Live data from Hacker News

I Got Access to My Secret Consumer Score

nytimes.com

111–120 of 341 posts

Re: I Got Access to My Secret Consumer Score

#111
post #71
post #68

Earlier quoted context omitted.

What items did you redact from your ID/passport?

I sent a driving licence and redacted the licence number, then overtyped the whole thing with the text in my previous post. My goal was to make certain that if it leaked, the overtyped expiry date should make it useless after a certain point, and the company name should make any company other than that one question the source. As a side effect, it'd also clearly identify the source of any leaks - but that wasn't my p…

>My goal was to make certain that if it leaked, the overtyped expiry date should make it useless after a certain point, and the company name should make any company other than that one question the source.

>As a side effect, it'd also clearly identify the source of any leaks - but that wasn't my primary goal.

Wouldn't a malicious actor just add block text over your text saying "only for identity verification for SomeOtherCompany" ?

They could do the same for the expiration date, although I wonder if any company actually bothers to check the expiration date

Re: I Got Access to My Secret Consumer Score

#112
post #94

Earlier quoted context omitted.

I mean people have been subjected to fraud scoring for decades, you get declined, you follow up, and you get in w/ a new data point for the next time.

Not when these new automated systems don't allow for a follow-up because it would be too expensive to code or hire a human to do it.

How many companies don't have a support@____ email address? Seriously, they'll figure it out, it's really not that large of a haul to get stuff corrected, and it's the difference between "we can't take credit card payments" and "a very low-percentage of real users have some extra friction / bounce somewhere else".

Re: I Got Access to My Secret Consumer Score

#113

I wonder if as an EUian I can say "say hello to my little friend GDPR"..

You can, but it would be a lot more powerful if you did it in writing in the form of a properly formatted DSAR request.

Of course I wouldn't formulate it like to that, fucking hell, downvoted, that taught me, trying to make a joke...

Re: I Got Access to My Secret Consumer Score

#114
post #89
post #26

I’m curious what sort of due diligence these companies must do to authenticate you as a person prior to satisfying an information retrieval request. Given that the exchange is entirely digital, it seems plausible that there are bad actors who would pose as someone else to gain access to their personal information. What sort of liability does one of these data controllers bear when they fail to properly authenticate a…

This is already a big (and largely unaddressed) problem with the big 3 credit CRAs, if you know enough about a person you can very easily request their credit report and get the keys to the kingdom (so-to-speak) - everything you didn't already know. I mean, I already request credit reports for my husband without issue, for example (with his permission! - he finds it much easier to just ask me to do those things for h…

CRAs are a scam from top to bottom.

A bank makes a lot of money, but in theory, it's doing an important job which benefits society. That job is independently assessing creditworthiness. Of course, it's hard to assess creditworthiness if you don't know if someone is making a lot of loans at different places. So, there needs to be a system for credit monitoring. But credit monitoring is not credit rating. Credit rating is the one job a bank is supposed to do. Letting someone else do it undermines the whole purposes of the independent financial system. We might as well just dissolve the banks and move to a centralized planned economy if that's what we're doing, so that at least the centralized rating agencies will be democratically controlled.

So, to begin with, CRAs shouldn't exist and undermine the basic purpose of the financial system. On top of that, they are incredibly incompetent and corrupt as seen by the Equifax breach. It was clear in the early 2000s that the old system in which people would present a few pieces of relatively obscure personal identity to open a line of credit was no longer workable because the data was now subject to trivial duplication. Instead of fixing this, the industry created the concept of "identity theft" in order to falsely shift blame onto an unrelated third party.

I "had my identity stolen" a few years ago. The event had nothing to do with me, so all of the language around this is wrong. What actually happened was first a criminal learned some information about me, then Verizon chose to give the criminal a line of credit on a cellphone, then the CRAs reported that I was profligate to anyone who asked. Saying "my identity" was stolen makes it seem like I was somehow a party to any of this. "My identity" is not a property of mine; it is a property of the reliability of the CRAs' data. What actually happened was the CRAs had their data polluted by the combination of a criminal and lax identity checking at Verizon, and then the various guilty parties forced me to do their data cleanup for them.

What should have happened in the mid-00s was that the credit monitoring agencies, created systems where you can prove your identity to a notary public and get some sort of signed certificate gizmo that you can use to get a cellphone or make a car loan. But because the whole US financial system is corrupt, it instead outsourced all of the liability onto consumers.

Re: I Got Access to My Secret Consumer Score

#116
post #97

Earlier quoted context omitted.

There's absolutely a difference between a binary "fraud/not fraud" flag and a continuous variable for quality of customer. They measure different things and have very different use cases.

Is there a perceptible difference to a consumer who has been flagged as "fraud" when they are not, in fact, someone who has committed fraud? If not, then there's no difference.

First off no one is saying "you look like fraud", they're saying details of your purchase looked suspicious. This is the first place where people need to pump the brakes, there is not some dire sinister plot, you went to make a purchase, it looked weird, we want to make sure it all checks out. This happens _all the time_ with credit card purchases, historically from the card issuer, but card issuers are actually encouraging retailers to be more vigilant in the face of massive increases in card fraud, so now it's distributed. Honestly, whenever I've had the minor inconvenience / world-concept-shattering experience of having a card transaction declined & needing to go through around 15 mins of rectification, I've actually appreciated that they are running systems to prevent rampant fraud, because it's an even bigger pain in the ass to clean up after that than it is to endure some extra information checks on rare occasion.

Re: I Got Access to My Secret Consumer Score

#118
post #33
post #14

So Airbnb was sharing all your messages to hosts with Sift? Food ordering apps were sharing all information about every order with them?

Selling is probably the correct word... as in "They are selling the information like facebook sold user's private messages."

My focus was on them transferring it to third parties, regardless of any accompanying money flows, so sell vs share doesn't matter to me.

Since I didn't provide the relevant context in my last post, here's the quote from the article:

>As of this summer, though, Sift does have a file on you, which it can produce upon request. I got mine, and I found it shocking: More than 400 pages long, it contained all the messages I’d ever sent to hosts on Airbnb; years of Yelp delivery orders; a log of every time I’d opened the Coinbase app on my iPhone. Many entries included detailed information about the device I used to do these things, including my IP address at the time.

Re: I Got Access to My Secret Consumer Score

#119
post #46
post #12

I am surprised these guys are able to operate outside the normal credit reporting laws. He’s referencing things that happened in 2009, which is well outside the usual 7 year limit for credit report data. Clearly, these companies are going to make the argument that this is not credit report data subject to consumer credit laws, but I’m curious if that has been tested at all. I would think an enterprising lawyer could…

Aren't the credit reporting laws pretty strictly scoped to making decisions about loans? I imagine these companies are pretty explicit with their clients that scores can't be used for those purposes.

> Aren't the credit reporting laws pretty strictly scoped to making decisions about loans?

Absolutely not. The Fair Credit Reporting Act is one of the laws governing background checks for hiring (in addition to credit reporting), for example.

(and if it comes out that the reports referenced in the article were used by someone somewhere to reach a hiring decision, I expect lawsuits will quickly follow)

Re: I Got Access to My Secret Consumer Score

#120
post #94

Earlier quoted context omitted.

Seriously. If companies are relying on the fraud estimates, it isn't going to be fun to be a false positive.

I mean people have been subjected to fraud scoring for decades, you get declined, you follow up, and you get in w/ a new data point for the next time.

Right, it's not a score, it's just a thing you have to argue with them to change. Not a score though.
Post reply on HN