Banks and data companies are moving to biometrics for proof of identity and you may have hit this. At least 3 credit card companies I use are signed up/using a biometrics/information provider. (they wouldn’t tell me who, despite federal disclosure requirements — I only knew they were using someone because my current accurate info was replaced by info from 7 years ago) There are companies trying very hard to find out…
Tell HN: Equifax free credit report dark patterns
61–70 of 108 posts
Re: Tell HN: Equifax free credit report dark patterns
#62Earlier quoted context omitted.
I understood the comment about aiding and abetting to be a reference to the fact that Equifax leaked about half of all Social Security Numbers back in 2017. For 145 million Americans the "harvested data" you refer to was data that the credit bureaus hoovered up and then failed to protect.
> Equifax leaked about half of all Social Security Numbers back in 2017. They weren't leaked , they were stolen . Does a bank "leak money" when it's robbed?
Re: Tell HN: Equifax free credit report dark patterns
#63[0] https://employees.theworknumber.com/employee-data-freeze
[1] https://krebsonsecurity.com/2017/11/how-to-opt-out-of-equifa...
Re: Tell HN: Equifax free credit report dark patterns
#64Earlier quoted context omitted.
> Equifax leaked about half of all Social Security Numbers back in 2017. They weren't leaked , they were stolen . Does a bank "leak money" when it's robbed?
If the bank failed to apply industry-standard security techniques then yeah, I'd say the bank leaked money. The criminals are obviously the most culpable, but when you're storing more than 100 million SSNs it's not unreasonable to expect your IT department to: * Update their dependencies within two months of a critical security vulnerability being patched (Mar 7 to May 12). * In the event of a breach, detect it withi…
They thought they did, but failed.
> In the event of a breach, detect it within a reasonable timeframe (76 days is not reasonable when you're the Fort Knox of financial information).
Impossible to guarantee. A sophisticated enough attack might never be detected, regardless of the competence of the security department.
> Have a reasonably well-segmented network such that a compromise in a single user-facing web app doesn't lead to your entire network being compromised.
It is impossible to so completely segment a network. If I can get the data via an authorized program, that means there's a path between networks and a hacker can potentially exploit that path.
Re: Tell HN: Equifax free credit report dark patterns
#65Earlier quoted context omitted.
> Equifax leaked about half of all Social Security Numbers back in 2017. They weren't leaked , they were stolen . Does a bank "leak money" when it's robbed?
IMO, Leaked is probably the better word here. Equifax did not steal the data in the first place either, they recorded/copied it from other sources which leaked or sold it to them.
Every data source (such as a bank or credit card) provides that data to CRAs because consumers granted permission to do so when entering into a business relationship. Either that, or it's publicly available data purchased from aggregators.
Re: Tell HN: Equifax free credit report dark patterns
#66Earlier quoted context omitted.
100% agree on the incentives Similar to why cookie accept/deny interfaces are atrocious. They're intended to be! I think a solution will require more creativity than "have the government do it", but the current system is clearly broken.
I don’t think government should do it at all. That would be same broken thing. I just don’t want a selected (not by me) set of companies collect information about me without my consent. I would rather have an opt-in system where I can select a vendor to make a report on me to provide to lender. Only when I want it.
I'd want a non-profit to handle it. I'd want full public disclosure of internal processes, data sources and data buyers. I'd want strong, unhindered oversight provided by a fully independent public board along with separate oversight provided by the FTC - with oversight entities able to exhort meaningful influence over methods, sources and customers.
Re: Tell HN: Equifax free credit report dark patterns
#67It's possible to opt out of the TheWorkNumber [0] by postal mail. You might consider it. [1] [0] https://employees.theworknumber.com/employee-data-freeze [1] https://krebsonsecurity.com/2017/11/how-to-opt-out-of-equifa...
Re: Tell HN: Equifax free credit report dark patterns
#68Earlier quoted context omitted.
