Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

281–290 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#281
post #150

Earlier quoted context omitted.

Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those au…

This is basically what Vanguard does if they get suspicious about your account security. Basically you have to show up at a notary with photo ID and get a form notarized.

Re: Cybersecurity Incident Involving Consumer Information

#282

Earlier quoted context omitted.

> customer is on the hook for 7 years 7 years? Are you sure it's not something like 7 days?

It takes 7 years for a bankruptcy to clear your credit record in the USA.

Not just bankruptcy. Banks and businesses contract with check verification companies such as ChexSystems. I had a friend who bounced a check and it took him a few weeks to reimburse the bank. By then the bank closed his account and reported him to Chex, who put a 5 year hold on his ability to get another checking account through any bank that used Chex verification (> 90%), essentially blackballed.

Re: Cybersecurity Incident Involving Consumer Information

#283
post #40

Time for criminal penalties for the management team. A breach like this will affect thousands of people monetarily and suck time from them they could have used elsewhere. If you've ever dealt with something like this, you know the hours it takes to rectify the damage. The only way corporations will learn to appreciate data security is when management teams suffer criminal penalties.

We don't know how the security breach happened. Should Equifax be criminally liable for using software which contains a remote-exploitable buffer overflow vulnerability? Or for the actions of a corrupt employee who stole some data and sold it on the black market?

It's possible that Equifax did something really negligent and if so maybe there should be a class-action lawsuit against the company. But it's also possible they did all the things they should have done and still failed because security is really hard and maybe the attacker got lucky.

Re: Cybersecurity Incident Involving Consumer Information

#285

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Sounds like such a freeze should be the default state.

Re: Cybersecurity Incident Involving Consumer Information

#286

Earlier quoted context omitted.

> customer is on the hook for 7 years 7 years? Are you sure it's not something like 7 days?

It takes 7 years for a bankruptcy to clear your credit record in the USA.

Ten, I think. Ten years. Or should I dispute that with the credit-reporting agencies?

Re: Cybersecurity Incident Involving Consumer Information

#288

Earlier quoted context omitted.

Why do we need to number people anyway? People are very consistent with spelling their own names. This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. Think about passwords. A SSN is only nine digits, 0-9. JohnHarrySmith19900101NewYork is far more secure. And doesn't dehumanize the recipient.

> People are very consistent with spelling their own names. Is this true of all people? > This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. For common names and large cities, probably not. > JohnHarrySmith19900101NewYork is far more secure. No, it's not; SSNs aren't passwords, and shouldn't need to be “secure” in that sense, but names aren't secret and birth dates and l…

> Is this true of all people?

Not even remotely.. My name has a space and an accent, it's always different. My wife's name is spelled differently on each of her birth certificate, drivers license, and social security card. And we have 'traditional' names.

Re: Cybersecurity Incident Involving Consumer Information

#289
post #121

Earlier quoted context omitted.

Bigbank is the only one in your scenario that actually has monetary loss since they lent out the money and most likely will never get it back. In identity theft, the company has the financial loss. FBI won't investigate unless its over 250k in losses as well.

Pretty twisted world where provable financial loss is the only or main measure.

[deleted]

Re: Cybersecurity Incident Involving Consumer Information

#290
The problem with the SSN is it is an identifier and a secret. It's a username and password in one, you can't change it and you need it for any substantial financial transaction.

Ideally, we'd have both a public username and a private password that we could change for our financial identification. This would eliminate most of the problems with these big data breaches. The backup for resetting a forgot password would be to show up in person and do some sort of biometric scan. Biometrics have to be done in person at a government office though since they aren't secret and cannot be changed. There shouldn't be an over the wire API for biometric identification because then you've got the SSN problem all over again, a combined username and password that's even more public than an SSN that can't be changed.

Post reply on HN