Equifax can't seem to get anything right. After exposing the personal information of potentially 143 million Americans to hackers,Brother in law Who Gave His Sister in law a Little Sex Education the credit reporting agency is under fire yet again for the way it attempted to secure the credit reports of those affected. It turns out that process, too, was vulnerable to cybercriminals.
Now, the company is scrambling to fix what can only be called a bungled response to the data breach. For some victims, it might even be too late.
SEE ALSO: Twitter is *not having* Equifax's response to that massive hackThe problem lies in how Equifax went about implementing credit freezes — something consumers worried about identity theft and fraud should implement. Essentially, if you request a credit freeze, Equifax will no longer send out credit reports to those who request it. That means if someone tries to open up a credit card in your name, the issuing bank won't be able to get a hold of your credit report. As such, they will deny the fraudulent application.
But what happens if and when you decide that you need a new credit card? Well, then, you simply put in an unfreeze request and validate that it's actually you (and not the aforementioned criminal) with a PIN provided by Equifax. Except, here's the thing: The PIN wasn't randomly generated. Instead, it was a timestamp based upon when you asked for the credit freeze.
And you guessed it: those PINs are vulnerable to being brute-forced by hackers.
This Tweet is currently unavailable. It might be loading or has been removed.
In other words, if someone had your social security number and tried to do something shady — only to find your credit was frozen — they could unfreeze it by guessing your PIN. Not too hot, right?
This Tweet is currently unavailable. It might be loading or has been removed.
The company is taking a lot of criticism for this online, and a spokesperson told Ars Technicathat it would change the process by which PINs are generated.
"While we have confidence in the current system, we understand and appreciate that consumers have questions about how PINs are currently generated," explained the spokesperson. "We are engaged in a process that will provide consumers a randomly generated PIN. We expect this change to be effective within 24 hours."
But what if you already received one of the shady PINs? Well then, you can request that Equifax change your existing one. Which, considering how badly the company has handled pretty much every aspect of this breach, is sure to go over flawlessly.
Topics Cybersecurity
Reddit and Pornhub hosted RussianBusinessman wins his 'right to be forgotten' from Google in UK courtPeople are grateful Mariah Carey is opening up about her experience with bipolar disorderSamsung CHG90 49Just a really lovely collection of beautifully imperfect medieval manuscriptsAfter 14 years, Steam gets some decent privacy settingsZuckerberg says Facebook won't comply with ICE's 'extreme vetting'Google will introduce selfReview: 'God of War' is a superb game, equal parts fresh and familiarAhead of GDPR, Messenger reminds users to check their privacy settingsMark Zuckerberg claims ignorance of soI wrote the Facebook report Ted Cruz can’t stop talking about. He’s getting it all wrong.Just a really lovely collection of beautifully imperfect medieval manuscriptsWoah, Tom Hardy is completely unrecognisable as Al CaponeAdam Rippon, Tonya Harding join 'Dancing With the Stars: Athletes'We'll never trust our 'friends' ever again after they sold out our Facebook dataReddit and Pornhub hosted RussianTesla clashes with NTSB over fatal Model X crash investigationAndroid P is probably going to copy the iPhone X's gesture controlsPeople are grateful Mariah Carey is opening up about her experience with bipolar disorder HTC now offers a souped up U11 flagship with 128GB of memory and 6GB of RAM Creepy video supercuts Trump and Scaramucci's hand gestures What's coming to Netflix in August 2017 Cersei was channeling her inner Joffrey in this week's Game of Thrones Marine makes bucket list for dying dog who saved his life No, Usain Bolt is not donating $2 million to Grenfell Tower fire victims We got a peek at the world's best airport's newest terminal Leslie Jones live Are we about to reach peak emoji? 'Game of Thrones': Grey Worm and Missandei hooked up After all that, Amazon's Whole Foods deal may be delayed It's Superheroes vs. smartphones at Comic Stage is set for 'Fujiwara effect,' a rare dance of cyclones this week LeBron James's pizza investment nets him a cool $24 million Google tests autoplay videos in search, because we aren't allowed to have nice things 4 ways entrepreneurs can save money without giving up Starbucks Microsoft Paint will soon be no more 'Game of Thrones' Theon isn't brave Mom talks about that heartbreaking photo of her trans son to fight discriminatory bathroom bill 'Game of Thrones' Season 7 scrolls: Read Ser Jorah's letter to Daenerys Targaryen
3.3049s , 8230.734375 kb
Copyright © 2025 Powered by 【Brother in law Who Gave His Sister in law a Little Sex Education】,Miracle Information Network