Live data from Hacker News

Equifax takes down web page after reports of new hack

reuters.com

81–90 of 143 posts

Re: Equifax takes down web page after reports of new hack

#81

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.

You can't see it, but I'm rolling my eyes fast at your comment.

Re: Equifax takes down web page after reports of new hack

#82

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.

More specifically their IT executive team. Odds are that the lower level tech staff are treated horribly

Re: Equifax takes down web page after reports of new hack

#83
post #34

Earlier quoted context omitted.

Unfortunately you have no way to protect your tax returns from Equifax, which now has a contract with the IRS thanks to the infinite wisdom of our government. http://fortune.com/2017/10/04/equifax-irs-contract-hackers/

This contract is a renewal of a previous contract with Equifax (which is why it was a "critical service that couldn't lapse"), and it involves Equifax giving data to the IRS, not the IRS giving your tax returns to Equifax.

So I wonder what would happen if the IRS attempted to Eminent Domain-ify the data they needed.

Re: Equifax takes down web page after reports of new hack

#84
post #78
post #69

Earlier quoted context omitted.

I'm reasonably sure the whole Fireclick infrastructure was abandoned, probably years ago. So Equifax's part was not having some mechanism in place to remove 3rd party references for 3rd parties that aren't delivering anymore. I strongly suspect that predated the change in ownership of the domain, which was almost a year ago. The fireclick.com domain is gone. The parent company (Digital River) doesn't mention offering…

I don't know, how can you reasonably defend from that sort of domain hijacking/repurposing? We fundamentally have to trust DNS at some level, but domain names are somewhat transient in nature. Is it fair to single out Equifax here, or is this just an example of an unsolved problem in the industry?

Somebody used to log into the backend that showed them the statistics. Surely they noticed when it disappeared?

Security scans also usually include breakdowns of 3rd party stuff.

But yes, there's ways it could go wrong. On the other hand, Equifax is one of very few places that has so much important data. I'd expect them to be leaders in this space, not lackluster followers. Subresource integrity, perhaps more due diligence on partners...stick with bigger players for code that shows up on your site, etc.

Re: Equifax takes down web page after reports of new hack

#85
post #84
post #78

Earlier quoted context omitted.

I don't know, how can you reasonably defend from that sort of domain hijacking/repurposing? We fundamentally have to trust DNS at some level, but domain names are somewhat transient in nature. Is it fair to single out Equifax here, or is this just an example of an unsolved problem in the industry?

Somebody used to log into the backend that showed them the statistics. Surely they noticed when it disappeared? Security scans also usually include breakdowns of 3rd party stuff. But yes, there's ways it could go wrong. On the other hand, Equifax is one of very few places that has so much important data. I'd expect them to be leaders in this space, not lackluster followers. Subresource integrity, perhaps more due dil…

I'd have to guess that someone cancelled the analytics at the business level, but never bothered to write up a change request to tell the devs to take it out.

Re: Equifax takes down web page after reports of new hack

#86

Earlier quoted context omitted.

Unfortunately you have no way to protect your tax returns from Equifax, which now has a contract with the IRS thanks to the infinite wisdom of our government. http://fortune.com/2017/10/04/equifax-irs-contract-hackers/

From your link: >"The Internal Revenue Service signed a $7.25 million contract with Equifax last month. The no-bid contract, first reported by Politico, is for Equifax to provide the IRS with taxpayer and personal identity verification services. The contract stated that Equifax (EFX, -1.34%) was the only company capable of providing these services to the IRS, and it was deemed a “critical” service that couldn’t lapse…

I'd guess it is just outsourcing of a government function, you know as a way to save taxpayers money and increase government efficiency ... like those private prisons, private torturers, private plutonium processors, etc.

Re: Equifax takes down web page after reports of new hack

#87

Earlier quoted context omitted.

Unfortunately you have no way to protect your tax returns from Equifax, which now has a contract with the IRS thanks to the infinite wisdom of our government. http://fortune.com/2017/10/04/equifax-irs-contract-hackers/

From your link: >"The Internal Revenue Service signed a $7.25 million contract with Equifax last month. The no-bid contract, first reported by Politico, is for Equifax to provide the IRS with taxpayer and personal identity verification services. The contract stated that Equifax (EFX, -1.34%) was the only company capable of providing these services to the IRS, and it was deemed a “critical” service that couldn’t lapse…

AFAIK in the US, you're not required to check in with local authorities when you move to a new city (contrary to many European countries where you need to notify them, else you'll be fined), so there's no official register the IRS could use to find all taxpayers... maybe that's the background.

Re: Equifax takes down web page after reports of new hack

#88

Earlier quoted context omitted.

freeze your credit report with Equifax, and then if any company requests it, they'll be denied (because you have to request it be unfrozen for them to receive it). If any company uses Equifax, you'll then be denied credit or they'll ask you to unfreeze it.. either way, you can complain to them, and make it clear you won't work with Equifax. Of course, in practice, this will mean you'll get denied credit from any comp…

I submitted a complaint to the CFPB requiring [1] Equifax to remove my credit record, due to their proven incompetence at protecting that data (citing their breech, several congresspeople grilling their CEO on CSPAN, etc). Its been 9 days and I haven't heard back from the CFPB yet (Equifax has 15 days to respond and up to 60 days to provide a final response), but Equifax has my complaint and even if it goes nowhere,…

As for verbiage, you may want try the phrase you later used in a follow up post. It's not really your personal data. After all, it was data from an interaction with another entity which makes it their data as well.

So, personally identifiable information (PII) is a less-debatable phrase and more legally defensible.

In the first case, if you do business with a bank then the data from that belongs to the bank as much as it belongs to you. They are reporting their information, namely that you interacted with them. Thus, that information would belong to them.

In the second case, it is personally identifiable information - which is something that's difficult to dispute. This also gives you interest in that data which is a stronger point to stand on.

As mentioned before, I am not a lawyer and this is not legal advice. However, I have extensive experience with the justice system due to my career and have taken quite a few classes concerning the law.

Also, the word 'shall' has stronger implications than 'will.' I am not sure why but it is handy to know. The defendant will comply vs. the defendant shall comply.

Best of luck.

Re: Equifax takes down web page after reports of new hack

#89

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.

Why is that a good start? They are ex employees. Perhaps they are no longer there because they quit due to bad leadership, bad security, bad company ethics, or maybe they were fired for continually reporting their security flaws?

I get that some people like meting out punishment, but it seems like a good idea to limit it to the people responsible.

Re: Equifax takes down web page after reports of new hack

#90

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.

I'm sure there was some incompetance at the individual level, but I think it's more likely that the key issue was that the management de-prioritized security, which lead to the IT team either not having staff on hand to fix issues that came up, or being assigned tasks other than fixing the security issues.

In that case, ruining the career of a low-level employee seems misplaced, especially when they most likely weren't the cause of these issues.

Post reply on HN