{"id":10239,"date":"2017-11-02T07:17:13","date_gmt":"2017-11-02T15:17:13","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/11\/02\/news-4012\/"},"modified":"2017-11-02T07:17:13","modified_gmt":"2017-11-02T15:17:13","slug":"news-4012","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/11\/02\/news-4012\/","title":{"rendered":"Equifax Reopens Salary Lookup Service"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Thu, 02 Nov 2017 14:04:20 +0000<\/strong><\/p>\n<p><strong>Equifax<\/strong> has re-opened a Web site that lets anyone look up the salary history of a large portion of the American workforce using little more than a person&#8217;s Social Security number and their date of birth. The big-three credit bureau took the site down just hours after <a href=\"https:\/\/krebsonsecurity.com\/2017\/10\/equifax-breach-fallout-your-salary-history\/\" target=\"_blank\" rel=\"noopener\">I wrote about it on Oct. 8<\/a>, and began restoring the site eight days later saying it had added unspecified &#8220;security enhancements.&#8221;<\/p>\n<div id=\"attachment_41054\" style=\"width: 590px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-41054\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/10\/twn-580x226.png\" alt=\"\" width=\"580\" height=\"226\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/10\/twn-580x226.png 580w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/10\/twn-768x300.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/10\/twn.png 864w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><\/p>\n<p class=\"wp-caption-text\">The Work Number, Equifax&#8217;s salary and employment history portal.<\/p>\n<\/div>\n<p>At issue is a service provided by Equifax\u2019s\u00a0<a href=\"https:\/\/krebsonsecurity.com\/?s=talx&amp;x=0&amp;y=0\" target=\"_blank\" rel=\"noopener\">TALX division<\/a>\u00a0called\u00a0<a href=\"https:\/\/www.theworknumber.com\/Employees\/index.asp\" target=\"_blank\" rel=\"noopener\">The Work Number<\/a>. The service is designed to provide automated employment and income verification for prospective employers, and tens of thousands of companies report employee salary data to it. The Work Number also allows anyone whose employer uses the service to provide proof of their income when purchasing a home or applying for a loan.<\/p>\n<p>What\u2019s needed to access your salary and employment history?\u00a0<a href=\"https:\/\/secure.theworknumber.talx.com\/twneeer\/PreAuthenticated\/EnterEmployerSearchCriteria.ascx?ReturnUrl=%2ftwneeer%2femployee%2fpostauthenticated%2fapplicationsequenceerror.ascx\" target=\"_blank\" rel=\"noopener\">Go here<\/a>, and enter the employer name or employer code. After that, it asks for a \u201cuser ID.\u201d This might sound like privileged information, but in most cases this is just the employees\u2019s Social Security number (or a portion of it).<\/p>\n<p>At the next step, the site asks visitors to \u201center your PIN,\u201d short for Personal Identification Number. However, in the vast majority of cases this appears to be little more than someone\u2019s eight-digit date of birth. The formats differ by employer, but it\u2019s usually either yyyy\/mm\/dd or mm\/dd\/yyyy, without the slashes.<\/p>\n<p>Successful validation to the system produces two sets of data: An employee\u2019s salary and employment history going back at least a decade, and a report listing all of the entities (ostensibly, the aforementioned \u201ccredentialed verifiers\u201d) that have previously requested and viewed this information.<\/p>\n<p>In <a href=\"https:\/\/www.nationalmortgagenews.com\/news\/equifax-restoring-the-work-number-portal-with-beefed-up-security\" target=\"_blank\" rel=\"noopener\">a story<\/a> in the financial industry publication <em>National Mortgage News<\/em>, Equifax said:\u00a0 &#8220;As access to the employee portal is restored, individuals must be re-authenticated and establish a unique PIN. Therefore, the data exposed in the cyber incident will not be sufficient to access The Work Number.&#8221;<span id=\"more-41208\"><\/span><\/p>\n<p>The publication said\u00a0Equifax declined to answer questions about whether the timing of the portal maintenance or the decision to add new security features were in response to the original Oct. 8 report here, quoting an Equifax spokesman saying the company opted to move up and expand a planned service outage.<\/p>\n<p>&#8220;At that time, we also decided to accelerate the implementation of select security enhancements to our platforms which extended the service outage timeframe,&#8221; the spokesman said.<\/p>\n<p>I walked through the newer, allegedly more secure portal with a friend and source who worked at a major firm that used The Work Number at some point previously, and at first we couldn&#8217;t figure out how to enter his default PIN. A quick search for his employer&#8217;s name and &#8220;The Work Number&#8221; turned up a PDF with instructions stating that the PIN consisted of the last two digits of the employee&#8217;s birth year, and the fourth and fifth digit of their SSN.<\/p>\n<div id=\"attachment_41353\" style=\"width: 609px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-41353\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/11\/TWN-staticprompt.png\" alt=\"\" width=\"599\" height=\"542\" \/><\/p>\n<p class=\"wp-caption-text\">Part of the new and improved security at The Work Number.