21 ms·
Senator to Ex-CEO: Equifax Can't Be Trusted with Americans' Personal Data
- deleted 9y ago[deleted]
- maxxxxx 9y agoI think they have to be careful not to focus on Equifax only. Instead they should think about systems where such a breach is just not possible. It's only a matter of time until other companies like credit card companies get breached. Same for Google and Facebook. We need a system where an individual can hand over information one a case-by-case basis and revoke that information anytime.
- throwaway9980 9y agoDisplaying data necessarily means copying data. Once data is copied and transmitted you have lost control of it. There isn’t a technical solution to stopping data from being copied and potentially stolen. You can mitigate the risk that it will be stolen with technical solutions, you can put processes in place that mitigate the risk, and you can deter by punishing thieves and negligent data processors. But ultimately it is risk mitigation and not elimination. Unfortunately there are no perfect solutions. The bulk of the risk is created by the outdated credit system itself and it’s reliance on easily obtained personal information as keys to the kingdom. Solve for x where x is “why can’t I just post my social security number on Facebook?”
- AnthonyMouse 9y ago> Instead they should think about systems where such a breach is just not possible. The underlying problem is the existence of centralized identity, as opposed to decentralized identity. It's the practice of identifying people by a single global identifier (e.g. SSN) instead of having your bank identify you with your bank card and your employer identify you with your employee ID. People are focused on identity theft here, but there are two points about that. The first is that identity theft doesn't exist without centralized identity, and the second is that identity theft isn't even the main issue. Centralized databases know very private things about you. They know if you've paid for services at an abortion clinic or a cancer treatment center or a mental health facility. They know if you've ever been on the payroll of a police department, or paid tuition at a police academy, even if you're currently working undercover. They know whether you patronize gay establishments, even if you're in the closet. They know your current address, even if you have a crazy ex who doesn't. That kind of information is inherently dangerous. In the wrong hands it can get innocent people fired or blackmailed or killed. Which means any central database containing all of it for everyone is inherently a huge vulnerability waiting to be exploited. And none of that goes away even if you replace the SSN with some kind of public key that doesn't itself need to be kept secret. But centralized identity is the linchpin of those databases and it isn't really needed for anything else. So we should get rid of it.
- maxxxxx 9y agoIt's a tricky issue but maybe we could make it illegal to store that data and instead you can release your data temporarily as needed.
- AnthonyMouse 9y agoIn other words decentralized identity? There is no reason to have Bank A release your credit history with them to Equifax just so Equifax can release it to Bank B. Cut out the middle man and just ask Bank A release the information to Bank B.
- colejohnson66 9y agoBut how does Bank A know to ask Bank B? That’s what Equifax and friends help with: aggregating the data (and then putting a number to it). It’s a great idea, but how would you implement it? If you cut out the middleman, banks will just form their own centralized system that holds all that data making it easier to access, and... oh, we’re right back where we started.
- AnthonyMouse 9y ago> But how does Bank A know to ask Bank B? Because you tell them to. When you're applying for credit with a new bank, you ask the existing bank to vouch for your history of making timely payments. In theory the person applying for credit could keep one set of accounts that they always pay and another set which is delinquent but not disclosed, but not disclosing delinquent accounts would be fraud and anyone willing to commit fraud has been able to commit identity theft this whole time without the system collapsing.
- Joeri 9y agoThere’s no effective taxation without centralized identity, so unless we move to a system of anarchy it won’t happen.
- 9y ago
- mrskitch 9y agoThis whole credit tracking industry is so unconstitutional it's crazy. I hope that this awakens people to the fact that their identities and personal data _should_ be theirs, and that they should fight tooth and nail to grant access to it. Centralizing information such as this is a "single-point-of-failure", or it is in spirit. I wish I had suggestions, but feel the something like a blockchain or other ledger is a step in the right direction. This Ted talk on the subject is interesting https://www.ted.com/talks/don_tapscott_how_the_blockchain_is_changing_money_and_business https://www.ted.com/talks/don_tapscott_how_the_blockchain_is...
