Cybersecurity Incident Involving Consumer Information
investor.equifax.com
investor.equifax.com
Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit reporting agencies inflicting this upon Alice. BigBank is the victim who lost money, and BigBank bears the responsibility for making the mistake of giving out a loan in Alice's name. The Fraudster committed a crime against BigBank, not against Alice. It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice.
The idea that Alice was victimized by Fraudster is a concept being perpetuated by the credit reporting agencies as a way to absolve themselves of responsibility, and place the burden upon the consumer, and to avoid realistic identity-verifiction which might slow or complicate the practice of issuing large amounts of debt to the general public.
Further - this rat race, where I have to give ever more intimate details about myself to verify who I am, "for my own protection", seems to only ratchet away my privacy until there is nothing about me left unpublic. Facebook, Banks, Airbnb, Credit Card companies, Telephony companies have ALL given me that line when I resist providing SSN, DoB, or whatever mine-able nugget they're looking for this month. Every time I give out a new kind of private information it inevitably leaks - defeating their point of having asked me - all the while my privacy is left scorched while they move on unconcerned to the next piece of my private life. It's uncomfortable.
I see this as you being too strict with your definition of "identity".
We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc.
"Stolen identity" in this sense means Alice's attributes (the ones which Big Bank uses to identify a person) have been compromised by a 3rd party. It's not that all of Alice's identity has been compromised -- only a subset of her identity. Sadly that subset almost entirely consists of "something you know" (which the internet usually also knows) rather than "something you have" (like a government-issued ID) or "something you are" (biological traits).
I totally agree about the rat race. I think the credit bureaus are complicit in keeping the burden of credit identity low and the availability of credit reports high in the US, both of which lead to perverse incentives for {credit bureaus, consumers, creditors, governments, etc}. But they aren't alone. Credit card systems {VISA, Mastercard, AMEX, Discover, etc} and credit card merchants have done the same, causing the US to fall far behind other developed countries in consumer security.
Additionally, I've heard horror stories about the effort required for consumers to "prove" to credit bureaus that their identity was stolen. It sounds a lot like the insurance company's policies in The Rainmaker.
> We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc.
Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly be pointing to one body (hence they supposedly identify Alice) while it is claimed at the same time that they can be replicated by a "thief", which necessarily implies that they don't identify Alice, and hence are not an identity, therefore tautological impossibility.
For example, it is claimed that being able to say the DoB of Alice is an attribute that identifies Alice's body. Then, it is also claimed that somebody else saying Alice's DoB supposedly is an act of stealing her identity, and that the set of such people is non-empty. Which means that being able to say Alice's DoB is not actually an identity in the first place, much less one that could be stolen.
> For example, it is claimed that being able to say the DoB of Alice is an attribute that identifies Alice's body.
And then we say that the stating the DoB authenticates anyone to make changes to Alice's account.
And then we say this is a terrible idea. And then we are in agreement.
And then we don't have to say completely unhelpful nonsense like the following:
> Then, it is also claimed that somebody else saying Alice's DoB supposedly is an act of stealing her identity, and that the set of such people is non-empty. Which means that being able to say Alice's DoB is not actually an identity in the first place, much less one that could be stolen.
If these credit bureaus insist on conflating the word "identity" with "authentication" then it is up to us, computer / information / system / security professionals to correct this error and continue with more clarity.
Not not to start a one-sided (credit bureaus aren't listening) philosophical argument that nobody was really talking about in the first place. This isn't about ontology, and it never was.
(Ontology is the field of philosophy that asks the question what "is" is, a.k.a. "identity" and it's very interesting but also very much irrelevant to this incident and the problem it poses to badly designed authentication systems)
An important part of our jobs is being able to clearly explain such computer security and authentication concepts to a layman. That includes properly framing the question. Digging into a philosophical argument because you feel you can argue your way around a particular word that is used, only feeds pedantry.
Except it's nonsensical to switch to "authentication" when the discussion is about how the term "identity theft" is misleading. It's not "authentication theft", it's "identity theft", and that is exactly why it is misleading.
The original point of this comment thread was that the credit reporting agencies want to keep it confusing so that it's not clear who exactly was the victim of the crime, so it's not obvious that the system sucks.
Attributes can be replicated -> attributes don't identify Alice
Why do you consider this implication necessary? It sounds nonsensical.
Counterexample: to verify an identity, the verifier must possess a replication the identifying attributes. If replication implies non-identity, then identity verification becomes impossible.
Note that we're speaking of identity in the context of a technical implementation.
Because it is implied by the definition that is implied by the concept of "identity theft".
Let's assume we define "identity" to mean "any set of attributes of Alice", so widening it essentially as far as possible. Then "is a human", being an attribute of Alice, would become an identity of Alice. Using that definition in the context of identity theft would then lead to the following sort of justification: Alice is responsible for paying back this loan because the person that we gave this loan to was a human and we identified Alice by her attribute of being a human to be the person we gave this loan to.
