8 ms·
The Equifax Hack Didn't Have to Be This Bad
- ErikVandeWater 9y agoTitle not supported by article.
- mfoy_ 9y agoIt is, and is related to some of the discussion in the main Equifax hack threads. The idea is that this information shouldn't be so sensitive because it isn't really secret in the first place. It also cannot be changed, so it doesn't really meet any reasonable criteria for authenticating information. To quote the relevant top-level comment I had in mind: >mikeash 2 hours ago [-] >If we're lucky, this will be the best leak of personal info ever. The primacy of the SSN in American society is idiotic. It's a "secret" that you have to hand out to dozens of different organizations. I've long thought that we should phase this out by committing to publish all SSNs (and the associated info, obviously, so it's not just a list of most 9-digit numbers...) which would force all these companies to stop treating it as confidential. The system is dumb and works poorly, but worked will enough that there was no impetus to fix it. Some people got affected by breaches, and it sucked for them, but it was always a small enough group that most people didn't care. Now that a majority of people's "secret" info is no longer confidential, maybe they'll realize they can't rely on it anymore. OK, the odds of this actually coming to pass are not great. But I can hope.
- dboreham 9y agoAlso note that other countries don't have this insanity.
- deleted 9y ago[deleted]
- gbarc888 9y agoWhich countries do you mean? How do they manage their credit scores?
- smnrchrds 9y agoCanada does unfortunately. It's called a Social Insurance Number (SIN) or Numéro d'assurance sociale (NAS) but other than the name, it is mostly the same. And Canada is on the list of the countries suffering from the breach. This should be interesting.
- mfoy_ 9y agoIndeed. I wanted to see if I was on the list, but the site they set up to check looked pretty sketchy. They've clearly demonstrated I shouldn't trust them with my SIN (not that I ever willingly did in the first place!) so why should I enter it again? Into a different domain, no less?!
- deleted 9y ago[deleted]
- logfromblammo 9y agoI recently encountered an advertisement advising people to keep their Medicare card number secret. So if the SSN stops being considered as a combination identifier/authenticator, other government agencies stand eager and ready to plunge headlong into the same mistake. The way around it is to pass a law that requires government agents and agencies to consider identifiers to be public, and authenticators to be secret, and that nothing can ever be both. The government could require itself to publish indexes of names to SSNs and SSNs to names, such that no stretch of anyone's imagination would ever generate a presumption that knowing the number proves you are the person to whom it is assigned. The ridiculous assumptions made in the credit and credit reporting industry that are held out to be reasonable should never be allowed to hold up in court.
- acdha 9y agoIs the problem really government agencies or the many companies which tried to cut costs by misusing an identifier as an authentication secret? The law you propose seems like it would have no effect whatsoever unless it applied to the private companies which created and perpetuate this problem.
- jessaustin 9y agoIf SSN didn't exist then some equivalent (perhaps driver's license number and state? that would be convenient for non-drivers!) would be used, because the problem is actually at a different level. The way the laws governing banks and the credit industry are structured, it's possible to be on the hook for debt without a reliable proof of having agreed to that debt. If the laws changed to require that proof (e.g. creditors must have a video of the debtor stating "I am Alice Smith my birthday is July 1 1970 I live at 123 Main St in Springfield and I agree to pay $100 on or before January 1" or something similarly difficult to fake at scale), nobody would care about SSNs anymore. Of course that would introduce friction to the process, but with consumer debt at its current levels maybe that would be a good thing?
- acdha 9y agoThe point is that SSNs are perfectly good for what they were designed for. The problem arose when companies decided to treat a username as a password but weren't forced to absorb the cost of their negligence.
- sillysaurus3 9y agoCGP has a good video on this: https://www.youtube.com/watch?v=Erp8IAUouus https://www.youtube.com/watch?v=Erp8IAUouus
- shmerl 9y agoIndeed. This pervasive usage of SSNs should be dropped.
