Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

politicat

(9,810 posts)
3. Well...
Thu Aug 24, 2017, 11:30 PM
Aug 2017

It's not good, but intranet is better than public. That should require a log-in to access.

That sounds more like a white hat notified the SCAO that they had a point of failure.

Your best, most paranoid bet? Do you need any credit accounts in the near future? If so, get them now, and lock down your credit with all three agencies. One of the monitoring services should be fine - life lock, carbonite or credit karma. Call your bank (or go in to a local branch) and any accounts you have, tell them this is a potential security hole, and set up a verbal password. (Since it's possible to gain access with SSN and DOB and some lucky/researched guesses.) Most financial service providers will do this, no problem. Just use a good pass phrase -- 4-6 words that make an image you can remember, like Prefer Cassandra Austen Over Auden or Zebra Implies Stripey Stockings. (Don't use those.) Download a password minder (we use the Safari keychain, Keeper and Keypass; I can recommend all) and change all of your passwords to pass phrases, then never reuse any password ever, and don't memorize any passphrase you use. Keep them in the minder. Ensure that you've got them backed up, and include a copy of your password minder's password in your estate paperwork (or don't, of there's something you don't want someone else to see).

We've kept our credit and financials locked down for years - Spouse was one of the DOD leaks about 8 years ago, and my SS card was stolen when I was a teenager (and I have absolutely vile, thieving parents, but that's a story for another day). It's never been a real problem. It probably saves us money in the long run -- it's too much of a hassle to apply for anything, so we really have to justify a credit purchase. It's not that bad, all things considered. It feels like a violation now, and you're perfectly justified to feel that way. We could probably unlock now, but it's a piece of fire and forget security that, once accomplished, is done, so I don't see the point in undoing it. It took me about 10 hours, total, and we've unlocked temporarily twice since (both times, to buy cars).

It's going to be okay.

Recommendations

0 members have recommended this reply (displayed in chronological order):

I'd say you should be concerned. TomSlick Aug 2017 #1
Thanks. Laffy Kat Aug 2017 #2
That's disappointing. TomSlick Aug 2017 #4
I Plan on doing just that. Laffy Kat Aug 2017 #5
Good Advice! burrowowl Aug 2017 #12
Well... politicat Aug 2017 #3
Great advice. Laffy Kat Aug 2017 #7
I'm afraid you should probably look into one of those identity protection places. pnwmom Aug 2017 #6
I just reviewed a few online and know which one I'm going to call in the morning. Laffy Kat Aug 2017 #8
Which one did you decide on? pnwmom Aug 2017 #9
Identity Guard. Laffy Kat Aug 2017 #10
Thanks for the info! pnwmom Aug 2017 #11
Latest Discussions»General Discussion»My jury selection demogra...»Reply #3