Earlier quoted context omitted.
I'm not sure that any country has really solved it convincingly. Sure, they do better than the US and its secret SSNs, but that doesn't say much.
I mean, countries may have national identity cards with chips and perhaps biometrics that make them hard to forge, but a) I believe there's opposition in the US to identity cards b) do they help establish identity remotely, e.g., online?
Three Years in Identity Theft Hell
91–100 of 195 posts
Re: Three Years in Identity Theft Hell
#92Earlier quoted context omitted.
Couldn't they verify the authenticity of the drivers license by contacting the department of motor vehicles? One shouldn't verify documents unless you're a member of the organization that issued them.
It was most likely a real license. Credit checks use the DL number. You need an SSN card to get a license or ID card and the SSN card is gained using security questions and has no photo, fingerprints or biometrics associated with it. I remember needing to get a new SSN card once and it was creepy how easy it was.
Re: Three Years in Identity Theft Hell
#93Re: Three Years in Identity Theft Hell
#94Earlier quoted context omitted.
What if you have no cell phone or computer?
At this point, cell phone is a necessity in India to get any services. Mobile subscriber base is about 1.1 billion (1) which means almost all adults have a cell phone connection. So the question is practically moot. (1) https://www.google.com.sg/amp/m.timesofindia.com/business/in...
Re: Three Years in Identity Theft Hell
#95Earlier quoted context omitted.
I guess you leave your front door open every morning before leaving for work?
I leave my house unlocked. If not, everyone around knows where the key is. Of course, this isn't something I suggest you do. It's certainly not practical for most people. I mention it only to show that there are varied security needs. On this particular subject, my credit has been frozen since the OPM breech.
the day you get robbed, it will absolutely make a difference for whoever insure your house and its content.
Re: Three Years in Identity Theft Hell
#96Earlier quoted context omitted.
The big problem is switch from SSN to what? Just another number that serves the same purpose? SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere. We don't need to make identity theft impossible just reasonably hard. Other nations seem to ha…
All they need is an ssn you can change if it gets stolen. To change it all that's needed is to go into a government office and do a biometric scan in person. That would be so ridiculously easy. Of course the government will never let a good crisis go to waste. Instead, we will all get chips under our skin that can't be removed that will be passively scanned by the authorities everywhere we go.
The entire problem is that people started using SSN as a shared secret, but it was classic password reuse. Use the same secret every fucking where.
No. If you want to establish trust, use a random secret for each new trust relationship.
If you want to establish identity ask the identity providers what kind of anti-forgery guarantees they provide. Oh, nothing, you say!? Then don't use that provider.
Banks are trying to use easy to forge things to make sure they won't lose money. Sounds like stupidity. So they limit their stupidity (hence you can't just register for a credit card online, otherwise bored Russian teenagers would have already bankrupted them).
Re: Three Years in Identity Theft Hell
#97Earlier quoted context omitted.
All they need is an ssn you can change if it gets stolen. To change it all that's needed is to go into a government office and do a biometric scan in person. That would be so ridiculously easy. Of course the government will never let a good crisis go to waste. Instead, we will all get chips under our skin that can't be removed that will be passively scanned by the authorities everywhere we go.
SSN is a primary key, not a shared secret. The entire problem is that people started using SSN as a shared secret, but it was classic password reuse. Use the same secret every fucking where. No. If you want to establish trust, use a random secret for each new trust relationship. If you want to establish identity ask the identity providers what kind of anti-forgery guarantees they provide. Oh, nothing, you say!? Then…
Re: Three Years in Identity Theft Hell
#98Earlier quoted context omitted.
The flaw in your logic is that you fail to realize i have access to 143 million bank accounts and can transfer any number of ways I want to. You also overestimate the competence of smaller banks. Neglecting all of that you do realize that International wire transfers do exist right?
It takes 1-3 business days for a US bank to transfer any amount and I am sure it will be even higher if the transaction is not matching a usual pattern of your victim. So 144 million bank accounts mean nothing with such long processing delays
Australia, NZ, Singapore, most EU countries all have instant person-to-person transfers with little to no fees and supported via the government. 500 euro can be gone like that. Poof. But it's all within the same country. And when it's within the same country, it's traceable, reversible and enforceable by law.
So the 1-3 business days isn't where the protection is at. It's the way we mark and track transactions. The real danger, is SWIFT transfers. Once that money leaves the country, it's very unlikely you'll ever see it again.
[1]: http://penguindreams.org/blog/the-american-banking-system-is...
Re: Three Years in Identity Theft Hell
#99I had my "identity" stolen by someone who tried to open accounts at local banks after somehow managing to swipe a copy of my drivers license (from our mail box, as far as we know) and seemingly only was able to rent a Uhaul in my name (unbeknownst to me until I tried to rent one to move). The banks kicked him back and he tried forging checks from others (not me). I filed the reports with the police. And checked my cr…
You just got lucky and caught it early.
Re: Three Years in Identity Theft Hell
#100Earlier quoted context omitted.
SSN is a primary key, not a shared secret. The entire problem is that people started using SSN as a shared secret, but it was classic password reuse. Use the same secret every fucking where. No. If you want to establish trust, use a random secret for each new trust relationship. If you want to establish identity ask the identity providers what kind of anti-forgery guarantees they provide. Oh, nothing, you say!? Then…
What if, when you replaced your SSN, banks could use a system that would return "invalid SSN" on any new credit application. The existing accounts would be suspended unless you called them and updated your SSN. It would be about as much as a hassle as updating all of one's autopays when a credit card number gets stolen.
They shouldn't even ask for it.
Currently fraud is held back by law enforcement. Which is triggered by fraud detection. Which is triggered when the wrong person gets a call from a collections agency.
And this chain of events is too long, but since there's no global (national) system to check if someone is a professional scam artist or a regular bloke, that's what banks are left with.