Live data from Hacker News

Equifax takes down web page after reports of new hack

reuters.com

131–140 of 143 posts

Re: Equifax takes down web page after reports of new hack

#131

Earlier quoted context omitted.

The IRS can use the previous year's filing address for all tax payers. They should be able to use the US Post Office to get address updates. In the US people generally file a change of address when they move in order to automatically receive mail at their new address. The fact that the IRS granted Equifax a 7 million dollar contract amounts to the US tax payer paying Equifax to put their identity at risk and cause th…

USPS address forwarding is only good for six months.

The point is not how long mail forwarding is good for but rather the USPS already has up to date mailing address information for US citizens.

If the IRS is using Equifax for proper address verification as the OP states, then that information is already available via the USPS which is a government agency with real oversight.

Re: Equifax takes down web page after reports of new hack

#132
post #96
post #39

Earlier quoted context omitted.

What is "your data" exactly? And in the limit, how far does this go? Here's a question: who owns your drivers license? Here's a hint: it isn't you. Can you "own" you mailing address? Copyright and trademark it, make everyone ask permission from you before they write it down? What about your salary? Should your employer have to ask every time they use your salary number in some way, say in aggregate statistics or repo…

"My data" is data about me because without me it wouldn't exist.

And this is my comment, which wouldn't exist without me, and I don't give you permission to read, link to, or reproduce it.

Re: Equifax takes down web page after reports of new hack

#133
post #125

Earlier quoted context omitted.

You can essentially opt out. Just never apply for credit in your life. Good luck. At the end of the day you do consent to this through participating in the banking/credit system. While the data may not exist without you, you are not the one recording it. Why does it not make sense to assign ownership to the one recording/creating the data in the first place?

You consent to X when you do Y, where Y is not explicitly consenting to X, is not a valid argument.

It's valid if X is having your picture taken and Y is being in public.

Re: Equifax takes down web page after reports of new hack

#134
post #6

The incompetence is mindblowing. Could this be a good argument for software engineers to get their professional license?

No, because then you get things like this happening:

https://www.clickondetroit.com/news/fake-architect-sentenced...

Also, consider how much of the software you use on a regular basis would not exist, if mandatory licensing were in place.

Re: Equifax takes down web page after reports of new hack

#135
post #39

Earlier quoted context omitted.

Doesn't this require you to trust Equifax to enforce and honor the freeze? I think the solution is "I don't want my report or any of my data in any sort of control or possession of Equifax". Where is that solution?

What is "your data" exactly? And in the limit, how far does this go? Here's a question: who owns your drivers license? Here's a hint: it isn't you. Can you "own" you mailing address? Copyright and trademark it, make everyone ask permission from you before they write it down? What about your salary? Should your employer have to ask every time they use your salary number in some way, say in aggregate statistics or repo…

If you're curious about the future of privacy, while flawed in some ways, the GDPR (General Data Protection Regulation) comes into effect in the EU next May. Here's their definition of personal data [1]:

  "Personal data means data relating to a living individual who is or can be identified either from the data or from the data in conjunction with other information that is in, or is likely to come into, the possession of the data controller. This can be a very wide definition depending on the circumstances."
And then we have this:

  "Right to change or remove your details

  If you discover that a data controller has details about you that are not factually correct, you can ask them to change or, in some cases, remove these details.

  Similarly, if you feel that the organisation or person does not have a valid reason for holding your personal details or that they have taken these details in an unfair way, you can ask them to change or remove these details.

  In both cases, you can write to the organisation or person, explaining your concerns or outlining which details are incorrect. Within 40 days, the organisation must do as you ask or explain why they will not do so."
It's true that enforcement is difficult -- I imagine it'll be more reactive than proactive. That said, a breach is handled quite well, assuming the law is enforced:

https://www.dataprotection.ie/docs/Data-Security-Breach-Code...

The GDPR is a solid step in the right direction, and a model for a better approach to privacy.

[1] https://www.dataprotection.ie/docs/A-guide-to-your-rights-Pl...

Re: Equifax takes down web page after reports of new hack

#136
post #53

Earlier quoted context omitted.

Well, these guys are simply too big to fail. Equifax cannot go bust, otherwise loads of consumer credit (mortgages, car loans etc) would freeze up, causing huge harm to the economy. The market likely knows this, hence the stable stock price.

Equifax cannot go bust, otherwise loads of consumer credit (mortgages, car loans etc) would freeze up Nope - there are two others who will gladly take up the slack.

My company would be really hampered if Equifax went bust. We do use two other credit bureaus, but some functions depend on data only Equifax provides.

We also use the different bureaus together for cross checking, often one bureaus file will be out of date or have errors, while the other is fine. So we'd have a much harder job of calculating risk if one of the big bureaus went out of business, simply because we'd be losing a major data source that drives our business.

I am very sure this case applies to other financial institutions as well.

Re: Equifax takes down web page after reports of new hack

#137

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

[deleted]

Re: Equifax takes down web page after reports of new hack

#138
post #51

Earlier quoted context omitted.

I'd be amazed if the average/combined skill level of engineers at any large company exceeds the average/combined skill level of the people trying to compromise its security. And that's not taking into account the bureaucratic overhead necessary to make changes in such an environment. There are very good, and very bad, reasons why upgrading insecure software and fixing other security holes takes too much time and effo…

Libraries, frameworks, and other security systems don't have to be developed in-house. It's just like basic data structures and algorithms: few ought to be rolling their own and should instead be using libraries.

All of those are insecure, so it's still a matter of staying ahead of attackers. And avoiding social engineering. And making certain the code that glues those libraries and frameworks together is secure. And making sure people don't accidentally leave an S3 bucket unsecured. And making sure every 3rd party contractor on-site doesn't take advantage of softer internal security. And making sure employees aren't bribed by competitors.

And making sure the business can still function while doing your best to limit functionality.

Re: Equifax takes down web page after reports of new hack

#139
post #125

Earlier quoted context omitted.

You consent to X when you do Y, where Y is not explicitly consenting to X, is not a valid argument.

It's valid if X is having your picture taken and Y is being in public.

I agree that people make themselves vulnerable to someone taking their picture by going outside, but I strongly disagree that people consent to having their picture taken.

Re: Equifax takes down web page after reports of new hack

#140
post #139

Earlier quoted context omitted.

It's valid if X is having your picture taken and Y is being in public.

I agree that people make themselves vulnerable to someone taking their picture by going outside, but I strongly disagree that people consent to having their picture taken.

Well, maybe it's more accurate to say that it's impossible to consent because no consent is required to take someone's picture in public. People generally exercise control by choosing not to be in public. You could say that having your picture taken is part of the terms of service of using public space. When you agree to something, you also agree to all of the consequences. Just because they are implicit doesn't make them invalid.

Don't get me wrong, I don't particularly like having my picture taken without my explicit consent. In the end, consent is all rather arbitrary because it's not like you can choose not to live in human society on Earth.

Post reply on HN