6 ms·
I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our onlin
by TravelTechGuy 9y ago
I think you are missing something. Here's what's needed to initiate your TransUnion freeze:
To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information:
1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III
2. Social Security Number
3. Date of birth
4. Current address
5. All addresses where you have lived during the past two years
6. Email address
7. A copy of a government-issued identification card, such as a driver’s license or state ID card, etc.
8. A copy of a utility bill, bank or insurance statement, etc.
So, if I hack TU, all I need to do is get the data of the people who asked for a credit freeze.
The problem is these companies, who non of us ever chose or nominated to collect our data, are careless with our PII. And until some accountability is added into the system, this will continue.
I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. Preferably with their jobs.
- scarmig 9y agoEquifax can handle its internal management and operations however it wants. Externally, though, I want Equifax to have to pay a fine for every individual whose information was compromised. Identity theft can easily cause five figures worth of damage, so $10k per individual would be fair. Maybe as a warning shot we could lower this to... $1k? $100? That's the only way to properly align incentives so companies will proactively defend against attacks like this.
- toomuchtodo 9y agoI would not doubt a class action lawsuit results from this, and I'd be very surprised if Elizabeth Warren didn't pursue congressional action against them (although not officers of the company unfortunately).
- scarmig 9y agoAnd then I'll get six months of free credit monitoring from Equifax? Oh boy!!1! More seriously, this is a breach big enough that Equifax should honestly no longer exist as a company. So call it $100/incident, and I'm happy. Other agencies would still exist, and, although they're just as terrible, it might get them to kick their asses into high gear to fix their security.
- abawany 9y agoThe NYT story states that they are already offering this to affected consumers: https://www.equifaxsecurity2017.com/potential-impact/ https://www.equifaxsecurity2017.com/potential-impact/ .
- stormcode 9y agoI went there and used the site and guess what? It doesn't work. It just said 'Thank You!' and gave me an enrollment date. It gave me no info as to if I was one of the people affected.
- icelancer 9y agoLikewise, WTF. I thought you were joking but nope, it returns this text: ----- Thank You Your enrollment date for TrustedID Premier is: 09/13/2017 Please be sure to mark your calendar as you will not receive additional reminders. On or after your enrollment date, please return to faq.trustedidpremier.com and click the link to continue through the enrollment process. For more information visit the FAQ page.
- sdenton4 9y agoThe number of affected people was 143MM, which I think is numerical shorthand for "everyone we've ever known about."
- tonyztan 9y agoThat means you are affected. If you enter a non-existent name and SSN, it will say that you are not affected.
- trapperkeeper74 9y agoThe content of the landing page (since it appears broken, here's the content from Reader View): Equifax Announces Cybersecurity Incident Involving Consumer Information [Equifax CEO statement] https://youtu.be/bh1gzJFVFLc https://youtu.be/bh1gzJFVFLc No Evidence of Unauthorized Access to Core Consumer or Commercial Credit Reporting Databases Company to Offer Free Identity Theft Protection and Credit File Monitoring to All U.S. Consumers September 7, 2017 — Equifax Inc. (NYSE: EFX) today announced a cybersecurity incident potentially impacting approximately 143 million U.S. consumers. Criminals exploited a U.S. website application vulnerability to gain access to certain files. Based on the company’s investigation, the unauthorized access occurred from mid-May through July 2017. The company has found no evidence of unauthorized activity on Equifax’s core consumer or commercial credit reporting databases. The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers. In addition, credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed. As part of its investigation of this application vulnerability, Equifax also identified unauthorized access to limited personal information for certain UK and Canadian residents. Equifax will work with UK and Canadian regulators to determine appropriate next steps. The company has found no evidence that personal information of consumers in any other country has been impacted. Read More
- notyourday 9y agoAnd? Who cares what a fake Indian says from a floor of the Senate?
- sctb 9y agoPlease don't post like this here. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- losteric 9y agoI expect managers to go to jail, in addition to a financial kneecap that forces other companies to vigilantly pressure their management for security. Well, maybe not expect. This is America... I expect infuriating golden parachutes. But I certainly hope for criminal charges and jail time.
- tombrossman 9y agoThis thing called "Identity Theft" does cause damage, but it's important to remember that if fraudsters trick a bank into thinking they are you, it is the bank's fault for failing to properly verify it was actually you. Doing so would cost them more money and it is much easier to do cursory checks instead. No doubt fraudsters impersonating you is a hassle and you must spend some time and money dealing with it if you are targeted, but do not lose sight of why it happens and who is ultimately responsible.
- damnfine 9y agoBut you still pay the fees from the banks failings, so it really does hurt everyone even when the bank eats it.
