Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

51–60 of 195 posts

Re: Three Years in Identity Theft Hell

#51
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.

India is switching to biometric verification linked to the national identity card. The last lease agreement I registered and the last phone connection I obtained both went through the biometric verification process

These are implemented as biometric two factor auth. So you show your id card, scan your finger print and validate via a code received to the registered mobile device on sms

Re: Three Years in Identity Theft Hell

#52

Earlier quoted context omitted.

Other countries have the equivalent of SSNs, i.e., a number issued by the government tax collector. However, other countries don't use it as a form of ID. In my experience, they use passports, ID cards, drivers licenses, etc., which are supposedly "hard to forge".

It's not just hard to forge: tgey expire often and change code frequently sp the exploytable window is smaller than for the quasi permanent ssn

Perhaps true to some extent, but a passport can last 10 years, which is plenty of time for identity theft.

Re: Three Years in Identity Theft Hell

#53

Earlier quoted context omitted.

The pin code they will give you to unlock it is the date/time stamp of when you locked it. And, if you happen to forget it, they will unlock it if you can cough up the very information supposedly compromised in the equifax leak anyway.

> And, if you happen to forget it, they will unlock it if you can cough up the very information supposedly compromised in the equifax leak anyway. Wait, what? Any more reading on this?

Here's the link to "obtain your forgotten or misplaced PIN". https://www.experian.com/ncaconline/freezepin And it says, "provide your e-mail address for faster delivery of your results."

Re: Three Years in Identity Theft Hell

#54

Earlier quoted context omitted.

These systems don't work well remotely, of course. Sometimes an organisation will accept an upload of a scan or a mailing of a photocopy. They sometimes require it to be signed by a somebody to verify that it's genuine (e.g., a Justice of the Peace). But by doing that, the "hard to forge" feature is lost entirely.

They do use a scan or a photocopy, but having that stored it is easier to check the identity of the real person once they claim there was identity theft.

The "verified photocopies" can be a bit of a joke. I know somebody who was having trouble finding enough ID for something. They printed an online bank statement, photocopied it, and got a JP to verify the photocopy against the original printout.

Re: Three Years in Identity Theft Hell

#55
post #47

Earlier quoted context omitted.

How would a more secure system work? Biometrics? Smart cards?

> How would a more secure system work? Just look what many other countries do.

I'm not sure that any country has really solved it convincingly. Sure, they do better than the US and its secret SSNs, but that doesn't say much.

Re: Three Years in Identity Theft Hell

#56
post #47

Earlier quoted context omitted.

> How would a more secure system work? Just look what many other countries do.

I'm not sure that any country has really solved it convincingly. Sure, they do better than the US and its secret SSNs, but that doesn't say much.

I mean, countries may have national identity cards with chips and perhaps biometrics that make them hard to forge, but a) I believe there's opposition in the US to identity cards b) do they help establish identity remotely, e.g., online?

Re: Three Years in Identity Theft Hell

#57

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The big problem is switch from SSN to what? Just another number that serves the same purpose?

SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere.

We don't need to make identity theft impossible just reasonably hard. Other nations seem to have it figured out.

Re: Three Years in Identity Theft Hell

#58
post #8

I submitted this like 2 days ago :D https://news.ycombinator.com/item?id=15247810

Sometimes things get attention and sometimes they don't. Also sometimes it's a slow news weekend and other times there's a ton happening. Don't ever stress about whether your submission gets traction.

No worries man, m just sayin

Re: Three Years in Identity Theft Hell

#59

Earlier quoted context omitted.

I'm not sure that any country has really solved it convincingly. Sure, they do better than the US and its secret SSNs, but that doesn't say much.

I mean, countries may have national identity cards with chips and perhaps biometrics that make them hard to forge, but a) I believe there's opposition in the US to identity cards b) do they help establish identity remotely, e.g., online?

You can activate German ID cards to work as RFID smartcards for online identification. Practically, there aren't all that many places to do it, and not many people do so. You also need a smartcard reader, but those were available reasonably cheap (no idea if a smartphone with NFC can do it or not)

(You also can have a certificate on it, but they missed an opportunity and didn't make it default, you have to ask for and pay extra for that. Would have been a chance to widely roll out certificates of the standard necessary to legally replace signatures, instead of other crap that has been proposed as a replacement sigh)

Re: Three Years in Identity Theft Hell

#60
post #57

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The big problem is switch from SSN to what? Just another number that serves the same purpose? SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere. We don't need to make identity theft impossible just reasonably hard. Other nations seem to ha…

All they need is an ssn you can change if it gets stolen. To change it all that's needed is to go into a government office and do a biometric scan in person. That would be so ridiculously easy.

Of course the government will never let a good crisis go to waste. Instead, we will all get chips under our skin that can't be removed that will be passively scanned by the authorities everywhere we go.

Post reply on HN