9 ms·
This report is brutal, it goes into great detail about the technical incompetence in many areas. Yet Equifax is doing better than ever. No new laws, no reform,
by notinversed 7y ago
This report is brutal, it goes into great detail about the technical incompetence in many areas.
Yet Equifax is doing better than ever. No new laws, no reform, nobody goes to jail. All the rich people get to keep their money.
Thoughts and prayers.
- ilrwbwrkhv 7y agoamen brother
- coldcode 7y agoReports like these without action or repercussions may as well be printed directly to a trash can.
- 2stepsfromfree 7y agogood enough for government work
- deleted 7y ago[deleted]
- m-p-3 7y agoMy financial institution was the subject of an internal security breach (rogue employee who managed to get his hands on millions of customers private information like social insurance number, DOB, etc) and what do we get offered to protect from identify theft? A five year subscription to Equifax..
- ryanmarsh 7y agoWell that’s one way to earn new customers.
- kalenx 7y agoOut of curiosity (not trying to be snarky here, I really want to know), what should be offered by Desjardins? I mean, no amount of money can prevent identity theft and I do not see hundreds of ways to reduce the risks -- especially ways that do not involve Equifax or Transunion... Realistically, apart from the obvious "this shouldn't have happened in the first place", what more could they be doing?
- Nextgrid 7y agoActual money? Paid for by the executives in the form of fines, bankrupting the company if necessary.
- kalenx 7y agoExcept in this case it is not a company but a credit union. Bankruptcy just means loosing everything for its _members_. Also, sure "here's one million $". Two weeks after this money is gone because someone stole your identity and empty your account. This is the kind of thing that money simply cannot solve.
- Nextgrid 7y ago> Two weeks after this money is gone because someone stole your identity and empty your account Do people actually lose large amounts of money due to ID theft? I've always considered ID theft to be the lenders being defrauded, and while it is a huge hassle to get sorted, the real person isn't legally liable for the debt fraudulently obtained in his name. Also, if you think money is a bad idea, what else do you propose? I'd rather take money with the chance of losing it rather than no money and "credit monitoring" which doesn't actually prevent ID theft, only alerts you after it's already too late. If anything, the money idea actually makes sense as insurance for future losses due to potential ID theft.
- sjy 7y ago> Bankruptcy just means loosing everything for its _members_. Surely it's typical for credit unions to have deposit insurance? If not, there should be regulations in place to ensure people understand that they are basically just shareholders.
- sl1ck731 7y agoNew SSN and a personal Equifax "slave" to update it anywhere and everywhere its used in my life would be a good start. They can offer a couple years of their BS identity protection, but your identity is ruined forever. Your SSN doesn't rotate or expire. There should be no time limit on any remedy they provide.
- cwkoss 7y agoSuggesting that Equifax can mitigate a PII breach is negligently incorrect.
- exabrial 7y agoThe real problem with fines and class action lawsuits is the money just goes to the federal government or the litigating law firm who takes a 50% cut. We as the people affected might see a $5 check. Unfortunately I don't think new laws would help anything, as evidenced in the past.
- paulddraper 7y ago> fines and class action lawsuits But they discourage similar behavior in the future, no?
- lisper 7y agoNot really. The shareholders are the ones who ultimately take the hit, not management. So unless there's a shareholder revolt, or the board starts firing people or clawing back compensation, the people who actually make the decisions feel no negative consequences at all.
- dabei 7y agoThere is always consequence. You only see the dramatic ones from outside.
- lisper 7y agoReally? Can you show me even a single example of a senior executive having their lifestyle meaningfully impacted? Having to downgrade to the next smaller size of private jet doesn't really count.
- deftnerd 7y agoWhat if management was fined through increased income taxes in some way? If structured right, it would prevent a 5 million personal fine to a CEO being made up with a 5 million company bonus.