- SilasX 9y agoWhere are you getting "unconstitutional"? A private organization remembers credit related events and reports them to lenders. I can understand pragmatic reasons to regulate exactly how they can go about that, but I don't see the connection to the Constitution.
- mrskitch 9y agoProbably a little over reacted on my part. Perhaps better said as un-American? Just seems to fly in the face of a lot ideologies folks here stand for.
- anotherproj 9y agoLike what?
- acdha 9y agoWhat value does a blockchain add? Beyond the obvious problems with privacy, the problem isn’t that there’s trouble getting personal info but rather two areas without effective corrective pressure: there isn’t an effective check on mistakes or a way to force errors to be corrected, and large financial organizations have successfully conned most of us into thinking that the cost for their failure to authenticate someone shouldn’t be their responsibility. A blockchain has no to negative value for the first problem – immutability means you'd need a way to force everyone to honor delete/update records — and since the whole point is not being anonymous, there’s no value for the second problem beyond what PKI does except that PKI has well-understood ways to deal with a compromise and the blockchain community is still working on the problem.
- Top19 9y agoThis is the choice quote: > "This simply is not a company that deserves to be trusted with Americans' personal data," said Sen. Sherrod Brown, D-Ohio, Obviously this quote leaves out a lot of nuance, but I like it and I like what Senator Brown has said in general. What Equifax has let happen is very bad, and I think moral judgments and perhaps even shame (which is how a society can enforce morality) should be brought onto its leaders individually. I hate how businesses and business persons have been making horrible, destructive decisions for decades (not that humans in all fields weren’t beforehand) and have been escaping any kind of shame. Indeed they’ve been praised in many cases. If you look at the top-level pages on Wikipedia (there are about 11 of them), one of them is for “Society”. About a third way down you’ll see “Business” listed under Society. I think this is a good reminder that business is a part of and functions for society, not the other way around. https://en.wikipedia.org/wiki/Portal:Contents/Society_and_social_sciences https://en.wikipedia.org/wiki/Portal:Contents/Society_and_so...
- X86BSD 9y agoThat is HILLARIOUS coming from the government that spilled MILLIONS of classified background checks from the OMB offices a few years ago. Absolutely hilarious and ironic and hypocritical. Also, the wife and I were one of the millions whose personal details were stolen from the OMB hack.
- LyalinDotCom 9y agoIs that before or after the same senators awarded Equifax a $7.5M no-bid IRS contract? <grin>
- deleted 9y ago[deleted]
- azinman2 9y agoWhat makes you think those senators on the banking committee are awarding IRS contracts?
- acdha 9y agoSenators don’t award contracts. In this case, the IRS is already using that service so when you see “no bid” that really means they didn’t want to take a production service offline while they re-bid it and/or hire the staff/contractors who would update the application to use something else. Remember that the rules government staff are required to follow are heavily based on up-front planning so putting out a bid means many months of delay. All of the anger directed at the IRS for this really should be directed into a positive direction of reforming the acquisitions process.
- olivermarks 9y agoMeanwhile, 'The IRS will pay Equifax $7.25 million to verify taxpayer identities and help prevent fraud under a no-bid contract issued last week, even as lawmakers lash the embattled company about a massive security breach that exposed personal information of as many as 145.5 million Americans.' http://www.politico.com/story/2017/10/03/equifax-irs-fraud-protection-contract-243419 http://www.politico.com/story/2017/10/03/equifax-irs-fraud-p...
- colejohnson66 9y agoIt’s probably a system written and it’s too late for a replacement
- LoSboccacc 9y agoTotal dodge of the ssn as authentication issue
- sethgecko 9y agoI was thinking, would it be a viable solution for the government to employ pen testers to test companies like banks/ISPs etc? It would more than pay for itself from the fines they would impose to those that hold sensitive citizen data and fail to hold high standards of security.
