Identity thieves bypassed Experian security to view credit reports
krebsonsecurity.com
krebsonsecurity.com
Oh wow, that's one of the dumbest security hole I've seen so far. That means you're either authenticated in the first screen, or the second assumes that you are whom you say you are if you lend on it. There's a clear lack of ethics from whomever built that, whom either didn't care, or didn't know enough know enough to excuse themselves from building it and ask for assistance.
I mean, this is not your regular system. Everyone is in there, not that they have much of a choice, and it's their most sensitive data, that you decide you're up to the task to protect.
I'm all for learning from your mistakes and I'm the first one to screw up once in a while, and to admit that I am not a security expert. But the size of this combined with how freaking dumb this issue is... This is most likely gross negligence. In most of other industries where people call themselves engineers, you would be putting your own professional reputation on the line when deciding you're up to the task. Then you would get in front of am ethics commission and likely get your license suspended or revoked.
If you look, you see it everywhere. When stack-exchange rolled out their CV feature they had a similar thing which leaked everyone's email address regardless of the public profile visibility or whether they had even used the CV feature.
Maybe originally the code had multiple levels of authenticating the user: 1) we know who you are, but you haven't proven it yet, and 2) you've proven it, now you can see everything.
But when they integrated with a 3rd party, which could have been a decade or more after the original code was written, some developer who didn't understand the code just lumped everyone who came over from annualcreditreport.com into basket #2, even though that user still had to go through the url flow to prove themselves. Just a guess.
I don't think most non-programmers realize how often preventing this kind of thing comes down to one developer making a stink repeatedly to indifferent higher-ups. If that one developer is incompetent or doesn't care, no one else does.
So much effort is put into checking that people are who they say they are (is Person X really Person X) , they forget to check that they're authorised (is Person X actually supposed to be accessing resource Y).
Given the URLs don't have the actual resource Identifier, it means the resource ID will have been gathered from somewhere else, typically one of three places:
1. Cookies / Localstorage - Easily manipulated and should never be treated as a secure place, it's easy to put simple values here and forget that they still need to be validated / checked server side, and that just because you have access to /foo/Y you might not also have access to /bar/Y.
2. Session - An ASP favourite, sticking something in a key like Session["FolderID"] you might assume you've validated and checked authorisation when you set the key, then later re-use (deliberately or accidentally) the same key elsewhere leaving it open for manipulation. And then you might assume you don't need to re-check authorisation when you read the key.
Probably just a lot more inexperienced developers treating it like a magic authenticated bag without enough warnings about improper use in the documentation.
Also a very easy "go to" store via global variable in ASP made it especially easy to use it as a go-to solution for anything that you couldn't be bothered to properly store.
That way no developer can come along five years later and accidentally grant the wrong access level or show the report to a not fully validated user. Put the security check on or as close to the thing being accessed as possible.
BOLA: Broken Object Level Authorization
IDOR: Insecure Direct Object References
[0] https://www.wallarm.com/what/broken-object-level-authorizati...
Backend does not understand what frontend looks like, does, or even supposed to do. Data team just wants to make sure stuff is mapped and goes where it is supposed to go without breaking anything. Nowhere there is a person who is responsible to say 'the fuck yo'.
Places which treat security as an audit checkbox are going to try to outsource that work to save money and they're going to get people who have enough skill to run a few basic tools but not to reason about the results or do anything creative. Experian seems highly likely to be on that side since they've been able to avoid any significant penalties for past negligence.
Even simpler, this would be prevented if /acr/oow set a decryption key as a cookie after validating the verification data that was then used by /acr/report to decrypt your credit report.
[1] Yes, it's possible to enumerate over all user's security answers, so it's not perfect, but it ensures a simple mistake with an if condition, doesn't release everyone's data.
I never really understood how they could take my information, which presumably belongs to me, and then could use it to make millions. How about my cut?
I'm not saying that I'm happy about the current state of affairs where we are spied on and sold and resold, but I just wanted to clarify that it's not so simple as you make it out to be that each person owns all information about themselves.
It is an accurate take. The problem starts when the gathering becomes an industrial level process and start charging money for it.
I am almost at a point, where I pray for a Target level breach that somehow involves the 3 bureaus. Maybe then other entities start suing one another over fallout. Until then it is just 'swy'.
