Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

501–510 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#501

Earlier quoted context omitted.

You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus

Americans don't like National ID cards because we remember the Third Reich and the USSR.

As opposed to who?? Are you implying that the European countries successfully implementing these systems do not?

Also, if I recall correctly, the UN had to actually remind the US about the actual dangers of the Third Reich only a few weeks ago.

Re: Cybersecurity Incident Involving Consumer Information

#502

Earlier quoted context omitted.

> I see this as you being too strict with your definition of "identity". > We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly…

Right, and this is the point where we, as computer system / information security / software (whatever, but) professionals switch to using the word "authentication", and stop being obtuse about the ambiguity in the multiple definitions of the word "identity". > For example, it is claimed that being able to say the DoB of Alice is an attribute that identifies Alice's body. And then we say that the stating the DoB authe…

> Right, and this is the point where we, as computer system / information security / software (whatever, but) professionals switch to using the word "authentication", and stop being obtuse about the ambiguity in the multiple definitions of the word "identity".

Except it's nonsensical to switch to "authentication" when the discussion is about how the term "identity theft" is misleading. It's not "authentication theft", it's "identity theft", and that is exactly why it is misleading.

Re: Cybersecurity Incident Involving Consumer Information

#503

Earlier quoted context omitted.

There is strong evidence for it here: http://www.cl.cam.ac.uk/~sjm217/papers/oakland14chipandskim.... And regardless of whether you claim the evidence is inconclusive, it is simply not acceptable to dismiss a known vulnerability in something important by saying "I don't know of any case where it has been exploited yet."

That's explicitly not what I said. I know that flaws have and will continue to be discovered in those authentication systems, and also that a theoretical shift in liability occurs. Any bugs will need to be fixed, and that's important. But you can't ignore the situation in practice – liability is not being shifted, and all UK banks and credit card providers are pretty happy to refund fraudulent transactions regardless…

It is good to hear that UK banks are apparently no longer shifting liability, but this case, and others, show that banks were shifting liability until it was irrefutably demonstrated that the system was not as secure as they claimed. 'Liability shift' is not a term invented by conspiracy theorists: banks were explicit about this being a primary goal of EMV, so it does not require a leap of faith to accept that it happened. Sadly, neither is a leap of faith required in accepting that the banks' first response to evidence of weaknesses was to deny their exploitability.

Does your statement about UK banks no longer shifting liability apply in cases of fraud against merchants?

Re: Cybersecurity Incident Involving Consumer Information

#504
post #411

Earlier quoted context omitted.

That seems reasonable, up to a point, but it also looks potentially self-serving and open to abuse (especially given the news about stock sales by insiders.) If a company in a position with this level of risk cannot staunch the leak within hours, it should be required to curtail its activities to the extent necessary to stop further leakage, until it has the proximate cause of the problem under control. Nor should th…

Building off your analogy, you don't order mandatory evacuations every time you see a tropical depression form out in the Atlantic. It's only when the tropical depression actually turns into a hurricane and is on a collision course that you warn the public. Data breaches are the same. If you put out a press release every time your infosec team discovered an attack, you'd be putting out releases every single day, mult…

You seem to be saying that, of the two analogies, mine is closer to actual practice.

Re: Cybersecurity Incident Involving Consumer Information

#505
post #478

Earlier quoted context omitted.

> People are very consistent with spelling their own names. Is this true of all people? > This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. For common names and large cities, probably not. > JohnHarrySmith19900101NewYork is far more secure. No, it's not; SSNs aren't passwords, and shouldn't need to be “secure” in that sense, but names aren't secret and birth dates and l…

> For common names and large cities, probably not. Would be interesting to see statistics for that. It wouldn't be New York in this case, but for example Brooklyn or Queens. Even for the most popular name combinations, the number of people with the same name born on one day in one administrative area will be extremely low. Esp if you require middle names to be included.

Or you can just use a number. Because unlike names, you can assume one thing about individuals in a population and that is that they are countable.

You still just need 33 bits of information to identify any human on the planet, anyway.