- AckSyn 9y agoThe pervasive want of private corporations to stockpile our private information is a huge concern as well. There's hardly any reason they should store anything beyond name and contact info.
- snomad 9y agoThe hack isn't just SSNs - it includes address history, date of birth, drivers license number - everything reasonably necessary to establish identity. Not sure why the focus is SSNs, any solution needs to be even higher. This is about companies stockpiling our personal information and us having little say in the matter.
- uobytx 9y agoThe reason the focus is on the SSN is because it enables credit. Privacy is important, but so is protecting your finances.
- vageli 9y agoWhen applying for credit, especially online, have you not been asked to verify some current loans from a list, or to pick out a past address from a list of addresses? I know I have. That data also enables credit.
- jmkb 9y agoDate of birth and address history (in addition to SSN of course) are often used by financial organizations to verify user identity online and on the phone. Recently I called to report a lost credit card, for instance, and the operator read through a list of 10 addresses. I had to confirm which ones I'd lived at at some point in my life, in order to verify my identity.
- nindalf 9y agoWouldn't it have been simpler and more secure to ask you for the address? I can rattle off all the addresses I've stayed at in the last 15 years with ease.
- bbarn 9y agoI couldn't. I am a city dweller living in a climate where almost like clockwork a post-two year rent hike makes me decide to move. not only that, being on a grid system every address tends to be some 4 digit combination of numbers very similar. Was that 1124 or 1421 10 years ago? I'd have to sit and picture the cross streets to figure it all out.
- AngeloAnolin 9y ago"The only thing Social Security numbers should be used for is to pay our taxes, which identity thieves are welcome to do." Likely they may not be paying taxes, but have already found a way to circumvent the system such that they collect something (aid, EI, etc).
- prdonahue 9y agoActually what they do is early filing to receive any refund that would be coming to you.
- MichaelBurge 9y agoDoes the IRS lose money if they give the refund to the wrong person? Or is the onus on you to find the criminal and sue him?
- 64738 9y agoYes, they lose billions per year in fraudulent refunds.
- guelo 9y agoConsumers don't use the credit reporting database, we have very little access to it besides restricted annual or paid for reports. The real users are the B2C companies like retail banks, cell phone companies, apartments, background checkers, etc. These B2Cs use the db in both read and write modes with little verification. The main incentive of the reporting agencies is to make it very easy for B2Cs to read and write to their db. Any strong encryption scheme would have to take into account the needs of the B2C's. Nothing is going to happen unless congress demands it because their is no market incentive to secure it. The data is already known to be frequently inaccurate but businesses don't care, they'd rather have a bunch of false positives than one deadbeat customer.
- tbrock 9y agoI'm very worried about this. I've done a lot to try and build my credit and protect my identity by restricting the information I give out. Now I can do nothing to protect it now besides hope someone doesn't target me. Anyone have ideas on how to ensure an identity is not stolen?
- ReidZB 9y agoYou can use a credit freeze: https://www.consumer.ftc.gov/articles/0497-credit-freeze-faqs https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq... > Also known as a security freeze, this tool lets you restrict access to your credit report, which in turn makes it more difficult for identity thieves to open new accounts in your name. That’s because most creditors need to see your credit report before they approve a new account. If they can’t see your file, they may not extend the credit. I've never done this, but it sounds effective - although if you want to open another line of credit, you'll have to temporarily suspend the freeze.
- itodd 9y agoYou also have to pay Equifax $10 to do this. Insane, right?
- dublinben 9y agoThat sounds like extortion to me. Equifax are running a protection racket.
- jjeaff 9y agoIt's not really effective. It can help, but a surprisingly large number of businesses will actually never actually run your credit. They will just keep your information on file and then when the scammer doesn't pay the loan, they start reporting the delinquency to the credit reporting agencies. And in that case, the freeze doesn't apply.
