Experian has officially acknowledged my Dec. 23 report to them about a security weakness that exposed any consumer's credit file if you knew their name, address, SSN and DoB.

Experian says the weakness persisted on their site for 47 days, from Nov. 9, 2022 until three days after I notified them.

New story here:
https://krebsonsecurity.com/2023/01/experian-glitch-exposing-credit-files-lasted-47-days/

Experian Glitch Exposing Credit Files Lasted 47 Days – Krebs on Security

@briankrebs meanwhile there was no abundance of caution for anyone who's last 4 SSN was exposed by them through their security questions
@briankrebs what happens when their free credit check has an exploit? do they offer MORE free credit checking? Is it an infinite loop? will we collapse into a black hole as the gravitational pull of free credit checks overwhelms the earth?
@briankrebs Many thanks for your work!!
@briankrebs As I wrote to Brian in email it’s said and funny how Experian treated this situation, had a long laugh did not had that in a long time since the War. But the question remains if I had not been persistent and kept knowing and trying to get ahold someone how long this who’d continue and Experian stayed silent.
Thank you Brian for taking time to listen to me and publishing this
@briankrebs interesting. What was the potential impact of this? I'm not too familiar with credit reports; what can an attacker gain from them which they wouldn't already be able to get with name/DoB/SSN?
@briankrebs lol you should look at banks
@briankrebs there's a bunch of websites that do that and it's how it works.
@briankrebs Classic response that basically boils down to "If you would like a copy of your credit report, or anyone else's, please contact us."