No. They should be liable for the damage they cause with negligently allowing hacks like this, but the existence of private businesses should be default-allow.
No. They should be liable for the damage they cause with negligently allowing hacks like this, but the existence of private businesses should be default-allow.
Is there even a license that the Equifax company needs to have, in order to do this type of work, that can be revoked? It needs to be revoked! But I'm afraid they don't need any license, they just woke up like this.
The right to covertly surveil and maintain dossiers on 50%+ of the citizens of this country should not be default-allow. Strongly disagree. People in power holding that kind of opinion, is exactly how we got here.
Don't you think that somewhere in the T&Cs of a loan you took or a credit card that you got or a phone contract you signed up for (or many other things) are lines explaining that your information would be shared with credit reporting agencies? So legally, you would've consented to the sharing of information at those times. If that isn't true, then I'd assume that you should be able to sue the institution that shared your information with all these agencies.
There is no way out of this (the cat is out of the bag) but we can go on about our lives without Equifax. They need to be unplugged.
We can't just unplug all three agencies and shut down the credit industry, but why can't we shut down Equifax? Take the drivers' license and the car keys away from the drunk driver.
They are the ones that let the cat out of the bag, they should no longer be allowed to collect our personal information. There is no reasonable argument that can be made that Equifax in particular, should be allowed to go on making money off of our personal data with the negligent failure that they have created for us and admitted to, after what all has happened.
Edit: When Sonny Vleisides plead guilty to Felony Mail Fraud in 2007, he was forbidden to engage in loan programs, gambling or gaming activities, telemarketing activities, investment programs or any other business involving the solicitation of funds. He went on to found the company called Butterfly Labs in 2010, a company that took pre-orders for Bitcoin mining equipment (in many cases soliciting funds for hardware that didn't exist, until it did).
Many people argued that this model was a direct violation of the terms of his supervised release. He stood in front of a judge in 2014 that said there was a "strong smell" of fraud with respect to his company.
Equifax it seems gets to skip the whole "plead guilty" thing and just announced their negligent failure directly to the world. When does Equifax get their 14 months in jail followed by a supervised release? Never, apparently, they just go on about their business and no charges are filed. It's absolutely ridiculous in my humble opinion. Maybe I'm the one who is being unreasonable, expecting that the wheels of justice can turn more rapidly than one can reasonably expect.
It's not exactly parallel, I'm stretching to draw parallels obviously, but there should be some parallels in the arena of legal action here. Has anyone argued that Equifax wasn't negligent in the circumstances leading up to the breach? What about in their actions since then? How much further does it have to go before we can get the FTC or US Marshals involved and shut the place down?
From the article.
At the end of the day, whether it's a private or public credit agency, they're still collecting all your data whether you want them to or not (modulo going full Thoreau and removing yourself from the economy), and still could get hacked and have all that stolen.
No, I disagree. A public agency would have the same value as a target. But its incentives would be better aligned (no profit motive), which could result in better practices and less actual risk.
Are they licensed to do this type of work? Shouldn't they need to be? Should that be revokable? What is the process for revoking that permission, and can we get it started already? It just came out that in their response to the breach, they've been linking their "customers" to a phishing site since September 9. It's time to revoke those grants.
To be fair, I'm pretty sure they can legally do that if this was actually the case.
Absent any law that says exactly how they may and may not collect and retain such data, you're probably right that it is exactly what it means. The owners of the data (the banks) authorized them, so they are authorized to have the data.
It does not change the fact that, if true, the law is an ass. I do not grant power-of-attorney to the credit-holders that I do business with. They are not authorized to sign documents in my name. They should not be able to authorize arbitrary agencies to hold my personal data in an irrevocable fashion.
(And if I understand the difference in law between US and Europe, in Europe they would not be able to permanently retain my personal data without any recourse for me to shut it down. But in the US, they may be allowed to do this.)
I think you're placing too many constraints on a hypothetical contract just to support your initial argument. Most likely the contract is carefully written in such a way that it's legal for them to do whatever they wanted to do with your data to begin with. It's pointless arguing over what ifs.
This is not normal, it is dysfunctional. I'm not arguing that it's not legal, I'm arguing that they need to lose their license. (Never mind that no such licensing requirement exists. Like I said, it's a dysfunctional system, and I don't know why we don't have more than 3 credit reporting agencies. It sounds like a great gig!)
With the amount of power these organizations and this information has over each of us, individually, I'd go so far as to say there is a human rights issue at stake. People's lives get fucked up through credit bureau mistakes, and what consequence is there for those bureaux?
