Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

101–110 of 195 posts

Re: Three Years in Identity Theft Hell

#101
post #95
post #71

Earlier quoted context omitted.

I leave my house unlocked. If not, everyone around knows where the key is. Of course, this isn't something I suggest you do. It's certainly not practical for most people. I mention it only to show that there are varied security needs. On this particular subject, my credit has been frozen since the OPM breech.

> I leave my house unlocked. If not, everyone around knows where the key is. the day you get robbed, it will absolutely make a difference for whoever insure your house and its content.

If someone around here takes something, they needed it more than I did. I live way out in an unincorporated township. People aren't inclined to steal when they know I'd just help them out if they need me to.

It's pretty great to live here. The only crime in my area is growing weed and that's now legal.

Re: Three Years in Identity Theft Hell

#102

I had my "identity" stolen by someone who tried to open accounts at local banks after somehow managing to swipe a copy of my drivers license (from our mail box, as far as we know) and seemingly only was able to rent a Uhaul in my name (unbeknownst to me until I tried to rent one to move). The banks kicked him back and he tried forging checks from others (not me). I filed the reports with the police. And checked my cr…

In every discussion about some social ill or technical issue, there's always the person that says, "it works for me."

That person is never helpful to the discussion.

A single anecdote of good fortune carries exactly as much weight as a single anecdote of misfortune.

Re: Three Years in Identity Theft Hell

#103
My solution is make a site called credit.gov

This would be the final say in any credit accounts, accounts not listed here are not legal debt (ie they cannot be collected or sued for)

You can still use SSN for identification but authorization would require more. I imagine maybe a few different levels of security:

1. Password (or list of passwords) you can set/change in person at any post office. The company adding the credit account would need this password to register the debt.

2. Yubikey or other auth token you can register at the post office to create one time passwords for companies creating credit accounts.

3. Every new credit account requires physical confirmation at the post office.

Then just setup really good cameras (maybe face scanner or biometric scanner) at every post office and make it like a 10 year felony to impersonate someone at the post office. The scammers will be out of the system very quickly.

Re: Three Years in Identity Theft Hell

#104
Why is this only a problem in the US?

I think that one of the reasons is that the US does not have a central government registry of all the people.

In Austria, we have the „Melderegister“. Every person that stays in Austria is required to register the address of their current residence. Your name and address is always in this registry, from the day you are born until you die (foreigners residing in Austria are also required to register).

Everything relies on this registry — voting rights, taxes, etc.

I think that Banks can check this register to verify your address. So even if an identity thief is successful in applying for a credit card, that credit card would be mailed to the victims actual address, so the identity thief would have to intercept postal mail as well.

So many problems that I read about in the US (using utiliy bills to proof you are a resident, registering to vote) just sound like a clumsy workaround to the fact that there is no „Melderegister“.

Re: Three Years in Identity Theft Hell

#105

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

I think I've seen you defending Equifax on every post related to identity theft since the breach. Do you work there or something, why are you so invested in this?

Re: Three Years in Identity Theft Hell

#106

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The SSN shouldn't be the critical key in that list.

So it would a "Credit ID," Passport Number, DL #, or something related. What's the difference, it will need to be stored next all your stuff, awaiting to be stolen. Now the banks eat the small % caused by fraud (cost of doing biz), your life is hell, but not theirs.

Scan your iris before getting the new loan isn't going to happen either, too costly and slow. If they ever do that online, they'll find a way to recreate that based on your existing scan, stored at the future Experian.

Re: Three Years in Identity Theft Hell

#107
post #58

Earlier quoted context omitted.

Sometimes things get attention and sometimes they don't. Also sometimes it's a slow news weekend and other times there's a ton happening. Don't ever stress about whether your submission gets traction.

No worries man, m just sayin

It might be worth reading Dang's comment history discussing reposts: https://hn.algolia.com/?query=dang%20porous&sort=byPopularit...

It feels shitty when someone else gets the points for something you submitted earlier, but life isn't always fair, and as long as you keep submitting good content and making good comments, things even out in the end.

Re: Three Years in Identity Theft Hell

#108
post #67

Earlier quoted context omitted.

It takes 1-3 business days for a US bank to transfer any amount and I am sure it will be even higher if the transaction is not matching a usual pattern of your victim. So 144 million bank accounts mean nothing with such long processing delays

One of the few instances where American Banking still being in the 1990s is a benefit[1] .. but not really. Australia, NZ, Singapore, most EU countries all have instant person-to-person transfers with little to no fees and supported via the government. 500 euro can be gone like that. Poof. But it's all within the same country. And when it's within the same country, it's traceable, reversible and enforceable by law. S…

Payments are immediate between countries too. On my vacation in Armenia (you know, former USSR and a pretty poor country) I paid in the supermarket with my Dutch debit card (chip with PIN), I immediately popped my phone and opened the banking app for my (small, Dutch local) bank, and it showed the withdrawal.

Re: Three Years in Identity Theft Hell

#109
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

Other countries have the equivalent of SSNs, i.e., a number issued by the government tax collector. However, other countries don't use it as a form of ID. In my experience, they use passports, ID cards, drivers licenses, etc., which are supposedly "hard to forge".

More importantly, we can 2FA from my id number to my address because there is a db mapping from id to post address.

With a locked mailbox (which is the default) it becomes a hassle to steal an identity.

If I get a new credit card it's sent to the address I id'd for.

Re: Three Years in Identity Theft Hell

#110

Earlier quoted context omitted.

Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.

To confirm your identify: national ID card, passport or driver license. To confirm your income: Your yearly income tax sheet, a payslip or your contract of employment. There is really no reason whatsoever for credit check and background check agencies to exist. All they do is ask for these papers anyway.

We have national id + complete index of people, but still have credit check agencies.

The difference is probably that here those agencies aren't somehow trying to guarantee my identity. They just answer what credit rating my identity has.

Post reply on HN