(post-singularity, evolved into an ever-merging amorphous network of consciousnesses, we can use multidimensional fractal subsets of R^n, but we'll cross that bridge when we get there)

Re: Cybersecurity Incident Involving Consumer Information

#506
post #176

Earlier quoted context omitted.

Why not just shift the presumption of liability (absent verification) to the financial institution instead of the consumer? Loan issuers can hire skilled professionals to do credit verification, so why should consumers bear the risk for their lack of due diligence?

"just" Consumers would love this. Financial institutions would not. Guess who wins this battle?

> Consumers would love this. Financial institutions would not. Guess who wins this battle?

And everyone thought SOPA and PIPA were done deals, that is until the great internet SOPA/PIPA blackout day that resulted in so many calls to congress that the congress critters backed down.

If enough voters could be motivated appropriately to contact their congress critters requesting jail time for the Equifax executive staff that clearly did not stress security sufficiently, there would be some change that would occur.

Remember, money (donors) only help the congress critters to pay for the costs of the election. They still have to get those voters to actually vote for them. So there's still a way to influence their viewpoint. It just takes _way_ more than a few handfuls of voters calling/writing to reach the point where they actually pay attention anymore.

Re: Cybersecurity Incident Involving Consumer Information

#507
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Agreed. Thought experiment: suppose instead that Fraudster convinced Alice that he represented BigBank, and so Alice was duped and gave her money to Fraudster thinking she was depositing into BigBank. The only thing she could expect from BigBank was politeness while explaining to her that she was duped. If it's a very friendly bank, she may tie up a manager for a couple hours, but that's it. If she keeps coming back,…

This is actually quite eye-opening. Thank you for that.

Re: Cybersecurity Incident Involving Consumer Information

#508
post #23

Earlier quoted context omitted.

I believe you CAN change your SSN https://faq.ssa.gov/link/portal/34011/34019/article/3789/can... . Especially if you have "cultural objections to certain numbers".

You can, but in very specific cases. The "cultural objections" bit requires documentation from a legitimate religious organization - you can't just say 123-45-6789 is the mark of Satan.

> you can't just say 123-45-6789 is the mark of Satan

Obviously you can't say it out loud, because you might evoke the wrath of the Old Ones.

Additionally, you can just engrave the surface your ID-card with the correct symbols in charcoal, a salted circle (actual salt, not the cryptographic kind), maybe some blood, and you should really be fine for most practical purposes.

I mean, this is not the Middle Ages any more. You can just Google this stuff.

Re: Cybersecurity Incident Involving Consumer Information

#509

Not sure if anyone else suggested this, but people should file complaints to the CFPB about this: https://www.consumerfinance.gov/ Not just about the hack, but the fact that their "check to see if you were affected by our shit" sites include a ToS that waives your right to participate in a class-action lawsuit. https://trustedidpremier.com/static/privacy-policy

This. And it doesn't even tell you if you have been effected.

Re: Cybersecurity Incident Involving Consumer Information

#510

Earlier quoted context omitted.

You just put the money in an account, pay the capital off every month, lose a little bit of interest and in 2 years you have a shiny credit rating even though it means zilch. I don’t really get that - doesn’t it mean that the person who took a loan is relatively responsible and was able to pay their loan back on time? Any system can be gamed, but I don’t get the impression that credit agencies are attempting to elimi…

> I don’t really get that - doesn’t it mean that the person who took a loan is relatively responsible and was able to pay their loan back on time? That's probably the reason why it would increase one's credit rating in a positive way. I have no doubts about these systems being broken in such a way that they consider people who take on credit, paying it back in time, as more "credit-worthy" than people who never neede…

> In Germany there is "Schufa", which is not a bank but basically a private company with a de-facto monopoly position in regards to credit ratings in Germany

Just for anyone from Germany reading: There are multiple, less well known agencies that are used by banks and others as well. They are definitely worth keeping an eye on. I will only mention Creditreform Boniversum, Arvato Infoscore, and Bürgel.

Post reply on HN