- alexanderstears 9y agoYes and no. If a "Too Big to Fail Bank" fails, we all pay. If a credit union in Utah messes up, their customers pay. Let banks compete on operational excellence.
- dmurray 9y agoIt hurts everyone foolish enough to still do business with the bank after they jack up their fees to pay for it. Or in jurisdictions where a small number of banks are given a monopoly, or competition is otherwise discouraged, it hurts everyone.
- hysan 9y ago$1k, $100, that's far too low in my opinion even for a warning shot. As someone who has had their info leaked by two universities before, both of whom subsequently paid for multiple years of credit/fraud protection, the sheer pain and stress of having random credit cards frozen and need to be replaced is worth far more than that dollar amount of my time. This is potentially messing with people's livelihoods with long term lasting effects. If monetary sums are given out, then I hope a fair amount is given out instead of a warning shot. Those tiny figures won't help at all and effectively send the message that companies are more important than the people they serve.
- ceejayoz 9y ago$1k would mean a $146 billion fine in this case. Hardly a "tiny figure".
- scarmig 9y ago$100 per each individual would be 14 billion dollars... Which would definitely put Equifax out of business.
- seanp2k2 9y agoPerfect. If they're in the business of selling access to sensitive information and cannot keep said sensitive information safe, they should not be allowed to continue to leak that sensitive information.
- deadmetheny 9y ago>Preferably with their jobs That's not nearly enough, considering the reach and impact this could potentially have. These people need to be getting life prison sentences before security is finally taken seriously enough by executives.
- TravelTechGuy 9y agoIt's high time we had an equivalent law to Sarbanes-Oxley for security. S-O made sure that when a C-level type guy signs a report, he knows his ass is on the line in case an illegal transaction just occur under his nose. If your company deals with PII, I want that data to be treated as important, if not more important, then company's funds. If you lose it, and you had any say in security (or lack thereof), you should do time.
- jstarfish 9y ago> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved on. It's more a problem with their reckless growth over the last decade than anything. (ed) Due diligence is obviously lacking, but I can personally attest that nobody in senior leadership there willfully ignores matters of security once it becomes known.
- scarmig 9y agoIf that were the case, then who approved the acquisition? Who did due diligence on it? Suddenly letting a bunch of untrusted, poorly audited code run on your infrastructure is itself a massive security breach. And even that doesn't explain how data was extracted for two months with no one noticing.
- maxerickson 9y agoI find it difficult to reconcile your second and third paragraphs. I guess choosing not to prioritize security (vs profit or whatever) when making acquisitions is different than just ignoring it entirely.
- TravelTechGuy 9y agoWe don't know if this has anything to do with any acquisitions - this is a conjecture, at best. At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in. Allowing data to slip out is negligent. If you're in the army, or the intelligence community, you get punished for this. It's about time the private sector felt some sort of accountability.
- damnfine 9y agoThis so much. The stream of corporations passing the buck into a black hole of irresponsibility needs to end now. If people arent held responsible, they will continue to make these failings without pause. I hope everyone is writing their legislators and congresspeople right now. They listen more than even my disillusioned self thought. The just might have bigger incentives to act otherwise. But if they dont know, they cant even choose to be corrupt or not, they are ignorant by proxy. Communicate to your leaders, and remember their response when you vote.
- justboxing 9y ago> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. Preferably with their jobs. Nope. Ain't gonna happen. Financial crime pays, big time! No one goes to Jail. They usually have an investigation followed by a hearing in Congress (if it is "BIG" enough), then come back and pay a fine. Media will report the fine as "MILLIONS OF $" but the fine hardly makes a dent in the Bank / Financial institute's coffer. W.r.t. this particular situation, here's a story that just broke. Three Equifax Managers Sold Stock Before Cyber Hack Was Revealed (bloomberg.com) => https://news.ycombinator.com/item?id=15196309 https://news.ycombinator.com/item?id=15196309 It's called INSIDER TRADING.
- sbov 9y ago> So, if I hack TU, all I need to do is get the data of the people who asked for a credit freeze. Sure, but TU already has all the above information anyways.
- notyourday 9y ago> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. Preferably with their jobs. No. With jail. And go bankrupt.
- ninguem2 9y agoNow there are news that they sold their shares last week.
- brational 9y ago> So, if I hack TU, all I need to do is get the data of the people who asked for a credit freeze. To what end? As has been pointed out they have all that info anyway so it's not like you're making the situation worse. But more importantly, if your credit is frozen who cares? What are they going to do with your SSN? Get a loan? Get a CC? Buy a house? That's the point of a freeze, it makes your PII less valuable. The actual concern is about the PIN. Because surely they could go through the trouble of PIN recovery to unfreeze your credit and then make use of it. But considering the numbers game, its not worth their trouble vs all the unfrozen accounts.