Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

151–160 of 195 posts

Re: Three Years in Identity Theft Hell

#151
post #127

Earlier quoted context omitted.

> or use post-ident Or use the eID functionality, which is growing now that the old IDs are starting to expire.

TBH, I haven't seen many websites that offer eID functionality, so I haven't bothered setting it up.

It's certainly a weird process to witness in Germany.

A couple of weeks ago I had a friend over who used my WLAN to eID for some service (i think it was pre-paid CC? Neither of us can't remember at this point) over his android phone using some "AusweisApp2".

He ended up in a video chat with a lady who asked him to show his face/ID and swivel the ID in the light so she could see the reflections of the security features.

I was sitting next to that whole process thinking about how difficult it would be to put on a convincing facemask and create a matching fake ID that would pass a video inspection.

Shouldn't be that difficult, most certainly less difficult than trying to convince a postman in person by showing them a fake ID at an address matching the fake ID.

Re: Three Years in Identity Theft Hell

#152
post #4

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

> I assure you that even though other countries have credit reporting, they do not use SSNs.

No, but many use systems which are not appreciably better than SSNs from a security and identity theft perspective.

Re: Three Years in Identity Theft Hell

#153
post #43

Earlier quoted context omitted.

It's worth noting that the perpetrator in the bloomberg article had a fake driver's license in the name of the victim. So ID cards aren't a complete solution either.

But you get that ID card using an SSN card. Other countries have a photo attached to your nation ID card and citizen identification number (and sometimes fingerprints too). But think about America right now. Do you honestly think we could get national ID numbers? Could you imagine people being asked for a DNA swab or fingerprint to establish their identity? The blow black would be monstrous, and I don't think it'd be…

> But you get that ID card using an SSN card.

Not necessarily. Not all states require an SSN in order to issue an ID.

> But think about America right now. Do you honestly think we could get national ID numbers?

Unfortunately (for all the reasons you mentioned and more), we're pretty close, as the REAL ID system is about to take effect.

That's going to be a huge problem for people living in the states that don't issue REAL IDs. It's also going to be a problem for legal immigrants and transgender people in every state.

Re: Three Years in Identity Theft Hell

#154
post #83

Earlier quoted context omitted.

Credit has little to do with income. I have over $70k in various credit lines and have never shown any proof of income whatsoever. I just name a number and they accept it (after checking my all-important credit score).

Again, that's an American thing. They will distribute credits to whoever ask for them, as much as they can just to make money out of people. In non insane countries, you are considered debt-free when you have no credit, not when you accumulate credits and pay them with one another.

> In non insane countries, you are considered debt-free when you have no credit, not when you accumulate credits and pay them with one another.

I'm not sure how you think the American system works if you think that "debt-free" has any meaning other than "no balances or debts outstanding".

Re: Three Years in Identity Theft Hell

#155
post #77
post #68

Earlier quoted context omitted.

What if you have no cell phone or computer?

At this point, cell phone is a necessity in India to get any services. Mobile subscriber base is about 1.1 billion (1) which means almost all adults have a cell phone connection. So the question is practically moot. (1) https://www.google.com.sg/amp/m.timesofindia.com/business/in...

> At this point, cell phone is a necessity in India to get any services

And in a delightful catch-22, Aadhaar is essentially a requirement for obtaining a cell phone.

You can bypass this with some other documents and providing a landline that they verify within a week, but it's incredibly cumbersome.

Re: Three Years in Identity Theft Hell

#156
post #37

Earlier quoted context omitted.

In Canada you can't do anything meaningful without a photo driver's license or a passport. My wife got a passport just to have a quality ID. Before that she couldn't even open a chequing account.

Ditto NZ and Aus. Also means that no national ID card or number is necessary. Seems kind of obvious to me. The use of SSN as proof of identity in the US just seems like misuse to me.

> Ditto NZ and Aus. Also means that no national ID card or number is necessary. Seems kind of obvious to me. The use of SSN as proof of identity in the US just seems like misuse to me.

It's the same in the US too. The problem in the article is that the person had a legitimate driver's license issued in the stolen name with his own picture on it.

It's not just a simple as "he had the SSN".

Re: Three Years in Identity Theft Hell

#157
post #127

Earlier quoted context omitted.

TBH, I haven't seen many websites that offer eID functionality, so I haven't bothered setting it up.

It's certainly a weird process to witness in Germany. A couple of weeks ago I had a friend over who used my WLAN to eID for some service (i think it was pre-paid CC? Neither of us can't remember at this point) over his android phone using some "AusweisApp2". He ended up in a video chat with a lady who asked him to show his face/ID and swivel the ID in the light so she could see the reflections of the security feature…

It's not impossible to fake and I don't think that'll ever be the point.

Rather, it's just very difficult compared to faking an SSN number on the internet.

The address in this case would be difficult since a lot of institutions pull your address from the local registry, so you can't convince them to not sent stuff to any victims address unless you manage to change their address in the registry too.

Re: Three Years in Identity Theft Hell

#158
post #133

In my country, its the bank that has the responsibility to ensure that they are talking with the right person. If not, then its the bank who will pay, not the customer. So, the banks here are pretty annoying, opening an account is a lengthily process.

^^^ This. Why is this not in fact the case?

Because banks think that if they inconvenience people, they'll lose customers.

Convenience trumps security in the US.

Re: Three Years in Identity Theft Hell

#159

Earlier quoted context omitted.

It doesn't even have to be in-person at that specific business. In Germany, the post office will authenticate your ID for any business that pays them for that service (either at a branch or during daily delivery). Alternatively, identification startups now allow to authenticate yourself via video chat without leaving your home. Video enables them to check most security features on the ID. The national ID also has an…

> Video enables them to check most security features on the ID. Video is just another form of photo copy, so how would that work?

You are required to respond to questions from them and verbally verify a) what you're are applying for b) read out the data written on the ID (passport or national ID) and c) move and wiggle the card around and occlude it with your finger so the agent can verify certain security features (holograms, picture, "shiny stripes" on the card). In my opinion, it would be quite hard to prerecord the whole process and/or reuse such recordings for multiple applications.

All in all this process makes it much much harder to steal an identity. Also, once you report your ID card stolen, its serial number will be blacklisted preventing it from being used. Add to this that there is a snail mail address on your cards which will typically be used to send login information such as passwords and PINS

Re: Three Years in Identity Theft Hell

#160
post #57

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The big problem is switch from SSN to what? Just another number that serves the same purpose? SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere. We don't need to make identity theft impossible just reasonably hard. Other nations seem to ha…

A big question in making credit providers liable for incorrectly granting credit is the specific definition of 'correctly'.

Sadly, just 'issued without approval' is a bit too wide a definition. You need to deal with 'john' helping others fraudulently impersonating 'john'. In that case, the bank should not be liable.

In general, I see potential for a weird type of coorperation. They verify identities for credit providers for a fee. In return, this coorperation takes on the liability of wrongly verifying identities.

Question is, given the importance of such a coorperation, how much regulation is needed? At what point is there so much regulation required that it is better left as a government-run service?

Post reply on HN