Live data from Hacker News

I Got Access to My Secret Consumer Score

nytimes.com

21–30 of 341 posts

Re: I Got Access to My Secret Consumer Score

#21
I would be more interested in knowing how the companies scoring customers operate. If their goal is to detect fraudsters they must be able to aggregate accounts with a different name and/or email from different systems, as surely a fraudster will use a different identity on each service?

Re: I Got Access to My Secret Consumer Score

#23
post #20

Earlier quoted context omitted.

So can Europeans send a GDRP right-to-be-forgotten request to all of these?

don't take my word for it, but I believe that you can only if they have opened a subsidiary in EU. The fine is percent of global sales (not profit).

I believe that statement is incorrect :-)

Re: I Got Access to My Secret Consumer Score

#24
post #21

I would be more interested in knowing how the companies scoring customers operate. If their goal is to detect fraudsters they must be able to aggregate accounts with a different name and/or email from different systems, as surely a fraudster will use a different identity on each service?

I think the point is exactly that fraudsters have no history. The system probably starts with a low score that increases as more data is collected. And then it can actually score you on the data rather than a "probably fraudulent account" flag.

Re: I Got Access to My Secret Consumer Score

#25
I was at a loss for why Sift was collecting data like this from companies like airbnb / etc, I worked a project using them around curbing some pretty gnarly levels of credit card fraud. I think it must be that these companies are utilizing their user content fraud scanning (“content integrity”) systems. I don’t know about calling this a consumer score though, but it is truly frightening if that’s how companies are utilizing that technology. I really enjoyed working with them — so I might be biased to see the good here — but they totally pushed back on biz folks on our side when they tried to nudge on things that the technology was not designed to do. So I would imagine / hope that they would have done the same in the case of something like constructing a “consumer score”, the tech is for flagging outright fraud, not for relatively scoring how good a customer is...

Re: I Got Access to My Secret Consumer Score

#26
I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a person prior to handing over all their data? Is it limited to tort liability, in which there needs to be proof that the transgression ultimately led to some particular damage? Given that this data is being traded on the free market, what’s to stop abusive employers, ex-spouses and criminals from exploiting this information?

Re: I Got Access to My Secret Consumer Score

#28
Will these systems be prone to false data?

I.e. if an organization fighting for free speech would create software generating false personas who create false messages, and other events, would they know any better?

For example, it wouldn't be too hard to generate hundreds if not thousands of fake Facebook, Instragram, Airbnb, Coinbase, Uber, Gmail, Amazon, etc. accounts doing "stupid things". Like ordering stuff and canecelling orders right away. Like generating fake emails en masse with "trigger words" in millions a day. Like creating fake posts on Facebook warning of fake incidents like "15% of Uber drivers have serious mental issues".

The whole thing could be scripted and run on bots worldwide in millions. After some time, serious chunk of internet traffic would be fake. How would these companies know any better?

Re: I Got Access to My Secret Consumer Score

#29
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

Wow, that's a good point.
Post reply on HN