Live data from Hacker News

Myequifax.com Bypasses Credit Freeze Pin

krebsonsecurity.com

151–160 of 206 posts

Re: Myequifax.com Bypasses Credit Freeze Pin

#151
post #106

Earlier quoted context omitted.

Some KBA questions don't show up on your credit report, that being said, they can still be guessed with some certainty if you know the person. Some examples either me or my husband have gotten: -What month was [person] born? [person] was my mom and one option was "I don't know [person]." Luckily they didn't ask the date, because I don't know that, but I do know the month. -Which of the following people are/were you a…

Here's a fun one for you! When I was a kid I was briefly a ward of the court. During that time, I had an official address that was not where I actually lived, and somehow the credit bureaus got ahold of that information. So whenever I need to answer the suite of questions for identity verification, if I get the "which of these places have you lived", there's a good chance I won't know the answer, because I was a kid…

Does that address show up when you request your credit report by mail?

It should be free (apart from postage).

Re: Myequifax.com Bypasses Credit Freeze Pin

#152
post #127
post #117

Earlier quoted context omitted.

> my ex as one of the answers. This one baffled me because we never lived together and never had a bank account or loan together Yikes. Where did they get that from? I wonder if they also collected tons of info from FaceBook like it seems everyone else has.

This was around... Oh... 8-9 years ago and I'm still trying to figure it out. It's honestly bothered me since then. I just really want to know how they connected us. I'm not mad they did, I just want to know how. We never had an insurance policy together or anything else like that either.

It could have come from the other side. If they listed your address for something (because she didn't want to list their own, or for any number of reasons), they could possibly determine that you lived together from that. Or some database got mixed up and used some shipping address for something they ordered to your residence as a home address. Having them associate you with them isn't all that weird.

What's weird is that they get this information from random sources and use it for verification without verifying it's actually accurate first. That's just bonkers.

Re: Myequifax.com Bypasses Credit Freeze Pin

#153
post #151

Earlier quoted context omitted.

Here's a fun one for you! When I was a kid I was briefly a ward of the court. During that time, I had an official address that was not where I actually lived, and somehow the credit bureaus got ahold of that information. So whenever I need to answer the suite of questions for identity verification, if I get the "which of these places have you lived", there's a good chance I won't know the answer, because I was a kid…

Does that address show up when you request your credit report by mail? It should be free (apart from postage).

[deleted]

Re: Myequifax.com Bypasses Credit Freeze Pin

#154

Earlier quoted context omitted.

In the end, you're really stuck between two places. Either you have something static, in which case it's got all the negatives of a static secret. Or, you have something dynamic, in which case you have to manage the infrastructure. The only thing that makes SSNs bad static secrets is that you should basically assume yours has been leaked at this point. Like others have said in this thread, they're not bad identifiers…

> Either you have something static, in which case it's got all the negatives of a static secret. Or, you have something dynamic, in which case you have to manage the infrastructure. I just described a system that is neither fully static nor fully dynamic. It has a static part (Unique ID) and a semi-dynamic part (numerical key) that can rotate as needed. > Your system is just another static piece of data to keep secre…

Please see my response here:

https://news.ycombinator.com/item?id=19341688

If the secret sauce is key rotation, then the best strategy is to rotate for every use. Building that strategy into the system basically results in OpenID. Take OpenID and allow the client to generate tokens offline, and that's SecurID.

And I still see value in the unique IDs, because they serve as a type of proof that key exchange has taken place. How does the bank go to court and demonstrate the the individual has validated their identity? The best way is to retain the key. Oh, but we're supposing that's illegal. So instead they'll show the unique ID and say, well then how did I get this unique ID?

I don't think you're applying enough hacker mentality to this. If we're going to approach this problem, let's approach it will the full capabilities that modern cryptography give us. There's no reason to share a secret with the company and extend trust to them; we already know how to securely share a secret between two endpoints (client and central authority) through untrusted middle men (company).

Re: Myequifax.com Bypasses Credit Freeze Pin

#155
post #92

Equifax has the unique ability to collect the most private information available, even when they have never or will never interact with that person. I think the entire credit system needs to be changed. If credit bureau's can't be responsible then citizens should get a choice in the matter. These companies have us by the balls and we have no recourse. It's a monopoly complete with price fixing and everything, except…

If only there were some kind of oversight by a government agency made to protect consumers from these types of things when the market based approach fails. This type of agency or bureau would be there to protect people when there was no legal recourse otherwise and establish rules so that corporate entities and businesses were beholden to someone. Meh, I'm sure the market will sort it out since you can just take your credit to another provider right?

