Live data from Hacker News

The Equifax Hack Didn't Have to Be This Bad

bloomberg.com

31–40 of 74 posts

Re: The Equifax Hack Didn't Have to Be This Bad

#31
post #12
post #9

The hack isn't just SSNs - it includes address history, date of birth, drivers license number - everything reasonably necessary to establish identity. Not sure why the focus is SSNs, any solution needs to be even higher. This is about companies stockpiling our personal information and us having little say in the matter.

The reason the focus is on the SSN is because it enables credit. Privacy is important, but so is protecting your finances.

Date of birth and address history (in addition to SSN of course) are often used by financial organizations to verify user identity online and on the phone.

Recently I called to report a lost credit card, for instance, and the operator read through a list of 10 addresses. I had to confirm which ones I'd lived at at some point in my life, in order to verify my identity.

Re: The Equifax Hack Didn't Have to Be This Bad

#32
post #20
post #15

I'm very worried about this. I've done a lot to try and build my credit and protect my identity by restricting the information I give out. Now I can do nothing to protect it now besides hope someone doesn't target me. Anyone have ideas on how to ensure an identity is not stolen?

You can use a credit freeze: https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq... > Also known as a security freeze, this tool lets you restrict access to your credit report, which in turn makes it more difficult for identity thieves to open new accounts in your name. That’s because most creditors need to see your credit report before they approve a new account. If they can’t see your file, they may not ex…

It's not really effective. It can help, but a surprisingly large number of businesses will actually never actually run your credit. They will just keep your information on file and then when the scammer doesn't pay the loan, they start reporting the delinquency to the credit reporting agencies. And in that case, the freeze doesn't apply.

Re: The Equifax Hack Didn't Have to Be This Bad

#33
post #15

I'm very worried about this. I've done a lot to try and build my credit and protect my identity by restricting the information I give out. Now I can do nothing to protect it now besides hope someone doesn't target me. Anyone have ideas on how to ensure an identity is not stolen?

There is only one solution and that is identity theft insurance.

All other solutions that purport to protect your credit are futile. Although I think some are now offering insurance as part of their guarantee.

I use Zander identity theft insurance. If my identity is ever stolen, they are supposed to take over all the hassles of getting me right. As well as up to a million dollars in damages including legal fees if necessary.

I have heard good things from customers who had their identity stolen. But I can't personally vouch for how well their recovery services work since I havent experienced a theft yet.

Re: The Equifax Hack Didn't Have to Be This Bad

#34
post #15

I'm very worried about this. I've done a lot to try and build my credit and protect my identity by restricting the information I give out. Now I can do nothing to protect it now besides hope someone doesn't target me. Anyone have ideas on how to ensure an identity is not stolen?

Move somewhere which has a reasonable personal identity scheme.

Re: The Equifax Hack Didn't Have to Be This Bad

#35
post #27

The Republic of Estonia uses such a system to identify members of its e-Residency program, even with no physical presence. Each e-resident has a public numerical key that serves as a unique identifier, and a corresponding private key that is never revealed. So an example to emulate then! Except: Estonia suffered an embarrassing blow to its much-vaunted ID cards that underpin everything from electronic voting to onlin…

Is there a link to this that's not behind a paywall. Very interested in understanding the flaws of such a system, as a 2 key system seems like the most viable and secure way to establish identity.

Google's cache of the page [1] seems to work.

[1]: https://webcache.googleusercontent.com/search?q=cache:wP7nTG...

Re: The Equifax Hack Didn't Have to Be This Bad

#36
post #27

The Republic of Estonia uses such a system to identify members of its e-Residency program, even with no physical presence. Each e-resident has a public numerical key that serves as a unique identifier, and a corresponding private key that is never revealed. So an example to emulate then! Except: Estonia suffered an embarrassing blow to its much-vaunted ID cards that underpin everything from electronic voting to onlin…

Is there a link to this that's not behind a paywall. Very interested in understanding the flaws of such a system, as a 2 key system seems like the most viable and secure way to establish identity.

Non-paywalled link: http://estonianworld.com/technology/possible-security-risk-a...

Re: The Equifax Hack Didn't Have to Be This Bad

#37
post #31
post #12

Earlier quoted context omitted.

The reason the focus is on the SSN is because it enables credit. Privacy is important, but so is protecting your finances.

Date of birth and address history (in addition to SSN of course) are often used by financial organizations to verify user identity online and on the phone. Recently I called to report a lost credit card, for instance, and the operator read through a list of 10 addresses. I had to confirm which ones I'd lived at at some point in my life, in order to verify my identity.

Wouldn't it have been simpler and more secure to ask you for the address? I can rattle off all the addresses I've stayed at in the last 15 years with ease.

Re: The Equifax Hack Didn't Have to Be This Bad

#38
post #29

Earlier quoted context omitted.

I recently encountered an advertisement advising people to keep their Medicare card number secret. So if the SSN stops being considered as a combination identifier/authenticator, other government agencies stand eager and ready to plunge headlong into the same mistake. The way around it is to pass a law that requires government agents and agencies to consider identifiers to be public, and authenticators to be secret,…

Is the problem really government agencies or the many companies which tried to cut costs by misusing an identifier as an authentication secret? The law you propose seems like it would have no effect whatsoever unless it applied to the private companies which created and perpetuate this problem.

If SSN didn't exist then some equivalent (perhaps driver's license number and state? that would be convenient for non-drivers!) would be used, because the problem is actually at a different level. The way the laws governing banks and the credit industry are structured, it's possible to be on the hook for debt without a reliable proof of having agreed to that debt. If the laws changed to require that proof (e.g. creditors must have a video of the debtor stating "I am Alice Smith my birthday is July 1 1970 I live at 123 Main St in Springfield and I agree to pay $100 on or before January 1" or something similarly difficult to fake at scale), nobody would care about SSNs anymore. Of course that would introduce friction to the process, but with consumer debt at its current levels maybe that would be a good thing?

Re: The Equifax Hack Didn't Have to Be This Bad

#39
post #9

The hack isn't just SSNs - it includes address history, date of birth, drivers license number - everything reasonably necessary to establish identity. Not sure why the focus is SSNs, any solution needs to be even higher. This is about companies stockpiling our personal information and us having little say in the matter.

And any central database of this information is vulnerable to a one time leak. One period of vulnerability and potentially this information is out there forever. Once that happens automated identity verification becomes much less reliable/convenient and there will potentially be a need for a more Turing-complete and/or hardware dependent process.

Re: The Equifax Hack Didn't Have to Be This Bad

#40
post #37
post #31

Earlier quoted context omitted.

Date of birth and address history (in addition to SSN of course) are often used by financial organizations to verify user identity online and on the phone. Recently I called to report a lost credit card, for instance, and the operator read through a list of 10 addresses. I had to confirm which ones I'd lived at at some point in my life, in order to verify my identity.

Wouldn't it have been simpler and more secure to ask you for the address? I can rattle off all the addresses I've stayed at in the last 15 years with ease.

I couldn't. I am a city dweller living in a climate where almost like clockwork a post-two year rent hike makes me decide to move. not only that, being on a grid system every address tends to be some 4 digit combination of numbers very similar. Was that 1124 or 1421 10 years ago? I'd have to sit and picture the cross streets to figure it all out.
Post reply on HN