Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

481–490 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#481

Earlier quoted context omitted.

> Why do you consider this implication necessary? It sounds nonsensical. Because it is implied by the definition that is implied by the concept of "identity theft". Let's assume we define "identity" to mean "any set of attributes of Alice", so widening it essentially as far as possible. Then "is a human", being an attribute of Alice, would become an identity of Alice. Using that definition in the context of identity…

The original parent posited that we have multiple identities, as in: multiple sets of attributes, each of which uniquely identify us within a certain context. > Let's assume we define "identity" to mean "any set of attributes of Alice", so widening it essentially as far as possible. Then "is a human", being an attribute of Alice, would become an identity of Alice. > That doesn't make much sense, does it? If Alice is…

> The original parent posited that we have multiple identities, as in: multiple sets of attributes, each of which uniquely identify us within a certain context.

In which case it's just not a refutation of the tautological impossibility at all. Either something uniquely identifies someone, or it does not. Uniquely identifying someone while at the same time being (trivially) being replicated by somebody else is just a contradiction.

> If Alice is the last surviving human being in the universe, it does.

Seriously?

> If Alice isn't the last surviving human being in the universe, than the premise of "is a human" as an identity is already nonsensical (because it no longer identifies), hence also any conclusions you derive from that premise are also nonsensical.

Which is exactly why "was able to tell us the DoB of Alice" as an identity is nonsensical, and hence any conclusion of the form "therefore, Alice's identity was stolen" is nonsensical as well, correct.

> You haven't checked that it's me, you've checked that it is someone who looks like me.

Which contradicts the claim that the verifier does not need a replica of you how exactly?

> Within any given context, that may or may not be treated as my identity. Hence, we're back at multiple identities, each in their own context.

Which still cannot be stolen. So?

> Which says nothing about identity, only about possession. Whether this possession is taken to be sufficient proof of identity again depends on the context.

Which contradicts the claim that the verifier in a context where it is taken to be sufficient proof of identity does not need the private key how exactly?

> Do you believe this hypothetical example to be true? If not, what's your point?

My point is that I am responding to your argument that was about an implication from that hypothetical case.

Re: Cybersecurity Incident Involving Consumer Information

#482
post #95

Earlier quoted context omitted.

And trustedidpremier.com was registered a week ago. https://whois.domaintools.com/trustedidpremier.com

Well, yes, this was in response to this incident. While they're just making a public statement now, we know from their own press release that the breach occurred in May. Regardless, it's certainly prudent to be wary of these sites since they're pretty indistinguishable from phishing sites.

According to them it occured through July. That means it probably took them a month to figure out exactly what happened and how to disclose it.

Re: Cybersecurity Incident Involving Consumer Information

#483
post #251

Earlier quoted context omitted.

All financial companies are required to have you SSN for reporting income for taxes and also report money movement under the anti-money laundering laws(AML). Know your customer(KYC) requires a financial company to gather documentation and information to verify your identity and to ensure your not on any list of people we're legally not allowed to provide services eg terrorist watch list. You don't need to provide a S…

Seems KYC as used in the real world doesn't do a very good job of verifying whether the "customer" is Alice or the fraudster... It'd be nice if _that_ requirement had enough teeth to reduce the ability of the financial institution to claim Alice is "the victim"...

how about having photo on the credit file. this would solve so many problems.

Re: Cybersecurity Incident Involving Consumer Information

#484
post #283

Earlier quoted context omitted.

We don't know how the security breach happened. Should Equifax be criminally liable for using software which contains a remote-exploitable buffer overflow vulnerability? Or for the actions of a corrupt employee who stole some data and sold it on the black market? It's possible that Equifax did something really negligent and if so maybe there should be a class-action lawsuit against the company. But it's also possible…

Isn't the traditional capitalistic argument that the people on top are the ones taking all the risk, which is why they should be making all of that money in the first place? Note that I'm not making that argument, but trying to understand how this situation differs.

You take a lot of the risk but not all. If this was due to weaknesses in their IT then managers should be liable. But it's possible that they had one of the most secure systems in finance and still someone found a way in via undisclosed exploits. In that case there's nothing a manager could've done.

But since the core database wasn't hacked, it seems likely that someone had a database dump on a development machine which was outside the scope..

Re: Cybersecurity Incident Involving Consumer Information

#485

Honest question from a European: how would this work if I moved to the US? Would I simply not get a loan because I don't have a credit score? Do I apply at private companies and give them all my loan history? Here in my country the government (or some agency) keeps track of what loans you have, and when a new company wants to issue you a loan you access the API with information like "2 years, €50 each month" and then…

Most European countries have credit agencies, just that they have different names. When moving country, you usually have to build up a new credit reputation. Even when you move within Europe. A clean history will mean that you can get some credit cards but bigger loans will often require a few years of history with at least a current account.

