<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LA Times: Hackers may have stolen the Social Security numbers of every American in Credit in the News</title>
    <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6782469#M29165</link>
    <description>&lt;P&gt;Interestingly, when I searched the tool, my info did not come up at my current or past addresses.&amp;nbsp; Turns out removing myself from all the public 3rd party database companies several years ago was a good play.&amp;nbsp; Unfortunately, I still assume everything is out there from so many other past breaches.&amp;nbsp; Plus, getting yourself out of these DBs is like playing a game of whack-a-mole, new ones pop up every year.&lt;BR /&gt;&lt;BR /&gt;I don't lose sleep trying to play defense, though.&amp;nbsp; The kingdom is sufficiently divided up so that a breach somewhere is fairly well-contained.&amp;nbsp; Other than keeping all my passwords on paper-only, siloing different accounts to different emails, using virtual card numbers, and letting nothing touch my bank accounts except income and credit card payments, there's not much else I can really do.&lt;BR /&gt;&lt;BR /&gt;Linux is not a serious option for me.&amp;nbsp; It does not support any of the industry-standard programs I must use for work and I do a lot of remote work so I must have full Win and Mac toolchains at home.&amp;nbsp; The FOSS alternatives to these programs don't even come close to cutting it, especially on the broadcast side.&amp;nbsp; I do, however, keep data and programs separate, no files are stored internally, so malware is just a shrug and a clean re-install.&amp;nbsp; Rather than trying to build an impenetrable castle that is constantly under attack by more and more sophisticated tech, I just reduce the consequences for getting hit down to an annoyance and make it easy to re-generate my setup.&amp;nbsp; Everything important is on cold storage, only shuttle drives get plugged in with a working copy of the specific files I need to use.&amp;nbsp; Version control becomes the main issue, although that would already be an issue regardless so it doesn't bother me.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2024 05:28:48 GMT</pubDate>
    <dc:creator>DXness</dc:creator>
    <dc:date>2024-08-23T05:28:48Z</dc:date>
    <item>
      <title>LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780480#M29104</link>
      <description>&lt;P&gt;Hackers may have stolen the Social Security numbers of every American. How to protect yourself (via LA Times)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The breach, which includes Social Security numbers and other sensitive data, could power a raft of identity theft, fraud and other crimes, said Teresa Murray, consumer watchdog director for the U.S. Public Information Research Group."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.henryherald.com/tribune/hackers-may-have-stolen-the-social-security-numbers-of-every-american-how-to-protect-yourself/article_602adcef-c2c8-5424-abf6-08ce2093ad1a.html" target="_self"&gt;https://www.henryherald.com/tribune/hackers-may-have-stolen-the-social-security-numbers-of-every-american-how-to-protect-yourself/article_602adcef-c2c8-5424-abf6-08ce2093ad1a.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 23:53:06 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780480#M29104</guid>
      <dc:creator>Yawgoog</dc:creator>
      <dc:date>2024-08-14T23:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780484#M29105</link>
      <description>Not the 1st time any of our data has been stolen. Seems like every two months a doctor's office / healthcare institution has a leak, and every month a tech company (ticketmaster, recently) has breaches.&lt;BR /&gt;&lt;BR /&gt;Freeze your credit reports.</description>
      <pubDate>Thu, 15 Aug 2024 00:23:22 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780484#M29105</guid>
      <dc:creator>Windchill92</dc:creator>
      <dc:date>2024-08-15T00:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780501#M29106</link>
      <description>&lt;P&gt;In addition to freezing credit reports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IRS: Get An Identity Protection PIN (IP PIN)&lt;BR /&gt;&lt;A href="https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin" target="_self"&gt;https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 00:56:57 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780501#M29106</guid>
      <dc:creator>Yawgoog</dc:creator>
      <dc:date>2024-08-15T00:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780791#M29107</link>
      <description>&lt;P&gt;A hacker is just a person who enjoys playful cleverness.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The person who designs Lady Gaga's costumes is a hacker.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy hacking!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 07:08:02 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780791#M29107</guid>
      <dc:creator>IsambardPrince</dc:creator>
      <dc:date>2024-08-16T07:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780816#M29108</link>