Pointing to a subclause in a contract to say "well, here's where you let them potentially fuck up your life with no recourse, and everything is legal" suggests to me that our thinking around the power these agencies, and around ownership of information about our lives, have needs revisiting.
It would not be so controversial if I claimed that Amazon grants customers a revokable license to audio and video content hosted on Prime, but my social security number and credit history evidently is not afforded as much protection under the law.
Paying rent is also bad for you.
Are you claiming that people don't know what credit reporting is when they sign loans? If so, that's a failure of basic financial education on the part of parents and K12. If someone imagines they have the right to delete the records of debts they don't want to pay, that person has been tragically misled about the fundamental nature of adulthood.
Knowing that lenders communicate with each other about your reputation, especially when you'd rather they wouldn't, is right up there with knowing what interest is.
There are three credit reporting agencies. Can you tell me why there aren't more? Because from everything I can tell, there is nothing short of purely criminal activity that could actually result in Equifax being required to go out of business. It seems that no amount of negligent behavior on their part can give me the right to say "cease and desist your retention of my record," while I've never so much as signed a document that came from Equifax. I have no direct relationship with them, and I have the right to get a restraining order if a malicious stalker is all up in my shit, so how is this situation any different? What makes them the authority? Because credit banks do business with them? That's nice... I want them out of business! In Europe, I would have this right. Nobody could maintain a file on me that I can't get a legal order for them to delete.
I'm not talking about debt holders. I'm talking about this parasitic company that evidently has no security team, or has chronically underfunded it to the point that we get where we are now, or had simply disregarded their advice umpteen times _after_ it became clear that the situation was very dire.
The struts vulnerability was disclosed months before they patched it. Any security researcher worth a dime could have told them it was a mistake to put up that equifaxsecurity2017 site that was literally (so much that their own Twitter account linked to it 9 times) indistinguishable from a phishing website and make the only way to know it was legit, a link from the front page of Equifax.com.
How did they get such a great gift from the law, if such is true then sign me up to be a credit reporting agency! I know how to build crappy websites and persist database records, it seems I meet all of the non-existent licencing requirements to be a CRA.
It is an agreement with my bank. That lets my bank off the hook, not the negligent credit reporting agency Equifax. I must still have some kind of rights when any kind of agency is legally allowed to store my SSN and personal information. If this was Europe, with their data privacy protections, I would be sure about that. The reality in this country is, I have no idea if "I must have" is a statement of fact or not.
It should be my right to revoke this privilege that they have gained, however they came about it.
If I can go into Google and click a box to completely expunge my google history, why can't I do the same with a credit-reporting agency?
I get that the thinking is, well, you could just expunge away bad credit choices... but, so what? Your blank credit history is now your red flag, as well as a bad one.
But if you wanted to opt out, you could.
What could possibly go wrong? (Hah, I didn't mean that as a jokey rhetorical question!)
And it's the bank's right not to write loans to people who think this, and they're exercising it.
The whole point of credit reporting is that you can't make your record go away.
I can't tell Equifax to get bent and delete my record. I'm not asking for my credit history to go away (and shame on you for being the tenth person to suggest that I am), I am asking for the harmful company that appears to have chronically underfunded their security department, or ignored their advice, or whatever else has gone wrong to land us here, where we are now, to go out of business.
If I can't have that, then I'd settle for them being required to delete MY personal record upon my request. Next time I need to pull my credit file, I'll warn the lender not to try to pay Equifax to look me up, because they're going to get back a null reference with a timestamp of some September 2017 date on it. What's so hard about that? If the lender doesn't like it, I'll take my money elsewhere.
Lenders can keep their own records and report them anywhere they want, within the terms of our agreement and the law. I should not be obligated to remain in Equifax's database until fraud, criminal mischief, or negligence on their part is proven in a court of law. I am just asking for some modicum of control over where my records are stored, kept and shared.
But... that's not an option for me, we don't have EU style personal data privacy and protection laws!
Why yes, you did through your agreement with any vendor (e.g. bank, credit union, credit card company, rental) that you have dealt with. This is a standard clause, although some places don't actually do it (my landlord for instance as I found out when I went for a car loan).
I hate this, but claiming you didn't consent is just not a credible answer without some additional legislation to force contracts to be explicit in whom a vendor may share information.
I can't say whether Equifax's agreement with the bank provides any clauses to allow for revocation of Equifax rights to store the information about me, but if it does not then I need to go out and find me a new bank with some better lawyers.