Re: Cybersecurity Incident Involving Consumer Information

#486
post #357
post #339

Earlier quoted context omitted.

The thief would have to physically resemble the victim's photo, height, age, gender, etc, which is some added defense in depth. For instance it would be hard for most males to pass themselves off as a typical female.

> The thief would have to physically resemble the victim's photo Why? Show up to a government station with your birth certificate, SSN, some telephone and utility bills, and they'll take the thiefs picture and put it on an identity card with your name on it.

They don't use the SSN to check for prior IDs issued by other states and/or the Feds, and compare the applicant's photo/gender/age/height/eye color, etc to them first?

Re: Cybersecurity Incident Involving Consumer Information

#487
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Clearly, both the bank and the individual are victims of the crime. Generally speaking, the impact to the customer is usually greater, as bank business model aren't dependent on every loan being repaid. Consumers stand to lose money directly and lose the opportunity to access capital. The credit agency or anyone else who has a breach is usually a negligent third party.

In some countries when you sign out a loan and a card you get picture snapped. but then this measure would stick banks with loans and not the consumer.

Re: Cybersecurity Incident Involving Consumer Information

#488

Earlier quoted context omitted.

> In no way was Alice's identity stolen - that's tautologically impossible. I see this as you being too strict with your definition of "identity". We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. "Stolen identity" in this sense means Alice's attributes (the ones which Big Bank uses to identify a person…

> I see this as you being too strict with your definition of "identity". > We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly…

Right, and this is the point where we, as computer system / information security / software (whatever, but) professionals switch to using the word "authentication", and stop being obtuse about the ambiguity in the multiple definitions of the word "identity".

> For example, it is claimed that being able to say the DoB of Alice is an attribute that identifies Alice's body.

And then we say that the stating the DoB authenticates anyone to make changes to Alice's account.

And then we say this is a terrible idea. And then we are in agreement.

And then we don't have to say completely unhelpful nonsense like the following:

> Then, it is also claimed that somebody else saying Alice's DoB supposedly is an act of stealing her identity, and that the set of such people is non-empty. Which means that being able to say Alice's DoB is not actually an identity in the first place, much less one that could be stolen.

If these credit bureaus insist on conflating the word "identity" with "authentication" then it is up to us, computer / information / system / security professionals to correct this error and continue with more clarity.

Not not to start a one-sided (credit bureaus aren't listening) philosophical argument that nobody was really talking about in the first place. This isn't about ontology, and it never was.

(Ontology is the field of philosophy that asks the question what "is" is, a.k.a. "identity" and it's very interesting but also very much irrelevant to this incident and the problem it poses to badly designed authentication systems)

An important part of our jobs is being able to clearly explain such computer security and authentication concepts to a layman. That includes properly framing the question. Digging into a philosophical argument because you feel you can argue your way around a particular word that is used, only feeds pedantry.

Re: Cybersecurity Incident Involving Consumer Information

#489

Earlier quoted context omitted.

> while it is claimed at the same time that they can be replicated by a "thief", which necessarily implies that they don't identify Alice, and hence are not an identity, therefore tautological impossibility. Attributes can be replicated -> attributes don't identify Alice Why do you consider this implication necessary? It sounds nonsensical. Counterexample: to verify an identity, the verifier must possess a replicatio…

> Why do you consider this implication necessary? It sounds nonsensical. Because it is implied by the definition that is implied by the concept of "identity theft". Let's assume we define "identity" to mean "any set of attributes of Alice", so widening it essentially as far as possible. Then "is a human", being an attribute of Alice, would become an identity of Alice. Using that definition in the context of identity…

> Let's assume we define "identity" to mean

... seriously, just stop.

Re: Cybersecurity Incident Involving Consumer Information

#490

Earlier quoted context omitted.

For £100 you get a shiny credit rating for no risk. That'll get you a mortgage for £100,000s. In the 60s/70s it was about knowing your bank manager, so he knew you'd be able to pay. I appreciate that it probably benefited a certain type of person, but the new system probably has the same prejudices built in. Now it's all about the ephemeral and easily game-able credit score. Until a few years ago you would get negati…

> I was not a good risk. Banks are using actuarial science to make loans. You were (possibly) an outlier. That doesn't matter. All that matters is that their risk models work in aggregate. If they're right enough of the time, they profit. It doesn't have to be perfect.

They had to be bailed out, remember?
Post reply on HN