That doesn't make much sense, does it?
The whole justification for calling it identity theft, and thus blaming the identified person, hinges on the implication that whatever attributes are being used to "identify" Alice do imply that it is in fact uniquely Alice who has those attributes. It only logically works if you can say "those attributes are the attributes of the person that we made the contract with, and they are unique to Alice, therefore Alice is the person we made the contract with", not if your claim is "those attributes are the attributes of the person that we made the contract with, which are shared by a whole bunch of people, therefore Alice is the person we made the contract with".
> Counterexample: to verify an identity, the verifier must have replicated the identifying attributes. If replication implies non-identity, then identity verification becomes impossible.
Erm ... no? Just two obvious examples:
In order to check that you are the person on a picture I have of you, all I need is the picture, no need to have a replica of you.
In order to check that you are in the possession of a private key, all I need is the corresponding public key, not the private key.
Also, if it were the case that identity verification were in fact impossible ... what would be your point then? You don't like the (hypothetical) fact that it is impossible, therefore it is possible?
> Note that we're speaking of identity in the context of a technical implementation.
Actually, we kindof don't. We are really talking about a legal implementation, where there really is no requirement to do anything as a "technical implementation"!?
> Let's assume we define "identity" to mean "any set of attributes of Alice", so widening it essentially as far as possible. Then "is a human", being an attribute of Alice, would become an identity of Alice.
> That doesn't make much sense, does it?
If Alice is the last surviving human being in the universe, it does.
If Alice isn't the last surviving human being in the universe, than the premise of "is a human" as an identity is already nonsensical (because it no longer identifies), hence also any conclusions you derive from that premise are also nonsensical.
> In order to check that you are the person on a picture I have of you, all I need is the picture, no need to have a replica of you.
You haven't checked that it's me, you've checked that it is someone who looks like me.
Within any given context, that may or may not be treated as my identity. Hence, we're back at multiple identities, each in their own context.
> In order to check that you are in the possession of a private key, all I need is the corresponding public key, not the private key.
Which says nothing about identity, only about possession. Whether this possession is taken to be sufficient proof of identity again depends on the context.
> Also, if it were the case that identity verification were in fact impossible ... what would be your point then? You don't like the (hypothetical) fact that it is impossible, therefore it is possible?
Do you believe this hypothetical example to be true? If not, what's your point?
... seriously, just stop.
As for fraud: There probably is no easy way around it. But that doesn't mean it's not fraud.
Online loan firm gives money to someone. Months later, they default, so they call who they think is the holder of the debt. That person has no clue what they are talking about. Finds out through first ever credit report they are defrauded. Victim calls loan firm, who requests lots of proof of existence as well as a police report, before they will help them. Process takes weeks. Victim finds out they signed up at Equifax during hack. Now they are in worse shape.
You don't need to provide a SSN to get cell service or provide real information. Lots fraud is done through tethering through burner phones.
Even government can't verify people and its problem because people give other people's SSN and DOB when they get arrested which is the worst type of identity theft as it can lead to the victim getting arrested or not getting a job(criminal record showing up in background check).
Don't give them any stupid ideas. This year Germany did exactly that: Require proper identification for purchased SIM cards. Lot's of people used that opportunity for some extra cash by selling pre-activated SIM's through Ebay, after the requirements had been changed.
Too bad they also introduced Euro roaming, so people are still free to buy their anonymous SIM's in other EU countries and use them in Germany.
I guess those are the consequences of a future where your mobile device is used for your personal authentication everywhere by everybody. [0]
[0] https://www.nytimes.com/2017/02/13/business/dealbook/banks-l...
I have separately worked with one of those companies with a client and their IT staff were utterly incompetent (I won't say which). Loads of different sites, lots of little fiefdoms, utterly inconsistent security policies on each site, blaming everyone but themselves because only half their sites could access a video on a major commercial video provider (not-youtube). We ended up having to host it on AWS cloudfront as none of them had blocked it yet. Their sharepoint could only host a 50mb file, which made their CEO look like a blockhead in the 20 min high def video.
Utterly incapable of hosting a simple video file so all their staff could access it in 2010.
I've also worked with a company one of those companies acquired for $100 million+, holding millions of people's personal details in the UK, with some very sensitive data. Some of the worst IT engineering I have ever seen, a bunch of tools written by the worst out-sourced IT teams I have ever seen (if you've ever worked with C#, these idiots made a project per .cs file. Yes, PER CS FILE. They also wrote the worst SQL I have ever seen, all of the stored procedures seemed to be duplicated but the duplicates had op_ before them. I eventually realised the op_ stood for optimized! They were still terrible and half the program used one set of SQL, the other half the optimised. Whenever I re-wrote one of these 'optimised' queries, I usually knocked it from seconds to milliseconds. Outsourcers in the naughties really did suck that bad, young 'uns).
We've given up huge amounts of privacy, but the scores are utter bullshit and the 2008 crash show what a load of nonsense they are.
