Live data from Hacker News

I Got Access to My Secret Consumer Score

nytimes.com

71–80 of 341 posts

Re: I Got Access to My Secret Consumer Score

#71
post #68
post #63

Earlier quoted context omitted.

I've sent a couple of GDPR Subject Access Requests out of sheer curiosity. The answer is - in my experience - 'it varies'. One requested a copy of a photo ID or passport and were happy to accept a partly redacted copy with 'FOR PROOF OF ID ONLY - (company), (date)' over-typed on the scan in red. Another requested I email them from an email address they had in their records, or log in to change it and resubmit the req…

What items did you redact from your ID/passport?

I sent a driving licence and redacted the licence number, then overtyped the whole thing with the text in my previous post.

My goal was to make certain that if it leaked, the overtyped expiry date should make it useless after a certain point, and the company name should make any company other than that one question the source.

As a side effect, it'd also clearly identify the source of any leaks - but that wasn't my primary goal.

I moved the text so the name and address (which they already had) and date of birth (which isn't really a secret) were clearly readable.

Re: I Got Access to My Secret Consumer Score

#72
The fact that the data is being sold to third-parties (e.g., Sift) by their collectors (e.g., Airbnb) is troubling. But what is even more troubling is that we don't know how scoring companies (e.g., Sift) are using the data and how they are generating scores.

Their models, if they are using ML, are opaque. Journalists haven't yet cracked this nut, instead just reporting on the fact that company A has bought personal data from company B. (That is likely to require anonymous leaks from the scoring companies.)

I think the hacker ethos could be applied to this problem by viscerally illustrating the threat. ('Hacker' used in the same way as the infosec community.)

Hackers could request their own data, hypothesize what could be gleaned from it, and use models (potentially academic ones trained on more general datasets) to produce derivative information.

Then hackers should make tools to make this process easier for the average journalist or consumer.

Re: I Got Access to My Secret Consumer Score

#73

Will these systems be prone to false data? I.e. if an organization fighting for free speech would create software generating false personas who create false messages, and other events, would they know any better? For example, it wouldn't be too hard to generate hundreds if not thousands of fake Facebook, Instragram, Airbnb, Coinbase, Uber, Gmail, Amazon, etc. accounts doing "stupid things". Like ordering stuff and ca…

If all this data would be more or less random (which is kind of implied by "run on bots worldwide in millions") this would merely add some random noise to large datasets. For this to create any real problems the noise generated by those bots would have to be somehow biased, of course in an incorrect way. This implies then, that for such idea to be even remotely effective one would need at least a peak in aggregated data to know real trends and program bots to blur the image generating fake trends.

Re: I Got Access to My Secret Consumer Score

#74
post #66

Earlier quoted context omitted.

> First, the very act of requesting your data is in a way confirming and verifying the accuracy of the data. Could you explain what you mean by that? And also hypothesize some implications of 'confirming and verifying the accuracy of the data'?

For example, checking if you ever had an account at companies mentioned in your data takeout - to spot if someone does shit while using your name/personal information, or some incompetent/malicious clerk mixed up data.

That doesn't verify any data though. At most, it implies a likelihood of having an account, but nothing about the specific data.

Re: I Got Access to My Secret Consumer Score

#76
post #60

Earlier quoted context omitted.

how does that not violate HIPAA ? I see it talking about "you can proactively opt out with hipaa" but everything I've ever seen about HIPAA is that all "opting in" needs to be explicitly granted by the patient.

I'm guessing you opt-in when you request a quote.

It still sounds sketchy since it sounds like your data is maintained at a 3rd party for a purpose that is not intended (unrelated to your care) on the idea that you may one day opt-in to the unintended use.

