Live data from Hacker News

I Got Access to My Secret Consumer Score

nytimes.com

91–100 of 341 posts

Re: I Got Access to My Secret Consumer Score

#92
post #72

The fact that the data is being sold to third-parties (e.g., Sift) by their collectors (e.g., Airbnb) is troubling. But what is even more troubling is that we don't know how scoring companies (e.g., Sift) are using the data and how they are generating scores. Their models, if they are using ML, are opaque. Journalists haven't yet cracked this nut, instead just reporting on the fact that company A has bought personal…

> The fact that the data is being sold to third-parties (e.g., Sift) by their collectors (e.g., Airbnb) is troubling.

It looks like Airbnb & co paid Sift instead, in addition to sending it their data: "Sift has this data because the company has been hired by Airbnb, Yelp, and Coinbase"

Re: I Got Access to My Secret Consumer Score

#93
post #64

Earlier quoted context omitted.

The only company to request proof thus far in the process is Zeta Global which presents a secure portal to upload your ID. However, to be honest, I'm not that concerned about emailing my ID if necessary.

On the Sift Google Form: "In order to process your rights request, Sift’s Privacy Team needs to collect the below information about you. We are unable to process your request without complete submission of this form and a copy of your valid government ID for verification purposes."

They havent provided me the Google form for Sift. I'll still submit it to them though. I've once been a Coinbase customer so they likely have it already.

Re: I Got Access to My Secret Consumer Score

#94

Earlier quoted context omitted.

A binary score is still a score.

Seriously. If companies are relying on the fraud estimates, it isn't going to be fun to be a false positive.

I mean people have been subjected to fraud scoring for decades, you get declined, you follow up, and you get in w/ a new data point for the next time.

Re: I Got Access to My Secret Consumer Score

#95
post #89
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

This is already a big (and largely unaddressed) problem with the big 3 credit CRAs, if you know enough about a person you can very easily request their credit report and get the keys to the kingdom (so-to-speak) - everything you didn't already know. I mean, I already request credit reports for my husband without issue, for example (with his permission! - he finds it much easier to just ask me to do those things for h…

I wonder what the additional risk is though given that, iirc from the times I've requested credit reports, the amount of info needed to retrieve it is enough to have already stolen my identity. So in that case it seems the additional risk is low.

Re: I Got Access to My Secret Consumer Score

#96
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

I suspect we as a society need new legislation to deal with these sort of issues. Before, much of this was incredibly difficult to impossible so legislation and regulation was entirely avoidable and relatively rare occurence could be dealt with on a case-by-case basis.

At this point, technology has enabled this sort of behavior at mass scale, now revealing far more personal and useful information about individuals.

A feasible model to work from may be go look at the healthcare industry and HIPPA requirements/liabilities and adapt as needed. Certainly not perfect but it's a good starting point for widespread data laws.

The question is, will our representatives actually give teeth to real data protection legislation (not a facade with no teeth only enacted by name) in the US or are they too deeply in bed with industry that they'll protect business rights over real people who suffer real direct damages.

Re: I Got Access to My Secret Consumer Score

#97

Earlier quoted context omitted.

A binary score is still a score.

There's absolutely a difference between a binary "fraud/not fraud" flag and a continuous variable for quality of customer. They measure different things and have very different use cases.

Is there a perceptible difference to a consumer who has been flagged as "fraud" when they are not, in fact, someone who has committed fraud?

If not, then there's no difference.

Re: I Got Access to My Secret Consumer Score

#99
Here in Germany there's a popular company called SCHUFA (https://en.wikipedia.org/wiki/Schufa) which collects (and sells) data about (non)solvent people since almost 100 years.

Thanks to law, one could already ask in the past about one's score. Thanks to GDPR, nowadays, they have to publish a much more detailed report of what they store about one. And it's really scary: It's written that I lost some scoring because I moved from a smaller building to one with more then 8 tenant parties (flats). So literally, I moved from a smaller house to a bigger one and now I am less creditworthy.

Re: I Got Access to My Secret Consumer Score

#100
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

The liability would be the same as a GDPR dataleak, or comparable. If the data leaked is sensitive enough, you might get fines and punishments by other regulatory bodies or industry bodies (PCI audit might be failed next time, so no card processing anymore).

The victim might be able to sue for damages incurred by the identity theft.

In my experience, some companies place high dilligence on the process. A bank I requested information from sent a postal letter containing a code to my mailing address. The Germany Postal Service has a special service to allow identifying people, so the letter contained the code and then I had to bring part of the letter back to the next postal station along with my ID card.

Once they got the confirmation of the ID card along with the code sent to me, they sent a CD-ROM with the information encrypted and the password via mail.

Post reply on HN