I highly doubt that Experian attracts the best and brightest. And when you have a company that doesn’t provide any features to the consumers whose data they collect, control, and sell except when sued, you get stuff like this.
They won't regard accessing credit files in this way as a security / privacy issue, but merely a billing issue.
I got job offer and told recruiter to put in writing that my payroll data will not be released without a court subpoena. Am waiting on response from recruiter. My outlook is that HR does not care about employees if they purposefully leak this info.
Those concerned may want to ask their HR about payroll data sharing.
https://www.experian.com/consumer-information/employment-inc...
Curiously, Stratfor also predicted 60% chance of the US going to war with the EU before 2036, due to EU privacy regulation threatening to shut down the increasingly adtech-based US economy.
Doesn't this kind of demand usually just result in you not getting the job?
It was sadly before my tenure at the company and I only became aware of it much later, but I would not be surprised if agencies are leveraging their other produces to incentivize more companies to share this salary data.
In the meantime I'm going to continue exercising CCPA wherever I can and hope we see some legislation or court cases at the federal level to address some of these issues.
The only real way around this is having shareholders that care about employee privacy, and I think _that_ will only happen if these privacy issues impact the bottom line in some way (difficulty hiring, increased costs, etc).
It's frustrating in that this behavior is cultural and endemic to how businesses operate in the US. Change is possible, but it requires support from more than just the line of business employees and management.
Yea, sure. I wasn't meaning to take a hard moralist or anti-system stance, when I say "the company is greedy" I understand the company and its people are a cog in a larger machine.
There is a simpler way out than waiting for a cultural change to stop that practice, though: regulation.
I'm not entirely sure, but I doubt that here in Europe it's so easy for companies to sell payroll data - if at all legal. At any rate it sounds like an abhorrent practice.
There's a lot of mythology around that, however: managers are giving a large amount of discretion about business decisions because it's extremely rare that there are no trade-offs for any decision. For example, you could save a lot of operational hosting expense by switching from AWS to Bob's Bait Shack and Server Farm. In this case, you could argue that the risk to employees is significant and would potentially spill over to the company if leaked information was used to compromise them.
We use them as a provider (unfortunately), and when they don't have the data on hand we have to handle cases where it can take a few days for them to call the business and confirm employment directly with someone who works there. At that point, I don't think where you work has a reasonable expectation of privacy since you walk there, probably put it on your LinkedIn, talk about it with friends/family, etc.
I stopped doing that when LinkedIn added their loginwall.
Clearly LinkedIn wants to harvest data while at the same time making it difficult for others to do so, which would go against my interest of making it public.
So I posted it on my own website. Goodbye to another centralized point of failure/control.
>it can take a few days for them to call the business and confirm employment directly with someone who works there
If you hire out this kind of work, half the min wage slaves getting screamed at with hot breath down their neck for "low productivity" are gonna call once at most and likely not at all and then check it off. Speaking as someone who has worked at a call center along with the populace which was basically people on work release/probation.
They'll just toss your application out without a human ever seeing it. You're clearly a noncompliant troublemaker and not worth hiring.
Equifax/TWN has a brilliant business model that should be illegal. Get paid to collect data, then resell it.
If there was any justice these companies would get the corporate death penalty.
I was happy and secure in the knowledge that it was locked until I had to unlock it the first time. The password I set didn't work, as they had apparently changed the log-in system with no alert (also, now the stupid log-in sends us spam e-mail that we can't opt out of).
I called them. I had my account unlocked, and the phone representative even gave me my own SS# within three minutes of being on the phone, and by answering questions that were publicly available information.
It's an absolute fucking train wreck and I wish the system as a whole and the credit companies in particular were destroyed.
The 3 questions fraud check system everyone uses to performatively pretend to ensure you are who you are, can only draw the questions it asks from — guess what — publicly available information.
It's illogical on its face.
// After identity theft, it gets worse, as thieves' fraudulent or real data will enter public records under your identity key, and now you can't pass your own check.
Would suggest replacing this in your vocabulary with “fines,” “license revocation” or “criminal penalties.” Corporate death penalties, i.e. judicial dissolution or charter revocations, while a good slogan, don’t make a lot of legal sense. As a result, I’ve found it in practice used to segregate activism and turnout operations (who like it) from rule and lawmaking influence (where it’s not a serious concept).
