Live data from Hacker News

Equifax takes down web page after reports of new hack

reuters.com

41–50 of 143 posts

Re: Equifax takes down web page after reports of new hack

#42
post #31

Yes, this was discussed earlier today: https://news.ycombinator.com/item?id=15456221 And debunked...it wasn't a hack of the Equifax web site, but a malware package delivered by 3rd party analytics company, Fireclick.

That's pretty interesting. Would users running ad blockers be protected from this kind of thing?

Re: Equifax takes down web page after reports of new hack

#43
post #34

Earlier quoted context omitted.

Unfortunately you have no way to protect your tax returns from Equifax, which now has a contract with the IRS thanks to the infinite wisdom of our government. http://fortune.com/2017/10/04/equifax-irs-contract-hackers/

This contract is a renewal of a previous contract with Equifax (which is why it was a "critical service that couldn't lapse"), and it involves Equifax giving data to the IRS, not the IRS giving your tax returns to Equifax.

The IRS is most certainly giving Equifax data or they wouldn't have sent inspectors there to verify the integrity of IRS data.

>Chief information officer Girza said the IRS sent inspectors to make sure no IRS data was compromised in the Equifax breach

http://www.snopes.com/2017/10/05/equifax-contract-irs/

Re: Equifax takes down web page after reports of new hack

#44
post #31

Yes, this was discussed earlier today: https://news.ycombinator.com/item?id=15456221 And debunked...it wasn't a hack of the Equifax web site, but a malware package delivered by 3rd party analytics company, Fireclick.

That's pretty interesting. Would users running ad blockers be protected from this kind of thing?

Only if they blocked an akamai url that was caching a netflame.cc url

Re: Equifax takes down web page after reports of new hack

#45

it's amazing how much the finance industry can get away with. like honest-to-goodness amazing. it's really impressive how these people can have such a death-grip on society. honestly, i'm more curious than mad. how is such a thing even possible? i mean, wow.

The finance industry as a whole spends a few billion dollars on lobbying. They spend the most on lobbying compared to every other sector. imo this is one of the things the tech industry hasn't fully optimized yet

Neither of your first two sentences seem to be true:

- [Lobbying Spending Database | OpenSecrets](https://www.opensecrets.org/lobby/top.php?showYear=2017&inde...)

And note that "Education" isn't spending that much less!

> imo this is one of the things the tech industry hasn't fully optimized yet

How would the tech industry "optimize" lobbying? Or even just lobbying by finance?

Re: Equifax takes down web page after reports of new hack

#46

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

freeze your credit report with Equifax, and then if any company requests it, they'll be denied (because you have to request it be unfrozen for them to receive it). If any company uses Equifax, you'll then be denied credit or they'll ask you to unfreeze it.. either way, you can complain to them, and make it clear you won't work with Equifax. Of course, in practice, this will mean you'll get denied credit from any comp…

I submitted a complaint to the CFPB requiring [1] Equifax to remove my credit record, due to their proven incompetence at protecting that data (citing their breech, several congresspeople grilling their CEO on CSPAN, etc). Its been 9 days and I haven't heard back from the CFPB yet (Equifax has 15 days to respond and up to 60 days to provide a final response), but Equifax has my complaint and even if it goes nowhere, it gives me something to hand over to Elizabeth Warren's office to show I have no control over my personal data and I have no control over having it removed regardless of how incompetent Equifax is.

Fingers crossed someone with Equifax's data dump starts dumping the data of Equifax senior management.

[1] Hat tip to patio11 on the language; don't use "I demand", professionals use "I require"

Re: Equifax takes down web page after reports of new hack

#48
The Web has gotten so much worse since we started putting serious stuff on it. It's kind of a population-terrorizing monster, at this point.

Could we, like... not do that? I seem to remember the world turning just fine when you couldn't push the right sequence of buttons and steal the personal data of half a country's citizens from the comfort of your home.

Re: Equifax takes down web page after reports of new hack

#49
post #6

The incompetence is mindblowing. Could this be a good argument for software engineers to get their professional license?

I'm not sure requiring a license to practice software development is a good idea, but it does seem that we could use some rules around development and maintenance of important applications. Perhaps legally mandated security audits for anyone storing things like financial data would be useful.

Re: Equifax takes down web page after reports of new hack

#50
Solution to the Equifax debacle:

1) If the value of the individual damages related to this breach are in excess of the market cap of the equifax company, all company stock should be seized and distributed equally among those affected by the breach.

2) In the future, if a company controls this amount of sensitive data, they should have mandatory breach insurance. This means that they are covered for a government mandated amount based on the legal liability if all their data was lost. This will mean that the insurers will do in-depth audits of the data security of the company, and they will be incentivized year-to-year to ensure their security practices are top notch. The present system incentivizes each CEO to have a head-in-the-sand approach to data security where a hack is considered a long-tail event unlikely to happen during the ceo's 3-5 year tenure and therefore is not really worth paying attention to. In addition, it would ensure that if the potential damage done if data is leaked exceeds the value of the business storing the data, the insurance will be prohibitively expensive and the company will not be able to continue with this line of business - as it should be.

Post reply on HN