A friend even told me at uni he'd got a £1000 loan out to get a good credit rating. You just put the money in an account, pay the capital off every month, lose a little bit of interest and in 2 years you have a shiny credit rating even though it means zilch.
equifax/experian/call credit basically get given all our personal spending habits for free, sell it on to everyone else for crazy money, don't add anything to the economy and as far as i can tell, are a huge security hole.
EDIT: Another anecdote on how incompetent these people are, a couple of years ago someone used my details to scam a few free phones. I got alerted to it when I started receiving insurance contracts for those phones in the post. The phone companies sorted it pronto, almost immediately admitting they'd been scammed, but I wanted to make sure my credit rating hadn't been trashed. In the UK these agencies must provide you with a credit report for a nominal fee so you can check for incorrect details, so I applied to the big 3.
One of them accused me of trying to hack their system because I'd forgotten a security question, eventually told me to fuck off after passing through various layers, then sent me a letter saying they'd detected a hacker trying to access my details. No, you idiots, that was me. Still never got my report from them.
Yes, they still use security questions.
I don’t really get that - doesn’t it mean that the person who took a loan is relatively responsible and was able to pay their loan back on time?
Any system can be gamed, but I don’t get the impression that credit agencies are attempting to eliminate all risk - after all, it’s obviously possible that someone who has had perfect credit for years might simply run away with your cash! But the system doesn’t have to be perfect, or detect all outliers, to have value.
It seems intuitively obvious that lending to someone who is frequently late with credit repayments is riskier than lending to one who isn’t, and this is the mechanism by which that information is shared.
In the 60s/70s it was about knowing your bank manager, so he knew you'd be able to pay. I appreciate that it probably benefited a certain type of person, but the new system probably has the same prejudices built in. Now it's all about the ephemeral and easily game-able credit score. Until a few years ago you would get negatively scored for not having a landline.
These scores are utter bullshit, they're simply about if you haven't screwed up yet, they're not actual assessments of your ability to pay or the risk you've exposed yourself to.
Again, I worked in the mortgage industry before the Northern Rock collapse, brokers used to be able to go to those guys and openly fudge people's incomes by calling them self-employed, they had a good credit score so no-one blinked an eyelid, get 105% mortgage, and then lo-and-behold, the bank collapsed. Yes, part of it was that they lost their access to easy bank credit, but another part of it was they lent to hugely risky people.
As a slight-side, my bank was willing to lend me crazy credit card money a few years ago because for 10 years I never missed a payment. In reality in those ten years I went through a patch of being the most business-un-savvy freelancer ever, selling myself at a stupid rate and not putting enough aside to pay my tax bill, to the point where I had to get a loan from a parent to pay it. I was flat broke, almost bankrupt, and these people were willing to lend me almost 9 months of my income.
I was not a good risk.
But because I paid on time for X years before, I was to the credit agencies.
Banks are using actuarial science to make loans. You were (possibly) an outlier. That doesn't matter. All that matters is that their risk models work in aggregate. If they're right enough of the time, they profit. It doesn't have to be perfect.
You do recognize how terribly inefficient that is, right? In this day and age its all about scale. Expecting a bank manger to have financial profile of all the clients using his firm is impractical.
For all it's faults, the credit reporting agencies are providing a service. It's not perfect and I think it's best they could do with the information available to them. I expect they will improve their score though once they start incorporating signals from social media and other sources.
Is it, tho'? It is well known that IT doesn't improve productivity[1]; all the benefits of automation get swallowed up in the extra people needed to support and maintain it. So we can assume that the ratio of bank employees to bank customers has remained constant over time. So actually there's no reason for bank's not to operate the old personal-relationship model; they would need to employ the same number of staff to do it, just locate them in branches rather than at head office.
[1] http://www.computerweekly.com/opinion/McKinsey-Why-IT-does-n...
But you were- you had access to a parent with money to bail you out.
That's probably the reason why it would increase one's credit rating in a positive way. I have no doubts about these systems being broken in such a way that they consider people who take on credit, paying it back in time, as more "credit-worthy" than people who never needed/wanted to take up a loan.
A bank obviously wouldn't want to miss out on the first group of people, why they couldn't care less about the second group of people from which they make no money in the form of interest.
It's also interesting how these kinds of rating systems seem to be "broken" all over the world. In Germany there is "Schufa", which is not a bank but basically a private company with a de-facto monopoly position in regards to credit ratings in Germany and they are quite infamous for mixing up people and thus giving them a negative rating, often without the people noticing until it's too late and their negative credit check denied them access to a rented flat/credit whatever, after which it's their responsibility to get in touch with Schufa to clear up their misidentification.
Just for anyone from Germany reading: There are multiple, less well known agencies that are used by banks and others as well. They are definitely worth keeping an eye on. I will only mention Creditreform Boniversum, Arvato Infoscore, and Bürgel.