      <description>&lt;P&gt;More detail on the data taken and the company that operates National Public Data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://krebsonsecurity.com/2024/08/nationalpublicdata-com-hack-exposes-a-nations-data/" target="_self"&gt;https://krebsonsecurity.com/2024/08/nationalpublicdata-com-hack-exposes-a-nations-data/ &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Where did National Public Data get its consumer data? The company’s website doesn’t say, but it is operated by an entity in Coral Springs, Fla. called Jerico Pictures Inc. The website for Jerico Pictures is not currently responding. However, cached versions of it at archive.org show it is a film studio with offices in Los Angeles and South Florida."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The Florida Secretary of State says Jerico Pictures is owned by Salvatore (Sal) Verini Jr., a retired deputy with the Broward County Sheriff’s office. The Secretary of State also says Mr. Verini is or was a founder of several other Florida companies, including National Criminal Data LLC, Twisted History LLC, Shadowglade LLC and Trinity Entertainment Inc., among others."&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 13:53:33 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780816#M29108</guid>
      <dc:creator>Yawgoog</dc:creator>
      <dc:date>2024-08-16T13:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780840#M29109</link>
      <description>&lt;P&gt;This doesn't sound shady at all...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hey, Sal! Let's get all the data!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 15:08:40 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780840#M29109</guid>
      <dc:creator>noonway</dc:creator>
      <dc:date>2024-08-16T15:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780864#M29110</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/1183745"&gt;@noonway&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;This doesn't sound shady at all...&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;There are probably dozens or hundreds of these shady companies out there.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 17:10:58 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780864#M29110</guid>
      <dc:creator>Yawgoog</dc:creator>
      <dc:date>2024-08-16T17:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780920#M29111</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/1183745"&gt;@noonway&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;This doesn't sound shady at all...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hey, Sal! Let's get all the data!&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Oh yes, lets found Shadowglade, the Twisted Trinity of Criminal Data LLC(s)! Might as well name it "Fraud Unlimited", lol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 19:58:40 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780920#M29111</guid>
      <dc:creator>KatzNDawgs</dc:creator>
      <dc:date>2024-08-16T19:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780993#M29112</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/1141236"&gt;@Yawgoog&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;In addition to freezing credit reports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IRS: Get An Identity Protection PIN (IP PIN)&lt;BR /&gt;&lt;A href="https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin" target="_self"&gt;https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Still can't verify w/ id [dot] me without selfie or video call&lt;img id="smileymad" class="emoticon emoticon-smileymad" src="https://ficoforums.myfico.com/i/smilies/16x16_smiley-mad.gif" alt="Smiley Mad" title="Smiley Mad" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, freeze your ChexSystems profile so no one can create new bank/CU accounts on your behalf.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 02:06:36 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6780993#M29112</guid>
      <dc:creator>Windchill92</dc:creator>
      <dc:date>2024-08-17T02:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781023#M29113</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/1171392"&gt;@Windchill92&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/1141236"&gt;@Yawgoog&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;In addition to freezing credit reports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IRS: Get An Identity Protection PIN (IP PIN)&lt;BR /&gt;&lt;A href="https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin" target="_self"&gt;https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Still can't verify w/ id [dot] me without selfie or video call&lt;img id="smileymad" class="emoticon emoticon-smileymad" src="https://ficoforums.myfico.com/i/smilies/16x16_smiley-mad.gif" alt="Smiley Mad" title="Smiley Mad" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, freeze your ChexSystems profile so no one can create new bank/CU accounts on your behalf.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I really don't know why anyone is panicking about this. Your information leaks all the time, usually because a bank or hospital uses Microsoft Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Almost everyone's data is already out there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to the way I do my computing, every component on the system is verified and would be rolled back immediately if it was to be tampered with, but untrusted applications like web browsers are running in another domain with restricted access to the host system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a shame that large companies don't care about best practices, but hey at least I get settlement checks a lot.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 07:26:18 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781023#M29113</guid>
      <dc:creator>IsambardPrince</dc:creator>
