Live data from Hacker News

The Equifax Hack Didn't Have to Be This Bad

bloomberg.com

61–70 of 74 posts

Re: The Equifax Hack Didn't Have to Be This Bad

#61

In 2008, the Federal Trade Commission created the Red Flags Rule, which required businesses and organizations to collect personally identifying information from their customers, even if not necessary for service. This put Social Security numbers into the hands of utility companies, telecom providers, doctors and countless other unreliable custodians. This is the first I've heard of this, and it's a different characte…

Wikipedia contains a lot of political disinformation / "selective" content and should not be used when looking for legal explanation.

Yes we know. Often it has links to authoritative/reliable/substantive sources. I was particularly interested in seeing those for the last section [0] I referenced above, because it's the one that actually agrees with TFA, but at this time that section is effectively unsourced. So even though this idea about the red flags rule comports with my prejudice about how regulation typically works, I am currently unable to confirm it. Can you point to a meatier consideration of whether this rule purportedly intended to decrease identity theft actually had this particular effect of increasing identity theft? One thing that makes me suspicious of this idea is that I can clearly remember giving a false social security number to the phone company when I moved in 2004, which was before 2008 when TFA claims the rule started and 2011 when wikipedia claims the rule started.

[0] https://en.wikipedia.org/wiki/Red_Flags_Rule#Red_Flag_Rule_a...

Re: The Equifax Hack Didn't Have to Be This Bad

#62
post #29

Earlier quoted context omitted.

I recently encountered an advertisement advising people to keep their Medicare card number secret. So if the SSN stops being considered as a combination identifier/authenticator, other government agencies stand eager and ready to plunge headlong into the same mistake. The way around it is to pass a law that requires government agents and agencies to consider identifiers to be public, and authenticators to be secret,…

Is the problem really government agencies or the many companies which tried to cut costs by misusing an identifier as an authentication secret? The law you propose seems like it would have no effect whatsoever unless it applied to the private companies which created and perpetuate this problem.

The point is these private companies are loathe to do anything that makes fraud harder or takes liability off the victims so yes, making laws is not only helpful it's the only thing that will ever work.

Re: The Equifax Hack Didn't Have to Be This Bad

#63
post #43

So since anyone who has access to the breached info can impersonate nearly anyone in the country... 1) Are we about to see the end of "Name, DoB, last four" as an authentication? (Damn well should if anybody can be me now) 2) Are the credit reporting agencies discredited as a business model? The other two are likely either hacked already or about to be, and given this standard of reporting we wouldn't know till month…

#1 seems almost certain if the spilled data really is as extensive as it seems. The government would be all but forced to go to some other mechanism (or at worst just open up a new space of numbers and give everyone a 12-digit "SSN+"). It's possible that the "possibly affecting 144M customers" bit is spun though and that only a tiny fraction of that ever left the datacenter. With #2, nothing is going to change. The c…

I don't know about that. The OPM hack was even worse in terms of data released. Seriously, it included actual images of peoples fingerprints ffs. Along with all biographical information of the people submitted to receive a security clearance background check. I think it may have hit fewer people, but I expect the result will be the same: 18 months of free credit monitoring and after that we pretend that somehow your SSN and all other details must no longer be a threat to you being out in the wild. Sure, in 30 years when someone digs it up and ruins your life with it, why make that OPM agency liable for it? I'm sure they hired top-notch security guys, paid them handsomely, and structured things such that not even the president of the USA could contravene their practices, right? Right?

Oh, a computer was involved. So hire the cheapest person you can find who can half make it work, let even the low level managers do whatever they want, and when it gets hacked blame somebody else. It's computers. NOBODY knows how they work!

Re: The Equifax Hack Didn't Have to Be This Bad

#64
post #9

The hack isn't just SSNs - it includes address history, date of birth, drivers license number - everything reasonably necessary to establish identity. Not sure why the focus is SSNs, any solution needs to be even higher. This is about companies stockpiling our personal information and us having little say in the matter.

I can't wait until the credit verification questions get even harder. "What check number did you use to pay the 13,753rd dollar of your car loan in 2001?" "In 2014, you signed up for an American Express Gold card. Which version of Firefox did you use to complete the application?"

When the Musk Mesh is in place, this will be a captcha: "To submit this form, think about the ex you still have feelings for"

Re: The Equifax Hack Didn't Have to Be This Bad

#65
It's something that people don't talk about much, but just the allowed existence of credit agencies violates human/civil rights.

These companies earn revenue by selling access to a database of all humans, which ranks each of us as to how valuable/risky we are to profit off of.

Many companies are starting to make hiring decisions based on this data, and obviously whether or not you are worthy of a loan has been much of the purpose of a credit rating (and these loans are necessary for nearly everyone in the US, unless you're exceptionally wealthy).

Disputing an unfair or illegal mark against your credit is an absurd process with very little recourse.

This is far worse than what the NSA has done, in my opinion, and it continues without much criticism.

Obviously this giant hack of Equifax is a very serious issue. But why should these credit companies be allowed to keep this kind of data about us anyway?