<\/p>\n<\/div>\n<p>After passing that screen, the only &#8220;security enhancements&#8221; I saw that my source encountered was a prompt to enter his full name, date of birth, Social Security number, address, phone number and email, followed by the usual retinue of four multiple-guess &#8220;knowledge-based authentication&#8221; (KBA) questions. I&#8217;ve long been a critic of these KBA questions, because the answers usually are available using sites like <a href=\"https:\/\/www.zillow.com\" target=\"_blank\" rel=\"noopener\">Zillow<\/a> and <a href=\"https:\/\/www.spokeo.com\" target=\"_blank\" rel=\"noopener\">Spokeo<\/a>, to say nothing of social networking profiles.<\/p>\n<p>Fortunately, you can reduce the likelihood that an acquaintance, co-worker, stalker or anyone else can glean your salary history by claiming your own account, changing the PIN and selecting a half-dozen security questions and answers. As always, it\u2019s best not to answer these questions truthfully, but to input answers that only you will know and that can\u2019t be found using social networking sites or other public data sources.<\/p>\n<p>I used to think that if you had <a href=\"https:\/\/krebsonsecurity.com\/2015\/06\/how-i-learned-to-stop-worrying-and-embrace-the-security-freeze\/\" target=\"_blank\" rel=\"noopener\">a security freeze on your credit file<\/a> at a credit bureau that the bureau would then be unable to ask these KBA questions. I&#8217;ve recently worked with several sources who had freezes on their files and yet were still asked these KBA questions. Those individuals may not have all been approved to continue whatever transaction was in progress after answering those questions, but in most cases it shocks folks who have freezes when they even get asked those KBA questions.<\/p>\n<p>However, it seems that each of the cases I&#8217;ve seen in which the person had a freeze on their credit file, the applicant was asked only non-financial questions. In other words, they were given questions that one did not necessarily need access to one&#8217;s credit card or mortgage statements to answer successfully &#8212; such as the names of previous streets resided on or the names of lenders used in the past.<\/p>\n<p>What&#8217;s interesting is that these types of questions tend to be easier to answer than, say, &#8216;What was the amount of your most recent car loan payment?&#8217; That suggests that ID thieves could find people with credit freezes an easier target of services like this one because they face far easier KBA questions after they provide all of the target&#8217;s static information (DOB, SSN, etc).<\/p>\n<p>If that sounds ironic or sad, remember that we&#8217;re talking about a company whose breach more severely impacted consumers who paid Equifax whatever fees the company is allowed to charge under state laws to freeze the consumer&#8217;s credit file.<\/p>\n<p>We all sort of assumed this was the case when Equifax initially disclosed on Sept. 7 that the breach resulted in the theft of SSNs and other data on 143+million people, as well as<a href=\"https:\/\/krebsonsecurity.com\/2017\/09\/equifax-hackers-stole-200k-credit-card-accounts-in-one-fell-swoop\/\" target=\"_blank\" rel=\"noopener\">\u00a0some 209,000 credit and debit card numbers<\/a>. But in written notifications recently mailed to victims of the breach, Equifax made it crystal clear that their credit card data was stolen because they once used it at Equifax to request a credit freeze or copy of their credit report.<\/p>\n<div id=\"attachment_41357\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-41357\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/11\/whatinfo.png\" alt=\"\" width=\"600\" height=\"139\" \/><\/p>\n<p class=\"wp-caption-text\">Part of the notice Equifax mailed this week to a U.S. breach victim.<\/p>\n<\/div>\n<p>Does your current or former employer share your salary data with Equifax? If so, were you able to access your salary history via <a href=\"https:\/\/secure.theworknumber.talx.com\/twneeer\/PreAuthenticated\/EnterEmployerSearchCriteria.ascx?ReturnUrl=%2ftwneeer%2femployee%2fpostauthenticated%2fapplicationsequenceerror.ascx\" target=\"_blank\" rel=\"noopener\">The Work Number site<\/a>? Sound off in the comments below about any &#8220;security enhancements&#8221; you encountered along the way.<\/p>\n<p>If you&#8217;re still unsure what you should be doing in the wake of the breach at Equifax, see <a href=\"https:\/\/krebsonsecurity.com\/2017\/09\/the-equifax-breach-what-you-should-know\/\" target=\"_blank\" rel=\"noopener\">this Q&amp;A<\/a>.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2017\/11\/equifax-reopens-salary-lookup-service\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/10\/twn-580x226.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Thu, 02 Nov 2017 14:04:20 +0000<\/strong><\/p>\n<p>Equifax has re-opened a Web site that lets anyone look up the salary history of a large portion of the American workforce using little more than a person&#8217;s Social Security number and their date of birth. The big-three credit bureau took the site down just hours after I wrote about it on Oct. 8, and began restoring the site eight days later saying it had added unspecified &#8220;security enhancements.&#8221;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[12310,14598,16309,10644,16310,12316,15651,16311],"class_list":["post-10239","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-equifax","tag-equifax-breach","tag-national-mortgage-news","tag-other","tag-spokeo","tag-talx","tag-the-work-number","tag-zillow"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=10239"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10239\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=10239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=10239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=10239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}