Live data from Hacker News

I Got Access to My Secret Consumer Score

nytimes.com

241–250 of 341 posts

Re: I Got Access to My Secret Consumer Score

#241

Earlier quoted context omitted.

Agreed. The whole idea of "identity theft" stinks of PR lubrication. Your identity cannot be stolen, but "identity theft" is a clever, cynical sleight of hand that obscures what really happened: credit fraud, specifically fraud that is the responsibility of the party issuing credit and the criminal propagating it.

I agree with this idea in principle, but I am unsure of how it would work in practice. Say you open a credit card, then try to say it wasn't you..... what would a bank need to do to prove it was you? The things they would provide are already the things they have... your signature, your information, etc. What EXTRA bit would they start collecting that would prevent fraud? Currently, banks ARE on the hook for fraud....…

It has been done better in other countries and could be done better in the US if there were political will to do it. There's a whole universe of cryptographically signed certificates that we in the US don't use. The hard part is not signing a cert; it's making sure the certs are given to the correct people and having a procedure for when a cert is lost. Estonia has done this well; Korea has done this poorly. But it's quite doable if you have political will for it.

Re: I Got Access to My Secret Consumer Score

#242
post #201

Earlier quoted context omitted.

Considering how many people are notaries and how easy it is to become a notary, I don't think it's any form of security. It's just an artificially created market for people to make quick bucks signing documents.

Notaries typically cannot notarize their own documents.

So get your friend to be the notary? It seems like an incredibly insecure system to me for the 21st century world when we have much better ways, e.g. signing keys.

Re: I Got Access to My Secret Consumer Score

#243
post #101
post #60

Earlier quoted context omitted.

how does that not violate HIPAA ? I see it talking about "you can proactively opt out with hipaa" but everything I've ever seen about HIPAA is that all "opting in" needs to be explicitly granted by the patient.

I imagine somewhere in their quoting algorithm they have a conditional like `if potential_customer.opted_out_of_hipaa then quote = max_possible_quote, msg = 'you can lower your quote by sharing your data with us'".

Unlikely

Re: I Got Access to My Secret Consumer Score

#244

Two points: First, the very act of requesting your data is in a way confirming and verifying the accuracy of the data. Second: Every prescription you've ever filled with insurance - and even some without - is recorded by companies like Milliman.[0] When you want to buy life insurance, health insurance, etc. they can request to see what medications you're on, have been on, etc. [0]. https://clark.com/insurance/how-to-…

How is that even legal? Isn't patient data specially protected?

Your healthcare providers, pharmacies included, can sign BAAs with other firms that allow them to share the data. Your consent is not required.

Re: I Got Access to My Secret Consumer Score

#245

Earlier quoted context omitted.

Another interpretation of that catchphrase is that once it's written, it can't be unwritten, and that's true with laws, or at least they've very difficult to change once on the books. We need to understand the full scope of the problem, rather than try to fix what isn't fully grasped, and honestly I have very little faith in the US government to accurately grasp the subtleties and nuances of the advertising and priva…

But that's not an interpretation of that phrase at all.

It's not up for debate whether or not what I wrote is an interpretation, what might be up for debate is how valid the interpretation is, and even still, you could strike all reference to the phrase from my comment and the point I made would stand.

Re: I Got Access to My Secret Consumer Score

#246

Earlier quoted context omitted.

> I suspect we as a society need new legislation to deal with these sort of issues. Why not ban targeted advertising altogether?

Because it has value, both to the advertiser and to the target, compared to un-targeted advertising. Advertising is an attempt to transfer information. Targeted ads means that the information is more likely to be relevant, whatever its other downsides. Let's not throw out that baby with the bath water.

No advertising is really untargeted. Even billboards tend to carry ads for the type of driver that passes by them and broadcast TV has ads for the type of person that watches that show.

Ads targeted to an individual without that individual's consent should probably be banned. In addition, the law should make it clear that when a company does hold data about individuals, the individual should have some rights to that data including the ability to block the sharing or transfer of that data.

So, when Google buys FitBit, every user of FitBit should have to explicitly opt-in to their data being transferred to Google.

Re: I Got Access to My Secret Consumer Score

#247
What rights does the rest of the non-US/non-EU world have?

In New Zealand we have some data privacy laws, but they only have teeth for New Zealand organisations; we don't have the political clout to have any outcome similar to the impact of the GDPR regulations.

Meanwhile businesses in other countries have few regulations to restrict how they treat me, because I am a foreigner.

I guess I should try and get a dual-citizenship in the EU so I can protect myself a little...

Re: I Got Access to My Secret Consumer Score

#248
post #158

I just tried requesting my information from one of the links provided in the article. As part of the process I had to upload an image of my government-issued ID. After that, I was told to expect an email confirmation link that I would have to click on before they could proceed. That was an hour ago and the email has not yet arrived. I don't really have any reason to suspect that this is a scam, but I can't help but n…

For the record: I finally did receive the confirmation email, two hours after making the initial request.

Re: I Got Access to My Secret Consumer Score

#249
post #146

Earlier quoted context omitted.

But I never gave Milliman permission to hold this data, so didn't they already violate HIPAA?

I think you misunderstand HIPAA. As long as they have a business associate agreement with the pharmacies and serve some vaguely care-adjacent purpose, the pharmacy can share your data with them without your knowledge or consent.

I can't tell if you're being cynical or serious, but if the latter I can't see how this is correct.

From "Pharmacy privacy Requirements here [1], I don't think "business associate agreement [with] some vaguely care-adjacent purpose" meets the standards for information-sharing. Rather the information must be being shared as part of specific treatment for a patient (discussing actual care) or payment.

[1] https://www.uspharmacist.com/article/hipaa-privacy-security-...

Post reply on HN