No matter what, Equifax may tell you you’ve been impacted by the hack
techcrunch.com
techcrunch.com
For every SSN entered, Equifax can say in a class action lawsuit that they have waivers from all the following SSNs ....
IANAL, but this looks like a sensible strategy for Equifax to save itself after screwing with people's SSNs and personal info.
It's a textbook scam.
This whole thing is just weird.
The sad thing is that they think the current solution is adequate. They do it this way because we are not their customers, we are their product. I would encourage to complain about this to your representatives. We could have much better protections about identity theft, have account frozen by default and without any fees. Have their credit checking services available for free.
Sadly, the business is structured so they actually are making money when it is easy to open a credit line, even illegitimate one.
Equifax themselves have said they'll only use the waiver with respect to the credit monitoring service, and not to the security breach:
https://techcrunch.com/2017/09/08/equifax-says-it-wont-bar-c...
You could say, "Maybe they're lying", but it seems like it would be pretty easy for the class action attorneys to act on your behalf here.
See: http://legal-dictionary.thefreedictionary.com/Promissory+Est...
Would it be possible to find any judge who can try this case, since the set of people affected by the breach is basically everyone?
IIRC, the judge doesn't need to recuse themselves of any/all cases where they are impacted, only that they must recuse themselves where they would be unable to be unbiased, or where there would be an appearance of being unbiased.
In the lower courts, when in doubt, that's decided by other judges. At the SCOTUS level, that's decided by the individual judge on an individual level.
So, yes... They will find a judge.
I freaking hate tactics like this, so I am offering to go through the mailing process for anyone who fills out the form at https://unarbitrate.org/. I'll pay to mail it, just because I hate this sort of thing. If you don't trust me with your data, the site also provides a way to print it and mail it yourself. But whatever it takes, I encourage everyone to opt out of this; you have nothing to gain by giving up these rights.
(I've submitted it to HN as well: https://news.ycombinator.com/item?id=15207151)
Reach out, should you need financial assistance.
with regards to giving up their right to class action
Relevant comedy: https://www.youtube.com/watch?v=CS9ptA3Ya9E
For what it's worth, here in Europe you could pretend to be someone else as well, if you have enough information, but what's the point when you can't touch their money?
You can spoof their identity, to instantly acquire material goods / lines of credit.
And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.
If you had the number of my credit card, my account number, my social security number (or the local equivalent), my address or my name, or whatever else, short of my 2FA device and my internet banking credentials, you won't be able to steal anything. (And at that point, you might as well walk up to my house, break a window and steal whatever the hell you need while I'm somewhere else, why bother with hacking.)
If the 2FA device is just a phone, there's a few things you can do, otherwise not really. Are you going to deploy a fake cell tower to steal the code? Probably just conning the cell company support person would be good enough. Not sure whether they'd mail a new SIM to a different address (and they'd probably let me know). Maybe they'd give it to you if you presented an ID. You could have a fake one made, I guess. It would be a bit weird if you didn't speak the local language though. Quite a lot of effort compared to copy pasting a credit card number. Not something you'd do on a large scale.
>And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.
Yes, but against a determined attacker that singles you out, you are fucked regardless of what you do, especially if it's your bank or similar service provider that screws up even if you don't.
When applying for new accounts, or logging in from new devices, you should be receiving an email and/or sms on the endpoints of your choice. And then able to stop those things from happening.
So now the practice is to fetch the credentials from the nearest bank office or something like that.
Isn't that what we're trying to prevent- becoming the victim of a determined attacker?
I don't really care about protecting myself from /only/ script kiddies.
If I put my money in a bank and they "accidentally" allow someone other than myself to withdraw it, /the bank/ has been defrauded, not me.
Thanks to corporate control of the US gov't, it is now me who has actually been defrauded, thanks to some fun mental gymnastics.
So, I have to spend time and money and frustration trying to convince the bank to uh... what's it called... oh yes, give me my money back, please.
The system is broken for sure, but I really truly hope we can vote some people into office who will turn the tables on how these laws currently work.
Otherwise we will all eventually be hacked, stolen from, or worse.
That's the funny part - there's no 2fa available for most internet banking in Canada or the US. In Denmark we get the NemID card mailed to us, but in Canada it's just your card number+password+sometimes they ask a security question like "what high school did you go to?"
My guess that this is misguided and muddled security thinking behind this, and is something that happens when the involved institutions do not have a coherent understanding of information security.
Why do you need that exactly? If you are selling something, it's quite simple: if you receive the money, you provide the service -- if not, you don't.
