SIGforum
EQUIFAX Security Breach

This topic can be found at:
https://sigforum.com/eve/forums/a/tpc/f/320601935/m/1290060034

September 09, 2017, 02:36 PM
newtoSig765
EQUIFAX Security Breach
quote:
Originally posted by ensigmatic:
newtoSig765 and any others who are interested: Here's a site that rates the various "identity theft and mitigation" services: Identity Theft Protection Reviews & Ratings

DO NOT just grab the ratings and run with the highest. Read about how they came to each, then look for other ratings, reviews, customer experiences, etc. Pick a plan that suits your exposure and needs.

Thanks! I'll look at them tonight.

I have not applied for credit in over ten years. Financed a car back then, don't use credit cards, trying to stay out of debt, so I don't know how vulnerable I am. Suspicious by nature, I also am hesitant to ask if I'm on the hacked list, since I may be exposing my data just by asking. I may talk to my bank Monday morning to get their opinion.


--------------------------
Every normal man must be tempted, at times, to spit on his hands, hoist the black flag, and begin slitting throats.
-- H L Mencken

I always prefer reality when I can figure out what it is.
-- JALLEN 10/18/18
September 09, 2017, 03:32 PM
ch3
What do the monitoring companies do when you have a freeze on all three credit bureaus?


NRA Endowment Member
USAF 1958-1970
Master Instructor 1969-1970
Georgia Gun Owners Member
September 09, 2017, 03:34 PM
erj_pilot
I had to kinda chuckle. Equifax's web page wants me to enter the last 6 digits of my SSN to see if I was affected. Uhhhhhh...excuse me. Fool me once, shame on you. Fool me twice......

I just thought it quite ironic to have to enter that data to find out if I'd been hacked. Didn't enter jack sh#t and exited the page. If anyone wants my paltry savings and CC access, they're gonna find a way to get it one way or the other.



"If you’re a leader, you lead the way. Not just on the easy ones; you take the tough ones too…” – MAJ Richard D. Winters (1918-2011), E Company, 2nd Battalion, 506th Parachute Infantry Regiment, 101st Airborne

"Woe to those who call evil good, and good evil... Therefore, as tongues of fire lick up straw and as dry grass sinks down in the flames, so their roots will decay and their flowers blow away like dust; for they have rejected the law of the Lord Almighty and spurned the word of the Holy One of Israel." - Isaiah 5:20,24
September 09, 2017, 03:56 PM
ZSMICHAEL
With all these hacks and breaches, it bothers me that there are those who want our medical records available in the Cloud, or other globally accessible storage medium. Maybe that's already the case and I'm behind the times - but I hope not.
---------------------------------------------------------------------------------------------------
Who knows. Health insurance companies have released plenty of stuff. A defense contractor with Tricare had their hard drives stolen several years ago. Medical records with all identifying data including social security numbers.


Health insurance company Aetna “stunned” some of its customers last month when it accidentally made their HIV statuses visible from the outside of envelopes, two legal groups said Thursday.

The letters, which contained information about changes in pharmacy benefits and access to HIV medications, were sent to about 12,000 customers across multiple states, Aetna confirmed in a statement.

For some of these customers, a plastic window on the envelope exposed not only the patient’s name and address, but also a reference to filling prescriptions for HIV medications. This meant that whoever picked up the mail that day — a family member, a friend, a postal worker — would have been able to see the confidential information, according to the Legal Action Center and the AIDS Law Project of Pennsylvania. It is not known exactly how many customers were affected.
September 09, 2017, 04:00 PM
Phelen_Kell
I'm affected. The last time was the OPM breach.
September 09, 2017, 04:11 PM
DoctorSolo
How do I make sure I get in on the class-action lawsuit?
September 09, 2017, 04:13 PM
ensigmatic
quote:
Originally posted by Ackks:
quote:
That's what it does, all right. Now imagine what happens when a prospective lender tries to perform a credit check and finds a security freeze on the credit bureau of their choice?

What happens?

If they cannot get a credit report it's unlikely they'll extend the credit. Particularly when they're told "Nope. Can't have it. Security freeze."



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher
September 10, 2017, 10:14 AM
joel9507
quote:
Originally posted by ensigmatic:
Not unless they can get to the PINs needed to unfreeze them, which are stored in my encrypted keyring.

Brings up an odd thought. They have to store the PINs somewhere on their side (to know when someone puts in the right one)....right?

So either, a) the PINS are as much at risk as the other stuff, or

b) the PINs are stored somehow more securely than the data that got hacked (in which case, why didn't they use that approach on the other information?!?)