Calling all identity thief peeps....
The question would then become whether the bank's identity verification procedures satisfy that burden. I think it would be a difficult endeavor, but it would be good to see it tested.
They absolutely should have known it was wrong -- their business is lending money to people! If their procedure is insufficient, they should have fixed this.
I would love to see the banks sued for libel, a massive class action suit. There are real monetery damages it one could put a number on, and the difference between a bad and a good 30 year mortgage will be a big number.
https://www.law.cornell.edu/uscode/text/15/1681h
In this case, maybe you could have a shot by arguing that since the bureaus know that like half the population's information was stolen, they are acting with reckless disregard for whether their statements are true if they don't now do additional investigation to confirm the identity of the subject of their statements in order to mitigate the effects of the breach.
If someone steals Alice's car and commits a hit-and-run, she will be inconvenienced when the cops show up at her door, but the person who reports her plates won't be committing slander.
The only thing she could expect from BigBank was politeness while explaining to her that she was duped. If it's a very friendly bank, she may tie up a manager for a couple hours, but that's it. If she keeps coming back, she'll soon be escorted out by security, or the cops.
Now, what if she started falsely telling others that BigBank took her money, and that significantly affected BigBank's reputation? Are we talking jail time, or just civil penalties?
Who's the victim?
Probably not jail time, and perhaps not civil penalties. Even civil defamation in US law generally requires knowing falsehood or reckless disregard for the truth, not just mere falsehood, and criminal defamation, where it exists, tends to have high . Unless the bank had provided concrete evidence so solid that it was unreasonable for her not to believe their denial of responsibility, there likely be no legal wrongdoing.
Jail time could be a possibility depending on jurisdiction. In the US, a handful of states have criminal defamation statutes - https://en.wikipedia.org/wiki/Defamation#Criminal_defamation...
There's some cost to this, but I still suspect quite a few people would accept it.
Also would you want to go in person to signup for paypal, venmo, etrade, betterment etc?
Honestly, maybe that wouldn't be such a bad idea. A well-designed system would probably wind up contracting the post office for ID verification for online services (since in my country at least, they do a pile of random related stuff).
1. The bank should capture the ID you used the first time you entered and do comparisons. They should also capture your ID when you come in again. This will raise the difficulty of impersonating you and the risk the criminal takes.
2. One thing I didn't think to say, because my bank only exists in North Carolina: geography should matter. If you live in a particular city, opening an account from another state should be seen as suspicious, and merit greater checks. This is the kind of thing some people should be able to relax, but it's probably a good default for most of us.
3. Should I have to go to my bank for PayPal, Venmo, Betterment, eTrade, etc? Those cases don't all sound the same to me. But here's what I'd consider: how often is a person going to need to do this, and does the activity involve requesting credit? We've currently optimized almost exclusively for convenience at the expense of security. I'm proposing that we shift that balance a bit.
It's probably not hard to forge a social security card and birth certificate if you have the relevant information. From there, a state ID (or maybe even passport) should be possible to get. I don't believe there is any biometric security on either. A determined identity thief might go that far.
This is the old "because a solution is not 100% effective, it's not good" chestnut. This solution would cut down on the theft by over 90%, I'd venture, probably more like 98%. There is huge difference between perpetrating a crime from the safety of a computer and physically walking into a bank to commit it.
http://www.iii.org/fact-statistic/identity-theft-and-cybercr...
Why? Show up to a government station with your birth certificate, SSN, some telephone and utility bills, and they'll take the thiefs picture and put it on an identity card with your name on it.
The solution is asymmetric cryptography, wherein identity is tied to a public/private keypair, and I can prove I have the corresponding private key without giving the other party the ability to impersonate me. Ideally, the government wouldn't know my private key, either, rather they would just give their own attestation that a given public key is owned by a person with a given name, DoB, SSN, and biometrics.
Along similar lines, any financial account would have its own keypair, with moving money out of the account requiring signing with the private key.
The state of cryptography today is way too obtuse for this to work right now, but I think it could be made more user friendly with specialized hardware to hold the keys and perform the encryption.
The idea that SSNs are secret, but we hand it out to half a dozen organizations is absolutely ludicrous.
http://www.htxt.co.za/2015/09/16/this-is-how-banks-and-home-...
7 years? Are you sure it's not something like 7 days?
I've tried all sorts of p2p methods over the years. All of the banks are too confusing, obscure, or too limited (i.e. only within their bank). Paypal and credit cards charge a not-insignificant fee. Venmo or Square Cash work fine if your group of friends accept them--but more than half the time, they don't for me.
I often do ACH transfers between my own accounts, but the first time I set it up a cringe a little bit and cross my fingers. It sucks waiting the 2 or 3 days waiting to see something. I can't see small businesses accepting ACH as payment because they want something in hand. If we had the setup I've heard about in Britain or Europe, I can see checks going away, but with as much churn as I've seen in this space in the 20 years since Paypal, nothing seems to stick.