(I'm saying that a scenario such as this whole series of negligent behavior and events, should trigger one of those clauses.)
Im not saying they never had a right to store the data, I'm simply saying that it should be revoked. Let's not give them more responsibility and more data, they've already proven repeatedly that they can't handle it.
You are trying to draw boundaries that don't exist.
Shouldn't they have some kind of licensing requirement in order to be held accountable for their security practices? Where is the line, that when they cross it, they should lose their accreditation? There isn't one, because there is no such accreditation (not to my knowledge anyway.)
It is not reasonable if there are only 3 credit reporting agencies and they do not have any licensing requirements. If I am mistaken about this, please correct me.
But as of now, those requirements don't apply to them. So acting like they do is distracting at best.
Let's figure out ways: a) to know what they have, b) to force them to accept corrections, and c) add major negative consequences if/when they f* up.
If 140MM Americans (or even 50MM, let's be reasonable) told Equifax that they wanted to be removed from their database in response to the breach, and Equifax was required to honor those requests, it would be a step in the right direction.
That would be enough to put some "fear of God" into the shareholders at the remaining credit reporting agencies, and it does not sound like an unreasonable request at all. Companies going forward would have a disincentive to do business with Equifax, because 1/3 of people are missing from their database. (Instead, we're all permitted to buy more "Credit Freeze and Monitoring" solutions from Equifax, for the low price of $0, plus a low low payment of $10 every time we need to freeze or unfreeze our credit again to access it in the future. So let's dig the hole even deeper!)
Citizens that want to have credit would not be incentivized to remove their credit history from all three reporting agencies; as you probably already know, having no credit history is worse than having a bad credit history.
Then again, if we allowed that, then what's to stop those hackers from benevolently making the request on behalf of all 140MM people whose information they have appropriated.
There is no negative consequence that will incentivize Equifax to do better next time, if the result of this breach and their subsequent bungling of the response, is that they are allowed to continue operating their business without interruption.
Take the keys to the car away from the drunk driver. That's step one.
CRAs are regulated by the government, with things like GLBA, CFPB, FCRA, and other acronyms covering what they can and cannot do, what their responsibilities are, etc. The CRAs have all been fined for improper handling of data, failing to adequately vet data provided to customers, etc.
CRAs get data from two places primarily: public records and CRA members (banks, credit card companies, retailers, etc.) The public records stuff is just that: public. Anyone can get it if they ask and are willing to pay the costs to gather it.
Member data is provided by members to CRAs, and you absolutely grant the right to them to do so when you signed up to use them. When you get a bank account, or credit card, or sign up for a store card, or really agree to do business with any entity on a financial basis, you approved it with your signature.
Your statement about "covert surveillance" is factually incorrect. You have a right under the law to view your entire credit file as held by all CRAs once per year. I also think (not sure) that you can get a copy if you're turned down for credit due to information on a credit report. So how is it "covert", if you not only know about it but can see it?
You have made a substantive comment and I don't have time to respond substantively to any more comments right now unfortunately. I'm not arguing that they didn't have the right to collect the data.
I'm arguing that we have two other credit reporting agencies that appear to be functioning properly, and one that looks like it is in a continuing state of dysfunction. There appears to be no end to their ongoing dysfunctional behavior, and no possible remediation for affected parties on the horizon at all.
I just want to know what other kind of business in America would still have any customers after the two weeks that Equifax has just had? Do you think that Equifax should now have the right to continue operating, all things considered?
I strongly suggest you do some research about that. You'll find that the other two CRAs have been equally "negligent" at different times.
> I just want to know what other kind of business in America would still have any customers after the two weeks that Equifax has just had?
Remember the Target data breach? Or the Home Depot breach? How about when Sony was distributing a rootkit on their music CDs? Or when Lenovo was distributing a malware package preinstalled on their laptops? Or when Best Buy was selling digital picture frames that had a virus? The list, sadly, goes on and on and on...
> Do you think that Equifax should now have the right to continue operating, all things considered?
Of course. Since you're here on Hacker News, I presume you must have some knowledge of computer security...do you really think it was negligence that caused all of this? Do you think that the other CRAs are in any way more secure or less negligent? Or banks? Or any business that uses, say Cisco switches (which have tons of vulnerabilities)? Or businesses that uses Microsoft Windows (too many viruses and worms to count)?
First they suppressed valuable information in the form of interviews with their CISO that were public until September 10, when they came down for some reason.
