Live data from Hacker News

No matter what, Equifax may tell you you’ve been impacted by the hack

techcrunch.com

141–150 of 157 posts

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#141

Earlier quoted context omitted.

What do you mean by, "you can't touch their money"? You can spoof their identity, to instantly acquire material goods / lines of credit. And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.

>What do you mean by, "you can't touch their money"? If you had the number of my credit card, my account number, my social security number (or the local equivalent), my address or my name, or whatever else, short of my 2FA device and my internet banking credentials, you won't be able to steal anything. (And at that point, you might as well walk up to my house, break a window and steal whatever the hell you need while…

You seem to have jumped over the question of identity theft for applying for lines of credit. I believe this is what most people are concerned about.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#142
post #125

Earlier quoted context omitted.

In Sweden you use a special authentication method you install on your phone through your bank to prove your identity. It's basically a national 2FA. So when you for example declare your taxes you enter your social security number and authenticate the action with your phone each time. So no, I don't think there's any Equifax equivalent where a data leakage would enable stuff like this.

How does the bank know it is you or your phone when you open an account?

You open the account in person, by showing them your ID card. The bank has access to the central national database of IDs, so they can compare if the ID card shown by the person matches the information coming from the central db, matching the person showing it on the picture. Hence you have strong in-person proofing, that is now the basis for the 2FA.

Thats how it should be done, except in the US there is no way to check against a national database of IDs, not even on the state level with DMVs. You literally trust the plastic card the person shows you and thats where the problems start. Online its even worse.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#143
post #141

Earlier quoted context omitted.

>What do you mean by, "you can't touch their money"? If you had the number of my credit card, my account number, my social security number (or the local equivalent), my address or my name, or whatever else, short of my 2FA device and my internet banking credentials, you won't be able to steal anything. (And at that point, you might as well walk up to my house, break a window and steal whatever the hell you need while…

You seem to have jumped over the question of identity theft for applying for lines of credit. I believe this is what most people are concerned about.

It should be simple:

When applying for new accounts, or logging in from new devices, you should be receiving an email and/or sms on the endpoints of your choice. And then able to stop those things from happening.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#144
post #142

Earlier quoted context omitted.

How does the bank know it is you or your phone when you open an account?

You open the account in person, by showing them your ID card. The bank has access to the central national database of IDs, so they can compare if the ID card shown by the person matches the information coming from the central db, matching the person showing it on the picture. Hence you have strong in-person proofing, that is now the basis for the 2FA. Thats how it should be done, except in the US there is no way to c…

I see, so if you temporarily steal a card from a person who looks like you, you can open acccounts in their name?

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#145
post #67

Earlier quoted context omitted.

In the US, a combination of personal information is taken by most as proof that you are who you claim to be. If you know enough of someone else's information, you can steal money rather easily. We need a better identity solution, but it's what we have right now.

There is probably no way to make that work, without improving the security. Same thing with credit cards, is it so hard to ask for a PIN when trying to pay with them? Or use 2FA like in any internet banking? For what it's worth, here in Europe you could pretend to be someone else as well, if you have enough information, but what's the point when you can't touch their money?

> Or use 2FA like in any internet banking?

That's the funny part - there's no 2fa available for most internet banking in Canada or the US. In Denmark we get the NemID card mailed to us, but in Canada it's just your card number+password+sometimes they ask a security question like "what high school did you go to?"

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#146
post #142

Earlier quoted context omitted.

How does the bank know it is you or your phone when you open an account?

You open the account in person, by showing them your ID card. The bank has access to the central national database of IDs, so they can compare if the ID card shown by the person matches the information coming from the central db, matching the person showing it on the picture. Hence you have strong in-person proofing, that is now the basis for the 2FA. Thats how it should be done, except in the US there is no way to c…

@EGreg below me - no, the national database has biometric information including finger and retina prints as well (definitely fingerprints, not sure of retina prints). The bank is able to check that too.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#147
post #141

Earlier quoted context omitted.

>What do you mean by, "you can't touch their money"? If you had the number of my credit card, my account number, my social security number (or the local equivalent), my address or my name, or whatever else, short of my 2FA device and my internet banking credentials, you won't be able to steal anything. (And at that point, you might as well walk up to my house, break a window and steal whatever the hell you need while…

You seem to have jumped over the question of identity theft for applying for lines of credit. I believe this is what most people are concerned about.

There have indeed been issues of identity theft here in Sweden where the thieves ordered a new login to the 2fa app and then managed to get hold of it from postal offices with bad verification processes.

So now the practice is to fetch the credentials from the nearest bank office or something like that.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#148
post #57

In Sweden your social security number is public information. What's the reason for it being private in the US? Sounds like a horrible thing to rely on for security anyway.

Well I mean, what it comes down to is you need someway of establing that it's actually you over a phone or Internet and you can assume that an equifax-equivalent would be storing that info regardless of exactly what it is in Sweden.

If I call my bank, the bank personnel can (and do) request a challenge to the 2fa app. Same with connections over the Internet.

The 2fa app is driven by a separate company that only does identification service.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#149
post #144
post #142

Earlier quoted context omitted.

You open the account in person, by showing them your ID card. The bank has access to the central national database of IDs, so they can compare if the ID card shown by the person matches the information coming from the central db, matching the person showing it on the picture. Hence you have strong in-person proofing, that is now the basis for the 2FA. Thats how it should be done, except in the US there is no way to c…

I see, so if you temporarily steal a card from a person who looks like you, you can open acccounts in their name?

Yes. If you steal the ID card or passport of a person who looks like you, you can do most things in life in their name. Take out a loan, travel the world, get married, etc.

The major benefits compared to SSN authentication still are:

* It's a physical object, you have to be physically present to steal each one instead of getting a hundred million at a time.

* Most people would quickly notice that their card is gone, report it, and get it revoked. You only have between a few hours to a week to use it, not the next 50 years.

Re: No matter what, Equifax may tell you you’ve been impacted by the hack

#150
post #144
post #142

Earlier quoted context omitted.

You open the account in person, by showing them your ID card. The bank has access to the central national database of IDs, so they can compare if the ID card shown by the person matches the information coming from the central db, matching the person showing it on the picture. Hence you have strong in-person proofing, that is now the basis for the 2FA. Thats how it should be done, except in the US there is no way to c…

I see, so if you temporarily steal a card from a person who looks like you, you can open acccounts in their name?

Yes if you forge a drivers license or passport with my name and id number, and you put your own photo on it (or happen to look like me) you could probably do something bad like get a phone contract or request a credit card in my name.

However, most of those scenarios have the added security that the CC or some necessary confirmation letter to sign is sent to the registered address of that id. So you'd also have to stalk my mailbox to actually get the credit card. This actually happens - so people use locked mail boxes to protect against this.

That is, even for this "manual" id method, there is 2fa in the form of regular mail, made possible by the fact that you can't use my id and give them your street address. When you show my id - they immediately know what address belongs to that id.

Post reply on HN