Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

121–130 of 195 posts

Re: Three Years in Identity Theft Hell

#121

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The SSN shouldn't be the critical key in that list. So it would a "Credit ID," Passport Number, DL #, or something related. What's the difference, it will need to be stored next all your stuff, awaiting to be stolen. Now the banks eat the small % caused by fraud (cost of doing biz), your life is hell, but not theirs. Scan your iris before getting the new loan isn't going to happen either, too costly and slow. If they…

> So it would a "Credit ID," Passport Number, DL #, or something related. What's the difference, it will need to be stored next all your stuff, awaiting to be stolen.

It should not be a passport number or driver's license number. It should be the original, physical passport or driver's license that you present in person. The physical object is much harder to steal or copy, and can be revoked.

You should not be able to open credit lines or accounts with a business without appearing at least once in person first.

Re: Three Years in Identity Theft Hell

#122

Earlier quoted context omitted.

Other countries have the equivalent of SSNs, i.e., a number issued by the government tax collector. However, other countries don't use it as a form of ID. In my experience, they use passports, ID cards, drivers licenses, etc., which are supposedly "hard to forge".

These systems don't work well remotely, of course. Sometimes an organisation will accept an upload of a scan or a mailing of a photocopy. They sometimes require it to be signed by a somebody to verify that it's genuine (e.g., a Justice of the Peace). But by doing that, the "hard to forge" feature is lost entirely.

Ukraine is experimenting and slowly rolling out an oauth-like system called BankID, where you bank can provide information to third party.

Re: Three Years in Identity Theft Hell

#123
post #9

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

> Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. This argument doesn't not follow logically. It's like saying you shouldn't lock your house because if somebody really wants to get in, they will do it.

It sounds like he's saying "don't worry about getting fucked by the Equifax breach; you were fucked already." Which certainly isn't reassuring, whether or not it's true.

Re: Three Years in Identity Theft Hell

#124

Earlier quoted context omitted.

The SSN shouldn't be the critical key in that list. So it would a "Credit ID," Passport Number, DL #, or something related. What's the difference, it will need to be stored next all your stuff, awaiting to be stolen. Now the banks eat the small % caused by fraud (cost of doing biz), your life is hell, but not theirs. Scan your iris before getting the new loan isn't going to happen either, too costly and slow. If they…

> So it would a "Credit ID," Passport Number, DL #, or something related. What's the difference, it will need to be stored next all your stuff, awaiting to be stolen. It should not be a passport number or driver's license number . It should be the original, physical passport or driver's license that you present in person. The physical object is much harder to steal or copy, and can be revoked. You should not be able…

It doesn't even have to be in-person at that specific business. In Germany, the post office will authenticate your ID for any business that pays them for that service (either at a branch or during daily delivery). Alternatively, identification startups now allow to authenticate yourself via video chat without leaving your home. Video enables them to check most security features on the ID.

The national ID also has an embedded smart card usable for authentication but for some reason using that has never took off.

Re: Three Years in Identity Theft Hell

#125
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.

I always look at Estonia when such questions arise. They are consistently on the frontend of public service innovation.

Re: Three Years in Identity Theft Hell

#126
post #119

Earlier quoted context omitted.

Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.

In Germany, my ID might be a form of identification but only in association with the person in question, the ID's number or data itself is not considered identifying by a few institutions (postal service, banks, etc; you always need physical presence for identification or use post-ident) The ID is government issued, cheap to obtain in case of loss (30€ and a bit of waiting until the new one arrives) and contains a ph…

> or use post-ident

Or use the eID functionality, which is growing now that the old IDs are starting to expire.

Re: Three Years in Identity Theft Hell

#127
post #119

Earlier quoted context omitted.

In Germany, my ID might be a form of identification but only in association with the person in question, the ID's number or data itself is not considered identifying by a few institutions (postal service, banks, etc; you always need physical presence for identification or use post-ident) The ID is government issued, cheap to obtain in case of loss (30€ and a bit of waiting until the new one arrives) and contains a ph…

> or use post-ident Or use the eID functionality, which is growing now that the old IDs are starting to expire.

TBH, I haven't seen many websites that offer eID functionality, so I haven't bothered setting it up.

Re: Three Years in Identity Theft Hell

#128
I've been a victim of identity theft in Europe. Took many letters to several police departments in the UK and various states in Germany over the course of five years...

I've not been stopped at EU airports for awhile but I am still not 100% sure if my name is on the Interpol blacklist still. The process of clearing your name is totally opaque. A helpful officer at London MET assured me to undertake the work to do it.

The amount of times I've had to explain the very concept of "identity theft" to enforcement is just crazy. And sadly I don't think they fully understand it most of the time.

I'm a little afraid to travel to eastern Europe, since this "advance fee" for a VW fraud in my name is particularly common there and I am tired of receiving threats. Sigh....

Re: Three Years in Identity Theft Hell

#129
post #57

Earlier quoted context omitted.

The big problem is switch from SSN to what? Just another number that serves the same purpose? SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere. We don't need to make identity theft impossible just reasonably hard. Other nations seem to ha…

All they need is an ssn you can change if it gets stolen. To change it all that's needed is to go into a government office and do a biometric scan in person. That would be so ridiculously easy. Of course the government will never let a good crisis go to waste. Instead, we will all get chips under our skin that can't be removed that will be passively scanned by the authorities everywhere we go.

One irony is that for my US visa I had to have an interview, supply a photograph, have my fingerprints taken and submit to an eyeball scan. Making the US visa inside my UK passport more reliable an identifier than the passport itself.

Re: Three Years in Identity Theft Hell

#130

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

> if that happens, the US will have no choice but to finally switch to a new system.

Impossible. A large part of the American people is obsessed with "the government is going to oppress us all". National IDs or anything similarly working are therefore a big no-go.

If you could solve this problem, you could presumably also solve the gun debate to a large degree.

Post reply on HN