has 15 days to respond and up to 60 days to provide a final response), but Equifax has my complaint and even if it goes nowhere,…

Do you have more information on how to do this? I'm thinking that doing the same thing makes sense going forward.

Re: Equifax takes down web page after reports of new hack

#64

Earlier quoted context omitted.

freeze your credit report with Equifax, and then if any company requests it, they'll be denied (because you have to request it be unfrozen for them to receive it). If any company uses Equifax, you'll then be denied credit or they'll ask you to unfreeze it.. either way, you can complain to them, and make it clear you won't work with Equifax. Of course, in practice, this will mean you'll get denied credit from any comp…

Unfortunately you have no way to protect your tax returns from Equifax, which now has a contract with the IRS thanks to the infinite wisdom of our government. http://fortune.com/2017/10/04/equifax-irs-contract-hackers/

From your link:

>"The Internal Revenue Service signed a $7.25 million contract with Equifax last month. The no-bid contract, first reported by Politico, is for Equifax to provide the IRS with taxpayer and personal identity verification services. The contract stated that Equifax (EFX, -1.34%) was the only company capable of providing these services to the IRS, and it was deemed a “critical” service that couldn’t lapse."

The IRS in the US needs Equifax to provide tax payer and verification services? Seriously what does that even mean? The IRS bas no other way to verify citizens?

Re: Equifax takes down web page after reports of new hack

#65
post #62
post #38

Earlier quoted context omitted.

Not exactly. Equifax has hardcoded references to an akamai cache of a domain (hints.netflame.cc) in their own pages[1]. That domain was owned by Fireclick (né Digital River) at one time, but changed ownership on November 15, 2016. The current owner is a Thai national using a personal Gmail address as the registration info. Equifax should be responsible for what 3rd party domains it is referencing in their pages. [1]…

That script was provided by Fireclick, so they're the ones that hardcoded it. It even specifically says "Please do not modify this code".

I'm not sure that bit matters, it's hosted on an Equifax server and served in their pages. And pulling in a script from a very sketchy domain.

Re: Equifax takes down web page after reports of new hack

#66
post #65
post #62

Earlier quoted context omitted.

That script was provided by Fireclick, so they're the ones that hardcoded it. It even specifically says "Please do not modify this code".

I'm not sure that bit matters, it's hosted on an Equifax server and served in their pages. And pulling in a script from a very sketchy domain.

The script they hosted was legitimate. The Akamai content that it loaded, was legitimate. But Fireclick let the domain lapse, and someone else is now impersonating them and serving malware, and not just to Equifax, either. Why is the story "Equifax hacked again" instead of "Akamai serving content from known spammer site"?

Re: Equifax takes down web page after reports of new hack

#67

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

freeze your credit report with Equifax, and then if any company requests it, they'll be denied (because you have to request it be unfrozen for them to receive it). If any company uses Equifax, you'll then be denied credit or they'll ask you to unfreeze it.. either way, you can complain to them, and make it clear you won't work with Equifax. Of course, in practice, this will mean you'll get denied credit from any comp…

That's not quite how credit freezes work, if they pull Equifax and only that bureau is frozen then they will usually just pull from another credit bureau. People who churn credit cards use this to their advantage - they often freeze the report with the most recent inquiries (usually Experian) to spread out inquiries more evenly over the three bureaus. I've never heard of anyone getting flat out denied for credit (besides mortgages) because they had a single bureau frozen. Sometimes it requires a phone call but usually its just automatic.

You also can't prevent them from reporting information about you to Equifax.

Anyways, you aren't really hurting anyone by denying yourself the ability to get credit, you're only hurting yourself.

Re: Equifax takes down web page after reports of new hack

#68
post #24

it's amazing how much the finance industry can get away with. like honest-to-goodness amazing. it's really impressive how these people can have such a death-grip on society. honestly, i'm more curious than mad. how is such a thing even possible? i mean, wow.

Because of our corrupt banking system and the politicians in bed with them.

Having been in that system, the reality is so much more bizarre than that.

The actual reality I observed is that the government inspectors and regulators are lawyers and older industry people who simply don't understand technology. Since the US government has limited technical expertise they rely on FIs to adhere to standards and propose self-regulatory measures.

Re: Equifax takes down web page after reports of new hack

#69
post #66
post #65

Earlier quoted context omitted.

I'm not sure that bit matters, it's hosted on an Equifax server and served in their pages. And pulling in a script from a very sketchy domain.

The script they hosted was legitimate. The Akamai content that it loaded, was legitimate. But Fireclick let the domain lapse, and someone else is now impersonating them and serving malware, and not just to Equifax, either. Why is the story "Equifax hacked again" instead of "Akamai serving content from known spammer site"?

I'm reasonably sure the whole Fireclick infrastructure was abandoned, probably years ago. So Equifax's part was not having some mechanism in place to remove 3rd party references for 3rd parties that aren't delivering anymore. I strongly suspect that predated the change in ownership of the domain, which was almost a year ago. The fireclick.com domain is gone. The parent company (Digital River) doesn't mention offering any kind of analytics service.

So, yes, technically the vector wasn't directly an Equifax server. But it was only a vector because nobody removed the reference.

Right now, they also reference crazyegg.com in their pages. If crazyegg goes belly up, the domain will be dormant, and when it expires, somebody might take it over. Does Equifax have an onus to deal with that, or can they blame someone else?

Re: Equifax takes down web page after reports of new hack

#70

Earlier quoted context omitted.

I submitted a complaint to the CFPB requiring [1] Equifax to remove my credit record, due to their proven incompetence at protecting that data (citing their breech, several congresspeople grilling their CEO on CSPAN, etc). Its been 9 days and I haven't heard back from the CFPB yet (Equifax has 15 days to respond and up to 60 days to provide a final response), but Equifax has my complaint and even if it goes nowhere,…

Do you have more information on how to do this? I'm thinking that doing the same thing makes sense going forward.

https://www.consumerfinance.gov/complaint

Complaint was with Equifax, Inc. I specified I required my credit file be removed, as Equifax has had several egregious security breaches and is incapable of properly securing my PII [1]. They have 15 days to respond.

[1] https://en.wikipedia.org/wiki/Personally_identifiable_inform...

Post reply on HN