The payment processor can use 2FA (this is actually done by a number of banks in Europe, when you enter the payment information, you get a text message with a code from your bank to confirm the transaction).
I think 3-D Secure is the protocol they use.
So no, I don't think there's any Equifax equivalent where a data leakage would enable stuff like this.
Thats how it should be done, except in the US there is no way to check against a national database of IDs, not even on the state level with DMVs. You literally trust the plastic card the person shows you and thats where the problems start. Online its even worse.
The major benefits compared to SSN authentication still are:
* It's a physical object, you have to be physically present to steal each one instead of getting a hundred million at a time.
* Most people would quickly notice that their card is gone, report it, and get it revoked. You only have between a few hours to a week to use it, not the next 50 years.
However, most of those scenarios have the added security that the CC or some necessary confirmation letter to sign is sent to the registered address of that id. So you'd also have to stalk my mailbox to actually get the credit card. This actually happens - so people use locked mail boxes to protect against this.
That is, even for this "manual" id method, there is 2fa in the form of regular mail, made possible by the fact that you can't use my id and give them your street address. When you show my id - they immediately know what address belongs to that id.
The 2fa app is driven by a separate company that only does identification service.
This makes the phone scam a lot more involved because you can impersonate someone on the phone but the mail makes it kind of 2fa. The credit card you tried to open in Bob's name will always be sent to the real address of Bob.
The bank didn't need to store much here - names and addresses they can lookup directly from the id number.
When I got my first driver's license in Georgia USA, 1986, the license number was my SSN. Every system used it to identify you: banks, doctors...
But things started to get weird. As other have already commented, everyone got confused, and let "Identity" = "Authorization".
Perhaps in a world of paper records, this system would have been ok. But always more transactions from remote locations. Many stores required you to write the last four digits of SSN on checks, or credit card slips, because they had no way of authorizing the transaction with your bank. Large vendors had these little modems that could dial up and talk to your bank, but small shops only had paper.
Anyway, it was in the banks' interest to roll out Point-Of-Sale transaction tech, because USA banking laws committed the bank to pay the vendor.
But fraud increased as the tech got faster. Someone noted that Social Security, by explicit law, cannot be used as ID in any situation that is not directly involving a Social Security pension or insurance.
The banks and medical systems rolled a lot of the shift away from SSN under their huge Y2K projects.
Here we are. Now they all ask for other publicly-available personal information, and still confuse ID with Auth.
Most countries have some type of citizen identification number, which is attached to some ID with a photo and/or finger prints. The US does not, and the political climate for the past several decades would probably never allow this. The Real ID act has been seen as a sign of the beast by religious fundamentalist and a basic erosion of rights by libertarians et. al.
Passport numbers can't be used either because not all US citizens/residents have a passport and the numbers change when you renew them. Most parents get a SSN for their child at birth. Even people I know with dual citizenship overseas have them (all except for one, and you don't really need one unless you want to go to America to work .. and then you'll also need to pay an immigration/tax lawyer to go back and reconcile all your taxes).
Here's a great video on it: https://www.youtube.com/watch?v=Erp8IAUouus
But knowing a persons name and social security number allows you to do all kind of misuse, i. e. identity theft. I have not lived in Sweden for 30 years, but I assume many things still work similar as here in Finland. Closing other people's credit cards and mobile phone subscriptions typically works by knowing the social security number. Ordering online without credit card and paying the bill (or not) after delivery, too.
/s
If I had to guess, I would say that Equifax is not checking against a list of people that they know are compromised, but rather against a list that they know have NOT been compromised. So if you check a name, and it is in Equifax's database AND it is known to be uncompromised, you get back a "you are safe message". For everyone else they give a generic "you maybe were effected", emphasis on the "maybe".
Obviously a fictional person with fictional details is not going to be in Equifax's database, so they would just throw the generic maybe message.
Equifax says the 7-yr old "may" have been affected. The 5 yr old comes back clean.
This sure looks scammy.
My comments ... https://twitter.com/hpcjoe/status/906549917509980160
This is an extinction level event for Equifax. They need to be disassembled, their stored data destroyed correctly and securely, their negligent officers charged.
This isn't an accident. You don't surface 0.134 BILLION bits of PII without some sort of criminal level incompetence.
Any organization that uses Equifax data in any decision making process needs to be held accountable, as there may have been earlier intrusions also undiscovered, that have altered. Which, if they then choose to use them in any decision process whatsoever, brings them liability for misuse of possibly tampered with data.
