Live data from Hacker News

The Equifax Hack Didn't Have to Be This Bad

bloomberg.com

51–60 of 74 posts

Re: The Equifax Hack Didn't Have to Be This Bad

#51
SWIM used to have access to Equivax data from home. In the early 90s, you could log into Equifax, type in a strangers address, and get their credit history, social, bills, and prior addresses among other things. Access was through tymnet using an +. That is it. The account_id was a ~16 digit number. The password was a 1 alpha + 1 alphanumeric. In those days it was security through obscurity, so I presume. Get an account number and after 936, you are in. Given this recent breach has nothing to do with how Equivfax/CBI was run years ago, it does make me cringe a bit.

Re: The Equifax Hack Didn't Have to Be This Bad

#52
post #9

The hack isn't just SSNs - it includes address history, date of birth, drivers license number - everything reasonably necessary to establish identity. Not sure why the focus is SSNs, any solution needs to be even higher. This is about companies stockpiling our personal information and us having little say in the matter.

I can't wait until the credit verification questions get even harder.

"What check number did you use to pay the 13,753rd dollar of your car loan in 2001?"

"In 2014, you signed up for an American Express Gold card. Which version of Firefox did you use to complete the application?"

Re: The Equifax Hack Didn't Have to Be This Bad

#53
post #44

Before the digital age, a stash of nine-digit numbers could be kept reasonably secure in a locked filing cabinet behind closed doors. So long as consumers volunteered the numbers judiciously, most people could make it through life without ever suffering a theft of identity. Old guy here. The reason I know my SSN by heart is that it was my student ID number in college and had to be given at the beginning of each semes…

You don't even have to be that old to remember this time.

I went to a well-known university and they used SSNs as student ID number until roughly 2001-2002. The first half of my university career, my SSN wound up on every Scantron sheet, exam blue book, and term paper I handed in. It was printed on the front of my ID, and even after they recalled old IDs and replaced them with non-SSN cards, the magstripe track data still had your SSN on it because some old dining hall POS system or something like that hadn't been converted.

It was like fish in a barrel for fraudsters, just root around in the trash after finals week and grab people's term papers. I had quite a few friends who discovered that during the time they were attending college, someone had opened a cell phone (or a credit card, in one person's case) in their name.

This was before the days of the free annual credit report law. So these folks never pulled their own files, and only discovered the fraud years after graduation, when they went to apply for a car or home loan and got denied.

Re: The Equifax Hack Didn't Have to Be This Bad

#54
post #51

SWIM used to have access to Equivax data from home. In the early 90s, you could log into Equifax, type in a strangers address, and get their credit history, social, bills, and prior addresses among other things. Access was through tymnet using an + . That is it. The account_id was a ~16 digit number. The password was a 1 alpha + 1 alphanumeric. In those days it was security through obscurity, so I presume. Get an acc…

In the 80's it was even worse. A credit bureau was available on telenet (a simple dial up service that allowed terminal connections to services) and there was no password, just an account number. You could query any social security number and see joint account information by simply adding /ty-jp or something similar. This being the 80's, you'd see the needed credentials taped to monitors.

Re: The Equifax Hack Didn't Have to Be This Bad

#55

In 2008, the Federal Trade Commission created the Red Flags Rule, which required businesses and organizations to collect personally identifying information from their customers, even if not necessary for service. This put Social Security numbers into the hands of utility companies, telecom providers, doctors and countless other unreliable custodians. This is the first I've heard of this, and it's a different characte…

A couple of people who handled Red Flags compliance for medical practices have told me they're only required to do some kind of identity verification, which can be as simple as checking a driver's license. They store SSNs to make it easier to report and collect on delinquent accounts.

Re: The Equifax Hack Didn't Have to Be This Bad

#56
post #51

SWIM used to have access to Equivax data from home. In the early 90s, you could log into Equifax, type in a strangers address, and get their credit history, social, bills, and prior addresses among other things. Access was through tymnet using an + . That is it. The account_id was a ~16 digit number. The password was a 1 alpha + 1 alphanumeric. In those days it was security through obscurity, so I presume. Get an acc…

Reading your comment reminded me of a similar system which gave access to phone numbers of people & businesses including non listed numbers.

Still I have yet to see people realise that if you want to undermine a country's financial system, screw up their credit rating agency's. I dont believe Equifax when they say only certain data has been accessed, these are normalised databases, I suspect the CEO is bluffing or being very lenient with the true if they are only referring to one table/file and not the rest of the database, and thats if they even know just how much data has been accessed. These agency's share information between themselves so the knock on effect is all the credit rating agency's will probably have duff data if any of it has been changed.

Still it could also be a back door way for the Central Banks to get money out into the economy if everyone can suddenly take out massive loans on the lowest interest rates known to man, because its not like the financial system in the West has ever recovered from the financial crisis in 2008, so when overt QE has failed, why not try some covert QE and blame it on the oh so spooky hackers.

Re: The Equifax Hack Didn't Have to Be This Bad

#58

Earlier quoted context omitted.

Actually what they do is early filing to receive any refund that would be coming to you.

Does the IRS lose money if they give the refund to the wrong person? Or is the onus on you to find the criminal and sue him?

Yes, they lose billions per year in fraudulent refunds.

Re: The Equifax Hack Didn't Have to Be This Bad

#59
post #44

Before the digital age, a stash of nine-digit numbers could be kept reasonably secure in a locked filing cabinet behind closed doors. So long as consumers volunteered the numbers judiciously, most people could make it through life without ever suffering a theft of identity. Old guy here. The reason I know my SSN by heart is that it was my student ID number in college and had to be given at the beginning of each semes…

Heh, it actually changed while I was in college. As a CS student, one of the required courses was a 'Computers and Society' course which was basically sort of like a 'where ethics meets technology' course, talking about the social impact of code and computing. The kind of thing many people today seem to have need to attend. But anyhow, during it we mentioned 'hey, why are our student IDs, used everywhere, our SSNs? Isn't that unsafe?' and we actually ended up getting it changed.

Didn't stop some professors from continuing to use them. I had one prof who would use the last 4 digits (oh, only the last 4, those aren't the most important ones or anything) as a way to post psuedoanonymous grades after tests.

Re: The Equifax Hack Didn't Have to Be This Bad

#60
post #27

The Republic of Estonia uses such a system to identify members of its e-Residency program, even with no physical presence. Each e-resident has a public numerical key that serves as a unique identifier, and a corresponding private key that is never revealed. So an example to emulate then! Except: Estonia suffered an embarrassing blow to its much-vaunted ID cards that underpin everything from electronic voting to onlin…

Is there a link to this that's not behind a paywall. Very interested in understanding the flaws of such a system, as a 2 key system seems like the most viable and secure way to establish identity.

If you search google using the url for the article and then follow the search link you can get behind the paywall. Here's a link to the google search result - https://www.google.com/search?q=https%3A%2F%2Fwww.ft.com%2Fc...
Post reply on HN