TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Experian’s credit freeze security is still a joke

659 pointsby pictureabout 4 years ago

29 comments

PascLeRascabout 4 years ago
I really, really wish I could opt out of having accounts with the big 3 credit bureaus. Freezes don’t appear to work - they usually say that I don’t have an active freeze whenever I go to lift one. Or their website is down entirely. Or they won’t let me get to the freeze section without clicking no on their paid monitoring services 8 times. For Transunion all I needed to lift a freeze was the last 4 of my SSN, so how does that help?<p>I don’t want to have my information with these companies. Please let me not participate. It’s like every American was given a Chase Bank account at birth that we can’t close, it’s weird.
评论 #26950460 未加载
评论 #26955125 未加载
评论 #26951862 未加载
评论 #26952637 未加载
评论 #26950537 未加载
评论 #26951335 未加载
评论 #26956463 未加载
评论 #26952129 未加载
评论 #26960567 未加载
评论 #26956618 未加载
评论 #26950317 未加载
TechBro8615about 4 years ago
My favorite part of this system is when they give you a year of it as compensation for a data breach, saying it’s worth 12x its monthly fee (which they make up). That’s not even touching on the fact that their solution to losing your data is asking you for more of it.<p>I’ve never been lucky enough to be compensated with such a service. But it wouldn’t surprise me if they were so helpful that they even auto-enroll you in another (paid) year at the end of your free trial!<p>One also wonders why reforming the credit bureaus is not a bipartisan priority in Washington. Congress is apparently only interested in fighting over the issues that nobody can agree on. Don’t hold your breath for any progress fixing systems that anyone except a lobbyist can clearly point to as broken.<p>The problems might get some attention if the corporate media chose to hype them, but guess who buys a bunch of advertisements on their news channels?
评论 #26950914 未加载
评论 #26951894 未加载
评论 #26950205 未加载
评论 #26951667 未加载
lhnzabout 4 years ago
<p><pre><code> &gt; The best part about this lax authentication process is &gt; that one can enter any email address to retrieve the &gt; PIN — it doesn’t need to be tied to an existing account &gt; at Equifax. Also, when the PIN is retrieved, Equifax &gt; doesn’t bother notifying any other email addresses &gt; already on file for that consumer. </code></pre> Hang on, so the attacker doesn&#x27;t even need to break into somebody&#x27;s email account first, they can just guess the questions and put in their own email address?! This is insane.
评论 #26949340 未加载
评论 #26949245 未加载
评论 #26950380 未加载
thatguy0900about 4 years ago
&quot;Finally, your basic consumer (read: free) account at Experian does not give users the option to enable any sort of multi-factor authentication that might help stymie some of these PIN retrieval attacks on credit freezes.<p>Unless, that is, you subscribe to Experian’s heavily-marketed and confusingly-worded “CreditLock” service, which charges between $14.99 and $24.99 a month&quot;<p>It&#x27;s great to see theyre taking the knowledge that being hacked doesn&#x27;t matter and putting it to good use
评论 #26951070 未加载
评论 #26954771 未加载
azinman2about 4 years ago
I put a pin on my account after the first Equifax leak. Recently I needed to unfreeze it, and discovered that upon creating a “my equifax” account that I was able to unfreeze it WITHOUT THE PIN. Ive complained to the FTC (including screenshots) but haven’t heard anything. It’s so unbelievably insane these companies are allowed to operate with such massive ramifications to society and individuals!
EGregabout 4 years ago
Funny, I just called to put a Fraud Alert on my credit report. I encourage everyone to do it - so this way reputable lenders are supposed to call you when they&#x27;re trying to open an account in your name. An attacker would have to port your SIM card as well...<p>However, all the information I was providing to set the alert, or remove it, is the exact information that any lender would receive on their application. The system if so horribly broken security-wise, I am shocked there aren&#x27;t more accounts being opened left and right by people who got them from applications emailed to thousands of lenders over the years.
评论 #26949442 未加载
评论 #26950519 未加载
aeontechabout 4 years ago
Experian somehow has allowed _someone_ to reset my account username and email not once but twice in the past month.<p>I&#x27;m, to put it mildly, not happy, and I&#x27;ve no confidence it&#x27;s not going to get reset again tomorrow.<p>Yes, I use a complex randomly generated password.<p>They do send an email to your previous address on the account notifying you of the fact though, which is the one silver lining.
RcouF1uZ4gsCabout 4 years ago
&gt; and were surprised to find that just one of the five multiple-guess questions they were asked after entering their address, Social Security Number and date of birth had anything to do with information only the credit bureau might know.<p>And a lot more than the credit bureau know those two pieces of information.<p>Honestly, the US really needs a government run public key ID service. The government in providing passports and drivers’ licenses is already doing identity verification. If along with your passport they would allow you to register a public key that people could use to verify your identity, it would be a huge help.
评论 #26950634 未加载
评论 #26949357 未加载
评论 #26949338 未加载
tristanbabout 4 years ago
It’s so incredibly frustrating as a victim of identity theft to have these fucktards give away my information without any form of care. I wish I had the means to sue them into oblivion.
评论 #26952439 未加载
willhinsaabout 4 years ago
Credit scams and identity theft are a problem for us because right now the banks don&#x27;t have to pay any cost of those mistakes. The most direct way to solve the problem of credit scams and identity theft is to put the onus on the bank who opened up the account incorrectly to assume responsibility for the debt, not on the person whose account details were spoofed to create the account.<p>This is quite humorously illustrated by a &quot;That Mitchell and Webb Sound&quot; skit: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=CS9ptA3Ya9E" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=CS9ptA3Ya9E</a>
