Equifax statement regarding extent of security incident announced Sep 7 2017
sec.gov
sec.gov
> names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers of 143 million U.S. consumers (since updated)
OK, so who is going to be the grown-up in this situation?
It's obvious now that these numbers can no longer be treated as secret or, in most cases, as identifying instruments.
Who will lead the effort to deprecate them and migrate all of the documents and accounts which rely on them?
Why is it so difficult to imagine a coherent, sober response from government and mega-corporate entities which have until now, been using SSNs as identifying data?
What incentives are there for Equifax, Experian, TransUnion, Innovis, etc who profit from this system existing to make it better?
Who in the government will go after them, or even better, come up with something which will render them obsolete?
couldnt that logic be applied to all laws making bad behavior have negative consequences?
All of them have been making money hand over fist on this, thanks to their exclusive ability to monitor and lock/unlock their own credit reports.
Even if you aren't paying these companies directly, you're paying a company paying them for credit reporting to watch for identity theft.
Calling it a perverse incentive is an understatement. Only the US Government could have stepped in and made it unprofitable, but it appears as there will be no significant punishment for Equifax, and instead as a result of this the Congress made it harder to file a Class Action Lawsuit against companies like Equifax, so the next time you won't even have that option...
Most services use public key crypto and your ID card doubles up as the thing you use to cryptographically sign any documents that require proof of ID. You can do this yourself for many official documents with a generic smart card reader, and most places that would require ID in general (like your bank) will use that same system too.
The nature of the system means that while there's still likely to be a list of personal/tax numbers lying around, they are not the secret and there isn't a central database of everybody's private keys out there. If the root cert is compromised it can be renewed and card holders can refresh their card through some system or another (where I lived I had to take it to an office for them to do it for me).
I enjoyed using that in favour of the UK method of telling somebody where I lived for three years and where I was born, along with various other details, in order for them to become convinced of who I am. All I had to do in Europe was plug in my ID and that was enough proof.
Of course, implementing such a scheme in the US and UK seems to be politically toxic for various reasons that can be summarised as paranoia (whether that's warranted or not), where the potential for the government to abuse it in myriad dystopian, conspiratorial ways is still far, far worse than what the corporate megaliths are doing with all of that information already, for profit, as if the natural state of government is to be less trustworthy than a corporation despite reality showing otherwise time and time again.
Ironically, for a lot of industries they're better off just giving it the see-no-evil-hear-no-evil-speak-no-evil treatment and ignoring that those numbers can/will be stolen.
It's a little bit like the opposite of the way everyone is doing facial recognition and biometrics these days - plausible identifiability, when it's to their interest not to notice that the person doesn't match the id.
Interesting - has anybody been vigilantly documenting this transition and its impact for consumers?
Have a link handy?
I've certainly noticed it in the common vernacular, but I haven't yet really considered what it means for bottom lines.
Do you some references or citations you could share about such a development? This is the first I have heard about this. Who is the "they" here? SEC? Banks? Lawmakers?
There is massive infrastructure built entirely around the use of SSN as the sole and final arbiter of who is who. You can change your social, yes, but many many systems ignore that entirely because it's for the part rare and something that happens 0-1 times in a person's life.
The government cannot just say "hey that whole SSN thing yeah we're not doing that anymore" without a decade or more of lead time. Companies like Equifax and other not-quite-as-dumpster-fire ones who rely on something like SSN can't just create their own and can't just use everything but.
It needs to change but it will take years if not decades to fully extricate it from the system, and that's if the government decides today that it needs to be done, which itself isn't clear right now.
The government itself has done it, certain parts at least. It took fewer than 10 years. Do you think the private sector would be slower than the public sector?
[$_] http://dpcld.defense.gov/Portals/49/Documents/Privacy/SSNRed...
Something seemed odd to her, called the police and established that no one by that name worked for them, may have dodged a kidnapping attempt.
To make an incoherent and possibly bogus story short: this felt to me like a possible outcome from the Equifax data breach. Random stranger knows your (previous) address, knows what you do for a living, knows your phone number. There could be even worse outcomes than identity theft from this.
Thanks to this breach, the only defense against someone getting my social security card fraudulently is that it has to be mailed to my current address.
Brian Krebs did a good article on the process placing a freeze on your file [1]
[1] https://krebsonsecurity.com/2015/06/how-i-learned-to-stop-wo...
Equifax market cap is currently $13.5B. Corporate death penalty would hurt owners of that stock, maybe funds in your own 401K account. Thousands of people would lose their jobs.
Would it have a preventive effect? Maybe but doubtful. There are too many systems with too much data that are too old and too interconnected to think that it's even possible to secure them all. If it wasn't Equifax it would have been someone else, eventually. Most of what Equifax exposed was probably already exposed in other leaks anyway.
Better solution should be developing new, secure methods of proving identity, where leaks don't matter because it's not possible to leak anything of value. All the old ways are now forever broken.
That they've managed to schmear consequences of that explosion across society is a pretty circular reason for not damaging them.
How does that get us any farther with the fundamental problem of how to prove identity when all the old schemes have been rendered useless?