Then they started tweeting out links to a phishing site that looked just like their own "equifaxsecurity2017" site. About this time, the CIO and CISO were removed from the picture entirely.
A few days later, each of these gaffes became known. Meanwhile they had delayed long past the timeline outlined in legal requirements for their reporting of the breach. Where are the Congressional interviews with their executive directorship?
Not on the calendar yet, why don't we schedule it for next February 30th. First of never. I'm just as incensed about the (seeming lack of) response of law enforcement, which admittedly I don't personally have much visibility into, but seems inadequate.
At a minimum I would argue that Equifax needs a "time-out." Ideally they would not be handling the response to this situation at all. They should go on the hook to pay someone competent to handle the response.
Not much to say about that one, for sure. I still don't understand why they wanted to make a completely separate site with that stupid name.
> Meanwhile they had delayed long past the timeline outlined in legal requirements for their reporting of the breach.
I think you'll find that they adhered to the letter of the law on that. Maybe you know when Equifax made the breach public, but you don't know when they first contacted the relevant authorities (law enforcement or regulatory).
> Where are the Congressional interviews with their executive directorship?
Oh, that's coming, for sure. Other companies have been called before congress for far less. But what good has ever come out of such a hearing? That's what you do when you want to save face with the American public and seem like you're going to do something. There might be hope...Al Franken is the ranking member on what I think is the relevant committee, and he usually does a good job in calling out BS when he sees it.
> I'm just as incensed about the response of law enforcement
How so? What would you expect from law enforcement here?
Copied from another sub-thread I posted in...
When Sonny Vleisides plead guilty to Felony Mail Fraud in 2007, he was forbidden to engage in loan programs, gambling or gaming activities, telemarketing activities, investment programs or any other business involving the solicitation of funds.
He went on to co-found the company called Butterfly Labs in 2010, a company that took pre-orders for Bitcoin mining equipment (in many cases soliciting funds for hardware that didn't exist, until it did).
Many people argued that this business model was a direct violation of the terms of his supervised release. He stood in front of a judge in 2014 that said there was a "strong smell" of fraud with respect to his company.
Equifax it seems gets to skip the whole "plead guilty" thing and just announced their negligent failure directly to the world.
When does Equifax get their 14 months in jail followed by a supervised release? Never, apparently, they just go on about their business and no charges are filed. I would expect for them to get a "time-out" after their bungling of the response to this breach, at the bare minimum.
But no, let's give them a participation trophy instead, let them continue handling the response to the breach, they've earned it...
You're presuming that Equifax is guilty of something. Of what? Of being victims of a hack? What about the SEC, who just notified the public now that they were hacked back in 2016?
You seem to think that Equifax is guilty of negligence. Good luck proving that. They're subject to security audits not only from the government, but in relation to the contracts they have with their various customers (standard stuff when companies deal with each other, not least of which when consumer data is involved). Their security wasn't good enough, but they didn't know that until too late. Same as Target. Same as Home Depot. Same as the SEC.
Equifax is going to get fined. They're going to lose business. They're going to eat the cost of providing identity theft protection/monitoring to the entire country. They're going to have to fight their way back to whatever previous stature they had. But any thought that they're going to be found criminally liable for this is simply not credible.
They should not have been in charge of the response, but there was no way for us to know that for sure until they had already flubbed it so badly.
They are guilty of handling the response very poorly in a way that has been hashed out and rehashed at least six dozen times on HN until the culmination (so far) yesterday, when we found out that their site was so easy to spoof it fooled even Tim, the Twitter guy from Equifax, who tweeted links to the spoof site out to eight or nine customers over the course of the response.
That was possible because of their initial poor (evidently hasty, and negligently so) response. I'm not asking to make anyone criminally liable, I'm suggesting that next time a company leaks sensitive records on 140MM Americans, we should remember this chain of events and somehow all do better. (And not have another repeat of this shit show, if possible... but who am I kidding, it will repeat.)
The poor response was probably made worse because of their internal culture that resulted in the CIO and CISO being canned (that sounds like all of their top technical leadership put out the door) right as the response was just getting underway. That too, in my opinion, was probably negligence!
I know we don't put companies in "time out" but it seems like we had better think about doing exactly that in this case, lest we soon find out what it will look like when the (next) other shoe drops.
The Equifax story will only continue to get worse! Just wait until their new free credit monitoring systems are breached, and we get to find out exactly what that mandatory class-action arbitration clause we've all heard about is actually intended to do!
Then who should have?
> we should remember this chain of events and somehow all do better. (And not have another repeat of this shit show, if possible... but who am I kidding, it will repeat.)
