Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

21–30 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#21

Earlier quoted context omitted.

You've sold me, now tell me how to do it

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

/me sighs

The Equifax site appears broken in at least some browsers. Transunion wants me to sign up for an online account, and Experian charges a $10 fee in my state to place a freeze.

All three want to collect my name, DOB, SSN, etc. _again_ in order to sign up.

This is complete and utter BS. Credit reporting agencies are one of the greatest/worst rackets in the modern financial system.

Re: Cybersecurity Incident Involving Consumer Information

#23
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

I believe you CAN change your SSN https://faq.ssa.gov/link/portal/34011/34019/article/3789/can... . Especially if you have "cultural objections to certain numbers".

Re: Cybersecurity Incident Involving Consumer Information

#24

Earlier quoted context omitted.

You've sold me, now tell me how to do it

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

I don't understand this. Equifax claims they just leaked my SSN, Drivers License, and other pertinent data to everybody. How would they possibly confirm that I am the one lifting the 'freeze'?

Re: Cybersecurity Incident Involving Consumer Information

#25

Earlier quoted context omitted.

You've sold me, now tell me how to do it

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

I think you are missing something. Here's what's needed to initiate your TransUnion freeze:

To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during the past two years 6. Email address 7. A copy of a government-issued identification card, such as a driver’s license or state ID card, etc. 8. A copy of a utility bill, bank or insurance statement, etc.

So, if I hack TU, all I need to do is get the data of the people who asked for a credit freeze.

The problem is these companies, who non of us ever chose or nominated to collect our data, are careless with our PII. And until some accountability is added into the system, this will continue.

I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. Preferably with their jobs.

Re: Cybersecurity Incident Involving Consumer Information

#27
post #20
post #9

Is anyone being punished for all of the massive security breaches which appear to be happening on a nearly daily basis?

Well, they try to find and convict the hackers, of course. Or did you mean the companies like Equifax, or Target, or Home Depot that are the victims of the break-ins?

In some of these cases, the victims have been negligent with the data entrusted to them by consumers, who are themselves victims.

Re: Cybersecurity Incident Involving Consumer Information

#29
post #20
post #9

Is anyone being punished for all of the massive security breaches which appear to be happening on a nearly daily basis?

Well, they try to find and convict the hackers, of course. Or did you mean the companies like Equifax, or Target, or Home Depot that are the victims of the break-ins?

I mean the companies like Equifax. Is there nothing illegal about being careless enough to leak this much important information to hackers? I personally think they should be held accountable.
Post reply on HN