评论 #26951926 未加载
Buttons840about 4 years ago
It&#x27;s important to realize that the credit monitoring services you can buy are provided by the credit companies.<p>The same company, which may at times make false claims about you, is in possession of a service &#x2F; technology they claim can detect those false claims.<p>Why is it not libel when these companies make false claims about me? Especially when they advertise that they have the ability to detect such false claims? &quot;Pay us and we will not make false claims about you&quot; they say. &quot;Pay us and we&#x27;ll double check with you before making claims we believe to be suspicious about you.&quot;
评论 #26949085 未加载
评论 #26949686 未加载
评论 #26949089 未加载
评论 #26950031 未加载
评论 #26952152 未加载
评论 #26949159 未加载
jfrunyonabout 4 years ago
&gt; A security freeze essentially blocks any potential creditors from being able to view your credit file, unless you affirmatively unfreeze or thaw your file beforehand.<p>I feel pretty sure they can probably pinky-promise that they really are inquiring about the right person and still do at least a soft inquiry.
Aeolunabout 4 years ago
This whole system with credit scores is utterly broken in the US.
jfrunyonabout 4 years ago
Most of the times I&#x27;ve gotten the credit bureau-style security questions (for example, trying to get my credit reports, or trying to open a bank account),<p>- Every single one is answerable by reference to my Facebook page and a few old area phonebooks [remember when most people used to list their name, phone number, and <i>home address</i> for the world to see? ah yes. good times.]<p>- And they usually tell me I&#x27;m wrong, which would make me suspicious that I was a victim of identity theft, except that the answers I give usually match the data in the report I eventually receive.
dylan604about 4 years ago
To me, the title is overly wordy: &quot;Experian is still a joke&quot;
评论 #26949312 未加载
myrandomcommentabout 4 years ago
When possible fill out the list of security questions with nonsense that you keep a record of&#x2F;or understand the pattern of answers to. &quot;What&#x27;s your favorite sport?&quot; &quot;Potato&quot;.<p>I fill them out, screenshot the form and keep that screenshot in an encrypted file that I keep backups of. Not even text searchable that way.<p>Also completely ridiculous I have to do any of this.
评论 #26951168 未加载
emrahabout 4 years ago
Aside from the reported problem, Experian is the worst of the three. Freezing&#x2F;unfreezing from the website doesn&#x27;t seem to work, asks for all kinds of PII to be mailed in yikes! Yet it does work (so don&#x27;t mail anything in!)<p>Total mess and they seem to have little to no incentive to fix&#x2F;improve anything
lr4444lrabout 4 years ago
If they mean that the InfoSec is a joke, okay fair enough, but a credit freeze itself is not a joke: it shifts more of the liability to the credit bureaus for allowing your record to be pulled, of in fact that does happen by a scammer. And they notify your device if you set up MFA.
hbcondo714about 4 years ago
Would anyone here be able to share their experience with freezing their children&#x27;s credit? We wanted to do this when our kids were born but when reviewing each credit bureau&#x27;s website, they are all asking to mail paper copies of SSN and birth certificates for each child in addition to the parents&#x27; SSN and birth certificates too. There doesn&#x27;t appear to be any way to freeze a minor&#x27;s credit online.
评论 #26952530 未加载
评论 #26950494 未加载
kemonocodeabout 4 years ago
I&#x27;ve been exposed to the ludicrous US credit system through my fiancee who was affected by the Experian hack, and frankly, I completely get anyone who wants to see it all torn down. I find it ludicrous there are <i>three</i> different credit bureaus and they all seem to be equally incompetent for something as critical as an attempt to summarize a perception of your trustworthiness into a neat little file.
dawnerdabout 4 years ago
Meanwhile, I can&#x27;t get equifax to unfreeze my credit. Whatever answers they have on file are wrong and tell me to call - except you cant reach a human without answering those same questions. They&#x27;ve yet to respond to actual mail I&#x27;ve sent them too.<p>Oh well, the other agencies unlock so it just takes a little talking whenever I need to run a credit check explaining equifax is jacked up.
评论 #26949852 未加载
komeabout 4 years ago
americans: why are you so addicted to credit ratings? ban them.
评论 #26950407 未加载
评论 #26951125 未加载
评论 #26950462 未加载
DanAtCabout 4 years ago
As a resident of California can I invoke the CCPA and get my information deleted from Experian et al?
exabrialabout 4 years ago
I&#x27;m still waiting for the $150 Experian owes me for leaking my private info all over the internet, after hiring a music theory major as their chief information security officer. Luckily all the lawyers in the case are now driving Lamborghinis.
Covzireabout 4 years ago
Wow, Experian is a total scumbag company.
1970-01-01about 4 years ago
The massive and swift fines they face are the punchline.
SocksCanCloseabout 4 years ago
so my buddy just built this: <a href="https:&#x2F;&#x2F;www.veradan.com" rel="nofollow">https:&#x2F;&#x2F;www.veradan.com</a>
评论 #26950213 未加载
评论 #26950198 未加载
systemvoltageabout 4 years ago
Can startup shake up this tripoly - TransUnion, Equifax and Experian? I am curious, what are the hurdles? To imagine any other way is impossible - if it is year 2050, I can&#x27;t imagine these 3 to keep holding Americans hostage.<p>Edit: Changing from SV to startup.
评论 #26949541 未加载
评论 #26949872 未加载
评论 #26949500 未加载
paul7986about 4 years ago
Their credit score is a racket ...my two other scores from other agencies are higher and very, very close to each other.<p>Experian offers a boost product where you authorize them to monitor your electric bills, etc ..once I did ... gave them permission to do so my Experian credit rating went up to the same number (a point or two off) then the other two. What a racket!!!