Live data from Hacker News

The Equifax Hack Didn't Have to Be This Bad

bloomberg.com

11–20 of 74 posts

Re: The Equifax Hack Didn't Have to Be This Bad

#12
post #9

The hack isn't just SSNs - it includes address history, date of birth, drivers license number - everything reasonably necessary to establish identity. Not sure why the focus is SSNs, any solution needs to be even higher. This is about companies stockpiling our personal information and us having little say in the matter.

The reason the focus is on the SSN is because it enables credit. Privacy is important, but so is protecting your finances.

Re: The Equifax Hack Didn't Have to Be This Bad

#13

"The only thing Social Security numbers should be used for is to pay our taxes, which identity thieves are welcome to do." Likely they may not be paying taxes, but have already found a way to circumvent the system such that they collect something (aid, EI, etc).

Actually what they do is early filing to receive any refund that would be coming to you.

Re: The Equifax Hack Didn't Have to Be This Bad

#14
Consumers don't use the credit reporting database, we have very little access to it besides restricted annual or paid for reports. The real users are the B2C companies like retail banks, cell phone companies, apartments, background checkers, etc. These B2Cs use the db in both read and write modes with little verification. The main incentive of the reporting agencies is to make it very easy for B2Cs to read and write to their db. Any strong encryption scheme would have to take into account the needs of the B2C's. Nothing is going to happen unless congress demands it because their is no market incentive to secure it. The data is already known to be frequently inaccurate but businesses don't care, they'd rather have a bunch of false positives than one deadbeat customer.

Re: The Equifax Hack Didn't Have to Be This Bad

#15
I'm very worried about this.

I've done a lot to try and build my credit and protect my identity by restricting the information I give out. Now I can do nothing to protect it now besides hope someone doesn't target me.

Anyone have ideas on how to ensure an identity is not stolen?

Re: The Equifax Hack Didn't Have to Be This Bad

#16
post #4
post #3

Earlier quoted context omitted.

It is, and is related to some of the discussion in the main Equifax hack threads. The idea is that this information shouldn't be so sensitive because it isn't really secret in the first place. It also cannot be changed, so it doesn't really meet any reasonable criteria for authenticating information. To quote the relevant top-level comment I had in mind: >mikeash 2 hours ago [-] >If we're lucky, this will be the best…

Also note that other countries don't have this insanity.

Which countries do you mean? How do they manage their credit scores?

Re: The Equifax Hack Didn't Have to Be This Bad

#17
In 2008, the Federal Trade Commission created the Red Flags Rule, which required businesses and organizations to collect personally identifying information from their customers, even if not necessary for service. This put Social Security numbers into the hands of utility companies, telecom providers, doctors and countless other unreliable custodians.

This is the first I've heard of this, and it's a different characterization than what one finds on e.g. Wikipedia (excepting the last section of that page). Still, I believe TFA. It's remarkable how often the impetus to "do something" leads to precisely the wrong thing being done.

Re: The Equifax Hack Didn't Have to Be This Bad

#18
post #4
post #3

Earlier quoted context omitted.

It is, and is related to some of the discussion in the main Equifax hack threads. The idea is that this information shouldn't be so sensitive because it isn't really secret in the first place. It also cannot be changed, so it doesn't really meet any reasonable criteria for authenticating information. To quote the relevant top-level comment I had in mind: >mikeash 2 hours ago [-] >If we're lucky, this will be the best…

Also note that other countries don't have this insanity.

Canada does unfortunately. It's called a Social Insurance Number (SIN) or Numéro d'assurance sociale (NAS) but other than the name, it is mostly the same. And Canada is on the list of the countries suffering from the breach. This should be interesting.

Re: The Equifax Hack Didn't Have to Be This Bad

#19
So since anyone who has access to the breached info can impersonate nearly anyone in the country...

1) Are we about to see the end of "Name, DoB, last four" as an authentication? (Damn well should if anybody can be me now)

2) Are the credit reporting agencies discredited as a business model? The other two are likely either hacked already or about to be, and given this standard of reporting we wouldn't know till months from now anyway.

Can't trust em, don't use em, don't trust anybody that does.

Oh joy.

Re: The Equifax Hack Didn't Have to Be This Bad

#20
post #15

I'm very worried about this. I've done a lot to try and build my credit and protect my identity by restricting the information I give out. Now I can do nothing to protect it now besides hope someone doesn't target me. Anyone have ideas on how to ensure an identity is not stolen?

You can use a credit freeze: https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq...

> Also known as a security freeze, this tool lets you restrict access to your credit report, which in turn makes it more difficult for identity thieves to open new accounts in your name. That’s because most creditors need to see your credit report before they approve a new account. If they can’t see your file, they may not extend the credit.

I've never done this, but it sounds effective - although if you want to open another line of credit, you'll have to temporarily suspend the freeze.

Post reply on HN