- jjeaff 9y agoThere is only one solution and that is identity theft insurance. All other solutions that purport to protect your credit are futile. Although I think some are now offering insurance as part of their guarantee. I use Zander identity theft insurance. If my identity is ever stolen, they are supposed to take over all the hassles of getting me right. As well as up to a million dollars in damages including legal fees if necessary. I have heard good things from customers who had their identity stolen. But I can't personally vouch for how well their recovery services work since I havent experienced a theft yet.
- jessaustin 9y agoIn 2008, the Federal Trade Commission created the Red Flags Rule, which required businesses and organizations to collect personally identifying information from their customers, even if not necessary for service. This put Social Security numbers into the hands of utility companies, telecom providers, doctors and countless other unreliable custodians. This is the first I've heard of this, and it's a different characterization than what one finds on e.g. Wikipedia (excepting the last section of that page). Still, I believe TFA. It's remarkable how often the impetus to "do something" leads to precisely the wrong thing being done.
- MicroBerto 9y agoWikipedia contains a lot of political disinformation / "selective" content and should not be used when looking for legal explanation.
- jessaustin 9y agoYes we know. Often it has links to authoritative/reliable/substantive sources. I was particularly interested in seeing those for the last section [0] I referenced above, because it's the one that actually agrees with TFA, but at this time that section is effectively unsourced. So even though this idea about the red flags rule comports with my prejudice about how regulation typically works, I am currently unable to confirm it. Can you point to a meatier consideration of whether this rule purportedly intended to decrease identity theft actually had this particular effect of increasing identity theft? One thing that makes me suspicious of this idea is that I can clearly remember giving a false social security number to the phone company when I moved in 2004, which was before 2008 when TFA claims the rule started and 2011 when wikipedia claims the rule started. [0] https://en.wikipedia.org/wiki/Red_Flags_Rule#Red_Flag_Rule_and_identity_theft https://en.wikipedia.org/wiki/Red_Flags_Rule#Red_Flag_Rule_a...
- pseudalopex 9y agoA couple of people who handled Red Flags compliance for medical practices have told me they're only required to do some kind of identity verification, which can be as simple as checking a driver's license. They store SSNs to make it easier to report and collect on delinquent accounts.
- zentiggr 9y agoSo since anyone who has access to the breached info can impersonate nearly anyone in the country... 1) Are we about to see the end of "Name, DoB, last four" as an authentication? (Damn well should if anybody can be me now) 2) Are the credit reporting agencies discredited as a business model? The other two are likely either hacked already or about to be, and given this standard of reporting we wouldn't know till months from now anyway. Can't trust em, don't use em, don't trust anybody that does. Oh joy.
- ajross 9y ago#1 seems almost certain if the spilled data really is as extensive as it seems. The government would be all but forced to go to some other mechanism (or at worst just open up a new space of numbers and give everyone a 12-digit "SSN+"). It's possible that the "possibly affecting 144M customers" bit is spun though and that only a tiny fraction of that ever left the datacenter. With #2, nothing is going to change. The credit agencies business isn't identifying people (as we are discussing, they outsource that to the government), it's tracking credit activity. And that works extraordinarily well from the perspective of its customers (the banks). If Equifax dies, Experian and TransUnion will just see more business. If they all die, the banks will find some way to do this for themselves.
- otakucode 9y agoI don't know about that. The OPM hack was even worse in terms of data released. Seriously, it included actual images of peoples fingerprints ffs. Along with all biographical information of the people submitted to receive a security clearance background check. I think it may have hit fewer people, but I expect the result will be the same: 18 months of free credit monitoring and after that we pretend that somehow your SSN and all other details must no longer be a threat to you being out in the wild. Sure, in 30 years when someone digs it up and ruins your life with it, why make that OPM agency liable for it? I'm sure they hired top-notch security guys, paid them handsomely, and structured things such that not even the president of the USA could contravene their practices, right? Right? Oh, a computer was involved. So hire the cheapest person you can find who can half make it work, let even the low level managers do whatever they want, and when it gets hacked blame somebody else. It's computers. NOBODY knows how they work!