      <dc:date>2024-08-17T07:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781408#M29118</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/1141236"&gt;@Yawgoog&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hackers may have stolen the Social Security numbers of every American. How to protect yourself (via LA Times)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.henryherald.com/tribune/hackers-may-have-stolen-the-social-security-numbers-of-every-american-how-to-protect-yourself/article_602adcef-c2c8-5424-abf6-08ce2093ad1a.html" target="_self"&gt;https://www.henryherald.com/tribune/hackers-may-have-stolen-the-social-security-numbers-of-every-american-how-to-protect-yourself/article_602adcef-c2c8-5424-abf6-08ce2093ad1a.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Weasel words. It's not "may have", its "have". Furthermore, I got 2 letter in the mail last week notifying me of other databases that have my info being hacked. Hacks should be expected. Plan accordingly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set-up all important accounts for 2 factor identification. Also, best not to allow merchants or even Amazon/Ebay to store CC info in their databases. Recommend freezing (or locking) credit reports as well. Also set-up to get text notifications for all purchases where physical card is not present and above X dollars even if card is supposedly present. I set X at $250.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use different, unique, passwords for all your key accounts. Of course, it is hard to remember 50 or even 20 complex passwords so, I keep mine in a password protected Excel file.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 04:37:14 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781408#M29118</guid>
      <dc:creator>Thomas_Thumb</dc:creator>
      <dc:date>2024-08-19T04:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781561#M29123</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/884935"&gt;@Thomas_Thumb&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Weasel words. It's not "may have", its "have".&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;It's not a weasel word. The hackers are talking a big game, but no one's been able to verify they've got the goods.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's wise to act as if someone's got your personal data and take precautions. That's not the same thing as actually believing what they claim.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 18:26:43 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781561#M29123</guid>
      <dc:creator>LADave</dc:creator>
      <dc:date>2024-08-19T18:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781566#M29124</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/1127022"&gt;@LADave&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/884935"&gt;@Thomas_Thumb&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Weasel words. It's not "may have", its "have".&lt;/P&gt;&lt;P&gt;Furthermore, I got 2 letter in the mail last week notifying me of other databases that have my info being hacked.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Hacks should be expected. Plan accordingly.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Set-up all important accounts for 2 factor identification. Also, best not to allow merchants or even Amazon/Ebay to store CC info in their databases. Recommend freezing (or locking) credit reports as well. Also set-up to get text notifications for all purchases where physical card is not present and above X dollars even if card is supposedly present. I set X at $250.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Use different, unique, passwords for all your key accounts. Of course, it is hard to remember 50 or even 20 complex passwords so, I keep mine in a password protected Excel file.&lt;/FONT&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;It's not a weasel word. The hackers are talking a big game, but no one's been able to verify they've got the goods.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's wise to act as if someone's got your personal data and take precautions. That's not the same thing as actually believing what they claim.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Weasel word or not:&lt;/P&gt;&lt;P&gt;Experian just changed the free account to offering daily credit score updates and the top banner on their page says&lt;/P&gt;&lt;P&gt;"A data breach just exposed 2.9B private records - don’t wait to protect your credit."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then there is this article from Time that includes a link to the data breach checker on the NPD website.&lt;/P&gt;&lt;P&gt;"National Public Data" NPD is the company that was data breached.&lt;/P&gt;&lt;P&gt;&lt;A href="https://time.com/7011872/social-security-data-breach-information/" target="_blank" rel="noopener"&gt;https://time.com/7011872/social-security-data-breach-information/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Data breach checker&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://npd.pentester.com/" target="_blank" rel="noopener"&gt;https://npd.pentester.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"National Public Data confirms massive data breach included Social Security numbers"&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.usatoday.com/story/tech/2024/08/17/social-security-hack-national-public-data-confirms/74843810007/" target="_self"&gt;https://www.usatoday.com/story/tech/2024/08/17/social-security-hack-national-public-data-confirms/74843810007/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My data is absolutely on that NPD checker page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 19:08:18 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781566#M29124</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2024-08-19T19:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781595#M29126</link>