Try cash? I use cash for almost all transactions like that and have never been turned down :-)
Eve lies to bob, and tells Bob she's Alice. Bob asks Claire, who says Yes, that's Alice." Bob gives Eve money, and Eve runs off.
This should not be Alice's fault, responsibility to solve, or problem to deal with. It is, because Bob is much, much more politically powerful than he ought to be.
I think you're confused. It's BigBank that's falsely placing a debt burden on Alice. The credit reporting agencies are only reporting what they are told. Imagine if Alice doesn't care about her own credit worthiness. Let's say she has no debt, and no intention of acquiring debt. What happens if criminal tricks BigBank? They say, "Alice, you owe us this money." Alice tells BigBank, "No, prove it or pound sand."
What happens then? BigBank goes to the court and tries to get a judgment against Alice for the money owed. If Alice isn't aware of the proceeding, the judge will grant BigBank's request, and now Alice will owe BigBank the money stolen by criminal.
BigBank's poor authentication and the judicial branch are the ones doing the real harm to Alice. If anything, the credit reporting agencies are providing value to Alice by warning her before BigBank goes after her in a secret proceeding and makes the debt hers.
1. Alice does have debt, and does intend to acquire debt in the future, like most people. The presence of this fraudulent debt in her credit report makes credit more expensive and hard to get.
2. Before filing suit and going to court, BigBank makes persistent but usually polite attempts to collect. But when she says "that wasn't me" they don't believe her, because lots of deadbeats say that sort of thing too.
3. Perhaps BigBank sells the debt to a collection agency, which is far more aggressive and (willfully?) ignorant of laws regulating how and when they can contact Alice. Perhaps they call Alice's employer, threaten to garnish her wages (even if they legally can't), or lie about Alice's ability to contest the debt.
4. If Alice is determined enough to keep fighting and go to court, she has still sunk significant time and money into fighting this. It's unlikely she'll be compensated fairly for that.
I agree the credit reporting agency is in some ways helping Alice, and would add that these agencies probably do reduce the rate of fraud overall. But they also have a responsibility to do a good job minimizing errors. We can't expect them to never make a mistake, but they should have some skin in the game when their inaccuracies hurt a credit applicant.
Don't kill the messenger. The credit reporting agencies are doing what they are obligated to do in that business. There needs to be penalties for BigBank beyond the money BigBank lost in the scam perpetrated by criminal.
Blaming the credit reporting agencies for bad credit reports is intellectually lazy. Blaming them for garbage computer security is much more appropriate in this story. A more interesting discussion here would be about the technical details of the hack.
If you wish to provide a service with a level of guarantee, responsibility and liability comes along with it.
https://www.nytimes.com/interactive/2014/08/15/magazine/bad-...
Think about the credit reporting agencies as a rather sloppy "master list" of who owes who money. It seems what is needed are stiff penalties for banks and collection agencies who falsely claim they are owed money. Until then, you can't live in peace. Someone is going to claim you owe them money if you have any money yourself.
That's a long process (5+ years sometimes).
Generally speaking, the impact to the customer is usually greater, as bank business model aren't dependent on every loan being repaid. Consumers stand to lose money directly and lose the opportunity to access capital.
The credit agency or anyone else who has a breach is usually a negligent third party.
The bank is a victim of fraud.
The individual is a victim of impersonation by the borrower, and slander by the bank and credit agencies.
The individual is victimised by the bank and the credit reporting agencies by their spread of misinformation.
I believe the Fair Credit Reporting Act allows Alice to remove inaccurate information from the report?
If there is a dispute between what BigBank says and what Alice says, it's not necessarily so easy to resolve, and that's the position the Credit Bureau has to deal with.
To absolve the fraudster of the primary fault is ridiculous. That said, this is the problem with difficulties in identity verification, we all want privacy and security at the same time. While they are not mutually exclusive, having both is much more complicated than one or the other.
1.(added to qualify that adjective "honourable" which I apply to individuals not companies, and individuals who risk sacrifice without burdening others. My career is in advertising and I am truly impressed when publishers are able to maintain standards that are able to raise their costs of sales. (a large publisher may not lose a account, but the sale often consumes expensive energy, even only to explain why policies exist. I work far from such high sensitivity issues, as does the company I started around the time of this recollection.)
2. last I spoke to Mike, he was telling me how he simply was never issued his shares in "ElReg" and he was long enough into The Inquirer to think that Limitations applied. But Limitations 80 runs from the time of discovery of tort, not the event of tort. Before the chance arose to catch up, and establish facts, Mike had passed away. RIP a great man and two great journalistic servants to the IT community. I did not establish the facts that were alleged, therefore my statement is hearsay, but protected by the statutory defence of genuine belief, and I had always faith in my source.
Edit: italics removed from footnote, earn out replaced phypo earnings, and great man replaced good man. Mike was exceptional and altruistic to a fault.