Massive fines, equal to market cap, or absolute liability, e.g. a $10k + legal expenses minimum owed to each person whose data leaked irrespective of actual damages, for example, are more specific and actually actionable.
No violence should be involved. Large layoffs resulting from that won't be pleasant one bit though.
Corporations are a legal fiction. What does dissolving the corporation mean? Revoking its charter? Then what happens to its assets? If you return them to shareholders, you’ve given a boon to its wealthiest, who can now re-organise it free of prior liabilities. If you liquidate them, you’ve delivered a junior fine, since with real fines the fine gets paid before creditors. If you take it, you’ve expropriated (also, fines with extra steps).
In every case, what you want from a “corporate death penalty” is better effected with actual penalties. A market-cap sized fine is more specific and more actionable than a “corporate death penalty,” which is why I suspect the latter is in circulation.
And sometimes these are bad and need to be dissolved.
Take everyone's favorite whipping boy, Facebook/Meta, as the example corporation. At every turn, they have shown that they have prioritized greed vs community good. Any good they provide is only to further their pursuit of wanting more. Because they are so large, any upstart competitor with a total opposite ethos that might come about gets annihilated by the behemoth.
If legal action were to give Meta the corporate death sentence preventing the company from operating and its execs from pivoting to somewhere else, then and only then could the competitors actually have a chance. So just because there's a death sentence for a corp doesn't mean the "people" lose as well.
Just do the second bit. The problem with judicial dissolution is corporations are a legal fiction. What you do with the people and assets is far, far more important. Ignoring the legal fiction to focus on those is my point. Take their stuff (fines). Force them to restructure (break-up). Limit their scope (corporate criminal penalties). Restrict their executives. “Corporate death penalty” is exactly non-specific enough to avoid specifying those prescriptions.
i don't think it's nearly as non-specific as you think. if you ask people what a corp death penalty would be, my assumption would be that people would think of it as the corporation no longer existing. if you're saying that corps would just spin off assets as a new name, new corp charter, same people, same processes, then yes, that would be a valid concern. but we can at least state that once, and all agree upon it rather than continuing to repeat it like we're unable to understand the concept.
I mean, look at this thread. I’m not saying the impulse is wrong. But “corporate death penalty” seems to be a good way to take a discussion which could lead to an outcome into one that won’t. That’s fine! People vent! But we shouldn’t confuse venting with deliberating.
I agree that there's an element of pedantry there, so if (as the GP suggested), someone is just venting and doesn't care about a specific outcome, saying "give them the corporate death penalty" is fine. But the downside is that if someone reads that, and looks up legal corporate dissolution, they might get the wrong idea that this sort of remedy will actually fix the problem. Or they might not even do any research, and just decide to start throwing around this term themselves, without really understanding what it means or what it does (and doesn't) accomplish.
But I also agree that listing out other specific remedies (market-cap-sized fine, jailing executives, whatever) is long-winded and annoying, and maybe not really useful or relevant unless the discussion is actually about what specific remedies might be effective.
If the fines are < the advantage to scoff the law, such a fine just puts a price tag that can be used in a cost-benefit calc for the company.
(1) Dissolution as a viable entity in the US
(2) All assets sold paid out to wronged parties before debt servicing or shareholders
(3) All officers barred from holding political, non-profit, or corporate office at any level in the US states or territories, as well as removing the veil of corporate liability from officers. All technology and security employees have liens put in place to pay affected parties as well.
When we mean death sentence, we mean it.
A strawman: Maybe proportion of ownership times current assets and all future income. Whatever fraction of their financial being is proportional to their share of the corporation is "dead".
If you have X% ownership share, you are fined X% of all your current assets and X% of all future income.
A message needs to be sent that it's not okay to invest in a company that is doing harm and then walk away from it. You're ethically and morally liable, the law should reflect that.
As with a couple of other things, it's basically the only developed country with this model (useless for-profit middlemen for no good reason), it really sucks for the average consumer, yet there is no actual change coming. Why? Is it American exceptionalism refusing to acknowledge that there are better ways used elsewhere? Is it free market "absolutism" hoping the market will fix itself?
