Live data from Hacker News

Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

gizmodo.com

51–60 of 99 posts

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#51
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

That's a damning article not only for Panera, but also for the press and their lack of journalism. It appears they just copy pasted Panera's PR.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#52
I was thinking holding cash in ESCROW for these companies might be a way to get them to take this shit seriously.

The idea is to lock up your payment in escrow for 12 months.

50% of it would be in escrow and 50% is sent to the recipient.

You then use a multi-sig transaction for the escrow.

If your customers find out you did something shady they can all revoke their payment to you and you lose 50% of your revenue for that year.

All it would take is for the N of the M wallet signatures to agree that what you did was a breach of contract.

This could be done optionally too. Companies that enable this type of payment would see more customers so the free market dynamics would take over.

It could also be legally required too of course.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#53
post #7

Another situation of too big to fail? I sure hope not. Why are they still in business? Any worthy regulation of any type would have shut them down already no?

> Why are they still in business? Lawsuits are progressing. It's possible legal costs (plus the accompanying reputational damage) will eventually force Equifax into bankruptcy. (I, for example, refuse to open credit lines if they require an Equifax credit check.) At the end of the day, you can't just kill companies because you don't like them. We don't have general data protection laws with heavy penalties in the Uni…

>I, for example, refuse to open credit lines if they require an Equifax credit check.

How do you know who the credit lines are going to check your credit through?

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#54

Anyone have a current status on how to effectively sue Equifax for data exposed?

Last year, I tried to sue them in Small Claims court (in California) using this as a guide: https://blog.legalist.com/i-won-8-000-from-equifax-in-small-... . For me, it was unsuccessful. They sent out a representative and we argued away from a judge (forget the term used) and I decided not to see the judge because if I argued before him and lost, I would be "unable" to bring it before a judge again. I've heard of thi…

I'm planning to do this (small claims court). When I looked into it a year ago I did not have confirmation that Equifax did business in the juristiction, which was a requirent. My previous employer (I'm still on their payroll as a part time employee) recently notified me that they are now participating in Equifax's "The Work Number" so I'm going to request my data in a month or so as confirmation of Equifax operating in this jurisdiction. I plan to claim damages as the service cost of enhanced credit monitoring service in perpetuity, at least up to the limit of $6,500. Any thoughts on this approach? What did you declare as damages and what was the representatives rebuttal?

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#55
post #4

How these guys are still in business and still collecting financial data on US citizens frankly baffles me.

Here in Canada you basically must go to them to do anything credit related ie get a car or home loan. I don't see how they have any incentive to do better because they are a monopoly. And I cannot get my credit score from the bank as it's illegal I must go through this joke of a credit agency.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#56
Hey Hacker News,

I am Victor, the CTO of Truework (https://www.truework.com), a startup providing an alternative to Equifax / TheWorkNumber.

We are working to change the way employment & income information is shared by employers with a more privacy focused approach where you, as an employee, decide if you want to give the information with the requester.

I started this company after I found out that Equifax shared my employment and income information without my consent when I was working at LinkedIn...

AMA

Also we're recruiting: https://www.truework.com/careers/ !

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#57

Hey Hacker News, I am Victor, the CTO of Truework ( https://www.truework.com ), a startup providing an alternative to Equifax / TheWorkNumber. We are working to change the way employment & income information is shared by employers with a more privacy focused approach where you, as an employee, decide if you want to give the information with the requester. I started this company after I found out that Equifax shared m…

Does Equifax actually have my employment and income information? I thought it was just credit reports, etc

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#58
post #49
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

That guy still works at Panera and guess where he worked prior as Sr Director of Security Operations... Equifax! https://www.linkedin.com/in/mike-gustavison-b020426/

Remember people like this when you're casually entering your private information online. Shocking.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#59
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

How do people so dangerously incompetent get hired into these roles? Edit: My question and the replies are incredibly depressing as an infosec practitioner.

Hairstyle, height and chin shape.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#60
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

This may be fixed in the very near future.

CCPA -- the California Consumer Privacy Act -- has real penalties for data breaches [0]. When there is pure negligence in play and the business doesn't cure with 30 days notice, the law seems to explicitly provide for a minimum $100 / person penalty. And up to $750. There are amendments in play to remove the 30 day cure grace period; whether they pass this year or not, we'll have them within 5 years (personal bet).

Basically, breaches can be an extinction event for a company in California starting 1 January 2020. A couple companies are gonna take one for the team, and shortly thereafter, boards will be very interested in security postures.

[0] https://iapp.org/resources/article/california-consumer-priva...

Post reply on HN