Re: The Equifax Hack Didn't Have to Be This Bad

#66
post #65

It's something that people don't talk about much, but just the allowed existence of credit agencies violates human/civil rights. These companies earn revenue by selling access to a database of all humans, which ranks each of us as to how valuable/risky we are to profit off of. Many companies are starting to make hiring decisions based on this data, and obviously whether or not you are worthy of a loan has been much o…

> It's something that people don't talk about much, but just the allowed existence of credit agencies violate human/civil rights.

What human right is being violated, and what treaty is that right listed in?

Re: The Equifax Hack Didn't Have to Be This Bad

#67
post #44

Before the digital age, a stash of nine-digit numbers could be kept reasonably secure in a locked filing cabinet behind closed doors. So long as consumers volunteered the numbers judiciously, most people could make it through life without ever suffering a theft of identity. Old guy here. The reason I know my SSN by heart is that it was my student ID number in college and had to be given at the beginning of each semes…

And both were probably illegal at the time. When Social Security was created, people were concerned about it becoming a de-facto national ID system, and it was illegal to use SSNs as an ID for anything other than taxes and Social Security Biz.

Medical insurance companies commonly broke the law but skirted it by saying it was "optional", and of course not telling anyone about the option. At least several times when I applied for insurance, I filled in "Assign ID" and had to correct the first level agent who insisted that I needed to provide and SSN. Patiently insisting that they needed to escalate the call, the first higher-level agents who knew would immediately accept it.

This sort of sloppyness confusing an IDentifier with an authentication has now gotten us into a world of trouble.

Re: The Equifax Hack Didn't Have to Be This Bad

#68
post #43

Earlier quoted context omitted.

#1 seems almost certain if the spilled data really is as extensive as it seems. The government would be all but forced to go to some other mechanism (or at worst just open up a new space of numbers and give everyone a 12-digit "SSN+"). It's possible that the "possibly affecting 144M customers" bit is spun though and that only a tiny fraction of that ever left the datacenter. With #2, nothing is going to change. The c…

I don't know about that. The OPM hack was even worse in terms of data released. Seriously, it included actual images of peoples fingerprints ffs. Along with all biographical information of the people submitted to receive a security clearance background check. I think it may have hit fewer people, but I expect the result will be the same: 18 months of free credit monitoring and after that we pretend that somehow your…

The Equifax dump (again, if it's really as described) is literally 10x larger than OPM. It's true that the OPM data was "worse" by abstract ideas of personal privacy, but not that the breach is worse from the perspective of "will drive government action".

Again, if there are really 144M valid SSN/name/address tuples out there in the wild, then very soon banks will simply no longer be able to authenticate applications for new accounts. They'll be swamped with fraud (remember that by US law, credit card fraud is their liability, not the consumer's), and demand action by the government to fix it.

But like I said, "if".

Re: The Equifax Hack Didn't Have to Be This Bad

#69
post #29

Earlier quoted context omitted.

Is the problem really government agencies or the many companies which tried to cut costs by misusing an identifier as an authentication secret? The law you propose seems like it would have no effect whatsoever unless it applied to the private companies which created and perpetuate this problem.

If SSN didn't exist then some equivalent (perhaps driver's license number and state? that would be convenient for non-drivers!) would be used, because the problem is actually at a different level. The way the laws governing banks and the credit industry are structured, it's possible to be on the hook for debt without a reliable proof of having agreed to that debt. If the laws changed to require that proof (e.g. credi…

The point is that SSNs are perfectly good for what they were designed for. The problem arose when companies decided to treat a username as a password but weren't forced to absorb the cost of their negligence.

Re: The Equifax Hack Didn't Have to Be This Bad

#70
post #66
post #65

It's something that people don't talk about much, but just the allowed existence of credit agencies violates human/civil rights. These companies earn revenue by selling access to a database of all humans, which ranks each of us as to how valuable/risky we are to profit off of. Many companies are starting to make hiring decisions based on this data, and obviously whether or not you are worthy of a loan has been much o…

> It's something that people don't talk about much, but just the allowed existence of credit agencies violate human/civil rights. What human right is being violated, and what treaty is that right listed in?

In just the UN's universal declarations of human rights:

Article 23, section 1 and 2, and possibly 3: as to being judged by employers based on a credit score.

Article 25, section 1: It is not possible to afford housing without a loan, and most of the variables of a loan (and even more importantly: whether you are able to secure a loan in the first place) are entirely determined by a credit score. Note that ~75-90% of Americans are unable to purchase a home without a loan: https://en.wikipedia.org/wiki/Wealth_in_the_United_States#St...

More from Article 25, section 1: Many of the other rights given in this document (like food, clothing, medical care) are also not achievable without smaller loans (like credit cards, also unattainable without a decent credit rating or a significant amount of accrued wealth).

I'm sure there's plenty more, this is just what I've seen at first glance. But I want to thank you for making me aware of this amazing UN document. It's kind of amazing the number of economic rights this document secures for all humans.

Post reply on HN