Neither free market absolutism nor exceptionalism are the reason that it's designed this way. At least, not in the way that I think you mean it. Rather, it's because the current economy of the USA is an inflationary credit economy. It's a very un-free market; a great example is education. The government subsidizes loans which drive up the price, and put people in debt so that they are more desperate to take jobs.
Sure, some Elon Musk guy might have enough credit worthiness to make a $44 billion purchase. But are _you_ Elon Musk or just some guy impersonating Elon Musk? Fraud may not be rampant enough currently but if Experian/etc continue to help fraudsters it will just keep getting worse.
Only when it drops off your report, which is 10 years after you pay it off.
If you were so concerned about having a line of credit on your record then open up a credit card and don't use it, no reason to pay thousands of dollars in interest to avoid an abstract fear of "tanking your credit score."
>it really sucks for the average consumer, yet there is no actual change coming
I am an average consumer. The credit system is great for me! I'm able to demonstrate my responsibility and as a result I'm able to obtain a large amount of credit products at very low cost as well as pay less for insurance. I guess you can argue that the government should be providing this service rather than private companies or there should be more regulations around security, but the system only "really sucks" for people who take out loans and don't repay them.
Rocket mortgage fraudulantly tanked our credit score and refused to fix it. The other bank's underwriting department looked at it, shrugged, and honored the mortgage office's request for an override to give us the best available rate.
IMO, Credit ratings are theater.
I know there are contrived ways I could have killed the value of the vehicle before the loan was done and they couldn't recoup it, but like, come on. My credit report was BLANK. It was never needed in the first place.
Anecdotally, neither me nor my partner have a credit score. I know several people where I’m living that are permanent renters/get owner financed loans, buy used cars with cash (or are simply given old cars, or don’t have a car at all).
I did a superficial search and found some census data (https://www.census.gov/data/datasets/time-series/demo/cps/cp...) but I have no idea how to read it.
Edit: Looks like my suspicions have some merit:
> 22% of Americans do not have a credit score. Half of this percentage has a stale credit score that makes it impossible to generate a valid FICO score while the other half do not have any credit file with any of the three credit bureaus—Equifax, Experian, and TransUnion.
> 18% of Americans have credit scores that fall in the 580-669 range of “fair.” those in the fair range are considered sub-prime and have lower chances of qualifying for a loan or getting better interest rates.
I haven't seen what happens at 10 years, but there's definitely an effect after about a year; mine dropped 50 points, which isn't really tanking, but could switch you into a different risk category depending on where you started. Finishing up my car payments didn't help either.
If you actually want to get the score that lenders use, experian.com will give you your FICO 8 score. This score considers all accounts open the same until they have been closed for 10 years.
> The FICO® Score pulled on [date] is the FICO® Score 8 based on Experian data, and is the same score that [name of institution] uses, along with other information, to manage your account.
Another says:
> The score provided here is FICO® Score 8, which is based on TransUnion® data and may differ from other FICO® Scores. Variations may also occur when your score is based on data from another consumer reporting agency or calculated at a different time. [name of institution] and other lenders may use different scores and other information in credit decisions.
I'm not going to intentionally interact with Experian directly, unless I have to, so not going to compare there. From what I recall, when I last opened a loan and they disclosed the scores, they were within spitting distance of what I was seeing from my banks at the time.
Now maybe FICO 8 score means something different than FICO Score 8; these guys like to be deceiving, and maybe some banks give the VantageScore, but mine seem to give a FICO Score 8.
I paid off my mortgage almost 15 years ago. I have zero debt, no car loans or anything, and pay off my credit cards in full every month. My credit lines are barely utilized (single digit percentage.) My score seems to vary from 790 to 810.
If you have no debt and pay cash as you go for your expenses, you will eventually drop because the credit bureaus will have no recent data to compute a score.
Maybe you are indeed an “average consumer” (whatever that means) but if you are, then the credit system is heavily skewed in your favor, with many “non-average consumers” falling by the wayside.
I've always thought the US system was super weird and backwards forcing debt on people. We don't have credit cards from every big chain and don't get harassed into signing up for cards in the mall, it's just not a thing.
We have the same safeguards you have, but we prove it with sensible spending instead of getting debt just to prove that we can pay it in time.
In the US, the loan originators look at year-end tax forms or recent pay stubs to verify income. They look at credit reports from e.g. Experian to verify defaults and other debt information.
