Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

141–150 of 195 posts

Re: Three Years in Identity Theft Hell

#141
post #4

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

I think the eagerness of US banks to offer credit is a big part of the problem. Having people endebted is an essential part of the system of wealth transfer and class control, and the system is set up to make this really easy. In the Netherlands, where I live, it might also be possible to obtain a fake id if someone would go through the length this impersonator went through, but I think it would be much harder to open bank accounts and get meaningful credit without questions being asked.

What I do not understand is why victims of this have not sued their banks over this yet. Suing should be the US couterbalance to this. People are innocent victims of fraudulent behaviour of their banks, and those banks are being robbed by thieves. Banks are supposed to guard their customers' money, which in this case they are clearly not doing. Maybe they do it unknowingly, or they are incompetent, but in the end those banks are behaving fraudulently too.

Re: Three Years in Identity Theft Hell

#142

Earlier quoted context omitted.

I mean, countries may have national identity cards with chips and perhaps biometrics that make them hard to forge, but a) I believe there's opposition in the US to identity cards b) do they help establish identity remotely, e.g., online?

Norway has a great system called BankID. To sign-up/login to all banks, government services and other places where you need to verify your identity you enter your SSN, personal password and code from your 2FA device (which banks give you freely)/phone app. https://www.bankid.no/en/

In other words, you also have a system of password reuse (a personal password instead of a per-account password?!)?

Also, how is the reliability of the 2FA device established? If there were some claim before a court that you authorized some sort of transaction, what would they have to demonstrate to prove your liability? What will the court do if you question whether the numbers generated by the 2FA device are actually cryptographically random?

Re: Three Years in Identity Theft Hell

#143

Earlier quoted context omitted.

> So it would a "Credit ID," Passport Number, DL #, or something related. What's the difference, it will need to be stored next all your stuff, awaiting to be stolen. It should not be a passport number or driver's license number . It should be the original, physical passport or driver's license that you present in person. The physical object is much harder to steal or copy, and can be revoked. You should not be able…

It doesn't even have to be in-person at that specific business. In Germany, the post office will authenticate your ID for any business that pays them for that service (either at a branch or during daily delivery). Alternatively, identification startups now allow to authenticate yourself via video chat without leaving your home. Video enables them to check most security features on the ID. The national ID also has an…

> Video enables them to check most security features on the ID.

Video is just another form of photo copy, so how would that work?

Re: Three Years in Identity Theft Hell

#144
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

I think the eagerness of US banks to offer credit is a big part of the problem. Having people endebted is an essential part of the system of wealth transfer and class control, and the system is set up to make this really easy. In the Netherlands, where I live, it might also be possible to obtain a fake id if someone would go through the length this impersonator went through, but I think it would be much harder to ope…

While not a bank account, let's not be smug about our country: http://m.telegraaf.nl/binnenland/article/24095858/man-in-pro... . (For the non Dutch speakers, Amsterdam guy had several houses rented in his name, some of which were used for mj plantations, and various other expenses incurred in gis name).

Identity theft is not just because of ssn or other unique semi secret numbers. It's part of it, yes, but the root cause is a combination of culture and lack of inventive (ie, identity theft is just not a big enough problem for actors to care).

Re: Three Years in Identity Theft Hell

#145

Earlier quoted context omitted.

Other countries have the equivalent of SSNs, i.e., a number issued by the government tax collector. However, other countries don't use it as a form of ID. In my experience, they use passports, ID cards, drivers licenses, etc., which are supposedly "hard to forge".

These systems don't work well remotely, of course. Sometimes an organisation will accept an upload of a scan or a mailing of a photocopy. They sometimes require it to be signed by a somebody to verify that it's genuine (e.g., a Justice of the Peace). But by doing that, the "hard to forge" feature is lost entirely.

You talking about Facebook?

Re: Three Years in Identity Theft Hell

#146
post #133

In my country, its the bank that has the responsibility to ensure that they are talking with the right person. If not, then its the bank who will pay, not the customer. So, the banks here are pretty annoying, opening an account is a lengthily process.

^^^ This. Why is this not in fact the case?

Re: Three Years in Identity Theft Hell

#147
post #47

Earlier quoted context omitted.

> How would a more secure system work? Just look what many other countries do.

I'm not sure that any country has really solved it convincingly. Sure, they do better than the US and its secret SSNs, but that doesn't say much.

National ID cards with biometric information along with PIN plus private keys for document signing and 2FA for online interactions isn't convincing enough for you?

Re: Three Years in Identity Theft Hell

#148
post #4

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

> The United States. I assure you that even though other countries have credit reporting, they do not use SSNs.

They use ID cards with at least some features to make forging said ID cards more difficult, unlike the US SSN which is pretty much just a number on a piece of paper.

This is mainly an issue of authentification and as long as your credentials remain crappy/easy to guess/easy to forge (like the US SSN system), that long it will stay easy to game the system.

Imho this def con talk about birthing and killing virtual babies might also be quite relevant to the issue, tho it's not entirely focused on the US: https://www.youtube.com/watch?v=9FdHq3WfJgs

Re: Three Years in Identity Theft Hell

#149
post #83

Earlier quoted context omitted.

Credit has little to do with income. I have over $70k in various credit lines and have never shown any proof of income whatsoever. I just name a number and they accept it (after checking my all-important credit score).

Again, that's an American thing. They will distribute credits to whoever ask for them, as much as they can just to make money out of people. In non insane countries, you are considered debt-free when you have no credit, not when you accumulate credits and pay them with one another.

Giving people credit without seeing how much they already owe and how they're repaying it is insane. Rich people can go over their heads and default just as well as poor people. There is an obvious and valid need for credit reporting agencies to exist.

Re: Three Years in Identity Theft Hell

#150

Earlier quoted context omitted.

Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.

In Sweden I got an identity card with a chip that I can use with BankID (a system that uses a card reader + PIN for most transactions). There is a Tax ID number but this is pretty much a public record (you can find out people's incomes very easily, in fact small local newspapers run every year "richest people in X articles") In addition, every time a company runs a credit check on me, the credit reporting company mus…

> In addition, every time a company runs a credit check on me, the credit reporting company must snail mail a copy of my credit report to my physical address.

Wow, that's really user-friendly, I wish it would be handled like that in Germany too.

Instead, German registration offices are selling citizen registration data in bulk to most interested parties and they couldn't even tell you to whom [0].

People can opt out of that process, by handing in a written objection with their initial registration, tho barely anybody actually does that because barely anybody is aware of their data being sold in the first place.

[0] https://www.golem.de/1010/78398.html

Post reply on HN