Live data from Hacker News

It's still easy for anyone to become you at Experian

krebsonsecurity.com

171–180 of 347 posts

Re: It's still easy for anyone to become you at Experian

#171
This makes me feel pure rage. The execs should be thrown in prison and the keys should be thrown away with them. Punish this at the highest levels, severely. The government needs to make examples out of them.

What even is the CISO doing? Sitting on her thumbs for a year?

Re: It's still easy for anyone to become you at Experian

#172
post #150

It's not just Experian. We publish an article every couple years or so with the same content and just the names changed: https://qbix.com/blog/2021/01/25/no-way-to-prevent-this-says... https://qbix.com/blog/2023/06/12/no-way-to-prevent-this-says... And then of course there is this: SIM swapping - someone can just steal your SIM and then get into a lot of accounts https://www.bloomberg.com/news/features/2023-08-04/tee…

Also, enable the SIM lock on your SIM! This will help prevent someone from receiving verification codes if they stole your SIM card.

Re: It's still easy for anyone to become you at Experian

#174

Earlier quoted context omitted.

“The credit agencies however offer you a real and valuable service. Without credit history it’s impossible to get credit.” I think I generally agree that this is a reasonable service, however the main reason you can’t get credit without a credit history is these services exist that can provide credit history to lenders. It is bizarre to think that loans would not exist without these services.

Loans did exist before credit, but it was almost always loans from friends/family or by providing a large down payment to the bank you wanted a loan from. You needed to be a known and upstanding member of the community to get a loan for anything substantial. And technically, you can get many loans today without a credit score. For example, there are bank statement mortgage loans, but they have caveats like: - you wil…

Additionally, while it may suck, and maybe there is some other emergent reality that sucks less, we practically live in this one. Don’t cut off your nose to spite your face.

Re: It's still easy for anyone to become you at Experian

#175

https://news.ycombinator.com/item?id=29834753 I was shocked to learn that last year about the level of detail they had. 1. All your mortgage, credit inquiries and bank account names 2. All your previous addesses and perevious employers 3. Your MONTHLY salary and combined comp per yer going back to 20XX when I came to the US. 4. Dates of employment per employer, bonus, overtime, RSU comp Does Experian and Transunion h…

> 3. Your MONTHLY salary and combined comp per yer going back to 20XX when I came to the US.

You work at a big company. Your employer is choosing to sell this information to credit bureaus.

I first learned about this practice in the mid-2000s. Like you, I was quite surprised, but they didn't have any data on my own income or assets yet, and I resolved never to work for an employer that would engage in this type of business practice.

I think employers should be legally required to disclose and obtain written consent to sell your income data, but beyond that point, it's really on you to decide what employment arrangements you are willing or unwilling to accept. It's sad that you had to find out this way given how easy it would be for these employers to just disclose it upfront. I'd recommend looking for a different employer.

Re: It's still easy for anyone to become you at Experian

#176
post #88

I’m guessing this will continue to happen until, I dunno, some the execs at Experian continually have their accounts compromised in the same way again and again.

The execs may be incompetent, they're probably not stupid, though- they don't use that shit.

This isn’t an opt-in service. It’s a dragnet surveillance system. All it knows is slurping up data. Are there case statements all over the codebases to exclude the execs of three different companies and congress?

Re: It's still easy for anyone to become you at Experian

#177
post #29

The fundamental issue here is that maintaining security is expensive, and it is cheaper to just deal with occasional hacks. The only solution is to make hacks extremely expensive to the companies that get hacked — through fines as well as lawsuits by victims of identity theft.

>The only solution is to make hacks extremely expensive to the companies that get hacked — through fines as well as lawsuits by victims of identity theft. It's notable this issue (verification by SSN) doesn't affect GDPR-land - the GDPR has fines of up to 4% of global turnover.

Fines for what? For getting hacked?

Re: It's still easy for anyone to become you at Experian

#178

FWIW 1. Freeze all your credit with experian, equifax and transunion 2. Opt out of them selling your info: https://consumerprivacy.experian.com/ https://myprivacy.equifax.com/opt-in-opt-out/personal-info https://service.transunion.com/dss/ccpa_optout.page

Experian allows unfreezing via their site in the article. If someone can easily recreate your account, they can unfreeze it which makes it pretty useless.

Re: It's still easy for anyone to become you at Experian

#179

Earlier quoted context omitted.

It is not that expensive. It is a couple pennies per pull (of a credit report/file) for somebody seeking identity proofing to use knowledge based authentication (the usual “where did you live, are these trade lines you?”). It is $1.50-$2.00 per proofing attempt with the government credential using ID.me or stripe identity. The problem is that no one is incentivized to slightly increases costs to reduce fraud because…

ID.me supports hardware 2FA, including Yubikey.

More importantly, they can require you provide a government ID and perform a liveness selfie check. This is the gold standard for remote identity proofing. Onboarding secure authenticators is best practice to bind digital identity to IRL identity when proofing occurs and identity assurance is high.

Re: It's still easy for anyone to become you at Experian

#180
post #29

Earlier quoted context omitted.

>The only solution is to make hacks extremely expensive to the companies that get hacked — through fines as well as lawsuits by victims of identity theft. It's notable this issue (verification by SSN) doesn't affect GDPR-land - the GDPR has fines of up to 4% of global turnover.

Fines for what? For getting hacked?

This isn't a "hack," this is pure almost malicious incompetence by everyone in the Experian security chain, straight up to the CISO herself.

They should absolutely be fined and punished harshly even beyond that. If SBF can go to prison, so can the CISO of Experian.

Post reply on HN