- rectang 7y ago
- briandear 7y agoHow is this about “rich people?” It seems turning this into a class warfare issue is a folly. “Rich” people had their data compromised too. Rich people are also affected by credit data issues — probably more significantly than poor people. Stealing the identity of people with few assets is a lot less profitable than stealing the identity of rich people. As far as Equifax shareholders — presumably the rich people to whom you are referring, the Canadian Pension Plan Investment Board has significant Equifax holdings; by crushing Equifax shareholders, you aren’t just affecting the so-called rich, but the health of pension funds which typically support the non-rich (rich people don’t rely on pensions for retirement as much.) I certainly want companies like Equifax held accountable when they break the law, but lamenting that shareholders haven’t lost money is to fundamentally misunderstand the financial system. The solution is to slowly ratchet up the unprofitably of Equifax when they do wrong so that it makes the sector less attractive over time. Simply crushing the company with a multi-billion fine would collapse the stock all at once, destroying significant percentages of pension funds which hurts the very people for whom you ostensibly feel sympathy. In short, naïve, knee-jerk reactions are dangerous for markets and can cause widespread harm. The right answer is to tighten regulations around this industry so that risk gets priced into the stock which makes it less profitable over time which gives institutional investors time to reallocate with minimal shock to those who can least afford such shocks.
- freehunter 7y agoTwo cars break down at the same time. Two people try to buy a new car, a rich person and a poor person. The rich person's car loan is denied. They buy a cheaper car, or pay to fix their broken car. They fight the credit fraud and even if it takes years, they win. Three years later they buy the new car they wanted all along. The poor person is denied a car loan. It was already the cheapest car they could find, and they don't have the money to fix the old car. They can't take time off work to go to the bank to fight the fraud, but it doesn't matter because they've already been fired due to not having a way to get to work anymore. Before they can find a new job, they're evicted from their apartment for missing rent. Tell me again how rich people are more affected by identity theft.
- Hello71 7y ago
- sickcodebruh 7y agoThis is why the idea that we can trust the market to regulate itself is completely ridiculous.
- atian 7y agoThe market decided that data breaches are not worth anything.
- mostlysimilar 7y agoThe market has no other options.
- rolltiide 7y agoThe data is worth a lot But not a cost or negative consequence to the organization that the data came from
- nickpsecurity 7y agoThe revenue that Equifax makes selling it further corroborates your position.
- souterrain 7y agoThose whose data was compromised are not equal participants in said “market”.
- paulkon 7y agoThe financial markets are for businesses, not people.
- deleted 7y ago[deleted]
- haberman 7y agoThe market relies on a sensible legal framework of ownership and liability. Society has to decide under what circumstances a person or business can be financially liable for their mistakes. The liability should match the real-world harm. Data breaches have significant real-world harm. Unfortunately Equifax got out of this without paying fines in several state at least. It was the regulators who failed us here, not the market: https://www.reuters.com/article/us-equifax-states-agreement/equifax-avoids-fines-in-deal-with-u-s-states-over-data-breach-idUSKBN1JN2YH https://www.reuters.com/article/us-equifax-states-agreement/... Customer data should be like radioactive waste. Companies should know that if they have it, they have to take appropriate measures to secure it, and if they don't they will take a significant financial hit. The financial penalties should be significant enough that if a business doesn't feel sure they can invest into proper security, it makes more sense to just not keep the user data.
- CyberBank 7y agoI think this is a bit short sighted and shows a lack of knowledge of the industry and the subject. I know for a fact that almost every large institution of even the slightest quality is currently in full panic mode regarding their cyber posture. Look at JPMC, spending nearly 1 billion dollars a year on cyber. I know most of the other big financials are right there as well in terms of % of revenue. In the financial industry alone, there's a huge uptick in regulatory responsibility globally for asset, vulnerability, and threat management. The SWIFT (messaging system that all major banks communicate and send money on) auditors and regulators are requiring almost all of these issues be "solved" for or having a meaningful workflow within your respective organization. Guess what happens if you don't meet it? You have a serious finding against your institution and you will struggle to do business with any of the other more mature cyber organizations that rely on SWIFT. Worse yet, when large customers request the output of these audits and findings -- if you do not comply, they will move their money. I know several of the largest financials lost massive clients and revenue due to not complying with the cyber standards set forth by SWIFT. I know for a fact within the US the OCC (governing body for financial institutions regarding cyber) is coming down very hard on the cyber posture of a lot of the banks and is making them move faster, otherwise they face a long uphill battle to expand or make significant changes within the US.