- gm-conspiracy 9y agoThis would be in conflict with the NSA's mission. Horde those 0-days.
- partycoder 9y agoMeanwhile: - Former Equifax CEO is walking away with 90 million dollars. - Equifax's stock price (NYSE:EFX) is recovering. - Equifax is being awarded contracts and continues to serve as a credit bureau. - The leaked information is being traded among fraudsters, and will remain to be traded for years. Welcome to the golden age of bullshit.
- MaxBarraclough 9y ago> The leaked information is being traded among fraudsters, and will remain to be traded for years Do we know that to be true? My understanding was that we have no idea what's being done with the leaked data. Has there even been a spike in fraud?
- spydum 9y agoMy prediction: tax return fraud is going to spike for 2017 returns. All other forms of identity theft profiteering are too high touch.
- partycoder 9y agoYou can set an IRS PIN to prevent that.
- deleted 9y ago[deleted]
- wu-ikkyu 9y ago>Do we know that to be true? Why wouldn't they sell the information when it is worth so much? >Has there even been a spike in fraud? Identity theft is at an all time high.
- MaxBarraclough 9y agoSo that's a 'no' on both counts, then?
- allengeorge 9y agoCall me cynical, but it's not going to change anything: * Equifax won't have fines levied against it * C-level staff won't have to pay fines (because they put in place or rewarded a corporate culture that made security a low priority) * Banks and other institutional customers won't stop using Equifax * No additional regulation will be created It's all theatre; we'll have "thoughts and prayers" directed our way while nothing of substance changes.
- acdha 9y agoThat cynicism is often self-fulfilling: the best way to ensure that outcome is to treat it as a given and not contact your representatives and state prosecutors asking for more.
- hpcjoe 9y agoWhile it is always "fun" (for some definition of the word fun) to pile on, and sometimes watch the otherwise clueless elected officials to get soundbites at the expense of a hapless CEO of a company that did bad things, or allowed bad things to happen on their watch ... the bigger picture is one of what sequence of events enabled this to occur. Placing the blame on an OSS component, or a "sole IT" person is both unfortunate, and generally wrong. None of this would have come to fruition had the business model not been one of "lets gather and curate high value information and intelligence about individuals", without an appropriate "gee, we have high value intelligence and information on individuals, maybe we should design our systems so that in the event of a failure of a security system, damage would be minimal." When you aggregate, curate, sell access to high value information, you damned well better have a good and fail safe security model. So if your DCs are overrun with hackers, the data exfiltrated would be unusable. More specifically, the principle I claim to be implicitly at play here is, with great power and/or information, comes great responsibility. Pointing fingers at lower level subordinates for their possible failings ... opening up and exposing the entire business model's core weaknesses in terms of data protection, and data access integrity and control ... means that the organization has simply failed to maintain, audit, test, and verify that its control systems are adequate to the task. Blaming an OSS component for all the damage means that the rest of the systems were not designed and built to the necessary level of safety and security. This is part of what I find unconscionable. They attempt to absolve themselves of blame by pointing fingers. When an organization does crap like this, you know they have many other problems. And yes, you cannot, and should not trust them going forward. If data was exfiltrated from them (and it was), is it possible that their data was altered in situ? Yes, yes it is. They should not be allowed to have such data in their control again. Seriously, if you can't control access to the data, you can't have the data.
- jasonkostempski 9y agoNo one can.
- featherverse 9y agoDuh, Senator. We knew this when Experian got hacked. Experian, Equifax, TransUnion, and any other credit bureaus are going to fail to protect people's personal data. There is no such thing as "unhackable", they are the biggest honey pots, and the majority of the Information Technology hiring pool is incompetent. The majority of competent candidates are underpaid or underappreciated and so they don't care as much as we need them to. Put all these things together and you have inevitable disaster after disaster after disaster. Credit Bureaus are old-think. They are unsafe, unsecure, and they don't fit with Future-Era lifestyle. Something better is required.