Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

21–30 of 195 posts

Re: Three Years in Identity Theft Hell

#21
post #14
post #12

Earlier quoted context omitted.

It does follow. Not locking your house is not going to cause massive harm. If somebody really wants to get in, they will do itm

I guess you leave your front door open every morning before leaving for work?

We are talking about leaving door unlocked, not leaving the door open. I lock the door every morning out of habit but I'm pretty sure its unlikely that something happen if I don't.

Re: Three Years in Identity Theft Hell

#22

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

How would a more secure system work? Biometrics? Smart cards?

Re: Three Years in Identity Theft Hell

#23

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

>the US will have no choice [but to switch to a better, non-SSN based system]

I absolutely hope this happens too...

... but I have a feeling all of the banks and agencies involved will find a way to plug their ears more and pretend nothing is wrong.

They will look at how costly and complex it is to create a halfway decent identity system (even though it's really not hard, other countries do it just fine with digital and physical keys/tokens).

And they will just continue to push the burden of ID theft onto consumers, rather than their businesses.

Re: Three Years in Identity Theft Hell

#24
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.

In Canada you can't do anything meaningful without a photo driver's license or a passport. My wife got a passport just to have a quality ID. Before that she couldn't even open a chequing account.

Re: Three Years in Identity Theft Hell

#25
post #4

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

Other countries have the equivalent of SSNs, i.e., a number issued by the government tax collector. However, other countries don't use it as a form of ID. In my experience, they use passports, ID cards, drivers licenses, etc., which are supposedly "hard to forge".

Re: Three Years in Identity Theft Hell

#26
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

Other countries have the equivalent of SSNs, i.e., a number issued by the government tax collector. However, other countries don't use it as a form of ID. In my experience, they use passports, ID cards, drivers licenses, etc., which are supposedly "hard to forge".

These systems don't work well remotely, of course. Sometimes an organisation will accept an upload of a scan or a mailing of a photocopy. They sometimes require it to be signed by a somebody to verify that it's genuine (e.g., a Justice of the Peace). But by doing that, the "hard to forge" feature is lost entirely.

Re: Three Years in Identity Theft Hell

#27
post #21
post #14

Earlier quoted context omitted.

I guess you leave your front door open every morning before leaving for work?

We are talking about leaving door unlocked, not leaving the door open. I lock the door every morning out of habit but I'm pretty sure its unlikely that something happen if I don't.

I don't know what you are trying to argue about, but somebody got hold of personal details, SSN and credit card details of 140 million people.

The argument that it is ok, because anyway if somebody wanted it really hard they would find a way to get my personal details, is illogical.

Re: Three Years in Identity Theft Hell

#28
post #9

Earlier quoted context omitted.

> Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. This argument doesn't not follow logically. It's like saying you shouldn't lock your house because if somebody really wants to get in, they will do it.

It does. Locking your house provides some security. But it would no longer provide security if every person in the country had a copy of your key.

One of us missed the point.

Re: Three Years in Identity Theft Hell

#29

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

This logic is so impressively bad I don't know where to begin. Okay how about this, I'm going to pretend I lack morals for a second.

I would do this with the information:

1. Write a script to webscrape sites like LinkedIn to find out if a name/address/ssn key could be tied to people like doctors, engineers and whoever else might have sufficient disposable income.

2. I would take out loans in their name. If I have to be there in person, I would go from city to city and find people I could easily get dirt on, like people that might be here illegally. I would then cut them in for a piece of the loan and then move onto a random city in a 200 mile radius.

3. Move away after I get away with enough to live on for the rest of my life.

4. Hell I might just sell the rest of the information and scripts to other people who lack scruples.

Re: Three Years in Identity Theft Hell

#30

Earlier quoted context omitted.

Other countries have the equivalent of SSNs, i.e., a number issued by the government tax collector. However, other countries don't use it as a form of ID. In my experience, they use passports, ID cards, drivers licenses, etc., which are supposedly "hard to forge".

These systems don't work well remotely, of course. Sometimes an organisation will accept an upload of a scan or a mailing of a photocopy. They sometimes require it to be signed by a somebody to verify that it's genuine (e.g., a Justice of the Peace). But by doing that, the "hard to forge" feature is lost entirely.

They do use a scan or a photocopy, but having that stored it is easier to check the identity of the real person once they claim there was identity theft.
Post reply on HN