This is all open data and can be verified with just a phone call to the tax office and debt authority. Some private aggregators exist for convenience but they're regulated in what they're allowed to share and for how long.
The private companies are also required to notify me anytime someone checks my score, the government agencies aren't.
It's been years since I had my mortgage approved but I vaguely recall the process being very similar.
Because our government is completely corrupt and doesn't represent the interests of the People, at all. It serves and is beholden to large corporate interests, chief among them banks and financial institutions. In a just system that represented our interests Equifax would be forbidden from compiling consumer data after what they did.
Failure of paying back a loan prior - why would I want them as a tenant?
If you had a friend that failed to pay back loans, would you want to make a future loan to them?
But, 24.8% of people who are employed have those permanent contract. People who do not have that, have it much tougher. To get back to the example of renting, landlords in France are scared of renting to tenants who don't pay because it's hard to evict tenants, so they often use something called a "Garantie Loyer Impayé" which is an insurance backed by the government that will pay back any unpaid rent to the landlord. But if you don't have a permanent contract, it's hard to qualify for this. When I was searching for an apartment 7 years ago, 80% of apartments rejected me because I was working as a contractor (and what's worse my income was from another country since I was working remotely). They used that insurance and that means that I couldn't qualify.
So, yes, if you have a permanent contract in France, things are relatively easy but, even then, I have a friend who is black and worked as an electronic engineer with a permanent contract but still had a hard time securing a mortgage because, for some unknown strange reason, he got rejected a lot more than his white friends.
Credit systems with clear rules like the US may be gameable but they have the advantage of actually protecting against racism, of enabling people with non-standard profiles access to credit and of actually being relatively easy to follow.
-USA tax system where Turbofax created a niche for itself and fights hard to keep the system as convoluted as it can be to detriment of everyone
-USA healthcare insurance system where insurance companies do the same
Seems like best way to profit is to become a parasite that does not fix the problem but just defends the current situation.
With a US social security number that I got as a student and good management of my credit card accounts that I kept since, I have a good US credit score and can easily get a mortgage in the US. Of course, it's possible to game it, but you can also get a very decent score by just managing your finances well.
So from my perspective, I think the US system works much better. Does it have issues? Yes, there's data leaks, there is some gaming of the system (by the way, paying off the mortgage won't tank the credit score, it'll lower it yes by a few points, but that's mostly inconsequential)
It doesn't matter what it "should be" proof of or what a reasonable person could infer from this income or documentation of it. If you don't have a CDI, which even many full-time employed people don't, you're in a hard spot.
The US system has issues but it's less broken than every other countries I've lived in.
The idea that everyone is forced to create a public profile so you have the option of getting a mortgage sucks. You have no right to a mortgage at other's expense. If you want folks to trust you, get a co-signer, put down roots and stay a while.
Without a credit score that follows simple algorithmic rules, how do you want to prevent this from happening? A credit score that has rules that people know in advance may be gameable but it also creates fairness by making it easy for everyone to know what to do to get a decent score.
Now, the fact is that the credit score could be managed by government agencies (although honestly, I'm not sure any government is much better in term of data security), there could be stricter fines in case of data breach (that sounds like a good idea), but those are implementation details.
That said, I'd agree that both of our plans could be implemented a lot better.
Being a French national and not being able to get a mortgage to buy an apartment for my mum is also more than a little frustrating. And that's despite having quite a bit of money saved.
I've rented apartments without credit by showing paycheck stubs and bank balance.
Outside of living off the grid, paying everything in cash, how do you want to have privacy about how you spend your money in this day and age?
Bulk surveillance is a problem as well, but a big topic for another day.
I guess where we differ is that between banks having lousy security, social medias and search giants selling all our data, the cat is already out of the bag when it comes to privacy and won't be put back until law is updated to have teeth, so I see that as a separate problem (which does bother me) that's orthogonal to the 3 companies credit scoring system.
That doesn't mean that it shouldn't be solved, I believe Equifax, Experian and Transunion should be heavily fined for any breach of data especially considering how important the data they have.
Do bank savings count for anything?
These are physical documents that should only have power when produced physically. It simply shouldn’t be possible to do anything with just the details or a copy, especially not taking out credit in my name or taking over my bank accounts.
