Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

111–120 of 195 posts

Re: Three Years in Identity Theft Hell

#111
post #9

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

> Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. This argument doesn't not follow logically. It's like saying you shouldn't lock your house because if somebody really wants to get in, they will do it.

The difference between breaking into a house and hacking into a machine is that a burglar can only break into so many houses and has a significant risk of getting caught. A hacker can get into an almost unlimited number of machines and is unlikely to risk any retaliation.

As a result you have the equivalent of dozens of people trying to pick the lock of your door every day, and the law can't do much to stop it. That requires you to pay f*ing attention to the quality of your lock.

Re: Three Years in Identity Theft Hell

#112
post #39

Earlier quoted context omitted.

That's not entirly true. The branch manager has discression. I know because when I first moved to Canada I had no such ID and opened an account after asking for the branch manager.

How did you not have a passport when you first moved to Canada? How did you get into the country?

Until 2008, US citizens didn't need a passport to enter Canada. What initially changed in 2008 was actually that you needed the passport to return back to the US.

I don't know what the rules were back then for moving to Canada, but you could stay 180 days at a time back then.

Re: Three Years in Identity Theft Hell

#113

Earlier quoted context omitted.

It's not just hard to forge: tgey expire often and change code frequently sp the exploytable window is smaller than for the quasi permanent ssn

Perhaps true to some extent, but a passport can last 10 years, which is plenty of time for identity theft.

If your identity gets stolen you get new passport with new number and put old one into stolen document database.

Cannot do this with SSN.

Re: Three Years in Identity Theft Hell

#114
post #57

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The big problem is switch from SSN to what? Just another number that serves the same purpose? SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere. We don't need to make identity theft impossible just reasonably hard. Other nations seem to ha…

Don't switch from SSN. Just accept that they are public identifiers and ensure 1) everyone has access to photo ID with that SSN and 2) an authority can lookup addresses from SSN to perform 2FA.

This means everyone in the US has to accept national ID.

(It could theoretically be done at state level but it would be a huge hassle compared to national, and your tax authority and others are already national and need to know every person that lives in the country).

Basically you need to trust the federal government to solve your ID problem. And if the answer to that is "Whoa that won't happen, people won't accept national anything" then the simple answer is you'll keep being subjected to ID theft.

Why is chip & pin a bullet to bite? Isn't that just better for all parties involved?

Re: Three Years in Identity Theft Hell

#115

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The SSN shouldn't be the critical key in that list. So it would a "Credit ID," Passport Number, DL #, or something related. What's the difference, it will need to be stored next all your stuff, awaiting to be stolen. Now the banks eat the small % caused by fraud (cost of doing biz), your life is hell, but not theirs. Scan your iris before getting the new loan isn't going to happen either, too costly and slow. If they…

I haven't seen password I'd or national card I'd used as identification, ever. The way it works is that you bring it physically and they look into it. Or that you send photo of the id (yes that is easier to forge, then again harder then forging utility bill) - that is done only where it is impossible to do physical check and never with loans and such.

Identity theft in Europe is extremely rare. It is possible to do something in your name, sure, but it does not happen nowhere near as often and damage is limited compared to ssn system.

Re: Three Years in Identity Theft Hell

#116

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

Hate to break it to you, but with very minimal browsing and $4 in bitcoin, anyone can buy any SSN of a US person born after 2003.

Re: Three Years in Identity Theft Hell

#117
post #116

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

Hate to break it to you, but with very minimal browsing and $4 in bitcoin, anyone can buy any SSN of a US person born after 2003.

anyone can buy any SSN of a US person born after 2003.

Why only 14-year-olds and younger?

Re: Three Years in Identity Theft Hell

#118
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.

In Belgium we have a national ID card which has a pin-protected chip and is required for all government and bank interaction. It is very hard to forge, and through a usb card reader I can use it for digital authentication (like for filing my taxes on the web). Getting one issued in the case of loss requires interacting with the police, so the threshold to someone fraudulently obtaining a real card in someone else's name is high.

Identity theft isn't something I hear about often here.

Re: Three Years in Identity Theft Hell

#119
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.

In Germany, my ID might be a form of identification but only in association with the person in question, the ID's number or data itself is not considered identifying by a few institutions (postal service, banks, etc; you always need physical presence for identification or use post-ident)

The ID is government issued, cheap to obtain in case of loss (30€ and a bit of waiting until the new one arrives) and contains a photo of you so it's of no particular value to someone who doesn't look like you.

IIRC identity theft isn't a huge problem in Germany but it exists, however most credit agencies offer options to lock down or delete data concerning such theft, I haven't interacted with any of them yet though.

Re: Three Years in Identity Theft Hell

#120
post #116

Earlier quoted context omitted.

Hate to break it to you, but with very minimal browsing and $4 in bitcoin, anyone can buy any SSN of a US person born after 2003.

anyone can buy any SSN of a US person born after 2003. Why only 14-year-olds and younger?

Because the kids these days will enter their SSN and their parent's Credit Card into anything that looks like flappy bird to unlock the extra jump boost or something like that.
Post reply on HN