Neither alternative makes makes me feel better, somehow.
September 10, 2017, 10:20 AM
Pipe Smoker
^^^^^

It's more likely that they store a hash of the PIN.



Serious about crackers
September 10, 2017, 10:28 AM
xwesler
"Based on the information provided, we believe that your personal information may have been impacted by this incident."

Ahhh crap.


----------
The first 100 people to make it out alive...get to live.
September 10, 2017, 10:58 AM
Spokane228
Froze all three this morning. Coincidentally, I was thinking about doing this last month because I was getting annoyed with paying for credit monitoring every month.
September 10, 2017, 11:20 AM
wrightd
credit freeze has always been more effective than monitoring, the latter only reports it, the former prevents it. I don't think much is truly secure anymore, except perhaps secret military communications. But we probably wouldn't ever hear about a breach like that anyway.




Lover of the US Constitution
Wile E. Coyote School of DIY Disaster
September 10, 2017, 01:12 PM
JALLEN
Not long ago, I was on the phone with Schwab.

The rep proposed I use the voice identification system they have which identifies a customer by voice. I was assured it is very secure, works even when hoarse, can't be fooled by Rich Little type characters.

Any merit to something like this?




Luckily, I have enough willpower to control the driving ambition that rages within me.

When you had the votes, we did things your way. Now, we have the votes and you will be doing things our way. This lesson in political reality from Lyndon B. Johnson

"Some things are apparent. Where government moves in, community retreats, civil society disintegrates and our ability to control our own destiny atrophies. The result is: families under siege; war in the streets; unapologetic expropriation of property; the precipitous decline of the rule of law; the rapid rise of corruption; the loss of civility and the triumph of deceit. The result is a debased, debauched culture which finds moral depravity entertaining and virtue contemptible." - Justice Janice Rogers Brown
September 10, 2017, 01:25 PM
ElToro
Apparently if you put your 6 digits in to see if your affected you waive your right to sue. Read the fine print. Thankfully my wife and I were not affected.


https://www.bloomberg.com/news...o-arbitration-clause
September 10, 2017, 01:37 PM
ZSMICHAEL
quote:
The rep proposed I use the voice identification system they have which identifies a customer by voice. I was assured it is very secure, works even when hoarse, can't be fooled by Rich Little type characters.



Hmmm. How about a recording of your voice?? I am always skeptical of these things. I do not know in this instance, but any system designed by man can be defeated. I am sure some tech savvy folks here will have a better answer.
September 10, 2017, 01:51 PM
radioman
quote:
Originally posted by DoctorSolo:
How do I make sure I get in on the class-action lawsuit?


Hint, wait for the class action people to do all the footwork, and then sue them as in individual, using their footwork as evidence and precedence.


----------------------
Let's Go Brandon!
September 10, 2017, 01:53 PM
radioman
quote:
Originally posted by ElToro:
Apparently if you put your 6 digits in to see if your affected you waive your right to sue. Read the fine print. Thankfully my wife and I were not affected.


https://www.bloomberg.com/news...o-arbitration-clause


Oh, good luck proving it was me who agreed to this, being how the information is "out there."

VPN and all, could have been anyone Wink


----------------------
Let's Go Brandon!
September 11, 2017, 11:19 AM
Pipe Smoker
As of a couple of minutes ago, Eqifux stock is down an additional 5%. Hope that it tanks completely.



Serious about crackers
September 11, 2017, 11:22 AM
sigmonkey
New merger coming; EquiFargo




"the meaning of life, is to give life meaning" Ani Yehudi אני יהודי Le'olam lo shuv לעולם לא שוב!
September 11, 2017, 11:47 AM
BamaJeepster
quote:
Originally posted by radioman:
quote:
Originally posted by ElToro:
Apparently if you put your 6 digits in to see if your affected you waive your right to sue. Read the fine print. Thankfully my wife and I were not affected.


https://www.bloomberg.com/news...o-arbitration-clause


Oh, good luck proving it was me who agreed to this, being how the information is "out there."

VPN and all, could have been anyone Wink


Equifax has removed that and explicitly confirmed that it does not apply.

quote:
We’ve added an FAQ to our website to confirm that enrolling in the free credit file monitoring and identity theft protection that we are offering as part of this cybersecurity incident does not waive any rights to take legal action. We removed that language from the Terms of Use on the website, www.equifaxsecurity2017.com. The Terms of Use on www.equifax.com do not apply to the TrustedID Premier product being offered to consumers as a result of the cybersecurity incident.

https://www.equifaxsecurity2017.com/



“Facts are stubborn things; and whatever may be our wishes, our inclinations, or the dictates of our passions, they cannot alter the state of facts and evidence.”
- John Adams