Live data from Hacker News

Equifax’s Maddening Unaccountability

nytimes.com

191–200 of 238 posts

Re: Equifax’s Maddening Unaccountability

#191

Earlier quoted context omitted.

I heard in US if somebody knows your SSN, he can take a loan accounted to you by phone. It is so strange. What gives banks right to do that?

There is a huge difference between taking a loan "on someone's behalf" (as their representative, eg by someone with power-of-attorney) versus via impersonating them. The former is rare but legitimate; the latter is fraud.

It may be fraud, but if it's possible, that's still a problem.

SSN can not be used as authorization, because it isn't secret information. And really, the same is true for credit card numbers; they're shared with too many parties to consider them secret.

Re: Equifax’s Maddening Unaccountability

#192

Earlier quoted context omitted.

That's the point, you have to pivot. If you don't have to jump through another host or two to get unfettered database access from web tier, you're doing it wrong.

It wouldn't have changed Equifax's situation at all. Everyone would still be just as outraged. It occurs to me that maybe it might seem like pivoting is a big process that takes months. In reality you can map out an internal network within a few hours. Most people keep the servers at the edge of their network meticulously up to date. Once you're inside, you find way more old software. Not to mention creds just laying…

That's one thing the org I work for does right.

We do have monthly tests, scans, and network BGP issues. And our governmental side has a different set of scans, which also include system security scans.

Whomever the oncall is, ends up doing them during the week. It's usually pretty quick, but can turn into a slog.

Oh, and all our machines are updated appropriately, not just the border machines. There are some services we're not able to adequately update, like FreeRadius - but for each of those we review the criticality and determine if we need the resources to make it work (aka: remote priv exploit)

Re: Equifax’s Maddening Unaccountability

#193
post #54

Earlier quoted context omitted.

There's incentive (as it's their job, or is said to be). What there isn't is a downside if they don't.

If we're talking about economic incentive, having no downside for not doing thing A is equivalent to having no incentive to do thing A. Re: opportunity cost.

Yes. In economics that's the context. But in terms of civics, I think the term is: voter apathy.

Re: Equifax’s Maddening Unaccountability

#194

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

I still hold that this shouldn't matter to consumers. My priority of problems is * When fraud happens, banks can pass the pain and burden of proof onto consumers. * Banks use insecure SSNs for authorization; some data is used for validating eligibility, authenticating the application, and authorizing the loan. * There are minimal regulations on storing different classes of personal information (We need sarbanes-oxley…

I see it differently.

It's my meta data. More valuable than phone meta data, and perhaps (to me) more valuable than my medical records. I have a relationship (as well as ethical and legal protections) with my doc. On the other hand, I've never met Equifax. They have no relationship with me other than to exploit my personal info. I never opted into that.

Yes. It lowers risk. But who benefits more? Who carries the risk? Me? Or them? It's the latter, yes. Yet we have no choice in the matter? That's not kosher.

Re: Equifax’s Maddening Unaccountability

#195
post #119

Earlier quoted context omitted.

Yes, many times. It is not that hard to not base your entire banking system on a single number anyone can use .

What gives banks right to consider SSN an authenticator? Is there a law allowing that? Common sense suggests it should only be possible if user explicitly accepted "I agree that knowing my SSN is enough to prove it's me and I agree to be liable to any debts created with just my SSN presented".

But isn't your SSN given by the government? Does the US government require anyone to sign such an agreement before they get an SSN? Without it, a bank claiming I owe them money because "we got your SSN" is fraudulent, plain and simple. Report the bank to the FBI.

But that's probably far too sensible European thinking.

I regularly keep hearing reports of how the US handling of money is basically medieval with some badly thought out insecure bits pasted on top. And some of that gets exported! It sucks that I need to own a credit card to be able to make international purchases on the internet. Why is there not an international version of iDEAL?

Re: Equifax’s Maddening Unaccountability

#196
post #105

Earlier quoted context omitted.

At some level I think the banks are stuck in a conflict of interest with regard to risk. The reason we need banks and credit agencies is precisely because there is risk . If transacting parties could trust each other without an intermediary we could all just trade directly and all would be fine. So banks are actually disincentivised to create a world where risk is very low. They also don't want it to be very high. Th…

I suppose at a very high level your thesis might be true, but at a practical level, I don't think it is. The banks have simply seen it's cheaper to eat the cost of fraud (and ensure the victim has the burden of proof wherever possible) than implement stricter security measures. This goes from the transaction terminal to the bank's server room. Europe has had chip cards for over 20 years. In the US, it was very recent…

Re: Cost of fraud.

Agreed. It still amazes me how prevalent credit card fraud is. Certainly that's preventable - if they want it to be. The problem is, the banks don't bear that cost, the consumer does. Even if the bank factors the loss into the cost of doing business, that still gets passed on to the consumer.

Re: Equifax’s Maddening Unaccountability

#197
post #190

Earlier quoted context omitted.

I suppose at a very high level your thesis might be true, but at a practical level, I don't think it is. The banks have simply seen it's cheaper to eat the cost of fraud (and ensure the victim has the burden of proof wherever possible) than implement stricter security measures. This goes from the transaction terminal to the bank's server room. Europe has had chip cards for over 20 years. In the US, it was very recent…

Well here in europe it didn't happen all at once. It was a gradual rolling of chip based cards, atms and terminals. There was a non-insignificant amount of time where some atms / pos terminals would reject your card because you/it didn't have the right technology. But ultimately I think its the people themselves that demand more security from their banks. E.g. Bank one introduces chip based cards and more people choo…

I think people would demand more security if they really understood how venerable the technology was. But no one beats that drum. So consumer remain ignorant and just keep shopping.

Re: Equifax’s Maddening Unaccountability

#198
post #52

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

We have all agreed. We gave permission to any company that extends credit. They give our information to these credit reporting agencies on an on-going basis, personal information, including what our payment behavior and history is. All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very sim…

If she still wants to use Uber, you can add a link to https://m.uber.com to her homescreen, no app needed. It also avoids the tracking after leaving the car (assuming she closes the site).

Re: Equifax’s Maddening Unaccountability

#199
post #52

Earlier quoted context omitted.

We have all agreed. We gave permission to any company that extends credit. They give our information to these credit reporting agencies on an on-going basis, personal information, including what our payment behavior and history is. All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very sim…

If an app wanted all that just to call a cab, I’d say “fuck no”, too. (Not an Uber/Lyft user, can’t confirm.) GPS, that’s all you need, and that’s all you’ll get. If you need more, ask me directly instead of digging through my shit.

Android, at least until very recently, had no way of asking at the point of use, despite being a feature in Symbian S60 since before the iPhone :|

Re: Equifax’s Maddening Unaccountability

#200
post #74

Earlier quoted context omitted.

> You may want to think twice. Try to design an architecture that doesn't have that. We have an architecture like that where I work. It's not that hard. Our web applications have very little direct access to databases; most of it is mediated by services downstream of the web app. That's certainly not a silver bullet, but it makes it impossible to exploit a RCE vuln in the web server in such a way that it lets you hav…

And let me guess. Those services give the webservers...the data that they ask for? Once you've compromised a server, learning how to ask for the data you want is not hard. You have access to all the webserver's code, can make full dumps of communications occurring normally in the app, etc.

The believe the usual way is to have a separate authentication service, to which you send the user's credentials and you get a token that you can use to request only that user's data.

That means, barring other exploits, you can only access the info from the users who logged in while you had control of the machine.

Post reply on HN