Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

341–350 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#341
post #55

Earlier quoted context omitted.

I would not doubt a class action lawsuit results from this, and I'd be very surprised if Elizabeth Warren didn't pursue congressional action against them (although not officers of the company unfortunately).

And then I'll get six months of free credit monitoring from Equifax? Oh boy!!1! More seriously, this is a breach big enough that Equifax should honestly no longer exist as a company. So call it $100/incident, and I'm happy. Other agencies would still exist, and, although they're just as terrible, it might get them to kick their asses into high gear to fix their security.

Maybe, the suggested demise of Equifax, the extreme perpetrator of neglect in this particular case, should lose the ability to print money, much like Symantec and other ssl cert issuers (identity certifies) for their recklessness; perhaps that doesn't go far enough.

Maybe the whole commercial enterprise of credit reporting (and identity verification) needs to be dramatically reworked in a more modern, sane design, with different governance and oversight.

Re: Cybersecurity Incident Involving Consumer Information

#342

Earlier quoted context omitted.

Your statement is nonsense. Regardless of your efforts, the best you can ever hope for is to minimize the chance of your car being stolen. You can never prevent it completely. If your car is stolen in spite of your best efforts, are you at fault? Do you still have to deal with the consequences as a victim of that theft?

Which thus makes it equivalent to a scenario where you have no power to influence things whatsoever?

Which makes your statement (that you have sufficient control to prevent the possibility of theft of your property) completely invalid. You can do everything right, and through no fault of your own have things go wrong.

Re: Cybersecurity Incident Involving Consumer Information

#343
post #36

Earlier quoted context omitted.

The SSN was never intended as a national ID. It was originally created alongside the Social Security Administration, to track what individuals put in and what they take out. People only received one upon becoming employed. Over time, the IRS realized that it could be used as a national ID, and adopted it for that purpose. They encouraged people to obtain one from a young age (even for their newborn children), and it…

Why do we need to number people anyway? People are very consistent with spelling their own names. This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. Think about passwords. A SSN is only nine digits, 0-9. JohnHarrySmith19900101NewYork is far more secure. And doesn't dehumanize the recipient.

There are 8 billion people on Earth. You are a number sometimes. It's okay for {your passport, your driver's license, your social security card, your credit card, your bank accounts, etc} to treat your account as a number.

The SSN just acts as a (largely) unique identifier. In the US, it also serves as proof that someone is eligible to work in the country. It's also the primary key for the account which collects my Social Security earnings over my career.

You are asking the wrong question. Neither of the keys you identify, whether it be "123-45-6789" or "JohnHarrySmith19900101NewYork", is "secure". Perhaps the latter has more entropy, but it's not the equivalent of your password when you log into a website -- it's the equivalent of your username. When you fill out a federal form like your tax form, anyone who sees the form sees your Social Security number.

If we were talking about making Social Security secure, your Social Security card would be plastic/metal and have a chip in it, similar to an EMV chip. It would have a private key which can be used to sign digital contracts and can be used to generate login tokens. It's effectively a private key that generates different public keys for each interaction/transaction you need to perform with it. Right now, Social Security is entirely about "what you know" with an easy to fabricate "what you have" and has no "who you are" factors.

Re: Cybersecurity Incident Involving Consumer Information

#344
post #78

Earlier quoted context omitted.

Requiring better proof of identity would create friction to consumer credit transactions.

Yes it would, and that (the extra friction) is exactly what should be done to fix the identity theft problem. It's far too easy to get credit in your name, so easy that it can be done by others. But the change won't happen by itself unless a shift of liability away from the users makes it so that every company doing anything on credit sees that it obviously makes business sense for them to implement the extra frictio…

Sorry, what I meant was: that's not happening because the status quo is better for the people who make the rules. :)

Re: Cybersecurity Incident Involving Consumer Information

#346

Earlier quoted context omitted.

Which thus makes it equivalent to a scenario where you have no power to influence things whatsoever?

Which makes your statement (that you have sufficient control to prevent the possibility of theft of your property) completely invalid. You can do everything right, and through no fault of your own have things go wrong.

> Which makes your statement (that you have sufficient control to prevent the possibility of theft of your property) completely invalid.

Luckily, I didn't say that.

Re: Cybersecurity Incident Involving Consumer Information

#347

Earlier quoted context omitted.

Your comparison is bullshit. I have control over how I secure my car from being stolen. It's complete nonsense to equate that to me being responsible for a bank's failure to protect themselves against fraud where I have no power whatsoever to influence how the bank secures itself against fraudulent loan applications.

Your statement is nonsense. Regardless of your efforts, the best you can ever hope for is to minimize the chance of your car being stolen. You can never prevent it completely. If your car is stolen in spite of your best efforts, are you at fault? Do you still have to deal with the consequences as a victim of that theft?

When someone takes out a loan in someone else's name, the only theft that truly occurs is the imposter stealing money from the bank it duped.

Re: Cybersecurity Incident Involving Consumer Information

#348
post #82
post #38

> Equifax discovered the unauthorized access on July 29 Well over a month later and they're just now getting around to telling people about a security breach that could affect almost half of all Americans... How is this ok/legal?

Discovering a breach is only a fraction of what has to happen before customers/public should be notified of said breach. It's not very helpful to anyone if you put out a press release that just says "we discovered a breach but have no idea who, if anyone, was affected, we have no idea what was stolen, and we have no idea who did it." There have to be investigations that happen prior to any of that being known/release…

That seems reasonable, up to a point, but it also looks potentially self-serving and open to abuse (especially given the news about stock sales by insiders.) If a company in a position with this level of risk cannot staunch the leak within hours, it should be required to curtail its activities to the extent necessary to stop further leakage, until it has the proximate cause of the problem under control.

Nor should the instigation of credit monitoring be delayed until the investigation is complete. To pick a contemporary analogy, it would be like not informing the public of an approaching hurricane until its precise point of landfall has been determined.

Re: Cybersecurity Incident Involving Consumer Information

#349
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

This may damage Alice's reputation temporarily however, once the bank determines that it has been defrauded, it should make the loan information inaccurate.

I believe the Fair Credit Reporting Act allows Alice to remove inaccurate information from the report?

Re: Cybersecurity Incident Involving Consumer Information

#350
post #316

Earlier quoted context omitted.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those au…

>carrying official ID It's probably not hard to forge a social security card and birth certificate if you have the relevant information. From there, a state ID (or maybe even passport) should be possible to get. I don't believe there is any biometric security on either. A determined identity thief might go that far.

> A determined identity thief might go that far.

This is the old "because a solution is not 100% effective, it's not good" chestnut. This solution would cut down on the theft by over 90%, I'd venture, probably more like 98%. There is huge difference between perpetrating a crime from the safety of a computer and physically walking into a bank to commit it.

Post reply on HN