Live data from Hacker News

I Got Access to My Secret Consumer Score

nytimes.com

81–90 of 341 posts

Re: I Got Access to My Secret Consumer Score

#81
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

"Of the responses, 24 per cent simply accepted an email address and phone number as proof of identity and sent over any files they had on his fiancée. A further 16 per cent requested easily forged ID information and 3 per cent took the rather extreme step of simply deleting her accounts."

https://www.theregister.co.uk/2019/08/09/gdpr_identity_thief...

Re: I Got Access to My Secret Consumer Score

#82
post #60

Two points: First, the very act of requesting your data is in a way confirming and verifying the accuracy of the data. Second: Every prescription you've ever filled with insurance - and even some without - is recorded by companies like Milliman.[0] When you want to buy life insurance, health insurance, etc. they can request to see what medications you're on, have been on, etc. [0]. https://clark.com/insurance/how-to-…

how does that not violate HIPAA ? I see it talking about "you can proactively opt out with hipaa" but everything I've ever seen about HIPAA is that all "opting in" needs to be explicitly granted by the patient.

If you want life insurance then you are required to give permission to view this data about you. If you don't want to give permission, then you don't get life insurance.

https://www.rxhistories.com/irix/medical-data/

>How It Works

>1 Applicants sign a HIPAA-compliant authorization, enabling insurers to retrieve their medical information

>2 Insurers electronically query Milliman IntelliScript in real-time

>3 Milliman instantly gathers information from multiple data sources

>4 Irix interprets the data and generates automated decisions based on the insurer's guidelines

Re: I Got Access to My Secret Consumer Score

#83
post #25

I was at a loss for why Sift was collecting data like this from companies like airbnb / etc, I worked a project using them around curbing some pretty gnarly levels of credit card fraud. I think it must be that these companies are utilizing their user content fraud scanning (“content integrity”) systems. I don’t know about calling this a consumer score though, but it is truly frightening if that’s how companies are ut…

A binary score is still a score.

There's absolutely a difference between a binary "fraud/not fraud" flag and a continuous variable for quality of customer. They measure different things and have very different use cases.

Re: I Got Access to My Secret Consumer Score

#84

God help these companies if they're collecting data on EU citizens. Contrary to what is posted elsewhere here, GDPR applies to: "a company established outside the EU and is offering goods/services (paid or for free) or is monitoring the behaviour of individuals in the EU." Enforcement might be difficult, but I'm sure that associated entities have interests in Europe as well.. I'm sure it's been fully risk-assessed an…

A quick DuckDuckGo search shows me that Coinbase has European customers for sure. The article states that the information knew exactly when the person opened the Coinbase app on their phone and the type of computer time and date they changed their password for Coinbase. I have been thinking that the only way they could have that information is if they were given it by Coinbase. I guess sure they could stop and not log anything on European customers but seeing how they are using this as a fraud detection system I feel it is likely they are using it on European customers as well.

Re: I Got Access to My Secret Consumer Score

#86
post #12

I am surprised these guys are able to operate outside the normal credit reporting laws. He’s referencing things that happened in 2009, which is well outside the usual 7 year limit for credit report data. Clearly, these companies are going to make the argument that this is not credit report data subject to consumer credit laws, but I’m curious if that has been tested at all. I would think an enterprising lawyer could…

The impetus for a company like Sift was better fraud detection. I haven't evaluated the platform in some time, but if I remember correctly; it democratized the fraud decision process by feeding Sift data on successful orders. Clients would score their own orders based on whether or not it was returned, charged back or simply a successful no-friction order. Something like 80% of customers have issued a chargeback, 86%…

Well sure. And a pretty core impetus for a company like Equifax keeping data on loan repayments is also better fraud detection. That's even more true in the insurance business which uses consumer credit agency data extensively.

Fundamentally what they are doing seems like the same thing. They're keeping a file on people that corporations are using to decide if they're trustworthy.

We decided a long time ago that consumers need to have the right to see and challenge that data for accuracy, as well as to have limits on how long it can be held against them. I see absolutely no reason why those principals should not apply here as well.

And it seems at least arguable that they already do. Clearly there's arguments on both sides, but reading the basic definitions here on what comprises a credit report and a credit reporting agency, and the prohibition on reports more than seven years old, it seems like a non-frivolous case could be made:

https://epic.org/privacy/financial/fcra.html

https://www.law.cornell.edu/uscode/text/15/1681a

Re: I Got Access to My Secret Consumer Score

#87
post #30

Just requested all of my data from the companies listed. I'm very curious to see the data they return.

I'd frankly be surprised if your request for records doesn't become a juicy data point on the record.

I agree.

Similar companies are the credit reference agencies - Equifax, Experian, TransUnion.

Every time you request your data from credit reference agencies, the request is logged. My log has many such entries, due to repeated checking I did while trying to get corrections sorted, and due to the third party companies I used to help with this.

So I'd expect the same to be true for the customer rating agencies.

In the case of credit agencies, they say that information ("soft" enquiries) is not used to assess credit risk - and that it's either not made available to companies that process applications, or must not be used by those companies in the assessmment.

To be honest, seeing the kinds of errors I've seen, as well as seeing the inner workings when it is being corrected, some of it shows very shoddy, and in some cases seriously unethical processes (that the companies know about).

So I simply don't believe that companies are diligent about following the "must not be used" rule for data they "may" receive and are supposed to ignore. To convince me, it would require a level of auditing, or quality of audit, that companies plainly are not getting.

And these are companies I still do business with because they are good enough. Goodness knows what to think of companies I wouldn't do business with, if I knew about them and had any choice in the matter.

Re: I Got Access to My Secret Consumer Score

#89
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

This is already a big (and largely unaddressed) problem with the big 3 credit CRAs, if you know enough about a person you can very easily request their credit report and get the keys to the kingdom (so-to-speak) - everything you didn't already know.

I mean, I already request credit reports for my husband without issue, for example (with his permission! - he finds it much easier to just ask me to do those things for him rather than doing them himself).

In this case, since email address is part of the report they could only send the report to the email address on file for "security," which would be a big improvement over what the big three CRAs are doing with annualcreditreport.com.

Re: I Got Access to My Secret Consumer Score

#90
post #63
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

I've sent a couple of GDPR Subject Access Requests out of sheer curiosity. The answer is - in my experience - 'it varies'. One requested a copy of a photo ID or passport and were happy to accept a partly redacted copy with 'FOR PROOF OF ID ONLY - (company), (date)' over-typed on the scan in red. Another requested I email them from an email address they had in their records, or log in to change it and resubmit the req…

> Another requested I email them from an email address they had in their records

Wow. They didn't mail it and require confirmation of receipt, they just required a (trivially forged) mail with that email address in From?

Post reply on HN