Live data from Hacker News

Equifax’s Maddening Unaccountability

nytimes.com

181–190 of 238 posts

Re: Equifax’s Maddening Unaccountability

#181
post #105

Earlier quoted context omitted.

At some level I think the banks are stuck in a conflict of interest with regard to risk. The reason we need banks and credit agencies is precisely because there is risk . If transacting parties could trust each other without an intermediary we could all just trade directly and all would be fine. So banks are actually disincentivised to create a world where risk is very low. They also don't want it to be very high. Th…

I suppose at a very high level your thesis might be true, but at a practical level, I don't think it is. The banks have simply seen it's cheaper to eat the cost of fraud (and ensure the victim has the burden of proof wherever possible) than implement stricter security measures. This goes from the transaction terminal to the bank's server room. Europe has had chip cards for over 20 years. In the US, it was very recent…

And even after pushing out chip reader terminals and cards with chips, banks in the US refuse to institute mandatory PIN code entry on all payments with the chip - as its everywhere in Europe. So nothing really changed.

Re: Equifax’s Maddening Unaccountability

#182

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

Part of it is that even the name of the crime Identity Theft insidiously paints it as something purely between the thief and the end consumer, whose identity was "stolen". Alice stole Bill's identity! But where is the company she stole it from? Where is the bank where she fraudulently used this information? These corporations' lack of accountability is built directly into the name we use for the crime! It's as if the…

The bank the identity thief borrows from does suffer and is the one on the hook for the money at the end of the day. So they are kind of accountable. It's the leakers like Equifax that are not.

Re: Equifax’s Maddening Unaccountability

#183

Earlier quoted context omitted.

I heard in US if somebody knows your SSN, he can take a loan accounted to you by phone. It is so strange. What gives banks right to do that?

There is a huge difference between taking a loan "on someone's behalf" (as their representative, eg by someone with power-of-attorney) versus via impersonating them. The former is rare but legitimate; the latter is fraud.

Yes and outside of the US nobody would be able to do a loan with a power-of-attorney without showing evidence of it

Re: Equifax’s Maddening Unaccountability

#184

Earlier quoted context omitted.

Can confirm. I bought a car last week in California with cash. Dealer did a credit check. The system is rotten and (short of moving country) impossible to avoid.

FYI dealers do this because they want to be able to offer you financing if your check bounces. It's also a way to ensure that you go through with the transaction because now your credit is worse and going somewhere else would lead to worse financing. Put a freeze on your accounts with the credit bureaus before you get serious about buying a car with cash. Tell them that they may not do a "hard pull" against your cred…

I have low patience with salesman who prefer to BS me with credit when I have the cash available

Re: Equifax’s Maddening Unaccountability

#186
post #52

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

We have all agreed. We gave permission to any company that extends credit. They give our information to these credit reporting agencies on an on-going basis, personal information, including what our payment behavior and history is. All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very sim…

We don't trust them. We are forced to say we do, because the other option (to go without all the services gated on that answer) is so uncomfortable as to be non-viable for most.

Re: Equifax’s Maddening Unaccountability

#187

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

The credit system sucks. But has anybody created a better alternative yet?

Most countries don't have credit scores at all.

There's typically a single public entity that holds insolvency records within the legal framework. In some countries nobody can query it but yourself; you're therefore asked to submit a copy of your record in some occasions.

As for solvency, when you sign a lease or contract a mortgage, you're asked to submit proof of income.

(Someone mentioned Germany earlier, it's a terrible example in my opinion, Schufa isn't much different than the US credit agencies, albeit more accountable hopefully).

Re: Equifax’s Maddening Unaccountability

#188
post #154

The author likens this to automotive safety, but I think a better analogy would be airline safety. When an airplane goes down, an immediate investigation is done by third parties to find the cause. Then remedial steps are drawn up and the entire industry is expected to follow them, not just the company involved in the accident. Data breaches need to be held to this standard.

This is a great idea I'm afraid will never happen.

I don't know. One airline disaster is arguably less economically destructive than this breach. It could end a $70B company, or lead to a bailout, or ruin credit application processes for years causing the US economy to stumble.

Nothing makes things change faster than disrupting the money flow.

Re: Equifax’s Maddening Unaccountability

#189
post #119

Earlier quoted context omitted.

The credit system sucks. But has anybody created a better alternative yet?

Yes, many times. It is not that hard to not base your entire banking system on a single number anyone can use .

What gives banks right to consider SSN an authenticator?

Is there a law allowing that?

Common sense suggests it should only be possible if user explicitly accepted "I agree that knowing my SSN is enough to prove it's me and I agree to be liable to any debts created with just my SSN presented".

Re: Equifax’s Maddening Unaccountability

#190
post #105

Earlier quoted context omitted.

At some level I think the banks are stuck in a conflict of interest with regard to risk. The reason we need banks and credit agencies is precisely because there is risk . If transacting parties could trust each other without an intermediary we could all just trade directly and all would be fine. So banks are actually disincentivised to create a world where risk is very low. They also don't want it to be very high. Th…

I suppose at a very high level your thesis might be true, but at a practical level, I don't think it is. The banks have simply seen it's cheaper to eat the cost of fraud (and ensure the victim has the burden of proof wherever possible) than implement stricter security measures. This goes from the transaction terminal to the bank's server room. Europe has had chip cards for over 20 years. In the US, it was very recent…

Well here in europe it didn't happen all at once. It was a gradual rolling of chip based cards, atms and terminals. There was a non-insignificant amount of time where some atms / pos terminals would reject your card because you/it didn't have the right technology.

But ultimately I think its the people themselves that demand more security from their banks. E.g. Bank one introduces chip based cards and more people choose that bank because they want more security. Then gradually some atms start to be "chip only", and banks start to see the chipless ones get all the skimmers and accelerate their replacement to lower costs which forces business to atart getting more pos terminals with chips to meet the demand of people with cards that have mag strip disabled.

Having more security seems to be what everybody wants and benefits from, its just that europe has smaller players which accelerates market forces in that direction, and meybe because european consumers just want more security in general.

Post reply on HN