I am quite serious when I say that Equifax should cease to exist as a result of this. All others should be audited for security, and audited hard.
Again, not being hyperbolic. But quite direct, with appropriate levels of anger at Equifax.
But this is a government with a grifter at the top, so I have almost no confidence attorney general Sessions will investigate this seriously, let alone destroy the company. He very clearly enjoys targeting e.g. black people who smoke weed with incarceration, destroying their lives, than punishing Equifax's officers, board, or shareholders with destruction.
I have more confidence in a handful of state attorneys general working on this effort.
I'm almost sure I once saw a quote from Bill Clinton's press secretary that said something like "We knew that if we could survive the first 5 days of a bad story, it would get dropped."
That perspective solidified for me during the Occupy Movement. Granted, it lasted much longer than 5 days, but ultimately, what of it? The FBI didn't investigate the bankers, it investigated the protesters.
You see it with Flint. You see it with Climate Change.
I've always been politically apathetic. Moreso as a foreigner where I recognize that living in a foreign country is a privilege, not a right. Plus I'm a cynical person (not a healthy habit). Which means that whenever I hear about "boycotts", or "writing to your representative", or "held criminally responsible", or "..." I always think two things. First, that people are naïve, and second, what's it going to take to drive people to take un-ignorable action?
Brave New World.
You can be cynical of the government and the regulators and still do something about it. If you are a landlord and running a credit check don't use Equifax. Maybe this will open the door for startup in the space.
I honestly think that criminally they are going to get a slap on the wrist if anything. The majority of damages will come from civil suits.
The anger will become a mob that enacts change when a critical mass of people lose access to food and/or shelter.
> what of [Occupy]
Occupy was very successful at (re-)introducing class warfare into the public dialog.
> First, that people are naïve, and second, what's it going to take to drive people to take un-ignorable action?
3rd, why isn't this anger organizing into larger activist/political movements? Well, with enough surveillance data and modern data analysis tools it's easy to find the "leaders" or "organizers" that bring people together. Remember JTRIG[1]?
What nodes in the graph of connections would you target? Intuition says go after the nodes with tons of connections to tons of people. Intuition is, as it almost always is, dead wrong. Removing those massively-connected people in a social network is basically useless. They are almost exclusively connected to people who are already connected to one another. They're the center of clusters, and you will almost never route through one in an attempt to find the path to Mr. Bacon.
Instead, what you want to look for are node which bridge clusters. People who are usually not strongly connected to one of the clusters they are associated with, but provide a conduit through which connections can be made. Because they are inherently a bit 'different' from the people in each of the clusters they bridge (few others bridge those two clusters), they tend not to be important figures. They're a member of a biker gang who hangs out with his great aunts knitting circle on Saturdays. They're the ones who facilitate the flow of ideas between groups that never speak to one another otherwise.
So you know who to target... but how many 'bridge' nodes like that do you need to really take out in order to significantly increase the 'distance' between nodes on the graph on average? Disturbingly few. Removing something like 25 nodes from the graph of tens of thousands of performers will make it so you need 15 or more connections on average to get to Mr. Bacon. (The book 'Linked: The New Science of Networks' details the research specifically, its been years since I read it though so I am fuzzy on exact numbers but it was definitely fewer than 30 you needed to remove)
Now, imagine a crazy scenario where you had access to the social graph of a country (somehow!) and knew who was talking to who. And your goal was just to maintain the status quo. Well, what does any large-scale social change require? An idea must spread to large numbers of extremely different, and almost entirely disconnected, groups. Any idea that remains sheltered in one or a few groups will die out of its own accord. A revolution doesn't happen because one minority wills it, there has to be buy-in from a wide array of groups. So remove those bridge nodes. Any widespread social change becomes very nearly impossible.
But what is "removing a node"? I'm not talking about black-bagging a person and dragging them off to some hole or blowing their brains out. Such things are entirely unnecessary and counter-productive. The more significant your action is, the more profound the unintended consequences will be and predicting the outcome quickly becomes intractable. Instead, notice that those bridges are usually connected more strongly to one cluster rather than the other. If their communication became more burdensome to the group they are less connected to... for how long would they persist in fighting to maintain it? If something nutty happened and they had to change their phone number, what're the odds they'll forget to give the new one to the contact in a group they're barely involved in?
You could have very quiet oppression through these means. I expect there would be unintended consequences, and have been trying to figure out for a few ways a good way to detect such changes in a social network, but its just a thing I keep in the back of my head, not something I actively work on. If you've got any ideas, I'd be happy to hear them.
