I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…
> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.
Equifax takes down web page after reports of new hack
81–90 of 143 posts
Re: Equifax takes down web page after reports of new hack
#82I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…
> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.
Re: Equifax takes down web page after reports of new hack
#83Earlier quoted context omitted.
Unfortunately you have no way to protect your tax returns from Equifax, which now has a contract with the IRS thanks to the infinite wisdom of our government. http://fortune.com/2017/10/04/equifax-irs-contract-hackers/
This contract is a renewal of a previous contract with Equifax (which is why it was a "critical service that couldn't lapse"), and it involves Equifax giving data to the IRS, not the IRS giving your tax returns to Equifax.
Re: Equifax takes down web page after reports of new hack
#84Earlier quoted context omitted.
I'm reasonably sure the whole Fireclick infrastructure was abandoned, probably years ago. So Equifax's part was not having some mechanism in place to remove 3rd party references for 3rd parties that aren't delivering anymore. I strongly suspect that predated the change in ownership of the domain, which was almost a year ago. The fireclick.com domain is gone. The parent company (Digital River) doesn't mention offering…
I don't know, how can you reasonably defend from that sort of domain hijacking/repurposing? We fundamentally have to trust DNS at some level, but domain names are somewhat transient in nature. Is it fair to single out Equifax here, or is this just an example of an unsolved problem in the industry?
Security scans also usually include breakdowns of 3rd party stuff.
But yes, there's ways it could go wrong. On the other hand, Equifax is one of very few places that has so much important data. I'd expect them to be leaders in this space, not lackluster followers. Subresource integrity, perhaps more due diligence on partners...stick with bigger players for code that shows up on your site, etc.
Re: Equifax takes down web page after reports of new hack
#85Earlier quoted context omitted.
I don't know, how can you reasonably defend from that sort of domain hijacking/repurposing? We fundamentally have to trust DNS at some level, but domain names are somewhat transient in nature. Is it fair to single out Equifax here, or is this just an example of an unsolved problem in the industry?
Somebody used to log into the backend that showed them the statistics. Surely they noticed when it disappeared? Security scans also usually include breakdowns of 3rd party stuff. But yes, there's ways it could go wrong. On the other hand, Equifax is one of very few places that has so much important data. I'd expect them to be leaders in this space, not lackluster followers. Subresource integrity, perhaps more due dil…
Re: Equifax takes down web page after reports of new hack
#86Earlier quoted context omitted.
Unfortunately you have no way to protect your tax returns from Equifax, which now has a contract with the IRS thanks to the infinite wisdom of our government. http://fortune.com/2017/10/04/equifax-irs-contract-hackers/
From your link: >"The Internal Revenue Service signed a $7.25 million contract with Equifax last month. The no-bid contract, first reported by Politico, is for Equifax to provide the IRS with taxpayer and personal identity verification services. The contract stated that Equifax (EFX, -1.34%) was the only company capable of providing these services to the IRS, and it was deemed a “critical” service that couldn’t lapse…
Re: Equifax takes down web page after reports of new hack
#87Earlier quoted context omitted.
Unfortunately you have no way to protect your tax returns from Equifax, which now has a contract with the IRS thanks to the infinite wisdom of our government. http://fortune.com/2017/10/04/equifax-irs-contract-hackers/
From your link: >"The Internal Revenue Service signed a $7.25 million contract with Equifax last month. The no-bid contract, first reported by Politico, is for Equifax to provide the IRS with taxpayer and personal identity verification services. The contract stated that Equifax (EFX, -1.34%) was the only company capable of providing these services to the IRS, and it was deemed a “critical” service that couldn’t lapse…
Re: Equifax takes down web page after reports of new hack
#88Earlier quoted context omitted.
freeze your credit report with Equifax, and then if any company requests it, they'll be denied (because you have to request it be unfrozen for them to receive it). If any company uses Equifax, you'll then be denied credit or they'll ask you to unfreeze it.. either way, you can complain to them, and make it clear you won't work with Equifax. Of course, in practice, this will mean you'll get denied credit from any comp…
I submitted a complaint to the CFPB requiring [1] Equifax to remove my credit record, due to their proven incompetence at protecting that data (citing their breech, several congresspeople grilling their CEO on CSPAN, etc). Its been 9 days and I haven't heard back from the CFPB yet (Equifax has 15 days to respond and up to 60 days to provide a final response), but Equifax has my complaint and even if it goes nowhere,…
So, personally identifiable information (PII) is a less-debatable phrase and more legally defensible.
In the first case, if you do business with a bank then the data from that belongs to the bank as much as it belongs to you. They are reporting their information, namely that you interacted with them. Thus, that information would belong to them.
In the second case, it is personally identifiable information - which is something that's difficult to dispute. This also gives you interest in that data which is a stronger point to stand on.
As mentioned before, I am not a lawyer and this is not legal advice. However, I have extensive experience with the justice system due to my career and have taken quite a few classes concerning the law.
Also, the word 'shall' has stronger implications than 'will.' I am not sure why but it is handy to know. The defendant will comply vs. the defendant shall comply.
Best of luck.
Re: Equifax takes down web page after reports of new hack
#89I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…
> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.
I get that some people like meting out punishment, but it seems like a good idea to limit it to the people responsible.
Re: Equifax takes down web page after reports of new hack
#90I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…
> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.
In that case, ruining the career of a low-level employee seems misplaced, especially when they most likely weren't the cause of these issues.