- avid-infovore 9y agoThe Republic of Estonia uses such a system to identify members of its e-Residency program, even with no physical presence. Each e-resident has a public numerical key that serves as a unique identifier, and a corresponding private key that is never revealed. So an example to emulate then! Except: Estonia suffered an embarrassing blow to its much-vaunted ID cards that underpin everything from electronic voting to online banking [...] a security risk that affects almost 750,000 ID cards and that would enable a hacker to steal a person’s identity. https://www.ft.com/content/874359dc-925b-11e7-a9e6-11d2f0ebb7f0 https://www.ft.com/content/874359dc-925b-11e7-a9e6-11d2f0ebb...
- unpwn 9y agoIs there a link to this that's not behind a paywall. Very interested in understanding the flaws of such a system, as a 2 key system seems like the most viable and secure way to establish identity.
- deleted 9y ago[deleted]
- taesis 9y agoGoogle's cache of the page [1] seems to work. [1]: https://webcache.googleusercontent.com/search?q=cache:wP7nTGn-RJ0J:https://www.ft.com/content/874359dc-925b-11e7-a9e6-11d2f0ebb7f0+&cd=1&hl=en&ct=clnk&gl=ca https://webcache.googleusercontent.com/search?q=cache:wP7nTG...
- avid-infovore 9y agoNon-paywalled link: http://estonianworld.com/technology/possible-security-risk-affects-750000-estonian-id-cards/ http://estonianworld.com/technology/possible-security-risk-a...
- mwg986 9y agoIf you search google using the url for the article and then follow the search link you can get behind the paywall. Here's a link to the google search result - https://www.google.com/search?q=https%3A%2F%2Fwww.ft.com%2Fcontent%2F874359dc-925b-11e7-a9e6-11d2f0ebb7f0&oq=https%3A%2F%2Fwww.ft.com%2Fcontent%2F874359dc-925b-11e7-a9e6-11d2f0ebb7f0&aqs=chrome..69i64.1316j0j7&sourceid=chrome&ie=UTF-8 https://www.google.com/search?q=https%3A%2F%2Fwww.ft.com%2Fc...
- deleted 9y ago[deleted]
- jdhzzz 9y agoBefore the digital age, a stash of nine-digit numbers could be kept reasonably secure in a locked filing cabinet behind closed doors. So long as consumers volunteered the numbers judiciously, most people could make it through life without ever suffering a theft of identity. Old guy here. The reason I know my SSN by heart is that it was my student ID number in college and had to be given at the beginning of each semester to get my course list, later for grades, etc. I had a credit union account from the 80's and as of the 90's my SSN was printed on each monthly statement. Both were before the "digital age" and neither could be considered "in a locked filing cabinet" nor under my control.
- ben1040 9y agoYou don't even have to be that old to remember this time. I went to a well-known university and they used SSNs as student ID number until roughly 2001-2002. The first half of my university career, my SSN wound up on every Scantron sheet, exam blue book, and term paper I handed in. It was printed on the front of my ID, and even after they recalled old IDs and replaced them with non-SSN cards, the magstripe track data still had your SSN on it because some old dining hall POS system or something like that hadn't been converted. It was like fish in a barrel for fraudsters, just root around in the trash after finals week and grab people's term papers. I had quite a few friends who discovered that during the time they were attending college, someone had opened a cell phone (or a credit card, in one person's case) in their name. This was before the days of the free annual credit report law. So these folks never pulled their own files, and only discovered the fraud years after graduation, when they went to apply for a car or home loan and got denied.
- otakucode 9y agoHeh, it actually changed while I was in college. As a CS student, one of the required courses was a 'Computers and Society' course which was basically sort of like a 'where ethics meets technology' course, talking about the social impact of code and computing. The kind of thing many people today seem to have need to attend. But anyhow, during it we mentioned 'hey, why are our student IDs, used everywhere, our SSNs? Isn't that unsafe?' and we actually ended up getting it changed. Didn't stop some professors from continuing to use them. I had one prof who would use the last 4 digits (oh, only the last 4, those aren't the most important ones or anything) as a way to post psuedoanonymous grades after tests.