There is an entire industry keen to get people unconstructively angry about unrealistic threats so they can sell gold and ammunition.
While I am upset on behalf of all affected consumers, mere words cannot adequately express the unbridled joy that I experienced when I found out that they were likely, at a minimum, going to lose hundreds of millions (or more) over this. Having dealt with high level executives at the company, I can tell you that an event like this is wholly unsurprising given their nonchalant attitudes toward...pretty much everything. I absolutely hope you are right that this is an extinction level event for them. My admittedly biased opinion is that they are an irresponsible company with far too much power over peoples' lives, run by malevolent executives. The company should probably cease to exist, at least in its current form.
So 134 Million then. I mean that's still an extreme amount of bits ofc. Just seems silly to use the "billion" signifier for something that is less than 1 billion.
Likewise it'd be strange to call something "1000 milliunits" instead of just 1 unit. (Unless ofc milli happens to be the frame of reference for some obvious reason like "15 millunits of x is a deadly dose".)
Again, stylistic.
The thing that really incenses me about this whole debacle is the system is designed to benefit from its own incompetence! All these "identity theft solutions" that the big credit bureaus provide are just a way to charge consumers more for a problem that the consumer had nothing to do with in the first place!
Equifax were already in the process of having the law rewritten in their favour by the Republican party, at least that might be derailed or delayed for a few years. https://www.americanbanker.com/news/equifax-breach-may-kill-...
There's some claims here about the history of Equifax as a form of legal redlining, but they're a bit hard to substantiate with simple googling: https://twitter.com/matthewstoller/status/906257077215133696
The same is not true of software-driven systems. There are no licensed developers, no regulatory body determining what tools must be made available, no guarantee of primacy of technical engineering concerns over business management. If a software engineer says "it needs more testing" or even "there is a bug that will kill people" and the CEO says "ship it", it ships and the courts will do nothing. This was proven to be true even in cases where incompetent management results in bad software that gets people killed in the case against Toyota with their "unintended acceleration" due to a firmware bug that would have been caught immediately if the developers had static analysis tools.
Companies fight against the establishment of any sort of standards because it would reduce their profit margins. Developers fight against the establishment of any sort of standards because it would raise the barrier to entry in the field and no matter who the standards body consists of, they will select standards which people disagree with, they will be reluctant and slow to change or update them, etc. Both sides are right. But the alternative is companies having free reign up to and including incompetence of the degree which gets people killed with no accountability. People are overall very bad at decisions between two scenarios with clear negatives on both sides. They feel entitled to a 'clean' option and are uncomfortable with saying "I embrace the negatives and accept the burden of working hard to try to minimize their harm in order to gain the benefits of this option." Accepting the negatives implies taking some responsibility for bringing them to fruition and no one wants to be responsible for that - even if the alternative is worse. Not every decision is easy.
So, instead of dissolution, I propose two very reasonable remedies that I would consider the absolute minimum in concert with whatever fines and sanctions may be levied:
1. Credit freezes/unfreezes must be offered free in perpetuity. “They cost us money to perform” is not a remotely appropriate objection - offering this for free should be a basic cost of doing business in the credit reporting industry.
2. Affected individuals (everyone, basically) must be granted a minimum of 10 years of credit monitoring following the breach. One year is a free sample you get with a coupon code from a podcast. Furthermore, the service must not auto-renew at the end of the term: send users a security report and let them decide if they want to opt-in to continued monitoring after the term ends.
When a charge of more than $100 is made on my credit card, I get a text message instantly. When I log into my banks web system, I get a text message instantly. I was able to set those things up. I don't see why it would be unreasonable to have a similar thing set up so that I could be alerted every single time my credit history is queried with information about who is querying it for what purpose, ideally with the ability to block it by replying to the text message.
That's what the 10yr monitoring is for?
"As specified on the website, Your membership subscription may be subject to automatic renewal. TrustedID may, in its sole discretion, terminate this Agreement (or suspend, terminate, or otherwise restrict Your use of and access to the Product) at any time, without notice."
Not only can they renew you automatically (unclear what the renewal term is, plausibly the autorenew could obligate you with another year of service you'd have to pay for); but they can also cancel the service, and not inform you. So you're "protected". Maybe. You don't really know, nothing about it is transparent.
What we do know, is they're bad at their job of protecting consumer credit data from people who shouldn't have it. They're not to be trusted, and therefore no good reason to agree to anything they offer.
Here's the message I got:
Based on the information provided, we believe that your personal information was not impacted by this incident.
Click the button below to continue your enrollment in TrustedID Premier.
