Equifax Breach is Very Possibly the Worst Leak of Personal Info Ever (arstechnica.com)
The breach Equifax reported Thursday is very possibly is the most severe of all for a simple reason: the breath-taking amount of highly sensitive data it handed over to criminals. Dan Goodin of ArsTechnica writes: By providing full names, Social Security numbers, birth dates, addresses, and, in some cases, driver license numbers, it provided most of the information banks, insurance companies, and other businesses use to confirm consumers are who they claim to be. The theft, by criminals who exploited a security flaw on the Equifax website, opens the troubling prospect the data is now in the hands of hostile governments, criminal gangs, or both and will remain so indefinitely.
Hacks hitting Yahoo and other sites, by contrast, may have breached more accounts, but the severity of the personal data was generally more limited. And in most cases the damage could be contained by changing a password or getting a new credit card number. What's more, the 143 million US people Equifax said were potentially affected accounts for roughly 44 percent of the population. When children and people without credit histories are removed, the proportion becomes even bigger. That means well more than half of all US residents who rely the most on bank loans and credit cards are now at a significantly higher risk of fraud and will remain so for years to come. Besides being used to take out loans in other people's names, the data could be abused by hostile governments to, say, tease out new information about people with security clearances, especially in light of the 2015 hack on the US Office of Personnel Management, which exposed highly sensitive data on 3.2 million federal employees, both current and retired. Meanwhile, if you accept Equifax's paltry "help" you forfeit the right to sue the company, it has said. In its policy, Equifax also states that it won't be helping its customers fix hack-related problems.
UPDATE (9/9/17): Equifax has now announced that "the arbitration clause and class action waiver included in the Equifax and TrustedID Premier terms of use does not apply to this cybersecurity incident."
Bloomberg reported on Friday that a class action seeking to represent 143 million consumers has been filed, and it alleges the company didn't spend enough on protecting data. The class-action -- filed by the firm Olsen Daines PC along with Geragos & Geragos, a celebrity law firm known for blockbuster class actions -- will seek as much as $70 billion in damages nationally.
UPDATE (9/9/17): Equifax has now announced that "the arbitration clause and class action waiver included in the Equifax and TrustedID Premier terms of use does not apply to this cybersecurity incident."
Bloomberg reported on Friday that a class action seeking to represent 143 million consumers has been filed, and it alleges the company didn't spend enough on protecting data. The class-action -- filed by the firm Olsen Daines PC along with Geragos & Geragos, a celebrity law firm known for blockbuster class actions -- will seek as much as $70 billion in damages nationally.
I was already affected by the US Office of Personnel Management hack, because I needed clearances to get my $55k job doing government IT support in Silicon Valley. It was a small price to pay.
Oh wait.
Equifax Breach is Very Possibly the Worst Leak of Personal Info Ever so far.
The equifax executives apparently sold stock immediately after learning of the breach. Jail them all for incompetence _and_ insider trading.
That company is rotten to the core. They have far too much power over our lives and very near zero accountability for how they handle that power. Allowing those hacks to decide how credit worthy someone is could be one of the worst ideas of the 20th century, and we have unfortunately held on to that terrible idea into the 21st century as well.
Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
We have PCI-DSS for companies that deal with credit card information. Why not for companies that store even more sensitive information that potentially allows a criminal to pretty much take over my life by essentially stealing my identity?
The damage here is way more serious than ANYTHING the loss of a million credit card numbers could mean. Could it be that it's just us that have to foot the bill instead of Visa and Mastercard?
No, that can't be. Government represents the people, right?
Fuckers, I hope some Supreme Court judge alongside of a few congresscritters get hit badly with this breach. I usually don't wish bad things to happen to anyone, but I really hope that one of them has their identity stolen, their credit rating trashed and their life basically ruined by this hack.
Because ONLY then we'll FINALLY see something happen.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Even if Equifax is found to have been careless with all that vital personal information, I doubt they'll get more than a slap on the wrist.
Why should corporations, government or the courts give a crap about people's privacy, when so many of the people themselves very obviously couldn't care less?
I've calculated my velocity with such exquisite precision that I have no idea where I am.
Equifax and the 2 other credit bureaus have a ton of non-credit related information on consumers as well. It will be interesting to see what else was not reported as part of the breach.
I'm going to sound like an old fart, but a lot of these "cyberattacks" end up being down to a very dumb misconfiguration like leaving FTP open, failure to patch security holes, and things like leaving data on unprotected public cloud storage. Part of my job is being a technical mentor to some of our more junior staff, and what I'm seeing is a lot of developers and CS people who really don't know the guts of how IT works. I'm not saying people should go back to punch cards and assembler, but having some clue about TCP/IP, DNS, what an open port on a server means, how a firewall works, etc. would go a long way to preventing some of the dumber things I've seen. Most of this is very much abstracted, and in a "cloud-first" world it's even more so. The network is just assumed to work underneath everything else, and i think this is where a lot of the misconfiguration problems get missed.