There's a revenge or punishment piece that maybe is necessary and appropriate, but it doesn't solve any of the real problems we now face.
And just because it's too late now doesn't mean the law can't be adjusted to prevent it from happening in the future. If you don't learn from mistakes, that's dumb. And obviously companies can't be trusted to do it themselves.
If the consequences of losing our data was high enough, more money would be spent protecting the data. Which I think is one of the good things for GDPR, it has stiff penalties and one of the considerations for the fine is negligence.
Equifax is probably going to end up making more money now because of the breach as more people now need "better" identity verification - a service that Equifax conveniently provides.
When are we as a society going to say enough is enough and take power back from these evil entities?
[Yes, I do consider them to be evil]
Capital punishment is meant as a deterrent, not a preventative measure (well, really, it's revenge for the mob) and so it could potentially work much better with corporations than with individuals.
Data breaches are only preventable when you have an inhumanly good security team. This is mot even possible for your average non-technically-inclined business leader.
Why don’t I have any say in all my financial transactions and “passwords” being sent to and vacuumed up by tech ologically incompetent, undeniably unethical bureau-corps?
It’s what I found so refreshing about Monero and other cruptocurrencies when I still used them (took a break from the scene). No one can steal your identity or your money withhout you yourself making a mistake.
By giving equifax the death penalty, future shareholders should choose between competitors, including on who will do the better job with accuracy and data security.
The privacy angle is minuscule compared to the human costs of not having consumer debt.
> The privacy angle is minuscule
It is infuriating to see the suffering of the individual victims of identity theft dismissed so cavalierly. If the credit reporting companies had to pay for all the harm they cause they would be bankrupt many times over.
Even if credit rating serves a purpose, how does the system get reformed to bring true redress to those negatively affected by it?
Having grown up in a credit-averse and cash-focused society, I don't think they're that necessary. What people do instead in build a relationship with your local bank. Of course, once you're used to a credit-driven society it's hard/impossible to go back. People apparently hate being told "No you can't afford that new car".
In my twenties when I left the military I lost the ability to pay back my debts. It took me some 9 years to decide to clean up my credit. Living without a credit score is absolutely possible right now.
- Credit existed before reporting agencies
- It's possible to verify creditworthiness without a reporting agency
- Reporting agencies aren't particularly good at their job anyways
You may dislike the first two arguments, because obviously they make debt more expensive. I don't think that's the worst thing in the world. So, I'll focus on the last point.
Credit reporting agencies often have incorrect info. Here's an FTC study that says one in five have wrong info that was corrected. [0]
You may argue that I should use the other number, ie. people who still had errors after fixing it: 2.2%. But, it oftentimes by the time you fix an error, the opportunity to get the thing you want (ie. job, apartment, car, house, etc) has passed.
But even if the data was correct, the way they generate the score manipulates people into taking on more debt than they should and take on worse debt.
Getting and using one or more credit cards is the easiest ways to improve your credit score, and this is honestly bullshit. Credit cards encourage bad spending habits and trap people in debt. The credit card companies rely on people carrying a balance and a really good way to make that happen is to make sure everyone uses their credit cards for everything.
Meanwhile, things that should improve your score often don't. For example, rent and utility payments only count if they are reported and a lot of landlords or companies don't report or only report if you don't pay.
Maybe it's not the credit reporting agencies' problem if people don't report good behavior. And, I don't know what efforts they've made at getting more people to report. But my bias tells me that they probably just don't care.
[0] https://www.ftc.gov/news-events/press-releases/2015/01/ftc-i...
>- It's possible to verify creditworthiness without a reporting agency
Absolutely, it was called "whether the banker knows you from church as a good Christian man".
That said, I'm not sure a world without consumer debt would be that much worse.
1. Prove you meet the conditions for changing it (you must show proof of identify _theft_ and how it disadvantages you)
2. Show up at an office, in person, with original documentation.
Sounds like a great startup idea: make fixing 143M citizens' identities as easy as ordering a pizza. Or create the Uber for people who will stand in line for you at the Social Security office.
[1]: https://faq.ssa.gov/link/portal/34011/34019/Article/3789/Can...
If you have someone's SSN, you can pretty easily deduce what city they were born in unless they are very young (they switched this process recently).
The leak of this data basically enables a denial of service attack against parts of the economy dependent on personal identity.
I know this is somewhat off point, but there's a https://en.wikipedia.org/wiki/Fallacy_of_division happening here when considering risk - individually, my chance of impact is low (I think?), but as a society, the risk of impact is very high.
I think that makes it worth replacing everyone's SSN, at a minimum.
Any time there's a privacy issue nowadays, I like to play "What if GDPR?" GPDR would have required this document be filed to the relevant authority in three days (Article 33). And the work to compile this document would have mostly been front-loaded by complying with the documentation requirements in Article 30. I don't think GDPR would have made a direct impact on preventing the breach (other than maybe causing someone to look at the towering pile of paperwork and consider thinking of the data as a liability), but affected users would have been much better prepared to know how they might have been affected and how to respond.