If the bank failed to apply industry-standard security techniques then yeah, I'd say the bank leaked money. The criminals are obviously the most culpable, but when you're storing more than 100 million SSNs it's not unreasonable to expect your IT department to: * Update their dependencies within two months of a critical security vulnerability being patched (Mar 7 to May 12). * In the event of a breach, detect it withi…
> Update their dependencies within two months of a critical security vulnerability being patched (Mar 10 to May 12). They thought they did, but failed. > In the event of a breach, detect it within a reasonable timeframe (76 days is not reasonable when you're the Fort Knox of financial information). Impossible to guarantee. A sophisticated enough attack might never be detected, regardless of the competence of the secu…
Oh, never mind then. Clearly since they thought they updated the dependency it's all good.
> Impossible to guarantee. A sophisticated enough attack ... It is impossible to so completely segment a network ...
While I will acknowledge that this seems to have been Equifax's approach to security (it's impossible to do completely so why bother doing it at all?), this is not widely accepted as a philosophy of security in any industry.
That a bank could still be robbed by a military incursion from a neighboring nation state is not sufficient reason to leave the vault door open overnight. The record abundantly shows [0] that Equifax had security protocols that were weak enough that no sophisticated actor was needed to bypass their protections.
As far as their failure to detect the breach, this is what the House investigation concluded:
> Equifax allowed over 300 security certificates to expire, including 79 certificates for monitoring business critical domains. Failure to renew an expired digital certificate for 19 months left Equifax without visibility on the exfiltration of data during the time of the cyberattack.
[0] https://oversight.house.gov/report/committee-releases-report...
Re: Tell HN: Equifax free credit report dark patterns
#69Earlier quoted context omitted.
IMO, Leaked is probably the better word here. Equifax did not steal the data in the first place either, they recorded/copied it from other sources which leaked or sold it to them.
> other sources which leaked or sold it to them. Every data source (such as a bank or credit card) provides that data to CRAs because consumers granted permission to do so when entering into a business relationship. Either that, or it's publicly available data purchased from aggregators.
Do we have an actual choice?
Re: Tell HN: Equifax free credit report dark patterns
#70The problem is, as you articulated, they are required by law to provide credit reporting information about you to you. They have no incentive to do this because they make their money by collecting and selling data about us. They have every reason to use this reporting requirement to collect more information about you. They have every reason to conflate credit freeze with credit hold , and confuse consumers in order t…
But I find comments like these often become popular and highly upvoted because of their formulation but end up serving very little utility and ultimately dismissive. I think they're upvoted because they are in factual and accurate, and we like the confirmation because it shows how intelligent we are. But I think they end up being dismissive because it is missing the point. It is dismissive because there are no actual points being addressed or solutions being offered. There is an implicit solution of the government generating said report, but I think this would need to be (more) explicit. It also seems that anytime these comments raise to the top that the conversations become very unorganized and off topic, because frankly there is little to go off of. If writing a purely educational response I think it is quite hard to do (and even this comment might have the same repercussions but I'm trying to add more and my intent here is to align the thread. No one need reply to my comment).
Personally I think a good solution would be for the law regarding these free reports should be updated to specify that they should not be a data collecting process. That they are only allowed to ask for information that they already have and that this is solely used to verify the authenticity of the user. Using this process to generate novel data is an abuse of the system. I also personally feel that the public should be able to have more recourse for mistakes that are made by these companies (within reason). I still feel like there has not been enough recourse for the Equifax breach and that not enough has been done to protect citizens. I don't think this is an unpopular opinion, but ensuring our politicians are aligned with public beliefs is a whole other conversation.
[0] Personally I feel it is pretty obvious and apparent that credit agencies operate to collect and process data about people. It is then also apparent, to me, that of course the incentives align to them getting even more data about you as possible. It seems to me that anyone that is doing yearly report generating is highly likely to be aware of the business model. But not everyone is me so maybe that's not the intent. And what's obvious to one person isn't always obvious to others.