Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Jimbo101

(776 posts)
Fri Sep 8, 2017, 11:52 AM Sep 2017

Amateur Equifax Respsonse ,....

According to an article at ARS Technica

,...the website www.equifaxsecurity2017.com/, which Equifax created to notify people of the breach, is highly problematic for a variety of reasons. It runs on a stock installation WordPress, a content management system that doesn't provide the enterprise-grade security required for a site that asks people to provide their last name and all but three digits of their Social Security number. The TLS certificate doesn't perform proper revocation checks. Worse still, the domain name isn't registered to Equifax, and its format looks like precisely the kind of thing a criminal operation might use to steal people's details. It's no surprise that Cisco-owned Open DNS was blocking access to the site and warning it was a suspected phishing threat.

Meanwhile, in the hours immediately following the breach disclosure, the main Equifax website was displaying debug codes, which for security reasons, is something that should never happen on any production server, especially one that is a server or two away from so much sensitive data. A mistake this serious does little to instill confidence company engineers have hardened the site against future devastating attacks.

It was bad enough that Equifax operated a website that criminals could exploit to leak so much sensitive data. That, combined with the sheer volume and sensitivity of the data spilled, was enough to make this among the worst data breaches ever. The haphazard response all but guarantees it.

9 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Amateur Equifax Respsonse ,.... (Original Post) Jimbo101 Sep 2017 OP
Worse, clicking the link to sign up for protection MineralMan Sep 2017 #1
I've tried their website to see if I was affected.... MLAA Sep 2017 #2
I refused to enter any info and simply left the web page. I fail to understand why... hlthe2b Sep 2017 #3
Go to Equifax, TransUnion and Experian and FREEZE your credit. CurtEastPoint Sep 2017 #4
+1 dalton99a Sep 2017 #5
Thank you customerserviceguy Sep 2017 #7
There is only one solution to this: customerserviceguy Sep 2017 #6
Stuff like this make me glad I'm poor and insignificant. panader0 Sep 2017 #8
Another problem with www.equifaxsecurity2017.com/ oppressedproletarian Sep 2017 #9

MineralMan

(146,286 posts)
1. Worse, clicking the link to sign up for protection
Fri Sep 8, 2017, 11:58 AM
Sep 2017

takes you to a third party website. I demurred on that. It's a very, very clumsy way to handle this, indeed.

MLAA

(17,277 posts)
2. I've tried their website to see if I was affected....
Fri Sep 8, 2017, 11:58 AM
Sep 2017

But after the I am not a bot test it just stalls. Anyone else have this problem? I am using my iPad.

hlthe2b

(102,225 posts)
3. I refused to enter any info and simply left the web page. I fail to understand why...
Fri Sep 8, 2017, 11:59 AM
Sep 2017

after the uproar towards Target's comparatively brief delay in notifying customers of a breach that was far less significant in terms of information accessed than this, that Equifax is not getting absolutely roasted. Where is the uproar? They learned this more than a month ago!

CurtEastPoint

(18,639 posts)
4. Go to Equifax, TransUnion and Experian and FREEZE your credit.
Fri Sep 8, 2017, 12:53 PM
Sep 2017

Unfreeze if you are applying for credit. THis way no one can open crap in your name.

Start here: http://clark.com/personal-finance-credit/credit-freeze-and-thaw-guide/

customerserviceguy

(25,183 posts)
6. There is only one solution to this:
Fri Sep 8, 2017, 01:46 PM
Sep 2017

Destruction of Equifax.

Let Transunion and Experian see what will happen to them if they fuck up badly. Credit bureaus have the most sensitive information on people, it should be protected at least with military-grade security. Also, you can have redundant layers of security to require several people's usernames and passwords to be able to get at information.

How can we accomplish this? I'm going to write to every one of my creditors and practically demand that they do not send information to Equifax, nor should they ever pay Equifax for a credit report ever again. If we can turn this into a movement, it will be unstoppable.

Creditors bear some of the heaviest costs of cyberfraud, as most consumers are protected from it by probably law, and at least customary practice. Creditors have every reason to punish Equifax for having lax security, and if together we drive them out of business, it will surely be a wake-up call for the other two bureaus to spend whatever it takes to stay in business.

I strongly suggest that any Facebook posts, Twitter tweets, or other electronic communications be as devoid as possible of political language, this is an issue that hits all of us, whichever way we vote. I hope somebody's started a petition with the White House to have Trump see this and get a bit of outrage for it, face it, every silly ass thing he says gets press coverage, whether it's deserved or not.

9. Another problem with www.equifaxsecurity2017.com/
Fri Sep 8, 2017, 07:19 PM
Sep 2017

I was just reading about (sorry don't remember where). Apparently buried in the fine print, is a provision that by accepting the free credit monitoring one agrees to arbitration and gives up their right to participate in any class-action suit. Maybe they have changed this by now but don't know.

Also the article pointed out that 1 year of credit monitoring is not enough.

Besides freezing your credit, one can also get a free credit report from each agency once a year--spread out every 4 months-- thus doing your own "credit monitoring" (of a sort).

Latest Discussions»General Discussion»Amateur Equifax Respsonse...