"The only thing Social Security numbers should be used for is to pay our taxes, which identity thieves are welcome to do." Likely they may not be paying taxes, but have already found a way to circumvent the system such that they collect something (aid, EI, etc).
Actually what they do is early filing to receive any refund that would be coming to you.
The Equifax Hack Didn't Have to Be This Bad
41–50 of 74 posts
Re: The Equifax Hack Didn't Have to Be This Bad
#42Earlier quoted context omitted.
The reason the focus is on the SSN is because it enables credit. Privacy is important, but so is protecting your finances.
Date of birth and address history (in addition to SSN of course) are often used by financial organizations to verify user identity online and on the phone. Recently I called to report a lost credit card, for instance, and the operator read through a list of 10 addresses. I had to confirm which ones I'd lived at at some point in my life, in order to verify my identity.
Re: The Equifax Hack Didn't Have to Be This Bad
#43So since anyone who has access to the breached info can impersonate nearly anyone in the country... 1) Are we about to see the end of "Name, DoB, last four" as an authentication? (Damn well should if anybody can be me now) 2) Are the credit reporting agencies discredited as a business model? The other two are likely either hacked already or about to be, and given this standard of reporting we wouldn't know till month…
With #2, nothing is going to change. The credit agencies business isn't identifying people (as we are discussing, they outsource that to the government), it's tracking credit activity. And that works extraordinarily well from the perspective of its customers (the banks). If Equifax dies, Experian and TransUnion will just see more business. If they all die, the banks will find some way to do this for themselves.
Re: The Equifax Hack Didn't Have to Be This Bad
#44Old guy here. The reason I know my SSN by heart is that it was my student ID number in college and had to be given at the beginning of each semester to get my course list, later for grades, etc.
I had a credit union account from the 80's and as of the 90's my SSN was printed on each monthly statement.
Both were before the "digital age" and neither could be considered "in a locked filing cabinet" nor under my control.
Re: The Equifax Hack Didn't Have to Be This Bad
#45The hack isn't just SSNs - it includes address history, date of birth, drivers license number - everything reasonably necessary to establish identity. Not sure why the focus is SSNs, any solution needs to be even higher. This is about companies stockpiling our personal information and us having little say in the matter.
In short, the pension cash-out was handed over to a third party. And a primary factor that party used in establishing that I was indeed the beneficiary, when I called to discuss the details, was to ask me questions about my address history.
In fact, where did they get these details? From an outfit like Equifax, or from the same set of data brokers from whom Equifax acquired them.
The mitigations against such a breach are so obvious -- technical "lockdown" aside. Data rate/query limits. Ongoing auditing that targets anomalous data flows and data rates for mandated attention. Etc. Etc.
You don't have to have "perfect" technology. In fact, you should expect and plan for never having perfect technology.
It shouldn't have been too hard to pick up such a sweeping outflow of records; it should have become apparent that the request channel was (systematically, once you analyse and determine the specific system being used) working its way through the U.S. population.
As for Equifax, if I had my druthers, this would be a corporate death sentence. They've demonstrated a fundamental breach of trust and a fundamental incompetence.
Criminal investigators should squeeze them like hell, flipping smaller fish to fully determine the chain of command and responsibility that decided upon and implemented this catastrophic neglect.
As for the shareholders? Well, ultimately they bet on a company that has demonstrated itself a complete failure. They were happy to take the profits, including the greater profits made by not paying for proper systems and staffing. If their investment now evaporates -- well, I'm getting to the point of simply saying, "So be it."
A few shareholder "disasters", like this, and there will be a lot less pressure for laissez faire short-term profit maximizing, and a lot more for oversight -- internal and external -- and regulation that prevents them from being screwed by incompetently or corruptly negligent management.
Re: The Equifax Hack Didn't Have to Be This Bad
#46Earlier quoted context omitted.
Also note that other countries don't have this insanity.
Canada does unfortunately. It's called a Social Insurance Number (SIN) or Numéro d'assurance sociale (NAS) but other than the name, it is mostly the same. And Canada is on the list of the countries suffering from the breach. This should be interesting.
They've clearly demonstrated I shouldn't trust them with my SIN (not that I ever willingly did in the first place!) so why should I enter it again? Into a different domain, no less?!
Re: The Equifax Hack Didn't Have to Be This Bad
#47Re: The Equifax Hack Didn't Have to Be This Bad
#48The Republic of Estonia uses such a system to identify members of its e-Residency program, even with no physical presence. Each e-resident has a public numerical key that serves as a unique identifier, and a corresponding private key that is never revealed. So an example to emulate then! Except: Estonia suffered an embarrassing blow to its much-vaunted ID cards that underpin everything from electronic voting to onlin…
Re: The Equifax Hack Didn't Have to Be This Bad
#49Earlier quoted context omitted.
Which countries do you mean? How do they manage their credit scores?
Using much more nebulous and unreliable forms of PII as identifiers, in my experience, which leads to situations where you could query someone's report if you know their name and street address.
Re: The Equifax Hack Didn't Have to Be This Bad
#50In 2008, the Federal Trade Commission created the Red Flags Rule, which required businesses and organizations to collect personally identifying information from their customers, even if not necessary for service. This put Social Security numbers into the hands of utility companies, telecom providers, doctors and countless other unreliable custodians. This is the first I've heard of this, and it's a different characte…