3 ms·
Looks like Equifax gets a junk bond rating in the personal information handling. This company should be shut down. 3.1B revenue and can't secure data, not even
by pgnas 9y ago
Looks like Equifax gets a junk bond rating in the personal information handling. This company should be shut down. 3.1B revenue and can't secure data, not even really trying. Greed.
- tudorw 9y agoWhich company can secure data? Are we're just assuming it's viable and reasonable, there are a lot more examples of failure than success, Sony, Apple, AT&T, Snapchat the US Army, https://en.wikipedia.org/wiki/List_of_data_breaches https://en.wikipedia.org/wiki/List_of_data_breaches I'm not really sure the protocol is up to the job, while theoretically it would appear possible to secure data on the internet, the reality seems to be that the complexity of the systems involved means there is no reliable solution.
- jv22222 9y agoHoly crap, that list of data breaches is incredible. And by incredible, I mean really difficult to believe. If anything should be #1 on hacker news for an entire month it should be that page right there.
- KGIII 9y agoWhat is remarkable, and it pains me to say this, is that Microsoft isn't on that list. With all the telemetry data they collect, they might have some good data stored. I'm sure people are trying to hack it, even right this minute. They seem pretty capable, so far, of keeping their own collected data secured.
- tluyben2 9y agoSome of these breaches, for instance the Gmail/Google breach, might have not been a breach of there systems at all. So far for that example (but there are more), one could apply that to Outlook/MS and get identical results. Aka; hack some service that has millions of emails/password (accumulated), filter all gmail emails, try to login to gmail with that compbi and if it works, put them into the list of 'hacked gmail accounts'. Not trying to stick up for Google here, but, like MS, there seems to not be a real breach there.
- bogomipz 9y agoAnd that entry is missing a bunch as well. Specifically It doesn't list the most recent T mobile breach. This breach was notable in that it was called a T Mobile Breach but the data was stoled from Experian's servers. T Mobile pointed the finger at Experian and Experian said they were just storing the data at T-Mobile's request. This breach affected 15 million people. The asshole's at T Mobile as well as Experian offered one years of free credit monitoring from Experian as a resolution. In order to elect to participate in the offer you were required to enter your social security number into a sketchy looking web page. See: https://krebsonsecurity.com/tag/t-mobile-breach/ https://krebsonsecurity.com/tag/t-mobile-breach/
- hodgesrm 9y agoThis reminds me of the famous Scott McNealy quote from 1999 ("You have zero privacy. Get over it.") A lot of people are making the assumption that digital information can be somehow protected when in fact it seems the opposite assumption is more likely to be correct--any information in digital form accessible on a network will be compromised. It's just a matter of time and not even a very long time in most cases. What if we take this as a starting assumption for information management? I think this leads you to a different way of thinking of information protection, specifically that we need to come up with ways to extend the time that private information remains protected. For example, what prevents us from having physical "information wallets" that we carry around with us and unlock only on demand and in return for specific services? This sounds a lot like an iPhone. Why don't we put things like medical records in them? I think the technology to do this is already on the horizon, especially if you assume that the information that people truly need to protect (e.g., financial records) is not that large.
- walshemj 9y agoYep should be nationalised with no compensation to share holders - that threat would be enough to make the remaining 2 behave