Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…
Cybersecurity Incident Involving Consumer Information
361–370 of 551 posts
Re: Cybersecurity Incident Involving Consumer Information
#362Earlier quoted context omitted.
How often to you apply for credit? It is, in any case, far less of an inconvenience than not paying the protection racket, having someone impersonate you, and having the credit oligopoly lie about you because of it, leaving you to somehow clean up their mess.
Some folks churn, so they apply for credit several times a month. It's not a very small niche community either.
Re: Cybersecurity Incident Involving Consumer Information
#363Earlier quoted context omitted.
It depends... Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 scheduled trading plans. The…
> The timing is extremely suspicious. But - if they can prove they didn't know, they're in the clear. Burden of proof for criminal cases is the other way around. They will likely spend lots on legal fees just trying to prove they didn't know about the hack at the time they decided to sell. They will likely end up settling out of court (guilty or not) because that's how the US legal system works. Also important -- Jul…
Re: Cybersecurity Incident Involving Consumer Information
#364Earlier quoted context omitted.
I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…
It's pretty much the flaw in not having a national ID scheme - everyone reaches for the next closest approximation, with no funding for security systems or refreshes to address flaws. Because this is an issue the government should address seriously.
Re: Cybersecurity Incident Involving Consumer Information
#365I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…
The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.
Re: Cybersecurity Incident Involving Consumer Information
#366Earlier quoted context omitted.
I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…
You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus
Re: Cybersecurity Incident Involving Consumer Information
#367Earlier quoted context omitted.
I was not saying either really. I was asking what sure fire way we have other than a number / name for identity.
Well, there is biometry, with the simplest form being a picture, if you want to somewhat reliably identify people.
Re: Cybersecurity Incident Involving Consumer Information
#368Earlier quoted context omitted.
> Which makes your statement (that you have sufficient control to prevent the possibility of theft of your property) completely invalid. Luckily, I didn't say that.
> I have control over how I secure my car from being stolen. Really? Those were your exact words, in the context of claiming that your ability to secure your car made the comparison to identity theft invalid.
The problem is that the power to do anything about the problem and the blame is not aligned, which leads to a situation that is equivalent to the bank leaving the key in the ignition of the unlocked car, not allowing you to change anything about that setup, and then expecting you to foot the bill when the car inevitably does get stolen.
Re: Cybersecurity Incident Involving Consumer Information
#369Earlier quoted context omitted.
You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus
Americans don't like National ID cards because we remember the Third Reich and the USSR.
Re: Cybersecurity Incident Involving Consumer Information
#370Earlier quoted context omitted.
You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus
Americans don't like National ID cards because we remember the Third Reich and the USSR.
I mean sure, it's not in your pocket. But are you going to move house in response to this breach?