Live data from Hacker News

It's still easy for anyone to become you at Experian

krebsonsecurity.com

331–340 of 347 posts

Re: It's still easy for anyone to become you at Experian

#331

Earlier quoted context omitted.

Why do you think that calling something theft blames the victim of the theft?

It isn't blaming the victim. I think they meant something else but worded it that way. What they meant was 'redefining the victim'. The victim is the bank, who got defrauded. They then call it 'identity theft' instead of 'bank fraud'.

> I think they meant something else but worded it that way

Well, we have no idea about that :)

Re: It's still easy for anyone to become you at Experian

#332

Earlier quoted context omitted.

It was creating for the purpose of tracking an individual's account by the Social Security Administration. It later became a de facto identifier and, even worse, is many times abused as a form of authentication, but it was never designed to be either. As a result, we have processes that ask for or require a social security number that aren't even related to the purpose for which it was created: Health care, loans, de…

> some citizens of certain religious sects, like the Amish, do not have social security numbers. Fun story: many years ago, I worked on some consumer tax prep software. Specifically because of the Amish, the SSN field was optional. Imagine that - an Amish person using tax prep software.

It should always be optional as not everyone using tax prep software will actually be a citizen of the country where they're paying tax or registered with said country's social welfare system. I found navigating bureaucracy a nightmare when I first moved to the UK because so many systems were set up to require a National Insurance (Social Security) number which I wasn't able to get until after I started paying tax. Notably I was denied a bank account until I complained about it on Twitter.

Re: It's still easy for anyone to become you at Experian

#333
post #80

Earlier quoted context omitted.

Was there a period where you could register those separately? My old google account receives emails for both domains.

There must have been, else I wouldn't be in this situation.

Nah, this person just doesn't know what their own email address is and types yours instead (yours with googlemail). This happens all the time and it really isn't something Google can do anything about.

Re: It's still easy for anyone to become you at Experian

#334
post #298

Earlier quoted context omitted.

“Everything works just fine” It definitely worked great for a lot of dictators, tax cheats and the sort… I think Switzerland is a great example of why complete privacy isn’t fair on ordinary taxpayers - it allows the ultra-rich to hide what they owe

You're behind the news. The USA pierced that privacy years ago.

that's why i used the past tense

Re: It's still easy for anyone to become you at Experian

#335
post #237

Earlier quoted context omitted.

“Everything works just fine” It definitely worked great for a lot of dictators, tax cheats and the sort… I think Switzerland is a great example of why complete privacy isn’t fair on ordinary taxpayers - it allows the ultra-rich to hide what they owe

I'm an American living in Switzerland for over 10 years, and this was definitely my impression as well. But that isn't really the case anymore here - you can no longer have anonymous (i.e. only numbered) accounts, and Switzerland is no longer a preferred locations for dirty money. The ironic thing is that one of those new hot spots, in addition to the usual suspects like Cyprus, the Caribbean, etc., is the USA. See h…

The reason the Swiss value their privacy from the Government is because of a surveillance scandal that happened in 1989. See https://en.wikipedia.org/wiki/Secret_files_scandal

Of course, privacy enabled the bankers to do shady things, but this wasn't the initial motivation. Swiss people value their privacy overall.

Re: It's still easy for anyone to become you at Experian

#336

Earlier quoted context omitted.

It isn't blaming the victim. I think they meant something else but worded it that way. What they meant was 'redefining the victim'. The victim is the bank, who got defrauded. They then call it 'identity theft' instead of 'bank fraud'.

> I think they meant something else but worded it that way Well, we have no idea about that :)

I think it is a reasonable inference given the context and the description and that it makes sense to think of it like 'victim blaming' because mixing common parlance with legal terminology often results in similar confusions (for instance breaking and entering is a legal term which does not have to involve breaking anything, and assault in common use means physical contact but legally it does not have to).

In any case if it meant literally 'blaming the victim' it makes no sense at all, so either we give the benefit of assuming the poster is able to make coherent statements or we don't.

Re: It's still easy for anyone to become you at Experian

#337
post #293

Earlier quoted context omitted.

I think the point that's trying to be made is, the traditionally recognized 'victim' is not the actual victim. The person whose "identity" was "stolen" is not a victim, the bank is. What was stolen was money--from the bank. But, we've designed our system, laws, contracts, etc such that the third party who was not involved at all has all responsibility of cleaning up the mess shoved onto them

I don't really understand this. If you pay me to store your car in my garage, and it's stolen, who is a victim of car theft?

I think you're imagining the ID thief going to the bank and withdrawing your money from your bank account (which probably happens too). I also think your analogy of a "friend" isn't right... you are the bank's PAYING customer... you pay them to secure your money and only give it to you! If they fail to provide the service they're offering to you... seems like they ought to be responsible for their failure.

But another, more common scenario here is that I convince the bank that I'm you and get a credit card or loan from the bank. Now the bank is knocking on YOUR door asking you to pay them back for the cash they handed to some random person... but they're the ones who messed up by giving cash to a random person and not verifying that they are who they say they are!

You aren't really involved... the bank messed up by going "Oh you say you're Bob? Okay here you go!" Why is it your fault that they failed to accurately verify the identity of the person they gave THEIR money to? You didn't play any role in them deciding who to give their money, nor in their ID verification procedures.

Re: It's still easy for anyone to become you at Experian

#338
post #141

Earlier quoted context omitted.

> We need DMVs to begin issuing IDs that are physical with digital capabilities, like credit cards. We need the equivalent of Apple/Android Pay for identity online. We need to mandate that banks support digital IDs. And we need strict enforcement for people who misuse a digital ID. And how will all this magically work online? Answer: you'll have to provide whatever digital secret gives you access, just the way you pr…

Actually, you can use cryptography to prove who you are without giving anyone else the ability to simply "copy" your ID and impersonate you later. It's how message signing works: https://en.wikipedia.org/wiki/Digital_signature#Authenticati... Some countries already have national ID systems that use cryptography like this to secure identify oneself online, such as Estonia: https://en.wikipedia.org/wiki/Estonian_identi…

If the crypto keys are on the ID card, how does my computer read the card? How do I know the hardware and software to do that isn't compromised?

Also, the Estonia system apparently includes keys allowing the manufacturer to perform card operations. How do I know that won't get hijacked?

Re: It's still easy for anyone to become you at Experian

#339

Stepping back, and looking at the situation as a whole: the real problem is a lack of privacy laws. Banks, businesses and employers should be prohibited from sharing your personal information with third parties. I live in Switzerland, where this is the case. Even the government doesn't get this information. If the government thinks you're cheating on your taxes, they have to use warrants and follow the same procedure…

This is very true. The company that I am at, not going to mention name but just going to say its FAANG, buys data from this company and uses it to allow for better tracking and graph building when we receive experian cookies. The USA does not care about its peoples privacy even though it constantly says that it does lol. If they cracked down on the privacy laws I feel that bank accounts will get affected since in the top 500 of stocks big tech sits on top.

Re: It's still easy for anyone to become you at Experian

#340
post #329

Earlier quoted context omitted.

Assuming the thief impersonated your friend, convincing you to hand over the keys and open the door so they could drive it off?

Can you finish your thought? I'm not following.

Sibling zaphod4prez laid it out for you, I hope.
Post reply on HN