Earlier quoted context omitted.
The big problem is switch from SSN to what? Just another number that serves the same purpose? SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere. We don't need to make identity theft impossible just reasonably hard. Other nations seem to ha…
Don't switch from SSN. Just accept that they are public identifiers and ensure 1) everyone has access to photo ID with that SSN and 2) an authority can lookup addresses from SSN to perform 2FA. This means everyone in the US has to accept national ID. (It could theoretically be done at state level but it would be a huge hassle compared to national, and your tax authority and others are already national and need to kno…
Three Years in Identity Theft Hell
161–170 of 195 posts
Re: Three Years in Identity Theft Hell
#162Re: Three Years in Identity Theft Hell
#163Earlier quoted context omitted.
I mean, countries may have national identity cards with chips and perhaps biometrics that make them hard to forge, but a) I believe there's opposition in the US to identity cards b) do they help establish identity remotely, e.g., online?
The Netherlands has an OAuth system for online identity verification, called DigiD, for anything government-related (taxes, healthcare, etc.) Other than that, occasionally a service asks for a copy of your passport, although that's not really allowed.
For illustration, when I'm logging in, I get the option to login with my password, OR to login with 2 factors. When the second factor is optional, it doesn't provide much defense. Some select services require the second factor, but its very few. Until very recently, the second factor was SMS, which is rather easy to fool.
Also, as far as I know, Digid isn't related at all to banking. Instead, you need to show ID (passport or ID-card, drivers license does not suffice in this case) to open an account with a bank. After that, each bank has their own system.
Re: Three Years in Identity Theft Hell
#164Earlier quoted context omitted.
I haven't seen password I'd or national card I'd used as identification, ever. The way it works is that you bring it physically and they look into it. Or that you send photo of the id (yes that is easier to forge, then again harder then forging utility bill) - that is done only where it is impossible to do physical check and never with loans and such. Identity theft in Europe is extremely rare. It is possible to do s…
>> The way it works is that you bring it physically and they look into it. Not gonna happen, banks for now will rather swallow the relatively low loses due to fraud. In USA you sign a piece of paper (pre-approved loan), or login online and the loan money is deposited in your account within a few days. All automated. So far it works out for them, if fraud loses increase, the banks, not us, will choose the next method.…
Re: Three Years in Identity Theft Hell
#165Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…
>The SSN shouldn't be the critical key in that list.
Nothing in that list is secret.
Re: Three Years in Identity Theft Hell
#166Earlier quoted context omitted.
Fixed, thanks. What do you feel are some sensible systems used by the rest of the world? One that's hopefully hard enough to break but easy enough not to cause massive hassles.
In Germany, my ID might be a form of identification but only in association with the person in question, the ID's number or data itself is not considered identifying by a few institutions (postal service, banks, etc; you always need physical presence for identification or use post-ident) The ID is government issued, cheap to obtain in case of loss (30€ and a bit of waiting until the new one arrives) and contains a ph…
In addition, each government service uses a different ID number and is forbidden from sharing information or using another service's ID number. So you have a fiscal number for taxes, a social security number for health things, an identity card number that only has meaning with the card itself. Your private (non-healthcare) insurance, your bank, and other private institutions can issue you their own number as well (or another kind of id key) but can not share them between themselves and cannot ask you to give them numbers of unrelated services. Citizens are responsible for forwarding themselves most information between separate services when needed.
In practice it makes it sometimes tedious to auth at any of these services (you have to find your number in whatever mail you received or card you got issued) but it really makes it more difficult to impersonate another citizen, as you would at most gain access to one service, and it wouldn't help you access any other.
Re: Three Years in Identity Theft Hell
#167Earlier quoted context omitted.
These systems don't work well remotely, of course. Sometimes an organisation will accept an upload of a scan or a mailing of a photocopy. They sometimes require it to be signed by a somebody to verify that it's genuine (e.g., a Justice of the Peace). But by doing that, the "hard to forge" feature is lost entirely.
Ukraine is experimenting and slowly rolling out an oauth-like system called BankID, where you bank can provide information to third party.
Over here it's basically used for everything that needs authentication / signatures - taxes, banking etc.
Re: Three Years in Identity Theft Hell
#168Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…
Seems like an opportunity to force the hand. I, like you, imagine such an action would induce systemic change.
Maybe.
Re: Three Years in Identity Theft Hell
#169Earlier quoted context omitted.
> Video enables them to check most security features on the ID. Video is just another form of photo copy, so how would that work?
You are required to respond to questions from them and verbally verify a) what you're are applying for b) read out the data written on the ID (passport or national ID) and c) move and wiggle the card around and occlude it with your finger so the agent can verify certain security features (holograms, picture, "shiny stripes" on the card). In my opinion, it would be quite hard to prerecord the whole process and/or reus…
Also, please don't use terms like "steal an identity", that is how banks frame things in order to make it appear that they are not responsible. Banks don't employ reliable authentication, thus they get defrauded by imposters--nothing is ever stolen from those who the importers pretend to be, it's only between the bank and the imposter, noone else is a party to that fraudulent transaction.
Re: Three Years in Identity Theft Hell
#170I had my "identity" stolen by someone who tried to open accounts at local banks after somehow managing to swipe a copy of my drivers license (from our mail box, as far as we know) and seemingly only was able to rent a Uhaul in my name (unbeknownst to me until I tried to rent one to move). The banks kicked him back and he tried forging checks from others (not me). I filed the reports with the police. And checked my cr…
My old flatmate was the victim of identity theft around 2010. After tons of paperwork, calling banks, closing accounts, working with the police .. he still lost about $3k that he didn't feel it was worth to try to recover. You just got lucky and caught it early.
I've been curious about the real-world impacts of identity theft for quite some time. In the article linked, the author's only obvious losses were a) on the home mortgage (couldn't cosign; worse rate) and b) at the airport, with TSA (which I don't get; how did his credit rating have an impact on the secondary security screening?).
It's unclear to me why I should care that much about identity theft, or what a thief can do. I'm not saying it wouldn't be a huge hassle to get calls from scammed creditors or be unable to obtain consumer credit, but I am fortunate enough not to need credit and I already have the credit cards and bank accounts I need.
There is the whole IRS fraudulent return thing, which could be quite tedious to sort out and meantime would take real money. But that's about all I can think of unless you need consumer credit.