She may not have to pay that bank loan back but that doesn't clear her credit up immediately.
The police investigator told him that the particular fraud that he was a victim to was impacting >500 people and >$5M
Credit Reporting agencies report the data passed to them by companies such as banks. In your scenario BigBank thinks it's given a loan to Alice, and when they don't get repaid, report that to the CRAs. Alice is a victim of the thief because her identity was appropriated to secure the funds. BigBank is a victim of the thief because they were defrauded. The CRA is a victim because they were just reporting the information that was provided to them in good faith by their customer BigBank. So saying that the CRAs are "victimizing" Alice is completely false.
Alice bears the burden and risk of clearing her name, just as a victim of car theft bears the burdens of reporting the crime, getting another vehicle, dealing with the any outstanding loans, etc. These burdens are inflicted by the thief, not the bank or CRA.
> perpetuated by the credit reporting agencies as a way to absolve themselves of responsibility, [...] and to avoid realistic identity-verifiction which might slow or complicate the practice of issuing large amounts of debt to the general public.
This completely misunderstands the role of a CRA. The CRA doesn't have to verify identity, it's up to the credit grantor to ensure they are dealing with the person they think they are.
Luckily, I didn't say that.
It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you need to allow access to your credit (credit check for rent, taking out a loan, etc), you can temporarily lift your credit freeze for a small fee. The fees associated with this are going to be much cheaper than any of the professional "identify protection" services that exist out there, and the freeze is significantly more effective at protecting you.
When a company leaks your social security number and personal details, which almost certainly will happen at some point if it hasn't already, then opening fraudulent accounts in your name isn't the only risk you face, but it's an obvious and dangerous possibility that can ruin you financially or make you spend a considerable amount of time and energy fixing the situation.
For every person in the US with kids, I also strongly suggest that you freeze their credit as well. There's no good reason for your 13 year old to take out a loan, but identity thieves don't care about how old their victim is.
In other words, is a freeze enough to stop new accounts from being created?
The computer says no, and the phone number just sends a letter that says no. I tried to to buy one from my bank, but as far as I can tell they only sell subscriptions...
The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.
https://www.transunion.com/fraud-victim-resource/important- contacts
[1] https://www.discover.com/credit-cards/member-benefits/securi...
https://www.bloomberg.com/news/articles/2017-09-07/three-equ...
Edit: Also discussed here https://news.ycombinator.com/item?id=15196309
Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 scheduled trading plans.
The three “sold a small percentage of their Equifax shares,” Ines Gutzmer, a spokeswoman for the Atlanta-based company, said in an emailed statement. They “had no knowledge that an intrusion had occurred at the time.”
The timing is extremely suspicious. But - if they can prove they didn't know, they're in the clear. Of course a breech like this quickly goes to the board, and it's hard to imagine that the CFO and President of US Information Solutions wouldn't know.
This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed).
Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen? Surely it's not just the one agency (SSA) that would need to make the change, but multiple agencies would need to coordinate the change?
(And of course, I would be personally responsible for informing my banks, brokerages, loan agencies, etc of my new SSN)
Does anyone have insight into how this could work?
It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a business or process that uses by SSN instead of proper two-factor authentication (...a large number of credit-based companies and financial institutions, sadly) my trust in them simply plummets, the same as it would for the login I use on less secure forum sites.
This is not proof of identity.
Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such.
SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could also be brought about through legislation making it not legal to ask for SSN as proof of ID (i.e. can only ask for SSN when required for the purposes it is intended for), but legislating such things is likely even further from your culture.
If the gov is going to issue a 'secret number ' why not a 2fa device?
But in all seriousness, we need to find ways to make real identity authentication user friendly, a la Yubikey, and then drive companies to replace this insane SSN-based system.
Um.
It is a scam to get people to sign away their rights to sue the bastards.
Honestly, they should have used a subdomain off of Equifax.com.
They keep taking...
https://www.consumerfinance.gov/
Not just about the hack, but the fact that their "check to see if you were affected by our shit" sites include a ToS that waives your right to participate in a class-action lawsuit.
https://trustedidpremier.com/static/terms
To my reading, the arbitration clause may only apply to people who take the step of signing up for the credit monitoring they offer. But, of course, they are urging everyone to sign up....
A breach like this will affect thousands of people monetarily and suck time from them they could have used elsewhere. If you've ever dealt with something like this, you know the hours it takes to rectify the damage.
The only way corporations will learn to appreciate data security is when management teams suffer criminal penalties.
It's possible that Equifax did something really negligent and if so maybe there should be a class-action lawsuit against the company. But it's also possible they did all the things they should have done and still failed because security is really hard and maybe the attacker got lucky.
[0] https://chrxs.net/articles/2017/03/23/responding-to-identity...
What a scam!
In my case, after entering the information on the "Potential Impact" page, it immediately informed me I was enrolled without actually informing me whether or not I was impacted! It basically looks like Equifax used their massive fuckup to generate business for a service they own that by its nature incentivizes them to have poor security to encourage people to stay subscribed!