Re: I Got Access to My Secret Consumer Score

#77
post #12

I am surprised these guys are able to operate outside the normal credit reporting laws. He’s referencing things that happened in 2009, which is well outside the usual 7 year limit for credit report data. Clearly, these companies are going to make the argument that this is not credit report data subject to consumer credit laws, but I’m curious if that has been tested at all. I would think an enterprising lawyer could…

The impetus for a company like Sift was better fraud detection. I haven't evaluated the platform in some time, but if I remember correctly; it democratized the fraud decision process by feeding Sift data on successful orders. Clients would score their own orders based on whether or not it was returned, charged back or simply a successful no-friction order.

Something like 80% of customers have issued a chargeback, 86% of chargebacks are "friendly fraud", increasing at a rate of 41% every two years. The dollar figure I've heard is $20+ Billion in friendly fraud.

So, obviously there's an altruistic nature to why a company like Sift has this data. But, I'm of the opinion that they saw the dollar value in this type of scoring and collection system.

Re: I Got Access to My Secret Consumer Score

#78
post #25

I was at a loss for why Sift was collecting data like this from companies like airbnb / etc, I worked a project using them around curbing some pretty gnarly levels of credit card fraud. I think it must be that these companies are utilizing their user content fraud scanning (“content integrity”) systems. I don’t know about calling this a consumer score though, but it is truly frightening if that’s how companies are ut…

A binary score is still a score.

Seriously. If companies are relying on the fraud estimates, it isn't going to be fun to be a false positive.

Re: I Got Access to My Secret Consumer Score

#79

Will these systems be prone to false data? I.e. if an organization fighting for free speech would create software generating false personas who create false messages, and other events, would they know any better? For example, it wouldn't be too hard to generate hundreds if not thousands of fake Facebook, Instragram, Airbnb, Coinbase, Uber, Gmail, Amazon, etc. accounts doing "stupid things". Like ordering stuff and ca…

Credit reference agencies are already prone to false data, and that's without anyone trying to game them.

When I checked this year, 2 out of the 3 major CRAs in my country (Equifax, Experian) had:

- An incorrect flag saying I was not registered to vote, and a note saying this significantly affected my credit rating.

- A bogus address that didn't correspond to any physical location. Nor did it correspond with any address used by any business, that I know of. (If it does, they won't be able to mail me!)

- Three credit application searches (hard searches) in 3 days, for applications I didn't make. (I complained to the relevant company, who agreed they were added due to software errors on their side, and "resolved" the complaint by agreeing to remove them; but in the end they didn't remove them, so my history has unremovable entries for applications I've never made.)

- An account with the largest telecoms provider (BT) in the country that I didn't have (I'd left them 2 years earlier, account fully closed and settled).

- Fictitious monthly entries on the above account showing new amounts being added each month, of seemingly random amounts (no obvious pattern), and flagged as severe, overdue, late payer etc. Not a good look on a credit record, and entirely fictitious. (Fixing this proved arduous, and I ended up having to use three companies in a daisy-chain of each one passing along a formal complaint to the next. I later learned from BT customer support that BT does this to other former customers without their knowledge as well, so for ethical reasons if I can muster the energy I'll be complaining about this to the government regulator)

I could say so much more about the complaints process, terrible customer service in every conceivable way from Equifax specifically, and more, but it would be rather off-topic.

Remarkably, just complaining about the above caused the errors to be acknowledged and correct data found magically by the companies involved, without me needing to provide replacement data. It's as if the companies involved had all the data they needed already, they just aren't using it until a customer finds out and complains.

Re: I Got Access to My Secret Consumer Score

#80
post #72

The fact that the data is being sold to third-parties (e.g., Sift) by their collectors (e.g., Airbnb) is troubling. But what is even more troubling is that we don't know how scoring companies (e.g., Sift) are using the data and how they are generating scores. Their models, if they are using ML, are opaque. Journalists haven't yet cracked this nut, instead just reporting on the fact that company A has bought personal…

I created a free service which makes it easier to get Sift (and others) to delete your data: https://opt-out.eu/?company=sift.com. It automates the process of sending GDPR erasure requests. I sent my request this morning. Support for GDPR SAR requests (get a copy of your data) is coming soon.
Post reply on HN