We may or may not see what actually happened. It could have been some state-sponsored hacking group planning a painstaking attack requiring intimate knowledge of everything. But knowing what I know about corporate IT, it was most likely some lowest-bidder contractor being forced to pull another 12-hour shift and missing something. Until companies have to actually pay for these issues, all we're going to get is "free credit monitoring" for a year, which costs them nothing, and _maybe_ we'll get a check for 11 cents from a class action lawsuit 20 years from now when it winds its way through the system.
"Three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers." https://www.bloomberg.com/news...
Calvin:Do you believe in the devil? Hobbes:I'm not sure man needs the help.
So, as a result, the US loan industry is going to end their grossly negligent practice of using my Social Security Number as the root password to my financial life, right?
i keep hoping that every single SSN for every american will leak so that the SSN can no longer be used the way it is using now... i wish the breach would be much worse until enough SSNs are available to everyone and the SSN can no longer be used as a personal identifier
I'm sure nobody will be jailed. A fine will be issued, which will be passed off as increased fees to clients. A few buzzwords will probably be thrown around about how amazing their security is now, but probably little will change. 5-10 years from now this will happen again. Maybe not to Equifax, but to some other company that didn't learn from the mistakes of the past.
I realize the SSC is used as a primary key, but if you think about it, to do their job, they could have just stored a salted hash of the social security number along with a plain text full name and address. To find someone, you lookup anyone with a similar name in the database (maybe filtering by address, etc.) and then you take the given social security number and compute the hash for the maybe at most a dozen results until you find the one that matches. Now you still have the ability to uniquely find a record by a social security number, but you never need to store the actual social security number for hackers to steal.
"I have never let my schooling interfere with my education." - Mark Twain
Maybe these types of incidents can break down reliance and acceptance of these credit agencies that have established themselves as critical and non-optional services that heavily effect major life events
But it won't because the institutions that rely on these agencies don't give a damn. They don't lose anything over it. Anything goes wrong and the government will bail them out and leave us holding the bag.
“He’s not deformed, he’s just drunk!”
The breach is annoying. It's also almost an inevitable thing.
Can we *now* start talking about moving beyond "a ten-digit number and some generally publicly-researchable information is enough to do almost anything as you"?
I mean, seriously. Next year will be the 40th anniversary of the publishing of the RSA algorithm. Secure smartcards have been around for 25 of those years, and some countries have been issuing them for 15+ years now. Bit of biometric, and Alice is your digitally-signed aunt.
No... we're still in a country minting pennies and shuffling 19th century bank-draft checks around, aren't we? Oh, and the exact same people who are freaking out about 'Voter ID protects the sanctity of the vote' simultaneously go bat-guano crazy if you propose an actually secure ID card system.
They make money from using our information, provide little benefit to us...
I'll bite. I agree that, as individuals, it doesn't feel like they provide a benefit. But by providing somewhat-accurate financial history to lending institutions, those lending institutions can more precisely estimate the risk associated with each loan. In doing so, they're able to lend more money, and at lower interest rates, than they'd be able to do otherwise.
I'm not arguing that there aren't loads of ways that Equifax et al could improve their business habits. Of course there are. But without these agencies, lenders would have a more difficult time gauging credit-worthiness, and that would mean it would be harder and more expensive for each of us to get a loan. And that, my friend, is the "benefit" provided to us.
Support a few technologists in Washington.
This is a double kick in the nads to anyone who was part of the Home Depot breach, since they were all given a year of premium Equifax credit monitoring.
Stop trolling. This is /.
Only civilized conversations allowed
The one equifax gave me was the same one I use on my luggage!
You are the product. The customers are the banks, companies, and landlords from whom you wish to borrow money or collateral (like a leased car or apartment).
And getting rid of the credit agencies won't have the effect most people seem to think it will. Lenders won't magically assume everyone is credit-worthy if there's no way to check people's credit. They're going to assume everyone is not credit-worthy. In other words, getting rid of credit reports won't make it easier for people with poor credit to borrow money. Nothing will change for people with poor credit. The only difference will be for people who had good credit - all the banks, companies, and landlords will assume everyone has bad credit, and everything will be priced accordingly.
Unless you can prove you have enough money in the bank to cover the loan or collateral. So only the 1% would be able to borrow cheaply. The 99% would have to pay the exorbitant interest rates formerly reserved only for people with poor credit. That is the benefit the credit agencies provide you - giving you (if you're fiscally responsible) access to cheap loans without you having to keep enough money in the bank to immediately pay back the entire loan at any instant. But because people don't like being denied a loan, somehow this default base state (unable to get a loan because the lender doesn't know if they can trust you) got twisted around in people's minds into being a negative. It's not a negative; it's the neutral state. And being able to get a loan after a credit check is not a neutral, it's a positive.
