Live data from Hacker News

It's still easy for anyone to become you at Experian

krebsonsecurity.com

221–230 of 347 posts

Re: It's still easy for anyone to become you at Experian

#221
post #88

I’m guessing this will continue to happen until, I dunno, some the execs at Experian continually have their accounts compromised in the same way again and again.

Unfortunately, the people in charge of these systems have enough money to hire people to do all of this crap for them. They don't do their own taxes, they don't open their own credit cards, they don't negotiate their own mortgages or car loans, nothing. They just tell their butler or financier or real estate agent or whatever "Go get me an X" and that other person deals with all the shit. Being the target of identity fraud just means they hire another gofer to deal with it full time for six months which costs them so little money, relative to their wealth, that's it's not even worth thinking about. And they're not even using their own credit, most of the time, they're using the "credit" of some shell corporation or limited liability corporation or trust or whatever other financial bullshit they hired a dozen lawyers to set up to commit tax fraud. So no, they experience none of the shit they perpetrate.

Re: It's still easy for anyone to become you at Experian

#222
post #220

The fact that we haven't nationalized credit reporting absolutely baffles me. These companies have so much power over our lives, are completely unaccountable, and are so incredibly incompetent.

Yes and then people claim the social credit scoring system in china is a dystopian hellscape. I happen to think it’s far less dystopian that privately run financial credit reporting agencies.

Re: It's still easy for anyone to become you at Experian

#223

Earlier quoted context omitted.

I would say this problem would also be solved if we stopped pretending that a Social Security number was a serious substitute for secure national ID.

There's an easy way to do that: pass a law exempting Social Security Numbers from all identity theft and fraud laws. Make it completely legal and tort-free to lie about social security numbers anytime, anywhere, except when dealing directly with the government (i.e. filing your taxes). That'll stop them being used, and right quick.

problem is: what to use instead? They don't really have an alternative, either

Re: It's still easy for anyone to become you at Experian

#224

This happened to me and I ended up calling them to get them to reset my email. It hinged on me answering security questions correctly. Which btw, some of these were also wrong since my identity thief changed some addresses on my credit report. What a fucking mess

What even is the next step if everything's been changed?

Re: It's still easy for anyone to become you at Experian

#225

My Experian was hijacked, unfrozen, and used to get a $100k loan from Ford Credit. Took me ages to clean up. Bastards.

The worst part of such an experience is that once you've reported a case of fraud on your credit report, if you at a later date want to open a new bank/credit/whatever account somewhere then you have to jump through ridiculous hoops, or will simply be denied outright because they won't believe that you're who you are since your PII was flagged in the past.

Sounds great, I how do I sign up for this ahead of time?

Re: It's still easy for anyone to become you at Experian

#226
post #222
post #220

The fact that we haven't nationalized credit reporting absolutely baffles me. These companies have so much power over our lives, are completely unaccountable, and are so incredibly incompetent.

Yes and then people claim the social credit scoring system in china is a dystopian hellscape. I happen to think it’s far less dystopian that privately run financial credit reporting agencies.

I think social credit scoring is another level closer to hell.

Re: It's still easy for anyone to become you at Experian

#227
post #223

Earlier quoted context omitted.

There's an easy way to do that: pass a law exempting Social Security Numbers from all identity theft and fraud laws. Make it completely legal and tort-free to lie about social security numbers anytime, anywhere, except when dealing directly with the government (i.e. filing your taxes). That'll stop them being used, and right quick.

problem is: what to use instead? They don't really have an alternative, either

Businesses can come up with their own ID systems. Google doesn't need your SSN for a Gmail account for example.

Re: It's still easy for anyone to become you at Experian

#228
post #220

The fact that we haven't nationalized credit reporting absolutely baffles me. These companies have so much power over our lives, are completely unaccountable, and are so incredibly incompetent.

Years ago I worked in the industry and I totally agree. Fair Isaac in particular has enormous power as basically the only source of models people use, and they are very opaque.

Re: It's still easy for anyone to become you at Experian

#229
Yet another reminder that account recovery is the weakest link in the security chain for online accounts. Consider all the work going into new tech such as passkeys -- none of it matters if it's possible for janky account recovery techniques to punch a hole through flawless authentication standards. Unfortunately, companies have come to expect that a large number of their users cannot be expected to reliably store and retrieve their login credentials, whether in a password manager or their head.

Re: It's still easy for anyone to become you at Experian

#230

Earlier quoted context omitted.

It is not that expensive. It is a couple pennies per pull (of a credit report/file) for somebody seeking identity proofing to use knowledge based authentication (the usual “where did you live, are these trade lines you?”). It is $1.50-$2.00 per proofing attempt with the government credential using ID.me or stripe identity. The problem is that no one is incentivized to slightly increases costs to reduce fraud because…

ID.me supports hardware 2FA, including Yubikey.

I think we should be asking how to design the procedure for when someone calls and claims they forgot everything and lost everything. An attacker can always call in and say this, and we'll need to call in and say this if we've been attacked.

My opinion: we should be able to visit a government office, get our picture and fingerprints matched, and then we can reset our email/password/2fa right there.

Post reply on HN