news.volyx.in

It's still easy for anyone to become you at Experian (krebsonsecurity.com)

874 points by todsacerdoti · 1015 days ago · 331 comments on HN

Article summary

Experian's account authentication process has serious security flaws, allowing anyone to recreate an account with the same personal information but a different email address, enabling identity thieves to hijack accounts easily. The author recounts their experience of having their Experian account hacked and emphasizes that the authentication weaknesses have persisted despite previous warnings. Experian's multi-factor authentication is ineffective when someone can recreate an account with new credentials. The company's lack of security measures puts users' sensitive information at risk.

Main themes

  • Experian security flaws
  • identity theft and impersonation
  • credit bureau accountability
  • consumer protection
  • institutional responsibility
  • data privacy and security

What commenters say

  • The term 'identity theft' is misleading and should be replaced with 'impersonation' to accurately reflect the victim and perpetrator.
  • Credit bureaus like Experian prioritize their customers, lenders, over the individuals whose data they collect and sell.
  • Institutions, not individuals, should be responsible for protecting themselves from fraud and identity impersonation.
  • Experian's security flaws and lack of accountability make it difficult for individuals to protect their personal and financial information.
  • The current system allows credit bureaus to push the risk of identity theft onto consumers, rather than taking responsibility themselves.
  • A significant fine, such as $50k per compromised account, would be necessary to get the attention of credit bureaus and drive change.
  • The concept of 'identity theft' implies that individuals are responsible for preventing their identity from being stolen, rather than institutions being responsible for protecting themselves from fraud.