100% agreement here.
> Then who should have?
Better question: what would be an appropriate response? Because this one isn't, that much is sure, but I don't have an answer for this question other than "one that is not so hastily and shoddily implemented."
Further, do you really think this was a hasty response? This is the response dictated by the law, coupled with recommendations from their legal team, and probably with input from regulators as well.
It was hasty, in terms of... just look at equifaxsecurity2017.com
Did they run this plan by even one security researcher before it was put into action? If so, that person's advice was either terrible, or ignored. No time at all had elapsed between the time we were alerted to the breach, and when Equifax revealed the 2-day old site that was protected by Amazon certificate.
I am building an HR web portal for employees to submit their identity when they do not go through our background checking service (some classes of employee who are exempt from the requirement to get a background check, for archaic reasons), and I am holding up Equifax's response to the breach as an example of "What Not To Do."
There is no legal requirement for them to put up a website that looks like a phishing scam, and respond to people who put in their information with a random value of "Yes you were affected/Check back later to find out if you were affected". There would certainly have been questions about "who was affected" but it would be better to answer with a blanket response of "everyone with a credit file" than to do as they did, and say "143 million Americans, now fill out this pointless form attached to a random number generator to find out if you are one of them."
Seriously, what were they thinking? Even the most charitable light isn't enough for this to make sense.
Butterymales! What about Hillary!
My credit history is still in the hands of Equifax and I have no control over that fact. That is problem number one for me. I want to get off of Mr Bones Wild Ride.
Your credit history is in the hands of all the CRAs, just like it has been since the first time you entered into any sort of credit agreement, or opened a bank account, or applied for a car loan, or rented an apartment, got student loans, or did anything where your "credit worthiness" comes into play.
Probably because they still weren't sure that their existing systems were secure. So instead of securing them, or unplugging them, they ... built a new system, both hastily and shoddily!
Then they sent out an e-mail to everyone, telling them to put a little bit more of their SSNs than we're all used to providing at the drop of a hat, ... put them into the bucket. Isn't that about the size of it?
I remember all of those things, and NONE of them were on the scale or level of impact of the Equifax breach. People who were affected by the Target breach, got replacement cards and moved on with their lives. Lenovo's malware package could be uninstalled and their hard drives could be reformatted.
People who are affected by Equifax breach... can do what? We are ALL affected by this breach. Every last American Citizen. The credit system itself, as we currently know it, now hangs in the balance.
I know that ALL of the credit reporting agencies have similar poorly designed systems, and THAT is EXACTLY what I am so goddamned mad about. Because THAT is a fact that is NOT going to change as a result of this. You know it and I know it!
We will still have the same 3 credit reporting agencies a year from now, and Equifax will STILL be profitable after whatever fines are imposed. We Need To Seriously Change This Shit Right.Fucking.Now! (NB. I have no specific suggestion, but I am so furious because of your apparent suggestion that there is no line that Equifax or any other CRA can cross that will earn them an honest decapitation. If not now, then when?)
This should NOT have been possible in any reasonable system designed to store sensitive data on every last American with a credit history, and the fact that it happened is all the evidence of negligence that you need. Someone exfiltrated ALL of the information they need to impersonate ANY American citizen with a credit file.
Nobody in particular needs to be held criminally negligent. No redress will make me happy about what has happened. The game is just over. The system is fucked, there's nothing left for them to protect. "Not for Identification Purposes" it's time to read the words on the card, and take them seriously.
I concede the possibility.
> We are ALL affected by this breach.
POTENTIALLY affected. There's been no disclosure of exactly how many records were accessed...I don't think they know, but it seems highly unlikely that their entire credit database could have been exfiltrated in that amount of time.
> I know that ALL of the credit reporting agencies have similar poorly designed systems
They don't actually. They tend to have above average security. It's just that it CANNOT be perfect. Just like we can't stop viruses, but Windows is still around.
> I am so furious because of your apparent suggestion that there is no line that Equifax or any other CRA can cross that will earn them an honest decapitation.
How about real criminal activity? You keep glossing over the point that Equifax was victimized here as well. What criminal intent, or even legitimate incompetence, can you claim that even remotely justifies that sort of reaction? Do you think this is Enron-level criminality? That was flat-out fraud, proven in court.
> the fact that it happened is all the evidence of negligence that you need
You're sadly mistaken as to the efficacy of computer security. The fact that it hasn't happened before, for a company that must be a target under constant and unrelenting assault, is actually a testimony to the how well they were maintaining security.
