16 ms·
I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most
by Posibyte 9y ago
I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons.
And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has suggestions on that, I'm totally open, because if Equifax was a dripping faucet, they'd be flooding the house by now.
- dsgfhasgjklas 9y ago> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." Freeze your account and complain to the service that uses it. Of course, you're not wrong—you have essentially zero leverage.
- astura 9y agoFreezing your account doesn't prevent you from data breaches, your account still exists in their database, they just say "its frozen" when someone requests it.
- dsgfhasgjklas 9y agoThat's true, but that's also true of anywhere that uses social security numbers for identity verification (which is an atrocious pattern considering how poorly ssns are anonymized).
- rgbrenner 9y agofreeze your credit report with Equifax, and then if any company requests it, they'll be denied (because you have to request it be unfrozen for them to receive it). If any company uses Equifax, you'll then be denied credit or they'll ask you to unfreeze it.. either way, you can complain to them, and make it clear you won't work with Equifax. Of course, in practice, this will mean you'll get denied credit from any company that has a contract with Equifax.
- djb_hackernews 9y agoDoesn't this require you to trust Equifax to enforce and honor the freeze? I think the solution is "I don't want my report or any of my data in any sort of control or possession of Equifax". Where is that solution?
- munin 9y agoWhat is "your data" exactly? And in the limit, how far does this go? Here's a question: who owns your drivers license? Here's a hint: it isn't you. Can you "own" you mailing address? Copyright and trademark it, make everyone ask permission from you before they write it down? What about your salary? Should your employer have to ask every time they use your salary number in some way, say in aggregate statistics or reporting? What about information about how you interact with your credit card company? Who owns that, you, or the credit card company? Do the two of you have some kind of joint ownership? We've made some of these decisions about health data and it has far-reaching consequences, some of them undesirable. It's also been very difficult to enforce. Do you want to extend that kind of regime to every piece of information about a person? Society might grind to a halt, we would be inundated with virtual and physical pop-ups asking "your landlord wants access to your phone number to place a call to you, will you allow it?" And what process would mediate this access control anyway, and how would we trust it?
- code_duck 9y agoAs far as copyright, small snippets of information or sentence fragments are not copyrightable, but collections of data are. >Society might grind to a halt, we would be inundated with virtual and physical pop-ups asking "your landlord wants access to your phone number to place a call to you, will you allow it?" That is how messaging works on many newer systems like Facebook or Instagram, and people appear to find that level of control desirable, not annoying. The only reason the phone system works with public numeric IDs that anyone can dial is that whole thing is a relic from 50 years ago.
- mattnewton 9y agoThe issue is that I am responsible for people using this data, but don’t own it like you mentioned. If the banks were responsible for giving out fraudulent loans and there was an easier way to prove that they were fradualent without this PI, then I wouldn’t care. But I have to care right now.
- hacker_9 9y ago"Too big to fail"
- Florin_Andrei 9y agoI would argue that having a single occurrence of a hack, isolated, seems unlikely. If a site got hacked, chances are they suck at security - and then subsequent hacks are actually more likely to happen over the near future. It takes time to turn corporate culture around, and security depends a lot on culture. Would be great to see some statistics that would either support or disprove my assertion.
- rdtsc 9y ago> Their stocks are still priced reasonably well, Exactly. And everyone is watching and learning a lesson from it - "If this goes unpunished, heck, we can get away with it too, screw all the security mumbo jumbo" In an investing and finance forum I saw people were gearing up to buy Equifax after the breach was announced. The idea was that price would dip then it would go back up. Maybe enough people did that.
- Simulacra 9y agoStock price seems to be the driving factor for corporate change in America. Until that price dips, or tanks, companies appear to use that as a barometer of their behavior.
- ModernMech 9y agoIf that's the case, it seems like the executives at Equifax who were dumping stock after they learned of the breach (but before it was reported) were jumping the gun. They should have just held on to it! "Three senior executives including the company’s chief financial officer sold $1.8 million in shares three days after the company learned on July 29 hackers had breached personal data for up to 143 million Americans." http://fortune.com/2017/09/29/equifax-board-executive-stock-sales/ http://fortune.com/2017/09/29/equifax-board-executive-stock-...
- astura 9y agoThat's short sighted - how you make money is sell when high, buy when low. So you sell right before the dip and then buy again at the bottom of the dip. They knew there was going to be a dip.
- leggomylibro 9y agoUnfortunately, the SEC might notice if those executives sold a bunch of shares on insider info, quit, and then bought more shares after the crash. I guess they probably wouldn't do anything, but they might notice.
- code_duck 9y agoFor this new issue, the problem is that by the time you're even halfway through the sentence "part of Equifax’s website was under the control of attackers trying to trick visitors into installing fraudulent Adobe Flash updates that could infect computers with malware", 90% of people I have decided that it's over their head and stopped listening.
- PatientTrader 9y agoThis has nothing to do with punishment. This is the result of a broken system. Most fortune 500 companies pay the ransomware price and the public is never aware of any breach. The idea of storing information on a connected network is the problem. We need to return to the brick and mortar way of storing data, i.e. Tightly guarded central facilities. Nobody should be able to steal 148 million accounts with the click of a button.
- hodgesrm 9y ago> And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." A good start might be never employ anyone who has worked in Equifax IT. There should be some sort of professional repercussions for being involved with an organization as incompetent as this lot seem to be.
- monsieurbanana 9y agoYou can't see it, but I'm rolling my eyes fast at your comment.
- warent 9y agoMore specifically their IT executive team. Odds are that the lower level tech staff are treated horribly
- KGIII 9y agoWhy is that a good start? They are ex employees. Perhaps they are no longer there because they quit due to bad leadership, bad security, bad company ethics, or maybe they were fired for continually reporting their security flaws? I get that some people like meting out punishment, but it seems like a good idea to limit it to the people responsible.
- hodgesrm 9y agoYour and other comments are good responses. My comment was mean-spirited and (worse) wouldn't solve the problem. A lot of the problems we are seeing can be traced back to the fact that the leadership who make decisions suffer little or nothing in the way of personal consequences. It seems past time for us to change the law so that this is no longer the case. That's about the only way things will change. It's dispiriting to see security breaches and misuse of personal data happening again and again.
- neilparikh 9y agoI'm sure there was some incompetance at the individual level, but I think it's more likely that the key issue was that the management de-prioritized security, which lead to the IT team either not having staff on hand to fix issues that came up, or being assigned tasks other than fixing the security issues. In that case, ruining the career of a low-level employee seems misplaced, especially when they most likely weren't the cause of these issues.
- discoursism 9y agoI agree that the situation is bad, but I do want to call out a technicality here. You don't have to work with them. Everyone around you chooses to work with them, because they believe that doing so is safer than not. And this impinges on you, because if they have bad info on you, it can hurt your interactions with people around you. There is little that you personally can do to control the sources others use to gather information about you. That's something that's only within the power of a legal framework. The statement, "I don't want to work with Equifax because I don't trust them," is meaningless, because you do not work with Equifax.
- throw-away-521 9y agoComments like this are why people stop reading the comment section.
- deleted 9y ago[deleted]