Live data from Hacker News

Three Years in Identity Theft Hell

bloomberg.com

181–190 of 195 posts

Re: Three Years in Identity Theft Hell

#181
post #57

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The big problem is switch from SSN to what? Just another number that serves the same purpose? SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere. We don't need to make identity theft impossible just reasonably hard. Other nations seem to ha…

For a long time SSN cards carried a notice that they were to be used only for social security and taxation purposes and never for identification. Maybe the government should take steps to make the SSN unsuitable as an identifier outside of those two agencies.

Re: Three Years in Identity Theft Hell

#184
post #64
post #61

So how does one protect against this if freezing is useless because all that information was leaked anyway?

Freezing doesn't protect the information, but it does protect your credit account from being added to. Once frozen, you are almost in a 2FA scenario where creditors are required to request any new accounts or credit hits, and the credit agency is required to then obtain your approval using the private information only you (should) know.

Using the information leaked from Equifax, hackers can lift your freeze. All they need to know is your address, SSN and Date of Birth. See: https://www.experian.com/ncaconline/freezepin

Re: Three Years in Identity Theft Hell

#185
post #4

Earlier quoted context omitted.

> the world The United States. I assure you that even though other countries have credit reporting, they do not use SSNs. > will have no choice but to finally switch to a new system. Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be rea…

I think the eagerness of US banks to offer credit is a big part of the problem. Having people endebted is an essential part of the system of wealth transfer and class control, and the system is set up to make this really easy. In the Netherlands, where I live, it might also be possible to obtain a fake id if someone would go through the length this impersonator went through, but I think it would be much harder to ope…

Or, they have relinquished their ability to legal redress in court AS A CONDITION of doing business with them, agreeing to arbitration.

Re: Three Years in Identity Theft Hell

#186

Counterintuitively, this is evidence that the Equifax breach isn't necessarily going to cause massive harm. If someone wanted to impersonate you, they could already. I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is…

The hassles and inconvenience this problem causes victims is sort of an unpriced externality of the credit industry. If those extending credit had to compensate the victims for their negligence, maybe they'd stop being so negligent.

And it would help if individual making the faulty decision to extend credit lost all their commissions for the week. It should be a blight on their record, with more than 5 instances causing them to lose their jobs. And CEO of the worst offending company gets a hefty fine.

Maybe that would focus the industry on solving this problem.

Re: Three Years in Identity Theft Hell

#187
post #113

Earlier quoted context omitted.

Perhaps true to some extent, but a passport can last 10 years, which is plenty of time for identity theft.

If your identity gets stolen you get new passport with new number and put old one into stolen document database. Cannot do this with SSN.

The question would then be how many organisations check the stolen document database when looking at a passport id.

Re: Three Years in Identity Theft Hell

#188
post #113

Earlier quoted context omitted.

If your identity gets stolen you get new passport with new number and put old one into stolen document database. Cannot do this with SSN.

The question would then be how many organisations check the stolen document database when looking at a passport id.

however, that clearly puts the blame where it's due. ssn changes being exceptions make easy to shield company from due process. id's, otoh, have specific procedures for handling.

Re: Three Years in Identity Theft Hell

#189

Earlier quoted context omitted.

I think the eagerness of US banks to offer credit is a big part of the problem. Having people endebted is an essential part of the system of wealth transfer and class control, and the system is set up to make this really easy. In the Netherlands, where I live, it might also be possible to obtain a fake id if someone would go through the length this impersonator went through, but I think it would be much harder to ope…

Or, they have relinquished their ability to legal redress in court AS A CONDITION of doing business with them, agreeing to arbitration.

This is a HUGE issue in the USA, one which, apparently, too few people know about, or take seriously.

More and more companies are insisting on customers signing binding arbitration clauses as a condition of doing business: car dealers, banks, airlines, you mention it. It's all very well to say, well, don't do business with them, when all the competition are doing the exact same thing. If you need, say, a new car, well, good luck getting one without signing most of your rights away, and this is no exaggeration.

Binding mandatory arbitration clauses mean that you cannot sue the company, and agree to accept the verdict of the arbitrator, for which there is no appeal, and who is generally hired by the company having the arbitration dispute and is therefore impartial /s.

I have read FTC field reports about vehicle warranty claims where one arbitration decision was so outlandish even the FTC wrote that it was irrational, and the vast majority were in favor of the dealer.

Re: Three Years in Identity Theft Hell

#190
post #113

Earlier quoted context omitted.

If your identity gets stolen you get new passport with new number and put old one into stolen document database. Cannot do this with SSN.

The question would then be how many organisations check the stolen document database when looking at a passport id.

If you want to legally lend money why shouldn't you be required to do look up? If you didn't you're liable...
Post reply on HN