> "Not for Identification Purposes" it's time to read the words on the card, and take them seriously.
100% agreement on this.
> POTENTIALLY affected.
This is true. We don't know if they got all of the records. Reports of "143 million Americans impacted" would seem to indicate that it was roughly everyone with a credit file.
But that is just a headline/byline, and we don't know until the hackers dump it and divest of whatever they got, and the data (honestly, I say hopefully) winds up as public information so we can all know exactly how bad it is.
No reputable news source has said anything other than "potentially affected" as far as I know.
> the data (honestly, I say hopefully) winds up as public information so we can all know exactly how bad it is.
I agree.
Even worse, while the author criticizes how Equifax got started - private investigators looking for affairs, etc - that is exactly what the OPM database is. They're looking for things that could be used to blackmail an individual so it includes financial history, marital info, drug use/abuse info, and potentially medical records.
My coverage of it at the time: https://caseysoftware.com/blog/why-this-security-breach-is-w...
And no, there has been zero accountability around it.
Whenever someone says "the govt can protect this info better!" remember that this is the same government that doesn't follow the law with regards to wiretaps, FOIA requests, background check info, and many, many other things. Oh, and the NSA can't even protect their best tools.
I am, however, worried about the information in my file that is about other people. They contacted and interviewed lots of my friends and family. Those notes, and the associations between these groups of people, are all in the data that was exfiltrated.
You know what my friends and family got? Nothing, not even a form letter. Me? I'll be fine. However, some of them are now associated with others and who knows what other connections can be drawn when you cross-check with other information from the hack?
So, yeah, I'm jaded and skeptical about the idea of having it be a government operation. People keep saying this is the worst hack ever. Man, if they only knew what was in the clearance application. I disclosed all sorts of things that I really don't want to be public information.
And I got a form letter that was barely an apology. Hell, I think my notification was actually on a post card. Yeah, I just double checked. They sent my notification on a post card, not even in a secure envelope.
I may be a bit biased.
I couldn't even transfer my free credit monitoring to someone who could actually use it. It was non-transferable. I had no use for it, as I'd opted to freeze my credit entirely.
I'm not sure which bothers me the most, the hack or the response? I do know that if I'd been responsible for spillage of classified information, I'd have gone to jail. If I'd been responsible for spilling that much classified data, I'd have never felt a ray of sunshine again.
I'm very disappointed by it. What is most disappointing is that there was no good reason for me needing the clearance, FOUO would have been fine. I can't be specific, but there was no reason my work, or the data, should have been classified. On top of that, I'd already sold my business and had retired - years prior. There was no good reason for retaining my records.
I'm currently reading about other countries that offer a government run service for credit reporting. I'm trying really hard to remain objective and unbiased, but it's really difficult.
I feel sorry for the people who are impacted by this. It's not easy to go through. I'm not sure it's quite the same, but I felt violated when I found out about the OPM hack. I felt let down, abandoned, unappreciated, and powerless. The information was some of my most private information and, worse, wasn't just about me. I felt as though it was my fault that my friends and family also had their privacy violated.
I am not that great with words, so that's about the best way I can think of to describe it. Disgusting is a good description. On a positive note, it does help me empathize with the folks impacted by this hack.
Not only did the OPM hack affect my privacy, it made me a cause of others losing some of their privacy. By extension, they made me responsible.
Fortunately, none of my friends and family hold me accountable and understand that I'm not to blame. Still... It's not a good place to be, emotionally. I've since gotten over it, for the most part.
I don't even know what was in their investigation notes. That's need to know and they don't think I need to know. I disclosed everything from drug use to promiscuity, with names, dates, and places. It wasn't just my information in those files. Who knows what can be done with that info by giving it big-data treatment?
Add that database to this one, and the many others, and I'd be surprised if you couldn't draw much larger pictures and associations. The world is not that big and cross-checking on large data sets is almost certain to further erode privacy.
One of the questions most investigators ask is "Is there anyone else I should talk to?"
Sometimes they say it in general, sometimes about specific situations or interests but they say it regularly and often. They know that the people you list will be neutral -> positive about you. They want more.
Stuff like, "We know you went to school together. Do you remember what sports they played?" Except we'd not gone to school together.
Crafty buggers. Either way, that data is all out there now. I'm not sure what all made it into the reports, I suspect most of it did.
Equifax spreads misery across the general population. I have seen no practical proposals which allow us ordinary people to claw back the time and frustration these private companies suck out of us. How endlessly should they be allowed to socialize their losses and force us to subsidize them?
