Equifax can't seem to get anything right. After exposing the personal information of potentially 143 million Americans to hackers,eroticized story the credit reporting agency is under fire yet again for the way it attempted to secure the credit reports of those affected. It turns out that process, too, was vulnerable to cybercriminals.
Now, the company is scrambling to fix what can only be called a bungled response to the data breach. For some victims, it might even be too late.
SEE ALSO: Twitter is *not having* Equifax's response to that massive hackThe problem lies in how Equifax went about implementing credit freezes — something consumers worried about identity theft and fraud should implement. Essentially, if you request a credit freeze, Equifax will no longer send out credit reports to those who request it. That means if someone tries to open up a credit card in your name, the issuing bank won't be able to get a hold of your credit report. As such, they will deny the fraudulent application.
But what happens if and when you decide that you need a new credit card? Well, then, you simply put in an unfreeze request and validate that it's actually you (and not the aforementioned criminal) with a PIN provided by Equifax. Except, here's the thing: The PIN wasn't randomly generated. Instead, it was a timestamp based upon when you asked for the credit freeze.
And you guessed it: those PINs are vulnerable to being brute-forced by hackers.
This Tweet is currently unavailable. It might be loading or has been removed.
In other words, if someone had your social security number and tried to do something shady — only to find your credit was frozen — they could unfreeze it by guessing your PIN. Not too hot, right?
This Tweet is currently unavailable. It might be loading or has been removed.
The company is taking a lot of criticism for this online, and a spokesperson told Ars Technicathat it would change the process by which PINs are generated.
"While we have confidence in the current system, we understand and appreciate that consumers have questions about how PINs are currently generated," explained the spokesperson. "We are engaged in a process that will provide consumers a randomly generated PIN. We expect this change to be effective within 24 hours."
But what if you already received one of the shady PINs? Well then, you can request that Equifax change your existing one. Which, considering how badly the company has handled pretty much every aspect of this breach, is sure to go over flawlessly.
Topics Cybersecurity
Facebook wants its augmented reality glasses to read your mindBen Smith reveals why BuzzFeed published the 'explosive' Trump reportsIndian soldier rants about bad food, being forced to sleep on an empty stomach, video goes viralAccused Capital One hacker 'had no malicious intent,' insists friendApple wants to make this one product in the U.S., but you won't be able to buy itLinkedIn ranks the 20 highest paying jobsDonald Trump's long history of troubling statements about vaccines and autismI traveled 5,000 miles for these photos of the solar eclipseApple hires contractors to listen to some Siri recordings: ReportWhy lactose intolerant people DGAF about avoiding cheeseSmoky satellite photo shows fires ravaging the ArcticYou'll have to wait even longer to borrow some new eThese pins support human rights just in time for the Women's MarchMark Zuckerberg made a Facebook employee 3D'Star Wars: Galaxy's Edge' proves Disneyland for childless millennialsNo, you can't watch Netflix while driving your TeslaEverything coming to (and going from) Netflix in August 2019Trump explores vaccine commission with prominent antiLet us now remember 11 of Michelle Obama's coolest momentsPeople are laughing over Drake's 'corny' Obama tribute on Instagram 'Stranger Things 2' is full of '80s references: How many did you miss? How to sign up for Samsung's Android Oreo beta for the Galaxy S8 Here's why some apps will look bad on the iPhone X Blizzard made a Blizzard Grammarly launches new iPhone keyboard app to fix your poor grammar A timeline of the rogue Trump Bitcoin price hits $7,000 for the first time Tourism isn't thinking much about climate change and that's a problem Mariah Carey's 'All I Want for Christmas Is You' makes iTunes charts 'World of Warcraft' is getting a new expansion that's all about Horde vs. Alliance Russian troll account duped the media, and everyone else The iOS game that lets you explore Australia as a wombat Disney researchers are working on fireworks you can 'feel' Silicon Valley preaches fasting, alarming eating disorder experts A World Series win got even sweeter after this Astros' player's on Uber and Lyft ban rightwing activist after racist tweets HTC U11+ has a 6 'Wonder Woman' has largest superhero origin story box office ever The iPhone X has been torn down to bits, here's what's inside LG V30 review: Great looks, disappointing camera
1.2471s , 8286.203125 kb
Copyright © 2025 Powered by 【eroticized story】,Wisdom Convergence Information Network