- otakucode 9y agoWell of course it didn't have to be this bad. But when criminal negligence for corporations remains unpunished in an industry for 40+ years, you're not going to have corporations that dedicate the time, let alone the money, to do things right.
- iblaine 9y agoSWIM used to have access to Equivax data from home. In the early 90s, you could log into Equifax, type in a strangers address, and get their credit history, social, bills, and prior addresses among other things. Access was through tymnet using an <account_id>+<password>. That is it. The account_id was a ~16 digit number. The password was a 1 alpha + 1 alphanumeric. In those days it was security through obscurity, so I presume. Get an account number and after 936, you are in. Given this recent breach has nothing to do with how Equivfax/CBI was run years ago, it does make me cringe a bit.
- technofiend 9y agoIn the 80's it was even worse. A credit bureau was available on telenet (a simple dial up service that allowed terminal connections to services) and there was no password, just an account number. You could query any social security number and see joint account information by simply adding /ty-jp or something similar. This being the 80's, you'd see the needed credentials taped to monitors.
- tr1ck5t3r 9y agoReading your comment reminded me of a similar system which gave access to phone numbers of people & businesses including non listed numbers. Still I have yet to see people realise that if you want to undermine a country's financial system, screw up their credit rating agency's. I dont believe Equifax when they say only certain data has been accessed, these are normalised databases, I suspect the CEO is bluffing or being very lenient with the true if they are only referring to one table/file and not the rest of the database, and thats if they even know just how much data has been accessed. These agency's share information between themselves so the knock on effect is all the credit rating agency's will probably have duff data if any of it has been changed. Still it could also be a back door way for the Central Banks to get money out into the economy if everyone can suddenly take out massive loans on the lowest interest rates known to man, because its not like the financial system in the West has ever recovered from the financial crisis in 2008, so when overt QE has failed, why not try some covert QE and blame it on the oh so spooky hackers.
- throwaway17761 9y agoApparently the Chief Security Officer's credentials are a degree in music[1]! I wish I was kidding. https://www.linkedin.com/in/susan-m-93069a/ https://www.linkedin.com/in/susan-m-93069a/
- beebmam 9y agoIt's something that people don't talk about much, but just the allowed existence of credit agencies violates human/civil rights. These companies earn revenue by selling access to a database of all humans, which ranks each of us as to how valuable/risky we are to profit off of. Many companies are starting to make hiring decisions based on this data, and obviously whether or not you are worthy of a loan has been much of the purpose of a credit rating (and these loans are necessary for nearly everyone in the US, unless you're exceptionally wealthy). Disputing an unfair or illegal mark against your credit is an absurd process with very little recourse. This is far worse than what the NSA has done, in my opinion, and it continues without much criticism. Obviously this giant hack of Equifax is a very serious issue. But why should these credit companies be allowed to keep this kind of data about us anyway?
- DanBC 9y ago> It's something that people don't talk about much, but just the allowed existence of credit agencies violate human/civil rights. What human right is being violated, and what treaty is that right listed in?
- beebmam 9y agoIn just the UN's universal declarations of human rights: Article 23, section 1 and 2, and possibly 3: as to being judged by employers based on a credit score. Article 25, section 1: It is not possible to afford housing without a loan, and most of the variables of a loan (and even more importantly: whether you are able to secure a loan in the first place) are entirely determined by a credit score. Note that ~75-90% of Americans are unable to purchase a home without a loan: https://en.wikipedia.org/wiki/Wealth_in_the_United_States#Statistics https://en.wikipedia.org/wiki/Wealth_in_the_United_States#St... More from Article 25, section 1: Many of the other rights given in this document (like food, clothing, medical care) are also not achievable without smaller loans (like credit cards, also unattainable without a decent credit rating or a significant amount of accrued wealth). I'm sure there's plenty more, this is just what I've seen at first glance. But I want to thank you for making me aware of this amazing UN document. It's kind of amazing the number of economic rights this document secures for all humans.