Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

361–370 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#361
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

"Mitchell & Webb Sound - Identity Theft"

https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: Cybersecurity Incident Involving Consumer Information

#362
post #211

Earlier quoted context omitted.

How often to you apply for credit? It is, in any case, far less of an inconvenience than not paying the protection racket, having someone impersonate you, and having the credit oligopoly lie about you because of it, leaving you to somehow clean up their mess.

Some folks churn, so they apply for credit several times a month. It's not a very small niche community either.

It is a small niche relative to the credit-using public at large, and there's no reason to accommodate them at the expense of everyone else.

Re: Cybersecurity Incident Involving Consumer Information

#363

Earlier quoted context omitted.

It depends... Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 scheduled trading plans. The…

> The timing is extremely suspicious. But - if they can prove they didn't know, they're in the clear. Burden of proof for criminal cases is the other way around. They will likely spend lots on legal fees just trying to prove they didn't know about the hack at the time they decided to sell. They will likely end up settling out of court (guilty or not) because that's how the US legal system works. Also important -- Jul…

What actually happens is that they get interviewed repeatedly. If they get caught in a lie (like Martha Stewart), they face criminal penalties for perjury. If they keep their story straight, they are acquitted.

Re: Cybersecurity Incident Involving Consumer Information

#364
post #194

Earlier quoted context omitted.

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

It's pretty much the flaw in not having a national ID scheme - everyone reaches for the next closest approximation, with no funding for security systems or refreshes to address flaws. Because this is an issue the government should address seriously.

National ID has nothing to do with this. National Password is the problem here.

Re: Cybersecurity Incident Involving Consumer Information

#365

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

I did this about 8 years ago, and have only needed to temporally unfreeze it 3 times. Besides the big 3, I also froze reporting from Innovis.

The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.

Re: Cybersecurity Incident Involving Consumer Information

#366

Earlier quoted context omitted.

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus

Americans don't like National ID cards because we remember the Third Reich and the USSR.

Re: Cybersecurity Incident Involving Consumer Information

#367

Earlier quoted context omitted.

I was not saying either really. I was asking what sure fire way we have other than a number / name for identity.

Well, there is biometry, with the simplest form being a picture, if you want to somewhat reliably identify people.

Out of 7 billion people, a fair number of them look like you. I'd hate to have an ass for a twin in your world.

Re: Cybersecurity Incident Involving Consumer Information

#368

Earlier quoted context omitted.

> Which makes your statement (that you have sufficient control to prevent the possibility of theft of your property) completely invalid. Luckily, I didn't say that.

> I have control over how I secure my car from being stolen. Really? Those were your exact words, in the context of claiming that your ability to secure your car made the comparison to identity theft invalid.

Yes, really. Having control over how I secure my car does not in any way imply that I can guarantee success. However, as a matter of fact, you can essentially get arbitrarily close to that, it's just a matter of your effort. Which is in contrast to banks being defrauded and blaming me for it, where I can not do anything about how the bank protects itself against the fraud.

The problem is that the power to do anything about the problem and the blame is not aligned, which leads to a situation that is equivalent to the bank leaving the key in the ignition of the unlocked car, not allowing you to change anything about that setup, and then expecting you to foot the bill when the car inevitably does get stolen.

Re: Cybersecurity Incident Involving Consumer Information

#369

Earlier quoted context omitted.

You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus

Americans don't like National ID cards because we remember the Third Reich and the USSR.

I think it's more that Americans don't like national ID cards because they're paranoid about the Mark of the Beast and mistrust Federal power on principle.

Re: Cybersecurity Incident Involving Consumer Information

#370

Earlier quoted context omitted.

You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus

Americans don't like National ID cards because we remember the Third Reich and the USSR.

I'm not sure I would proclaim that unironically in a discussion of a giant American company accidentally losing track of a database containing detailed personal information about ~1/2 the country.

I mean sure, it's not in your pocket. But are you going to move house in response to this breach?

Post reply on HN