LifeLock CEO’s Identity Stolen 13 Times
wired.com
wired.com
I cross-referenced the SSN death index to ensure dead people had not risen from the grave to apply for credit. I also excluded the popular "fake" SSNs used in advertising (http://en.wikipedia.org/wiki/Social_Security_number#SSNs_inv...), and I most definitely added Todd Davis's number to the list. This last step seemed like a no-brainer given all of the publicity at the time.
While I can understand a small boutique store not going to those lengths to prevent a fraudulent account, I am a little surprised that AT&T and Verizon were among the casualties.
The "theft" part occurs when someone is assigned that SSN starts using it and finds out that they have $300,000 in bad loans on their credit file. This is usually a kid who is applying for student loans or their first car loan. Then they must spend time/money cleaning up their credit file.
http://news.debix.com/index.php/2008/11/teenager-tarnished-b...
Discolsure: I'm a former employee and current investor in Debix.
Verifying the SSN using that service for banking (as I'm reading it) is a clear violation of the system.
Reference (http://www.ssa.gov/employer/ssnvshandbk/ssnvs_bso.htm)
If you were using a different service I'd be interested, as we are always looking for new ways to do validation of accounts.
http://www.ssa.gov/ and http://www.socialsecurity.gov both have a lot of useful information about structure and allocation of SSNs if you are looking to do something similar.
And that's when I realized how easy it is to steal a person's identity.
Who manages/offers this service? Experian/TransUnion etc. could do this for a very small fee. Sure, there would be the issue of lost PINs, unavailability of Internet access, not having your cell on you etc. but I think it could work very well. Right now, it is possible for someone to find out my SSN# from a piece of paper from a trashcan and immediately buy a phone in my name. At least I can change my pin if someone finds out.
How it works is when you're about to apply for credit somewhere, you ask them "what bureau are you checking?" Then you go online to that bureau and temporarily "thaw" your credit just for that inquiry. And there's a nominal charge for this service.
At least that's what happened when somebody tried to use my identity to buy a Hyundai in Florida.
The 'thaw' scenario would kick in if you were to legitimately apply yourself for an auto loan at a Hyundai dealership in Florida, and have that loan not be rejected.
There was such a product provided by Debix (http://debix.com). It relied upon a law called the Fair Credit Reporting Act which allowed consumers to place a fraud alert on their credit file, which the creditor was supposed to call. Debix placed the fraud alert on behalf of consumers, but directed the creditor to call Debix which delivered the credit request using exactly such an authentication mechanism that you describe. This was 2003.
Lifelock used the same mechanism (though without the phone authentication, IIRC). Experian sued Lifelock saying that the FCRA did not allow for companies to set fraud alerts on behalf of consumers, only consumers were allowed to set them. In May of last year, a judge agreed with Experian, and Lifelock later settled and stopped using fraud alerts. http://www.finextra.com/news/fullstory.aspx?newsitemid=20078
Unfortunately, this ruling also meant that Debix could no longer set fraud alerts, so they had to cancel this product.
The truth is such a product creates friction in the instant credit market, which is a huge source of income for credit bureaus. So they have very little incentive to slow that process down and would rather just catch any exceptions using monitoring.
The credit bureaus are an industry crying out for disruption. These guys are dinosaurs and are living it large because there is no real alternative. Unfortunately, they also seem to have plenty of political capital to prevent any real legislative reform in this area.
Disclosure: I used to work for Debix and have ownership in the company.
Someone recently suggested the 'nuclear' option of making everyone's social security number public and forcing all institutions to figure out a better model. This may be too extreme but something like that may be necessary
It's like requiring everyone's username to double as their password. It is seriously broken system, something else has to be figured out.
Reminds me of the old joke:
Store Cashier: If you'll just give me your SSN, I'll sign you up for our rewards program.
Customer: Can you keep a secret?
Store Cashier: Of course!
Customer: So can I.
why is it that the most important piece of identification you receive in your life, that you also need to keep forever, is printed on a crappy piece of paper???
To make matters worse, I had my username wrong, and so they helpfully told me "my" SSN, which was someone else's.
We live in a world where I have an 8 digit alphanumeric password protecting my weather preferences, but nothing protecting my credit.
buys some socks from the gap
cashier: may I have your number?
me: why on earth do you need that? People actually answer you when you ask them that?
As a German citizen, I find this whole matter very weird. I don't understand the need for the social security number system you have over there.
Names don't work because there are many people with the same name, and besides, they are alphabetic. Phone numbers occasionally transfer to others, as do physical addresses, etc. A Social Security number is always unique to its possessor (theoretically) and, for most adults, is available immediately in memory.
As such, it's become a popular "customer ID", as it were, in a lot of systems. If you assign each individual their own ID, they will forget it and mix it up with other IDs from other places, so an SSN is easy for everyone involved.
The problem is that people assume that an SSN is exclusive knowledge and use it as an authenticator -- when something is a universal identifier that you must write on many documents and give to many people (usually along with all other personal stats like address, phone, names, etc.), it just isn't reasonable at all to think that that can function secretly.
