Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

71–80 of 195 posts

Re: Three Years in Identity Theft Hell

#71
post #14
post #12

Earlier quoted context omitted.

It does follow. Not locking your house is not going to cause massive harm. If somebody really wants to get in, they will do itm

I guess you leave your front door open every morning before leaving for work?

I leave my house unlocked. If not, everyone around knows where the key is.

Of course, this isn't something I suggest you do. It's certainly not practical for most people. I mention it only to show that there are varied security needs. On this particular subject, my credit has been frozen since the OPM breech.

Re: Three Years in Identity Theft Hell

#72
post #71
post #14

Earlier quoted context omitted.

I guess you leave your front door open every morning before leaving for work?

I leave my house unlocked. If not, everyone around knows where the key is. Of course, this isn't something I suggest you do. It's certainly not practical for most people. I mention it only to show that there are varied security needs. On this particular subject, my credit has been frozen since the OPM breech.

Yeah, that’s the problem when we start arguing with analogies. Things can get derailed easily. Mea culpa.

Re: Three Years in Identity Theft Hell

#73
post #39

Earlier quoted context omitted.

In Canada you can't do anything meaningful without a photo driver's license or a passport. My wife got a passport just to have a quality ID. Before that she couldn't even open a chequing account.

That's not entirly true. The branch manager has discression. I know because when I first moved to Canada I had no such ID and opened an account after asking for the branch manager.

How did you not have a passport when you first moved to Canada? How did you get into the country?

Re: Three Years in Identity Theft Hell

#74
post #64
post #61

So how does one protect against this if freezing is useless because all that information was leaked anyway?

Freezing doesn't protect the information, but it does protect your credit account from being added to. Once frozen, you are almost in a 2FA scenario where creditors are required to request any new accounts or credit hits, and the credit agency is required to then obtain your approval using the private information only you (should) know.

Freezing doesn't protect the information, but it does protect your credit account from being added to.

Going to take the liberty of adding to this because the imprecision might cause some people to develop a poor model of how financial institutions work: you don't have a "credit account." You have a few firms which have partial views of your "credit history", sourced by reports from some firms you've previously done business with before. What a freeze does is that those firms (CRAs) who could disclose your credit history to a bank will, instead, report to the bank "That file is frozen."

How is this different from your mental model? Because credit decision is between a financial institution and a bank -- they don't have to ask anyone else's permission, including the CRA, to lend you money. They also don't have to "respect" a freeze on your file; it's purely advisory. It may deter _some_ banks from issuing you _some_ credit but it will likely not deter _all_ banks from issuing you _all_ credit products.

Re: Three Years in Identity Theft Hell

#75

Earlier quoted context omitted.

I'm not sure that any country has really solved it convincingly. Sure, they do better than the US and its secret SSNs, but that doesn't say much.

I mean, countries may have national identity cards with chips and perhaps biometrics that make them hard to forge, but a) I believe there's opposition in the US to identity cards b) do they help establish identity remotely, e.g., online?

The Netherlands has an OAuth system for online identity verification, called DigiD, for anything government-related (taxes, healthcare, etc.) Other than that, occasionally a service asks for a copy of your passport, although that's not really allowed.

Re: Three Years in Identity Theft Hell

#76
post #67

Earlier quoted context omitted.

It takes 1-3 business days for a US bank to transfer any amount and I am sure it will be even higher if the transaction is not matching a usual pattern of your victim. So 144 million bank accounts mean nothing with such long processing delays

Tell that to all the banks that had been sued for millions for losses due to phishing attacks. My mom's bank was one of them. The criminals got the money out successfully somehow.

It does not mean they were not caught later by bank insurance company

Re: Three Years in Identity Theft Hell

#77
post #68
post #51

Earlier quoted context omitted.

India is switching to biometric verification linked to the national identity card. The last lease agreement I registered and the last phone connection I obtained both went through the biometric verification process These are implemented as biometric two factor auth. So you show your id card, scan your finger print and validate via a code received to the registered mobile device on sms

What if you have no cell phone or computer?

At this point, cell phone is a necessity in India to get any services. Mobile subscriber base is about 1.1 billion (1) which means almost all adults have a cell phone connection. So the question is practically moot.

(1) https://www.google.com.sg/amp/m.timesofindia.com/business/in...

Re: Three Years in Identity Theft Hell

#78
post #43

Earlier quoted context omitted.

To confirm your identify: national ID card, passport or driver license. To confirm your income: Your yearly income tax sheet, a payslip or your contract of employment. There is really no reason whatsoever for credit check and background check agencies to exist. All they do is ask for these papers anyway.

It's worth noting that the perpetrator in the bloomberg article had a fake driver's license in the name of the victim. So ID cards aren't a complete solution either.

But you get that ID card using an SSN card. Other countries have a photo attached to your nation ID card and citizen identification number (and sometimes fingerprints too).

But think about America right now. Do you honestly think we could get national ID numbers? Could you imagine people being asked for a DNA swab or fingerprint to establish their identity? The blow black would be monstrous, and I don't think it'd be entirely unjustified. With 1% of our population incarcerated or on probation, with no national health care and being the largest state sponsor of terrorism in the world, there is good reason for Americans not to trust their government. Add in all the fundie religious people crying "sign of the beast" and Alex Jones followers yelling "national RFID chips" and you're stuck with a situation that cannot change.

Re: Three Years in Identity Theft Hell

#79
post #66
post #43

Earlier quoted context omitted.

It's worth noting that the perpetrator in the bloomberg article had a fake driver's license in the name of the victim. So ID cards aren't a complete solution either.

Couldn't they verify the authenticity of the drivers license by contacting the department of motor vehicles? One shouldn't verify documents unless you're a member of the organization that issued them.

It was most likely a real license. Credit checks use the DL number. You need an SSN card to get a license or ID card and the SSN card is gained using security questions and has no photo, fingerprints or biometrics associated with it.

I remember needing to get a new SSN card once and it was creepy how easy it was.

Re: Three Years in Identity Theft Hell

#80
> “We demand convenience over security,” Velasquez said.

Banks send a constant stream of credit card offers through the mail and pay people to use credit cards (with rewards). Stores are always trying to get you to sign up for their credit cards and offering big discounts if you do, and car dealerships offer special deals - but only if you agree to finance your car. People might want more credit, but lets be honest - the financial industry is doing everything it can to shovel debt onto the American public.

Imagine if a loan shark went door to door in a neighborhood paying residents $500 to take one of his loans. That seems almost cartoonishly evil, but that's more or less what the financial industry does. And it's not hard to see why - the average credit card has an annual interest rate of 15%. Even after you factor in things rewards and people who don't pay, you're still looking at a very nice rate of return.

It's hard to see how identity theft isn't directly linked to financial institutions trying to make credit as easily available and as widespread as possible. Instead of viewing identity theft as a high price to pay for the convenience we want, it should be viewed as yet another terrible consequence of the financial industry's efforts to push as much debt onto Americans as they can.

Post reply on HN