The onus of protection is on the consumer - the very people who never authorized the companies to collect and sell their financial identity. The concerned consumer needs to call back every 3 months to continue a fraud alert.
For those who don't know the value in placing a fraud alert is that it forces anyone extending you credit to first call you and verify that you actually intended to open the line of credit in your name. This is something that should be standard operating procedure and not a special consideration.
There are three companies to do it at. The cost is low and it is mandated to be free in some jurisdictions.
You want to rent an apartment, change your cell phone carrier, get home owner's insurance, order cable - all of these things require a credit check and you having to pay 5 dollars to each agency and making 3 separate calls to each of them to do so.
To be clear, I only know about the freezing. I got free monitoring but didn't take advantage of it. Instead, I just froze my credit and hope for the best. I don't really need credit for anything, so it has been fairly painless.
This is the sad part about it is there is no way to opt out of having your identity put at risk by these thugs.
>"I got free monitoring but didn't take advantage of it."
This is perhaps the most incensing part of all of this. Is that after one of these breaches the agency offers 1 year of credit monitoring and then after that its $16.95 a month.
They have attempted create another revenue opportunity for themselves by being reckless with your data. It's mind blowing.
Locking your credit means that the only people allowed access to your credit file are your current creditors. The fraud alerts means that the only way someone can grant your a new line of credit is by verifying with you personally that you intended to apply for this new credit.
Locking your credit is permanent and it needs to be done with all 3 agencies separately and each time you want to unlock your credit, example someone needs to run a credit check or you want a new credit card then you need to phone each of the 3 credit agencies separately and they each charge you 5 dollars for that privilege.
The fraud alert doesn't cost anything but can only be done for 90 day increments and then it is automatically revoked.
And if there is any glitch in the locking/unlocking or fraud alert, the agencies will resort to snail mail and letter writing to resolve issues. Everything is set up to be maximally inefficient and painful for the consumer to discourage doing so.
Also the 3 credit agencies manage a site that was mandated by congress after another scandal that allows consumers to request their own credit file for free once a year [1].
This site in addition to intentionally looking sketchy is also designed to be maximally painful to use. You will be asked things liked exact dates that you lived a certain address 15 years ago. If you fail any of these(which is quite easy to do) you will be instructed to send a letter, along with ID to the agency to request your personal credit report.
It is actually much much more difficult for a person to obtain their own credit report from these agencies than it is for a complete stranger to request it.
For anyone that had their credit locked or frozen previously the hackers would have also gotten access to the pin numbers that permit the unlocking of one's credit file. What's to stop someone from using the PIN to unlock it and create before opening credit in a victims name?
They should absolutely not allow PIN retrieval online and without a whole lot of serious vetting. That they do is yet another metaphorical kick in the teeth. I am just now learning about the PIN retrieval, so this may result in my needing to change strategies.
Fortunately, I don't rely on credit. If I need credit, I can easily qualify for a secured loan. It also helps that I sat on the board at my credit union for a while. So, credit isn't a problem.
I do feel sorry for those who aren't able to just stop using credit. See, according to what I've heard/read, freezing your credit actually negatively impacts your credit score. If you're freezing it, you must be at risk. Or so they seem to think. So, by defending yourself you are actually potentially harming yourself.
It is already eating up your time, perhaps some money, and adding stress to the lives of many innocent people. Then, when you want to alleviate some of that stress, or reduce your risk of harm, it harms you even more. There isn't even a realistic option to opt out of the game.
It's pretty horrifying and it is difficult to not be angry about it. I'm fairly well insulated but I can certainly empathize. I wish I had the answers. I wish I had a solution. I don't and I'm not sure anyone does.
Do you have a link or some further explanation for this? I don't think this is true. It's actually the opposite - when someone runs your credit which can happen without your knowledge or approval then your credit will get dinged. By freezing it and not allowing anyone but existing creditors to access your profile you prevent this.
Not having enough credit will keep you from obtaining a higher FICO score however. For instance you can have perfect credit but if you have to few credit cards your FICO score will be lower than someone who has perfect credit and has more credit cards. It's insane but true, its a metric called "balance to limit ratio":
http://www.experian.com/blogs/ask-experian/getting-more-cred...
Citation of my error:
https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq...
Though, that link is strange in a new and interesting way. The page seems to indicate you can pull your credit score while your account is frozen. Except, if I look at Credit Karma, they say you can't register and access your credit report if your account is frozen.
https://help.creditkarma.com/hc/en-us/articles/202041774-I-h...
