Live data from Hacker News

It's still easy for anyone to become you at Experian

krebsonsecurity.com

261–270 of 347 posts

Re: It's still easy for anyone to become you at Experian

#261

Stepping back, and looking at the situation as a whole: the real problem is a lack of privacy laws. Banks, businesses and employers should be prohibited from sharing your personal information with third parties. I live in Switzerland, where this is the case. Even the government doesn't get this information. If the government thinks you're cheating on your taxes, they have to use warrants and follow the same procedure…

Do you know how Swiss financial privacy and credit reporting laws compare with countries in the EU?

> Around 36 percent of the Swiss own their homes or apartments, the lowest rate in the West and well below the 70 percent average in the European Union, and the 67 percent in the United States. [1]

I’m sure there are many factors, but I would be less willing to finance someone’s large purchase without more information about their creditworthiness.

[1] https://www.nytimes.com/2023/11/06/realestate/zurich-switzer...

Re: It's still easy for anyone to become you at Experian

#262

Earlier quoted context omitted.

It was creating for the purpose of tracking an individual's account by the Social Security Administration. It later became a de facto identifier and, even worse, is many times abused as a form of authentication, but it was never designed to be either. As a result, we have processes that ask for or require a social security number that aren't even related to the purpose for which it was created: Health care, loans, de…

It still sounds like a good way to uniquely identify a person? How else would an institution confirm that it's talking about the same person?

It is used that way in Finland and a fair few other countries and works perfectly well.

Re: It's still easy for anyone to become you at Experian

#263

Earlier quoted context omitted.

It was creating for the purpose of tracking an individual's account by the Social Security Administration. It later became a de facto identifier and, even worse, is many times abused as a form of authentication, but it was never designed to be either. As a result, we have processes that ask for or require a social security number that aren't even related to the purpose for which it was created: Health care, loans, de…

It still sounds like a good way to uniquely identify a person? How else would an institution confirm that it's talking about the same person?

The same way they do for people who aren’t from the US?

Some combination of name, address, birthdate, etc.

But the problem isn’t using the SSN as a semi-unique ID. It’s using it for that and also assuming it’s secret. SSN shouldn’t be any more secret than name or address (and shouldn’t be used to unlock or access accounts).

Re: It's still easy for anyone to become you at Experian

#264
post #239

Earlier quoted context omitted.

This is a scam.

Excuse me, you're calling me a scammer? I suggest you click on my username and see that it is a very legitimate account, with twice the karma as you to boot. I think you're more likely to be the one scamming! Don't listen to 'Aeolun, everyone!

Look, you are literally posting on the internet, on an anonymous account, that if someone sends you their personal details and credit card info everything will be taken care of.

Your first reaction should absolutely be that it’s a scam, and only then further evaluate if it might possibly be true because this is HN.

I could have potentially used the word ‘looks like’, but it’s just a matter of degree.

Re: It's still easy for anyone to become you at Experian

#265

Earlier quoted context omitted.

So you've found the problem. If they are immune from the crime, they won't stop practicing it.

My understanding is that in most cases, slander/libel is never a crime anyway. It's merely a tort (wrong). It never rises to the level of a crime. The few instances/places where slander is a crime in the US (historically or otherwise) are very problematic and subject to abuse. Perhaps this specific kind of slander should be criminal, but it might be the only kind that should be. Not only would you need to justify tha…

Well, ok. There's no need to make it a literal crime. Those companies just need to be responsible for correcting the damage they cause.

Re: It's still easy for anyone to become you at Experian

#266

Earlier quoted context omitted.

Even the term "identity theft" needs to go. My identity wasn't stolen! I'm still the same person. The bank got tricked by a scammers and somehow the bank tries to make that my fault. Edit: Imagine this the other way around! Grandma gets scammed by someone pretending to be her bank. So the bank's identity got stolen. So now the real bank needs to fix it, provide more proof of identity to all customers and jump through…

Why do you think that calling something theft blames the victim of the theft?

It isn't blaming the victim. I think they meant something else but worded it that way. What they meant was 'redefining the victim'. The victim is the bank, who got defrauded. They then call it 'identity theft' instead of 'bank fraud'.

Re: It's still easy for anyone to become you at Experian

#267

Stepping back, and looking at the situation as a whole: the real problem is a lack of privacy laws. Banks, businesses and employers should be prohibited from sharing your personal information with third parties. I live in Switzerland, where this is the case. Even the government doesn't get this information. If the government thinks you're cheating on your taxes, they have to use warrants and follow the same procedure…

[deleted]

Re: It's still easy for anyone to become you at Experian

#268
post #161
post #25

Earlier quoted context omitted.

A statutory fine of $50k per compromised account would get the attention of the credit bureaus. (It might drive them out of business, but it sure would get their attention.)

For reference, Equifax leaked the personal information of 147 million people (myself included). Multiplying that by $50k is over 7 trillion dollars. In actuality, they were ordered to pay up to $700 million in total which works out to about $4-5 per person. I agree with you, but the gap between what you propose and the status quo is staggering.

So yeah, in this case Equifax would go bankrupt and other companies would get very valuable lesson to spend more money at security side of things. I see no issue here.

Re: It's still easy for anyone to become you at Experian

#269

Earlier quoted context omitted.

There’s no such thing as identity theft, it is impossible to steal an identity, the person still has their identity. It is impersonation. The victim is the entity that has fallen for the impersonation (likely a bank, etc), the perpetrator is the one who did the impersonation, and the impersonated person is just some uninvolved third party. I know it is pedantic but it is important to keep in mind because dumping the…

100% agree, except the impersonated person is impacted when their credit score eventually gets screwed and they can no longer get loans themselves. So, in that regard, they are also a victim.

[deleted]

Re: It's still easy for anyone to become you at Experian

#270

Earlier quoted context omitted.

My understanding is that in most cases, slander/libel is never a crime anyway. It's merely a tort (wrong). It never rises to the level of a crime. The few instances/places where slander is a crime in the US (historically or otherwise) are very problematic and subject to abuse. Perhaps this specific kind of slander should be criminal, but it might be the only kind that should be. Not only would you need to justify tha…

Well, ok. There's no need to make it a literal crime. Those companies just need to be responsible for correcting the damage they cause.

Don't forget compensating the injured party for any consequential losses. Which in this case might be a house or the income from a good job. See how fast they clean up their act if they can be held responsible for six or seven figures of damages every time they make a serious mistake.
Post reply on HN