Apache Struts Statement on Equifax Security Breach
Apache Struts Statement on Equifax Security Breach
Posted Sep 11, 2017 22:12 UTC (Mon) by dskoll (subscriber, #1630)In reply to: Apache Struts Statement on Equifax Security Breach by ssmith32
Parent article: Apache Struts Statement on Equifax Security Breach
Credit agencies should be required to keep at least one phone number and one email address in your record. If someone wants to do a credit check on you, they should be required to email, text or call you to let you know (1) who is doing the check, (2) what the purpose of the check is and (3) a random PIN that's good for 24 hours.
If you consent to the check, you phone a number or go to a web site, enter the PIN, and the check goes through. If not, you phone the number or go to the web site, indicate that you don't want the check to go through, and it doesn't.
Can that be hacked? Undoubtedly. But it would raise the difficulty substantially. It would also make it much slower for credit agencies to sell credit checks about you, which is why it'll never happen, even though Google, Yahoo, etc. have used similar schemes for much lower stakes for years.