Given the number of incidents that have at this point affected nearly every person in at least the US, what value does the data held by the big 3 have? Almost anyone can claim that any information held by Equifax now was the result of fraud.
And how does Equifax prove that data wasn't modified in their systems by an intruder?
“Except as otherwise expressly provided in this Agreement, all claims, disputes, or controversies raised by either You or TrustedID, Inc. arising from or relating to the subject matter of this Agreement or the Products (“Claim” or “Claims”) shall be finally settled by arbitration”
But IANAL.
https://www.equifaxsecurity2017.com/potential-impact/
Which says it would tell me if I'm likely impacted, but instead it just gives a date where I can enroll in some free product, but no info on whether I'm likely compromised.
Anyone have a workaround? This is important to anyone that wants to identify if they've been "pwned."
> Thank You
> Based on the information provided, we believe that your personal information was not impacted by this incident.
So if you just get the enrollment date, I think that means you’re affected.
Well over a month later and they're just now getting around to telling people about a security breach that could affect almost half of all Americans...
How is this ok/legal?
I work in cybersec and I would actually say that under 1.5 months from discovery of unauthorized access to releasing this press release (and already having the equifaxsecurity2017 website up and running) is astonishingly fast work.
https://www.equifaxsecurity2017.com
/s
Maybe it doesn't matter much, since they've likely already got it. But, it feels a bit too soon.
An interesting side-note: That domain was registered about two weeks ago on 8/22/2017. Whois reveals not a single pointer to Equifax (e.g. equifax.com email address, etc.). It shows only DNStination Inc., and so is effectively private.
When you click the "Enroll" link, then "Begin Enrollment" button, it takes you to https://trustedidpremier.com, which was registered on 8/28/2017, using a different registrar (Amazon, with Whois Privacy). There's not even a reference to Equifax in the domain itself.
As of today, someone registered equifaxsecurity2018.com with a private (this time, Domains By Proxy) registration. Given the timing and the fact that this is a different registrar from the original, it's a good bet that's not Equifax. Or is it? Who knows?
And SSL-wise, these don't even appear to be using extended validation certs (FWIW). At least one is an Amazon cert, free to anyone who hosts on AWS.
They are virtually training people to be phished and creating another potential disaster with all of these additional domains, private registrations, etc.
Also, equifaxsecurity2017.com appears to be a stock Wordpress site. Equifax is a bunch of fucking amateurs. Their security culture is broken.
No one else had that email address. Guess what, I started getting phishing emails to that exact address.
Tried letting them know, but it went nowhere.
In other words, when they say "143 million US customers" they really mean "the vast majority of Americans with a credit card".
Astounding.
So, assuming each person whose info was compromised is a separate incident, willfully negligent violation could result in up to a company-shattering $143B fine, but no less than $14.3B on the low end. I imagine that that even the lower figure would be hard for them to absorb as well.
I have to imagine that class action lawyers all over the country are licking their lips, if there's an opening via FCRA. I'm not sure what the FCRA says about PII data security practices, though - it might just be having processes in place and the like.
https://www.equifaxsecurity2017.com/
whois: ... Domain Name: equifaxsecurity2017.com Registry Domain ID: 2156034374_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.markmonitor.com Registrar URL: http://www.markmonitor.com Updated Date: 2017-08-25T08:08:31-0700 Creation Date: 2017-08-22T15:07:28-0700 ...
I am having a difficult time reconciling those two sentences.
https://krebsonsecurity.com/2017/09/breach-at-equifax-may-im...
Can someone notify me when the class action has been initiated?
Kind of funny, isn't it?
I think most people are unaware of the depth of data Equifax has on them, beyond simple credit scores (e.g. health information).
Which makes the above quote from the article even more unconscionable. There should be no need for an outside firm to figure out what happened. They should have in-house expertise that is unmatched (although third-party audits ahead of time would be wise).
Is this grounds for a class-action lawsuit?
iPhones now have the Secure Enclave, Androids have the Secure Element. You can store private keys there.
Authentication is done by apps signing challenges. This can be done in many ways, including oAuth, QR codes to authorize new devices etc.
Identity can be done by posting signed identity claims across websites, and adding/repudiating public keys in a personal scuttlebutt-type blockchain.
You can then easily sign into site X and prove your identity on sites Y and Z, without any sites necessarily tracking you between them.
Here is my semi-humble proposal for a decentralized, secure auth protocol that works with everything out there:
If you have experience writing tech specifications, please reply, I need someone to write the normative section of that protocol properly.
Ideally, we'd have both a public username and a private password that we could change for our financial identification. This would eliminate most of the problems with these big data breaches. The backup for resetting a forgot password would be to show up in person and do some sort of biometric scan. Biometrics have to be done in person at a government office though since they aren't secret and cannot be changed. There shouldn't be an over the wire API for biometric identification because then you've got the SSN problem all over again, a combined username and password that's even more public than an SSN that can't be changed.