When asked for an SSN, a lot of people don't refuse because they imagine the fight would be fruitless and they'd be denied access to the thing they were trying to get. Some people don't understand much about SSNs or how easy it is to steal identities with them, so they don't mind giving it out. There are certain places where an SSN is legally required (for instance, opening a bank account) and sometimes it's hard to know if you're obligated to give the info or not.
Perhaps it wouldn't be so bad if the SSN were used merely as a user ID and there was an authenticator required in each case, but as it is now, in most cases, you can walk in with an SSN and a few widely published data like name and address, and obtain all kinds of loans and accounts from all kinds of places in the name of the SSN's registered owner, because people assume that only the real owner is able to know the SSN. It's this assumption that is responsible for our difficulties.
Who, precisely, is going to return printer paper?
And besides, maybe you got the wrong size for your printer?
I usually always give out my phone number (I am a geographer, like I was excited when the census came.) and I have never had calls from the GAP or other stores solicitating anything.
Take off the tinfoil hats and help us geographers!
I've always worried that enemy forces would capture our troops, steal their identities, and then ruin their credit.
Anyway, I have access to the SSN of just about everyone in the army over the last five years. The do give the special forces people substitute SSN numbers but other than that it's fairly easy information to get access to if you if you are doing any sort of analysis of army trends.
When I started grad school they used SSN as the ID number too. I went to the registrar and asked them to change mine. They said they couldn't do it because, as a TA, I was considered an employee and they "had to" use my SSN. You can imagine I wasn't happy.
As the talk began, the presenter passed around a sheet and asked everyone to sign in - with their name, school, and social security number.
It made it halfway around the big conference hall, and halfway through the talk, before someone finally raised their hand and asked about the incongruity of being at a talk about the importance of keeping SSN's secret, while being asked to sign in with them.
Credit bureaus are designed to protect lenders, not lendees.
experian and transunion build a business off the backs of consumer data. consumers are reliant on their records, but generally have to pay to get access to them, even to correct a report.
like i said - it's a big, staid, slow-changing opaque industry. looking at it through the right lens makes for a big opportunity.
I think you need to re-read that, then explain the difference.
A "consumer" is not a class of person, it is the act of being a customer.
AT&T isn't even bothering to check photo ID. Being defrauded is a risk they have eagerly assumed. Presumably they make more money this way, despite fraud.
On the back of my debit and credit card I sign it with "Check ID" since the cashier is supposed to at minimum verify the signature. I've had cards stolen multiple times and have had them used before I could cancel them. So much for verifying the signature.
This is a funny prank where a guy went out trying to get people to actually look at the back of the card :)
P.S. To be more clear: the company giving the loan should prove that I signed the documents, not I that I didn't sign them. The presumption of innocence if you will.
Years ago I rented at a crappy apartment complex. When I left their check out basically meant you always owed them ~$200. I paid and moved out of state. 6 months later I get a collections call saying I didn't pay the bill. I told them I paid it, she said it wasn't and said it was going on my report unless I paid that day. Luckily I paid by check and my bank (like all banks I guess now) keeps canceled checks online for pretty much ever. So now I had to go back 6 months and find this check then call the apartment then the collections agency, etc... A HUGE hassle and time waster for me all because the apartment complex employed incompetent people.
The kicker was that the girl trying to collect from me said "people make mistakes and you can't blame them." Um, when I make a mistake and forget to pay a bill you guys jump all over me. You make a mistake and it's still my problem to solve.
1) He will never be responsible for any of these claims from merchants ("seller beware") 2) Any major transaction would not go through since they'd pull a credit report and see his profile is frozen (I believe LifeLock just freezes credit for you on your behalf)
Given the above, it seems like this is a trade-off between the time spent getting this stuff off your credit report (I think you would just file an error with the bureau, but perhaps it's more involved), vs. the benefit gained by the marketing tactic.
After all, it's not always the case that product->quality == marketing->quality.
Got what he deserved, especiall yconsidering he was fined for deceptive advertising because of crappy security.
I've never liked those commercials... now I have a concrete reason to dislike the company.
Bring on the ID thefts! He's quite literally asking for it.
Or Lifelock is pretty good.
http://www.lifelock.com/our-guarantee
Money quote: "Under the Terms and Conditions, NO money passes directly to our LifeLock members."
http://www.lifelock.com/about-us/about-lifelock/terms-and-co...
"LifeLock will retain and pay for those third party professional services that are reasonably necessary in LifeLock's judgment to assist you in restoring losses or recovering your lost out-of-pocket expenses caused by such fraud. "
Disclosure: I worked for and have ownership in a competitor to Lifelock.
We need more of him.
Doesn't work in the other countries, as long as you don't send in copies of your passport or identity card to claim a fake lottery win ;).
Sub 10k in fraudulent charges on an SSN that is published? Like this?
According to Wikipedia, Identity theft doesn't result in the high dollar figures I was expecting http://en.wikipedia.org/wiki/Identity_theft#Spread_and_impac...
Identity theft is a serious issue, most young techies haven't been a victim simply because time and risk haven't converged. It can impact your life for years, making it extremely difficult to get a mortgage, car loan, or even land a job in some cases.
I wish there was a way for all CEOs to do something similar. Too bad it's kind of difficult for, say, a social web service.
Everyone is seeing if his ss# is still there?