Maybe if they can't make a positive match against their "safe" list, they give the warning.
They seem to be matching on SSN alone, I entered a completely different last name, and still was told that I'm not impacted, so maybe no one with the last 6 digits of my SSN was impacted.
It is perplexing to pay $5-10 to each of these companies that have collected my data without my permission to stop the sale of that data. In particular after they have mismanaged that data and put me at risk.
They will probably see a large surge in revenue based on this breach.
[1] https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq...
[0] https://www.nytimes.com/2017/09/08/your-money/identity-theft...
There are quite a few, actually.
I'm sure Techcrunch verified this is legit, but there's going to be a lot of similar sites shared on Facebook popping up that are similar to get your data.
1. Enter SSN
2a. Impacted by this hack
2b. Not impacted by this hack but will be impacted by next
I think it'd be nearly impossible to be an adult living on your own and not have your SSN in a credit agency's database.
Is anyone else mortified that this is the reality? Where companies are allowed to dictate how much legal privilege we have to seek legal recourse if they legitimately screw up?
Specifically, having current address info released for people who that could go badly for. eg ex-partners of violent people, maybe law enforcement (?) people, etc
If that's the case, then the fallout (and scrambling-to-relocate by people endangered) from it could be even more massive then so far mentioned. :/
Though it'd be nice if this caused new data privacy and protection regulations. (But it won't)
They could issue that response regardless of what you type and cover all possibiliites.
My guess: to account for typos, they are responding with "may have been impacted" if they get a hit on either the name or SSN, not only when there is a match on both.
Fraudulent charges on an existing account is not the concern when someone has your SSN and other high-value information - it's the ability for someone else to open an account in your name that you have no knowledge of.
And here is the really sad bit, when you tell the debt collector that its a bogus account and not you, by law they have to stop hassling you but instead of 'retiring' the debt they just resell it to another debt collector to get back some of the money they paid for it. So the cycle doesn't stop.
No doubt these layers of protection will fail for some people. Maybe Equifax should be required to set up a fund to pay out to such people. But it's not apocalyptic like people are making it out to be. OPM leaked the records of about 20 million people a few years ago. So far, there hasn't been any sort of mass-scale impact as a result of that breach.
(although that appears to be ordinary incompetence)
I suspect the reason for this might be that I froze my info years ago.
In some way they must be screening against people who are frozen, or I got lucky.
Quote from the article:
> In the early hours after the breach announcement, the site was being flagged by various browsers as a phishing threat. In some cases, people visiting the site were told they were not affected, only to find they received a different answer when they checked the site with the same information on their mobile phones.
[1]: https://gixtools.net/2017/09/equifax-breach-response-turns-d...
1. Equifax was never hacked.
2. Equifax accidentally deleted a substantial portion of their database.
3. Come up with a system to get the information they lost back, via a "have I been pwned?" checker.
3a. If you enter your details and they are not in their database, they assume it is one of the persons they deleted, add it to their database, and give you a "maybe hacked" message. Obviously a fictitious person would never have been in any of their databases, deleted or otherwise. So, assuming this fake person must be a deleted person, they add the info and show the "maybe hacked" message.
3b. If you enter your details and you are one of the lucky (haha) persons that were not deleted, you get a "you are safe" message.
4. Equifax gets a lot of their database they deleted back with little effort on their part.
What do you think?
They'd probably give it to them for free if that would avoid a huge public disclosure.
Though the proposed scenario is impossible, if Equifax really did lose most of their database, asking users to type in their current name/address/SSN (or buying it from a competitor) wouldn't help them, the valuable data is in the credit history, and without that data, Equifax has no business, so they'll go bankrupt. Even if they asked consumers for the data, few people know all of the data that the credit agencies have on them.
Surreptitiously recreating a database? They can get a list of SSNs from the government, what is a user going to add to that? One of their addresses? All of their previous financial activity? What do you think the database contains?
Not to mention the idea that Equifax doesn't have backups.
Although most people know of stories where backups were broken, didn't work, (etc) for some reason, it would be truly mind boggling for it to be the case here.
Deleting a substantial amounts of production data... seen that before (I used to be a NetBackup Admin for large places). But recovery procedures do exist, and for them not to have multiple levels of recovery available for their core mission data is extremely unlikely.
Also the data that leaked is not the valuable data to them. See how proudly they stated that no core databases were affected? Not giving a damn about us?
What's valuable to them and to banks that use them are the actual information about our credit. If that was compromised that would kill them, because they would lose trust of their real customers (banks).
crazy alternate theory