      <description>&lt;P&gt;There are so many problems that lead to people's data being breached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Often, it's not really anything on my end, although I quit using Microsoft Windows over 20 years ago because it's a virus sewer and it breaks down a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Almost every Windows user ends up with some form of malware shortly after they connect their PC to the Internet. Windows wasn't designed to be secure. It was designed to gain marketshare rapidly and to keep it, and that meant prioritizing user convenience over security every time the two came into contention.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While most users are moving the client side over to something more secure, be it Chrome OS, Mac OS, or Linux, or even an iPhone or Android phone, Windows is still out there causing a lot of problems and data breaches, and so is Microsoft Azure, which also is not secure and injects security holes into any guest OS it manages even if the guest would be relatively secure on bare metal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When banks and hospitals and government agencies use Windows computers, and store records inside EHR companies and stuff (health records) which run in Azure or AWS and don't control their own computing infrastructure, they're making it almost guaranteed that there will be a breach. Many of them don't know they're being breached and also don't want to know because it will get them sued for negligence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Illinois, our government IT infrastructure is a mess. When I moved here in 2016, most government agencies including the Department of Human Services and the DMV (Secretary of State) were still on Windows XP, on some old Dells that were full of "shag carpeting" level dirt it had been so long since anyone put them there or cleaned them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When some of them finally started upgrading, they made the mistake of using Windows again. When I talked to someone from the government that had a Windows laptop and some black tape over the webcam, I commented "A hardware kill switch and a secure operating system would be better."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But these people are leaking your data all the time. Government and corporate IT are a disaster, and the government protects Microsoft because it's a large American company that's very well connected politically.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Between ChromeOS, and Fedora Kinoite (that's the atomic workstation with KDE), I don't do any of my computing in Windows, in fact ChromeOS will detect files that have been tampered with and roll them back if it is even possible to manipulate them. Linux applications and external file systems have been walled off and locked down hard, including to my amusement, mounting remote drives using &lt;A href="https://en.wikipedia.org/wiki/9P_(protocol)" target="_self"&gt;9pfs&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would say that the ChromeOS security model borders on paranoid, but that it surprisingly doesn't get in the way as much as you might think it would.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the Fedora Kinoite system, there's a verified boot path where the system just won't run if anything to the kernel has been tampered with, and the first thing it does is mount the root filesystem read-only, making it impossible to tamper with. System update images go out daily and are essentially a tree of binaries, much like a git revisioning, and most kernel tunables are off limits to userspace, even many of them if you become the root user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Systems are just getting harder to attack, at least systems that are not Windows, and that's a good thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Windows at least prods the user to update now, but due to the fact that the operating system is such an outdated morass and Microsoft's developers are so incompetent, it usually results in a system that's somewhat broken or non-functional, they move bugs around and there's very little overall security improvement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a non-related issue, since Linux works so much better on any computer (ChromeOS too) than Windows would, you can keep older hardware around for a lot longer and not end up in some unsupported state. My late 2016 Lenovo laptop would die with Windows 10 next year normally, but thanks to Linux it has no real end date. Whenever the hardware fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If people buy a Mac or Windows system or something and the computer is unsupported or even worse, unusable, in 5-6 years, when the hardware may have lasted 15, did they really get their money's worth?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft has slapped a new coat of paint on the Titanic. They made Windows 11 look deceptively like a modern operating system. But it's a mirage. One of their many bugs even exposed the underlying Windows 10 Shell, albeit in a broken state, but it is still there because of legacy programs that would break without it. Every security problem in IE 11 still affects Windows 11, and there's a lot of those. Even VBScript is still there (for now).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any IT security proclamation should order companies and state and local governments to migrate from Windows and Azure within 5 years.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think for now the key point would be to remember, you're only in direct control of the IT in your own household, and by using Windows, you'll only add to whatever problems these companies and government agencies that standardized on Microsoft will dump on your doorstep.