Hackers aren't stealing identity, they are stealing credentials (so as so assume an identity, if the world makes this easy for them to pull off).
Institutions want to pretend that credentials = identity, so that if they give your money to the wrong person, it's your fault (your identity was stolen, what else could we do?) rather than their fault (their chosen system of credentials sprung a leak, causing them to misidentify some loser as the real customer).
Finally, a big enough leak that maybe some people will begin to comprehend the distinction here.
If the government is going to bail them out any time they lose money, their "risk" is exactly zero.
Which is exactly what happens. What are you getting at? Equifax sells snake oil, and make a pretty penny for it. There are suckers at every level.
“He’s not deformed, he’s just drunk!”
One way to protect yourself (to a certain degree) is to put a lock on your personal information with each of the three credit-reporting companies (Experian, Equifax, and TransUnion.) That way, nobody can access your information unless you lift the lock, either selectively, or for a finite period of time. Some of the agencies charge money (typically $10) for such a lock, or to lift it temporarily, but it's worth it IMHO.
If it weren't for deadlines, nothing would be late.
...not perfectly, of course. A previous poster is correct that no system is perfect. But systems that are well-regulated can be pretty good. The airline industry used to drop planes as frequently as we hear about major data-breaches today: like every month. Now it's less than one per year, despite travel having increased over 10 fold.
We could be hearing about 1/100th as many data-breaches, as well. A bunch of financial services would get a little more expensive, but only a little, just like airline fares have not gone out of sight - they didn't even go out of sight after 9/11 when new regulations made flying more expensive. Just not much.
This company has NO reason to spend more money on security next year. Why would they? The actual financial consequences of this event are really quite minor for them. No fines, no lawsuits, and almost no compensation. (The "year of monitoring" will cost about as much as a coffee for each of the 1% that sign up for it.)
If Corporate Death Penalty were the consequence of an event like this, you'd see OpenBSD web sites with custom web servers written to only provide the application; you'd see humans paid to monitor the logs in real time, and more humans to watch them. You'd see the difference between how civilians do things and how the military do things, not caring that they spend a hundred dollars where a civilian would spend five. And you'd see some real results. Right now, failure is not just an option, its the cheaper one.
People prattling on about how "nothing could have prevented this" are exactly like those who said the same about the Titanic - until new regulations that were "utterly unaffordable" the day before Titanic were suddenly gospel: double-hulls were very expensive, watertight compartments that go 20ft above water line, enough lifeboats for everybody, 7x24 ice patrols, 7x24 wireless monitoring on every ship. All of that was "impossible" the day before Titanic. The security equivalent is still "impossible" here, because there is essentially no penalty for failure.
Why was the system with everyone's SSNs connected to internet at all? Why was it not air gapped?! You don't need plaintext SSN included on anyone's credit report, it's only used for authentication (shouldn't be, but too late to change it now I guess). So why not treat it as passwords? As in, properly salted and hashed. And then you don't have to worry about it being stolen. Did they even hire any security experts when designing the system?!
One way to protect yourself (to a certain degree) is to put a lock on your personal information with each of the three credit-reporting companies (Experian, Equifax, and TransUnion.) That way, nobody can access your information unless you lift the lock, either selectively, or for a finite period of time. Some of the agencies charge money (typically $10) for such a lock, or to lift it temporarily, but it's worth it IMHO.
It was... If someone now has every piece of information that Equifax has for you, they can probably lift the lock, as well.
Looks like Equifax's Chief Security Officer Susan Mauldin is unqualified for her position. She doesn't seem to have the necessary education or experience.
You could go to her LinkedIn profile to check yourself. Only problem is she deleted it.
https://www.linkedin.com/in/susan-mauldin-93069a
Thankfully, someone did a screen capture: http://i.imgur.com/QiXX3it.jpg
Unless and until the FTC starts fining these companies large enough fines to cause the execs to take notice, these breaches will continue and only get worse. Security is a process and a breach like this usually required multiple lazy or sloppy decisions just to make the exploit possible. These breaches aren't national state actors writing custom exploits. These are script kiddies trolling for sloppy systems they can exploit. And those systems wouldn't be exploitable by those kiddies unless the engineers and IT folks were being so lazy and sloppy with security. There aren't even good risk reward decision making on these issues. The attitude is if I can save 1 dollar by doing less security, we will. Until fines and criminal charges start becoming a real risk, companies will continue to be breached over and over again.
"Those that start by burning books, will end by burning men."
I guessing, but I bet if everybody puts the 90 day fraud lock on the credit, all of the banks, lending institutions, and money based businesses will really feel the squeeze.
I understand the 90 day fraud lock is free.....
You are being ripped off every second of every day, so that advertisers can help rip you off even more tomorrow.