It's surprisingly hard to find consistent information. I think this highlights another problem with the system.
I don't know anyone outside of high finance who had a good opinion of Equifax before the breach was announced. Their recent hardships has certainly not helped that.
For myself, I definitely think that companies and their officers should absolutely be liable for negligence.
I like your idea that companies should be able to bear the cost of a possible future liability. I don't know how we can implement it besides some form of insurance (like sometime else said a $10 fine per person per breach but I'd up it to (2000 * minimum wage per hour) for every incident per person. At some point though we will need criminal charges for negligence or worse attempts of cover up (Equifax). We need to make it easier to convict CEOs and the board to put them in prison in case of attempted cover up or non disclosure.
Hence I think your latter point is right, executives really need to be more criminally liable. It's hardly unheard of, even if Ken Lay died before sentencing.
Of course the hackers are directly responsible for the damage, but Equifax's negligence sure didn't help. Maybe a fractional multiplier for sharing responsibility.
In the case of information disclosure risks, the parties for whom that information concerns often have little or no say in the actions which have direct bearing on them.
That's they "why not". It's not the company, it's everyone else.
just because someone gets my information by no means any company should accept a credit application, especially those outside of the area where the person has residence. It is this lack of safeguards that we should take issue with. Those issuing credit should always be liable for any loss.
Frankly, I don't know what should be done about b), but nationalization of credit reporting is not going to make any difference. As for a), as has been pointed out many times, one problem is that the people responsible do not have enough skin in the game. So long as the companies are private, something could, in principle, be done to to increase that, but in a nationalized industry, the responsible people would have even less personally at risk.
I look at a market as a machine that we can deploy. It does a specific thing, but only with the right inputs and working conditions. Here, we are not Equifax's customers. Harm to us is a negative externality, which is a classic kind of market failure:
http://www.economicsonline.co.uk/Market_failures/Types_of_ma...
So markets don't fix this even in theory.
Personally, I'd like to see this problem turned over to an institution something like the Smithsonian: not a regular part of government, but a trust with a specific purpose. I'd be even happier with it if it had directly elected privacy commissioners, so that it was more accountable to the people whose data it safeguards.
We're only going to end up with more data that's about people, even if it's not generated or held by those people. Having a home for that data, one with a public purpose and public accountability, seems way better to me than leaving it for a private, profit-making corporation to exploit.
Economic historian Gavin Kennedy has made something of a career debunking this fallacy. Among his many writings:
The sorry invisible hand myth owes more to imagination and hope than it does to economics from Adam Smith. Its modern form really began its take off with Paul Samuelson’s successful textbook, “Economics: an analytical introduction”, McGraw-Hill 1948, and continued through to edition 20 in 2010. It had an earlier oral presence at Chicago (where Samuelson was an undergraduate) and Cambridge, England (A. C. Pigou). Even Oscar Lange postulated (1938 and 1947) a rival and “better” invisible-hand role by socialist planners. The Soviet planned economy challenged capitalism from the 1930s and in Cold War rivalry, with large communist parties and social-democratic in Western Europe, the myth asserted the innate superiority of capitalism with its “invisible hand”. Since the current recession, increasing questions appeared about its existence. Warren Samuel’s last book, “Erasing the Invisible Hand, essays on a elusive and misused concept in economics”, 2011 (Cambridge) exposes the modern history of the mythical “invisible hand” since its heyday from the 1960s through to the late 1990s
http://adamsmithslostlegacy.blogspot.com/2012/04/political-s...
Why is that commonly accepted, but it's horrible to contemplate regulation of Equifax for the same essential reasons?
Adding accountability to the general public via regulation may make them more bureaucratic. It may make them less. That's up to the invisible hand to decide, once their incentive structure matches their real world impact.
Mind you, I agree about adding accountability. I just doubt that's really a solution; it's part of a solution.
Equifax is definitely the latter.
If they are are so liable, then to remain profitable they will find a way to pass on their cost to the customers. Those customers in turn, will pass it on to the consumer. So then you end up footing liability insurance bill for the privilege of being subject to a credit search.
What's the idea; that if a whole network of criminals now has my personal info, there will be an insurance-backed fund that will instantly buy me a whole new identity, so life goes on merrily?
Nope! We must rather completely get rid of this Equifax and make it a criminal offense for anyone to share such info with any emerging Equifax-like agency, or with anyone else.
Your data going to Equifax is the fucking security breach. What happens afterward is just a footnote.