news.volyx.in

Identity thieves bypassed Experian security to view credit reports (krebsonsecurity.com)

475 points by picture · 1335 days ago · 187 comments on HN

Article summary

Identity thieves exploited a security weakness in Experian's website to access credit reports by bypassing multiple-choice questions about a person's financial history. The vulnerability was discovered by a security researcher who found that editing the URL in the browser could grant access to anyone's credit report. Experian has since patched the issue, but the duration of the vulnerability is unclear. The incident highlights concerns about the credit bureau's cybersecurity and data protection practices.

Main themes

  • credit bureau security
  • corporate accountability
  • cybersecurity
  • data protection
  • regulatory action
  • personal responsibility

What commenters say

  • The corporate death penalty is an ineffective concept because it does not hold individuals accountable for wrongdoing.
  • Fines and penalties should be imposed on executives and shareholders to deter negligence and wrongdoing.
  • The government should audit private companies for security after major data breaches to prevent future incidents.
  • The concept of a corporate death penalty is not clearly defined and may not be an effective deterrent.
  • Personal penalties for executives, such as non-financial penalties, are necessary to ensure accountability.
  • The credit bureau's security practices are inadequate and put consumers' personal and financial information at risk.
  • The vulnerability discovered in Experian's website is a classic example of a security flaw that can be easily exploited.
  • Regulatory action is necessary to hold credit bureaus accountable for their cybersecurity and data protection practices.