The question was: "According to our records, you purchased or leased one of the following vehicles in the previous year. Which vehicle do you currently own?"
A. Maserati Granturismo
B. Ferrari 458 Italia
C. Aston Martin Lagonda
D. Honda Accord
So... 2 Italian supercars, another supercar with only 200 ever produced, or a mass market sedan.
Bonus - of the 4 questions, you only needed to answer 1 correctly to pass the check.
Yes, but the penalties have to be such that the exec does not simply view it as "cost of doing business" and mark it down as a business expense.
I guess we're arguing for non-financial penalties...
Basically, when it comes to voting, is this going to be the reason why you vote one way or the other? Or is it going to be the usual cocktail of taxes, abortion, immigration etc? If you have an opinion - no matter how strong - but they already have your vote, why should they care about it?
“Identity Theft” blames to the exploiter, instead of the (possibly negligently) exploitable system; it is shifting blame, but not principally to the victim.
> We should instead talk about "Banks being defrauded by criminals due to lax procedures".
If we want to focus responsibility on the banks, we should instrad talk about “Banks failing to safeguard customer funds”, or “Banks enabling criminals to steal customer funds.”
It’s completely upside down. And good luck getting the local police to fix the issue.
Also if you look at your Social Security Card, it states "Not to be used for identification". But Companies, Univ and everyone ignored that because they wanted a Unique Number. Not may people realize the SSN is recycled as people die off.
I wish the US Gov would sue all Companies and Orgs that used the SSN for ID purposes for trillions and return that amount to people with Social Security Numbers.
Unfortunately, we have several anyway, but that’s no reason to accept a universal inescapable federal ID that we would never be able to roll back.
> I wish the US Gov would sue all Companies and Orgs that used the SSN for ID purposes for trillions and return that amount to people with Social Security Numbers.
At least on that we agree. The SSN bas become a poor, backdoor replacement for federal identification documents — which is exactly what people were worried would happen, and why they received the sop of “not for identification”. That didn’t last long:
https://www.nytimes.com/1998/07/26/weekinreview/the-nation-n...
The issuer of an universal ID gains gatekeeping power. Besides the danger of people getting excluded, children and marginalized demographics won't have one.
Ironically widespread deployment of an ID can sometimes lead to more fraud. Bureaucracies tend to confuse identification, authentication, and authorization. Possessing a scan of a passport is often accepted as possessing the passport which is accepted as authority to transact with that name. Through the transitive property possessing a hacked .jpg can allow a fraudster to transact as you. When businesses and bureaucracies are not liable for fraud or their errors, they focus on the ID tokens as a way to improve throughput instead of assessing the legitimacy of the transaction in a holistic manner.
https://www.publictechnology.net/articles/news/government-pl...
Shouldn't Experian have been thoroughly audited by the gov't after the last major data breach? The above sounds pretty out in the open, no?
That sounds pretty unconstitutional. Why would the USG audit a private company for security?
This company needs to be shut down. It's incapable of safeguarding PII in a reasonable way.
Unreal.
I actually wrote to one of the credit agencies a few years ago (forget which one), attempting to get my free report. Three months later, the agency sent me an insane form to fill out to get the report. They also started mailing me ads, telling me how easy it was to obtain my credit report...if I paid them. Nice.
Companies all the time do hard inquiries to access your credit record.
EDIT: don't get me wrong, it's not good this was able to be done. But what's the actual impact though?
At best it implies poor security by the credit agencies might increase the risk that "identity thieves will ruin your financial future" but it doesn't say how access to a credit report will do this.
Guessing: something in the report (what exactly?) might make taking out bogus loans easier by selecting the most vulnerable victims (why?)
I would definitely investigate this further to see if this knowledge was in the hands of criminals/scammers who were selling access for $$ over the past few years.
verifying identity is another matter, but I’d expect what you put on the credit application to be the data that explains the defensible reasons to not give a loan, without needing a magic credit score.
Theoretically they verify these numbers. Otherwise people would lie. Presumably, in the credit score calculation, they also have actuarial tables that allow calculating the odds of delay or default for each person.
To say "identify thieves do this" implies "this is harmful" is a post-hoc fallacy.
And if they don’t, banks and credit reporters don’t get to slander me until the end of time about patently false debts.