Re: Myequifax.com Bypasses Credit Freeze Pin

#156

Earlier quoted context omitted.

> Either you have something static, in which case it's got all the negatives of a static secret. Or, you have something dynamic, in which case you have to manage the infrastructure. I just described a system that is neither fully static nor fully dynamic. It has a static part (Unique ID) and a semi-dynamic part (numerical key) that can rotate as needed. > Your system is just another static piece of data to keep secre…

Please see my response here: https://news.ycombinator.com/item?id=19341688 If the secret sauce is key rotation, then the best strategy is to rotate for every use. Building that strategy into the system basically results in OpenID. Take OpenID and allow the client to generate tokens offline, and that's SecurID. And I still see value in the unique IDs, because they serve as a type of proof that key exchange has taken p…

Please see my response here:

https://news.ycombinator.com/item?id=19341434

How are you paying for giving out half a billion SecurID-like tokens?

I'm talking about a code that can be printed on your driver's license, you're talking about a piece of electronics that has to be shipped to every person in the US, the logical differences are stark.

Re: Myequifax.com Bypasses Credit Freeze Pin

#157
post #3

> the data being asked about in these KBA quizzes is culled from public records Yesterday, when opening a savings account with a major US financial institution, one of the KBA questions asked for my Zodiac sign. The other two were about a mortgage and the year I was born (±1 year). I do not understand why any competent institution would find these secure and it appalls me that is all the information needed to open an…

When I opened my mortgage they required us to share via email everything in plain text. We did not have a choice of lender. I told my wife that these people were going to be hacked. Within 3 months we got a letter saying all of our information had been exposed. Oh whale, nothing that wasn't already out there from the numerous other breaches that I had zero control over.

Re: Myequifax.com Bypasses Credit Freeze Pin

#158
post #61
post #3

> the data being asked about in these KBA quizzes is culled from public records Yesterday, when opening a savings account with a major US financial institution, one of the KBA questions asked for my Zodiac sign. The other two were about a mortgage and the year I was born (±1 year). I do not understand why any competent institution would find these secure and it appalls me that is all the information needed to open an…

Zodiac sign? Seriously? I don't know what mine is because that is not a belief system/religion I subscribe to so I had to Google it. Turns out my birthdate must be on the border because different sources have it as a different sign. They might as well ask what color my aura is.

[deleted]

Re: Myequifax.com Bypasses Credit Freeze Pin

#159
post #92

Equifax has the unique ability to collect the most private information available, even when they have never or will never interact with that person. I think the entire credit system needs to be changed. If credit bureau's can't be responsible then citizens should get a choice in the matter. These companies have us by the balls and we have no recourse. It's a monopoly complete with price fixing and everything, except…

If only there were some kind of oversight by a government agency made to protect consumers from these types of things when the market based approach fails. This type of agency or bureau would be there to protect people when there was no legal recourse otherwise and establish rules so that corporate entities and businesses were beholden to someone. Meh, I'm sure the market will sort it out since you can just take your…

You seem to be describing the CFPB?

Re: Myequifax.com Bypasses Credit Freeze Pin

#160

Earlier quoted context omitted.

Please see my response here: https://news.ycombinator.com/item?id=19341688 If the secret sauce is key rotation, then the best strategy is to rotate for every use. Building that strategy into the system basically results in OpenID. Take OpenID and allow the client to generate tokens offline, and that's SecurID. And I still see value in the unique IDs, because they serve as a type of proof that key exchange has taken p…

Please see my response here: https://news.ycombinator.com/item?id=19341434 How are you paying for giving out half a billion SecurID-like tokens? I'm talking about a code that can be printed on your driver's license, you're talking about a piece of electronics that has to be shipped to every person in the US, the logical differences are stark.

So every OpenID provider has issued millions of dollars in tokens? No, of course not. All the tokens allow is offline generation of secrets. But if you don't need offline generation, then you don't need expensive tokens. I specifically call this out in my linked response; I don't know why you're still stuck on it.

Also, soft tokens are a thing and are basically free to generate. I've got several loaded on my phone right now, and have the code backed up in my password vault.

Also also, printing secret codes on drivers licenses seems like an amazingly bad idea... Every bar bouncer I interact with sees that thing!

Post reply on HN