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Being a veteran of the "client side" problem, I can go on forever about all the malware I've found that had cloaked itself and been on the user's system for a long time. A lot of it gets defensive if someone finds it there and will actively try to ward them off if they go to remove it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frankly, there's a lot of money to be made in "IT" just by wiping people's computers, reinstalling Windows, and waiting for them to be back again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It doesn't even take "top level" people to do this. The company that hires them pays them minimum wage or less and bills the customer like they had their car in the shop. &lt;img id="smileytongue" class="emoticon emoticon-smileytongue" src="https://ficoforums.myfico.com/i/smilies/16x16_smiley-tongue.gif" alt="Smiley Tongue" title="Smiley Tongue" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This one incident I know about, a guy hired someone and only paid him $8,000 a year to go out wiping people's Windows computers, even the local government, up in Canada ($8,000 CAD per year), and when this person behaved unprofessionally and got himself fired, he tricked his old boss into signing a reference paper that referred to him as an employee not an independent contractor, and decided to use that paper as evidence for suing his old boss for retroactive pay and benefits an employee would have had.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No good deed goes unpunished.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The person in question who did this is a fairly unstable person who was barely employable, so even taking them on and paying them at all was essentially an act of charity. You wouldn't want this fellow in your house.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;His erratic behavior got so bad that the police arrested him for electronic harassment of his boss at one point, then he added that to the lawsuit and got another $2,000 for "pain and suffering". He claims his boss just never paid it and nothing happened.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;He's now been unemployed for years and goes around filing revenge lawsuits against everyone including the Crown Prosecutor and the police officers that arrested him.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Usually in the Windows world, when you say IT you mean people that are just weird and don't have any actual skills.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The people writing malware that gets into Microsoft systems, hides, and stays there, are higher level than the people removing it, writing security software, or even Microsoft themselves. That's my observation and opinion.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;It's so intricate and beautiful, the malware source code. It never ceases to amaze me how they find and take full advantage of the garbage piles Microsoft leaves everywhere.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In one case that I was particularly impressed with, to get around User Account Control, a malware group didn't even do anything fancy. They just included an old version of the Windows calculator that had permission to bypass UAC as a signed Windows component and then injected malicious code into it at runtime.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In another example, they used an old driver signing certificate that was expired and shouldn't have been allowed to sign anything new, by faking the time stamp at signing, and having Windows run the code anyway, even though Windows realized something was wrong with the signing process. Microsoft later had to step in and outright revoke a lot of certificates even though it means that old Windows drivers will fail to install even if they were signed correctly during the certificate lifetime.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By taking advantage of the way Windows is designed to make things easier for users, and to "support" old unmaintained drivers which are likely full of bugs, you can elevate your permissions, and install malicious payloads disguised as device drivers, completely bypassing UAC and Kernel Patch Guard, and then you can hide from antivirus because you're part of the kernel, and you won't even trigger a Secure Boot failure to load the OS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This doesn't even touch on how to hide from an initial scan using NTFS Data Forks, and exploiting the sandbox of Windows Defender by baiting it into scanning your malware and running it, then busting out of the sandbox. Thus requiring no user interaction to even get going. If the file ends up on the file system, the user is already toast.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even bugs in real time security software can be perverted to make the computer less secure. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://ficoforums.myfico.com/i/smilies/16x16_smiley-happy.gif" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Total Cost of Ownership of Windows can be worse than just a data breach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can end up with password stealers, botnets, Remote Access Trojans, creepy people watching you on your webcam. Some people wonder how they get their passwords stolen so often. It's not always just crappy passwords. People get password stealers. In many cases this allows whoever gets the password dump to start making changes to their bank and credit card information so they can clean them out and start racking up all sorts of fraud charges. Sometimes you'll just get a screen that says all your files are encrypted now and you need to pay them to get it back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's taken out banks and credit unions, hospitals, it's been responsible for chicken and gasoline shortages. Windows is awful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The people writing this malware want money and they don't care how they get it. They hit Windows so hard because it's comically bad and it has a lot of users. That's fine with them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Many years ago when I still used Windows, I got infected with some malware, despite my more cautious than usual approach it didn't stop it.