Really? "We lost your info. Sign up for our credit monitoring service!"
We need regulatory framework on cybersecurity and failure to adhere to it must result in mandatory jail time
Here in my country the government (or some agency) keeps track of what loans you have, and when a new company wants to issue you a loan you access the API with information like "2 years, €50 each month" and then the program responds with 'approved' or 'not approved'.
Giving all of these private companies all this data seems counter to American values of independance etc...
"By consenting to submit Your Claims to arbitration, You will be forfeiting Your right to bring or participate in any class action (whether as a named plaintiff or a class member) or to share in any class action awards, including class claims where a class has not yet been certified, even if the facts and circumstances upon which the Claims are based already occurred or existed."
Sign for their TrustedID Premier and lose your rights.
Set up a web page that will automatically opt out of the settlement and file a small claims court suit against them seeking $1K in damages. $1K is lower than actual damage done (in wasted time) for most people. It is also lower than the cost of defending against the suit in court.
~143 million people were impacted, so that's ~ $143B in liability. Their market cap is $17B. Problem solved.
Even better, most victims never consented to doing business with them, so there cannot be any binding arbitration issues to get in the way.
Was all this data available and accessible through the same application? I wonder how likely it was something incredibly trivial, like SQL injection, or whether they were truly targeted and infiltrated
I'm not going to post it here, but I wouldn't even mind saying it over the phone while standing in line somewhere. Its just not the real attack vector.
Result here shows that whispering it and writing it down on posted notes for a bank teller have zero bearing on your identity security.
Now if they knew that there is a $1000 fine per each stolen identity information, then the equation will shift and it will be a much better business decision to invest into protecting user data.
The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver's license numbers.
So what are they saying? Was all this information accessed or not accessed?
Credit Karma sent me an email this morning with the subject line "Your New Score" and I almost spit coffee all over my workstation. In fact my score only went down a point on Trans-Union, but it still was pretty scary to see in my inbox.
[0]: https://techcrunch.com/2017/09/07/equifax-data-breach-help-s...
Fairly ambiguous and I trust that sentence about as far as I can throw it. I too am interested in the answer to this, both personally and as an employee of a company that uses their services.
Why is this posted now?
When they have no clue on what they are conveying about them to the people, these kind of clueless incidents do happen.
My issue was swiftly resolved, but I felt the cold chill as replies came revised to note that overnight instructions for a separate matter were being notified to reflect the possible conflicts of interest the association rules require disclosed.
Barristers chambers can be used by opponent litigants, but with leave from the Master of Court, if not the Justice or Judge. I am thankful for my memory fading, and I actively discourage mistaking me for a authority. But I am not unwelcoming to inquiry from any request for anecdotal vignettes of IP and Companies Court cases, should be there need and understanding of my limitations. Laddie, LJ, was the solitary Lord Justice to ever resign the Queen's Bench. He was protesting the woeful incapacity of the Higher Courts to try specialised and particularly IP cases.
It was Laddie who handed down the scintillating condemnation of Manchester United soccer club for suing fans who knitted scarves in club colors.
Closer to home for many, Laddie is the one loss lamented by Patry, who wrote both testaments and the dead sea scrolls on US copyright and became a instrumental counsel to the growing young Google. Be unaware of this two names at your peril, in a litigious world of degenerate law for inventors and artists, and all who de novo create.
Edit, "bible" was a redundant word; separated paragraphs for clarity.
There are more than three - https://en.wikipedia.org/wiki/Innovis for example - but the big three are the ones with market power. Anyone can start one - but it's tough getting banks and landlords to use you, especially in the beginning when you've got no data. Massive barriers to entry.
Actually, if someone did this (well) as a service I would probably even pay a small amount of money for it. Startup idea?
Oh good, sounds like Equifax's valuable data is safe, it's just that of their unwilling 'customers' that leaked.
Don't worry, for $9.99 a month they'll help you clean the mess they made. I am being sarcastic, but I wouldn't be surprised at their audacity.
quote from FT.com
What a cop out. "Concern and frustration" are not the problem here. Identity theft is.
Almost certainly. Any time you've taken a loan, opened a bank account, rented a car, etc. you've likely agreed to it in the fine print.
Whether you had any choice in the matter is a far more important question.
You can use my public key/public SSN to make inquiries about me and check my credit history. But to open an account or take out a loan etc, you also need my private key, private SSN, which is not stored once the account modification is done.
IMHO, this never going to happen, but seems like it could be a solution to these problems?
What, and no one ever lost their Bitcoins via a key breach?
Owning our own data has very, very significant security implications. The average human isn't technically prepared to be their own infosec department.
One can even fake DNA if you have enough time, money and expertise...
Edit: Seems that if you have a date you're impacted. https://www.reddit.com/r/personalfinance/comments/6yq36a/equ...
If you enter your information, you agree not to sue them.