Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

451–460 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#451
post #396

Earlier quoted context omitted.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those au…

Thats how traditional banks work. You walk in Chase with your government ID to open up an account. It doesn't work. You can get high quality forgeries of government IDs made in China and there's no public DB to verify information on the card. RealID requirement for states to open up their driver license DBs only applies to government agencies(eg: TSA). Also would you want to go in person to signup for paypal, venmo,…

> Also would you want to go in person to signup for paypal, venmo, etrade, betterment etc?

Honestly, maybe that wouldn't be such a bad idea. A well-designed system would probably wind up contracting the post office for ID verification for online services (since in my country at least, they do a pile of random related stuff).

Re: Cybersecurity Incident Involving Consumer Information

#452
post #441

Earlier quoted context omitted.

The problem is that you need a replacement, something that can actually be used as a solid proof of identity. The countries that don't have comparable identity theft problems have done so mostly by using an ubiquitous government issued ID that's hard to forge and hard to obtain by someone claiming to be you. In USA there seems to be a strong opposition and a legal barrier for the government to make such an ID. Not mu…

Can you expand on the systems that are "hard to obtain by someone claiming to be you" and biometrics? In my readings, I've found that biometrics is not unique across a large population, it changes over one's life span (which means you wouldn't know when it has changed enough to update the system that stores it), changes with one's profession (like physical labor) and health, and that the error rates across a huge pop…

Biometrics alone aren't sufficient, but they're a reliable way to prevent identity theft if you have a secure record linking the identity to the biometrics - there will be people with similar faces and may be fingerprint matches, but fraudsters aren't going to easily find a thief that happens to look similar to you, match your fingerprints, and forge a document just to get a small loan or some electronics on your credit. The point is that biometrics can't be treated as "something you know", and the system should be designed in a way that these biometrics getting compromised isn't a big problem; I mean, my EU ID card has a chip with my fingerprints on it, but getting a copy of my fingerprints won't really risk "my identity", all they're good for is to prevent someone else using my documents if they steal it even if their face looks similar.

Getting such a secure record, though, generally requires a decent level of gov't infrastructure throughout all areas, and can't be built up quickly. Size alone isn't an issue - if it works for half a billion people in EU, then it'd work for a billion people elsewhere, but the infrastructure needs to be there.

I.e., you need a population where all or nearly all births have been properly tracked and reliably registered for a long time, so you can't build it faster than decades if it wasn't the case; you need a general low corruption environment where mass issuing of fake IDs by corrupt officials won't happen (a limited number of fakes by organized crime might be inevitable, but they won't disrupt the system); you need an effective policing system where everyone, including the most poor, would report stolen wallets and documents to be revoked; you need effective infrastructure where it's trivial for everyone giving credit or goods "on lease" to verify online the validity of some documents.

I'm not sure how it's in India, and I assume that some of these might be a problem, but for USA (as the original article) all these things are in place and such an ID would work if it was implemented.

Re: Cybersecurity Incident Involving Consumer Information

#453
post #69

Earlier quoted context omitted.

Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity . Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such. SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could als…

The problem is that you need a replacement, something that can actually be used as a solid proof of identity. The countries that don't have comparable identity theft problems have done so mostly by using an ubiquitous government issued ID that's hard to forge and hard to obtain by someone claiming to be you. In USA there seems to be a strong opposition and a legal barrier for the government to make such an ID. Not mu…

SSN is a fine ID, but it cannot be used as authorization. I think that a government issued photo ID, such as a passport, is probably the current best bet if you require the other part to save a photocopy of it. Perhaps in this digital age you could have a system where you need to sign in with 2 factor authentication to verify any claims to authorize you.

Biometric is a very poor ID. With current technology we can fake fingerprints and iris, the two most commonly used biometrics. They also have the issue that you cannot change them, so if you do get compromised and flag it, then you cannot use that option yourself.

Re: Cybersecurity Incident Involving Consumer Information

#456
post #134
post #111

Doing some junky googling, estimates for how many Americans have a credit card sits in the ~160-180million range. In other words, when they say "143 million US customers" they really mean "the vast majority of Americans with a credit card". Astounding.

About half of the country.

Given the average US household size of 2.53 [0], this affects far more than half the country.

[0] https://www.census.gov/data/tables/2016/demo/families/cps-20...

Re: Cybersecurity Incident Involving Consumer Information

#457
post #176

Earlier quoted context omitted.

Why not just shift the presumption of liability (absent verification) to the financial institution instead of the consumer? Loan issuers can hire skilled professionals to do credit verification, so why should consumers bear the risk for their lack of due diligence?

"just" Consumers would love this. Financial institutions would not. Guess who wins this battle?

For sure, and that's precisely the problem.

Re: Cybersecurity Incident Involving Consumer Information

#458
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

There's a nice comedy sketch on this point by Mitchell & Webb: https://m.youtube.com/watch?v=CS9ptA3Ya9E

Re: Cybersecurity Incident Involving Consumer Information

#459

Earlier quoted context omitted.

For £100 you get a shiny credit rating for no risk. That'll get you a mortgage for £100,000s. In the 60s/70s it was about knowing your bank manager, so he knew you'd be able to pay. I appreciate that it probably benefited a certain type of person, but the new system probably has the same prejudices built in. Now it's all about the ephemeral and easily game-able credit score. Until a few years ago you would get negati…

> In the 60s/70s it was about knowing your bank manager, so he knew you'd be able to pay. You do recognize how terribly inefficient that is, right? In this day and age its all about scale. Expecting a bank manger to have financial profile of all the clients using his firm is impractical. For all it's faults, the credit reporting agencies are providing a service. It's not perfect and I think it's best they could do wi…

You do recognize how terribly inefficient that is, right? In this day and age its all about scale.

Is it, tho'? It is well known that IT doesn't improve productivity[1]; all the benefits of automation get swallowed up in the extra people needed to support and maintain it. So we can assume that the ratio of bank employees to bank customers has remained constant over time. So actually there's no reason for bank's not to operate the old personal-relationship model; they would need to employ the same number of staff to do it, just locate them in branches rather than at head office.

[1] http://www.computerweekly.com/opinion/McKinsey-Why-IT-does-n...

Re: Cybersecurity Incident Involving Consumer Information

#460

Earlier quoted context omitted.

> In no way was Alice's identity stolen - that's tautologically impossible. I see this as you being too strict with your definition of "identity". We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. "Stolen identity" in this sense means Alice's attributes (the ones which Big Bank uses to identify a person…

> I see this as you being too strict with your definition of "identity". > We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly…

> while it is claimed at the same time that they can be replicated by a "thief", which necessarily implies that they don't identify Alice, and hence are not an identity, therefore tautological impossibility.

Attributes can be replicated -> attributes don't identify Alice

Why do you consider this implication necessary? It sounds nonsensical.

Counterexample: to verify an identity, the verifier must possess a replication the identifying attributes. If replication implies non-identity, then identity verification becomes impossible.

Note that we're speaking of identity in the context of a technical implementation.

Post reply on HN