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I decided to hit them back. I got into their Command &amp;amp; Control server and disrupted it by instructing the malware to delete itself. It was funny watching many thousands of zombie systems just start disconnecting from the IRC server all at once. I had started lurking in there by making myself look like an infected computer when I was really a person watching the system work.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 23:30:34 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6781595#M29126</guid>
      <dc:creator>IsambardPrince</dc:creator>
      <dc:date>2024-08-19T23:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6782469#M29165</link>
      <description>&lt;P&gt;Interestingly, when I searched the tool, my info did not come up at my current or past addresses.&amp;nbsp; Turns out removing myself from all the public 3rd party database companies several years ago was a good play.&amp;nbsp; Unfortunately, I still assume everything is out there from so many other past breaches.&amp;nbsp; Plus, getting yourself out of these DBs is like playing a game of whack-a-mole, new ones pop up every year.&lt;BR /&gt;&lt;BR /&gt;I don't lose sleep trying to play defense, though.&amp;nbsp; The kingdom is sufficiently divided up so that a breach somewhere is fairly well-contained.&amp;nbsp; Other than keeping all my passwords on paper-only, siloing different accounts to different emails, using virtual card numbers, and letting nothing touch my bank accounts except income and credit card payments, there's not much else I can really do.&lt;BR /&gt;&lt;BR /&gt;Linux is not a serious option for me.&amp;nbsp; It does not support any of the industry-standard programs I must use for work and I do a lot of remote work so I must have full Win and Mac toolchains at home.&amp;nbsp; The FOSS alternatives to these programs don't even come close to cutting it, especially on the broadcast side.&amp;nbsp; I do, however, keep data and programs separate, no files are stored internally, so malware is just a shrug and a clean re-install.&amp;nbsp; Rather than trying to build an impenetrable castle that is constantly under attack by more and more sophisticated tech, I just reduce the consequences for getting hit down to an annoyance and make it easy to re-generate my setup.&amp;nbsp; Everything important is on cold storage, only shuttle drives get plugged in with a working copy of the specific files I need to use.&amp;nbsp; Version control becomes the main issue, although that would already be an issue regardless so it doesn't bother me.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 05:28:48 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6782469#M29165</guid>
      <dc:creator>DXness</dc:creator>
      <dc:date>2024-08-23T05:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: LA Times: Hackers may have stolen the Social Security numbers of every American</title>
      <link>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6782572#M29168</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ficoforums.myfico.com/t5/user/viewprofilepage/user-id/1138916"&gt;@DXness&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I still assume everything is out there from so many other past breaches.&amp;nbsp; Plus, getting yourself out of these DBs is like playing a game of whack-a-mole, new ones pop up every year.&lt;BR /&gt;&lt;BR /&gt;Other than keeping all my passwords on paper-only, siloing different accounts to different emails, using virtual card numbers, and letting nothing touch my bank accounts except income and credit card payments, there's not much else I can really do.&lt;BR /&gt;&lt;BR /&gt;Linux is not a serious option for me.&amp;nbsp; It does not support any of the industry-standard programs I must use for work and I do a lot of remote work so I must have full Win and Mac toolchains at home.&amp;nbsp; I do, however, keep data and programs separate, no files are stored internally, so malware is just a shrug and a clean re-install.&amp;nbsp; Everything important is on cold storage, only shuttle drives get plugged in with a working copy of the specific files I need to use.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I change passwords too often to maintain them in a hard copy only format. I think an air gapped laptop that has never connected to the internet or network has sufficient security for updating passwords stored on a thumb drive that is dedicated to the air gapped computer. The computer connects to an offline printer via usb for hard copy printing of my pwd list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no doubt all my other computers and smart phone have been hacked and are being monitored.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Aug 2024 02:02:04 GMT</pubDate>
      <guid>https://ficoforums.myfico.com/t5/Credit-in-the-News/LA-Times-Hackers-may-have-stolen-the-Social-Security-numbers-of/m-p/6782572#M29168</guid>
      <dc:creator>Thomas_Thumb</dc:creator>
      <dc:date>2024-08-24T02:02:04Z</dc:date>
    </item>
  </channel>
</rss>

