Relevant comedy: https://www.youtube.com/watch?v=CS9ptA3Ya9E
For what it's worth, here in Europe you could pretend to be someone else as well, if you have enough information, but what's the point when you can't touch their money?
You can spoof their identity, to instantly acquire material goods / lines of credit.
And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.
If you had the number of my credit card, my account number, my social security number (or the local equivalent), my address or my name, or whatever else, short of my 2FA device and my internet banking credentials, you won't be able to steal anything. (And at that point, you might as well walk up to my house, break a window and steal whatever the hell you need while I'm somewhere else, why bother with hacking.)
If the 2FA device is just a phone, there's a few things you can do, otherwise not really. Are you going to deploy a fake cell tower to steal the code? Probably just conning the cell company support person would be good enough. Not sure whether they'd mail a new SIM to a different address (and they'd probably let me know). Maybe they'd give it to you if you presented an ID. You could have a fake one made, I guess. It would be a bit weird if you didn't speak the local language though. Quite a lot of effort compared to copy pasting a credit card number. Not something you'd do on a large scale.
>And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.
Yes, but against a determined attacker that singles you out, you are fucked regardless of what you do, especially if it's your bank or similar service provider that screws up even if you don't.
When applying for new accounts, or logging in from new devices, you should be receiving an email and/or sms on the endpoints of your choice. And then able to stop those things from happening.
So now the practice is to fetch the credentials from the nearest bank office or something like that.
Isn't that what we're trying to prevent- becoming the victim of a determined attacker?
I don't really care about protecting myself from /only/ script kiddies.
If I put my money in a bank and they "accidentally" allow someone other than myself to withdraw it, /the bank/ has been defrauded, not me.
Thanks to corporate control of the US gov't, it is now me who has actually been defrauded, thanks to some fun mental gymnastics.
So, I have to spend time and money and frustration trying to convince the bank to uh... what's it called... oh yes, give me my money back, please.
The system is broken for sure, but I really truly hope we can vote some people into office who will turn the tables on how these laws currently work.
Otherwise we will all eventually be hacked, stolen from, or worse.
That's the funny part - there's no 2fa available for most internet banking in Canada or the US. In Denmark we get the NemID card mailed to us, but in Canada it's just your card number+password+sometimes they ask a security question like "what high school did you go to?"
Most countries have some type of citizen identification number, which is attached to some ID with a photo and/or finger prints. The US does not, and the political climate for the past several decades would probably never allow this. The Real ID act has been seen as a sign of the beast by religious fundamentalist and a basic erosion of rights by libertarians et. al.
Passport numbers can't be used either because not all US citizens/residents have a passport and the numbers change when you renew them. Most parents get a SSN for their child at birth. Even people I know with dual citizenship overseas have them (all except for one, and you don't really need one unless you want to go to America to work .. and then you'll also need to pay an immigration/tax lawyer to go back and reconcile all your taxes).
Here's a great video on it: https://www.youtube.com/watch?v=Erp8IAUouus
When I got my first driver's license in Georgia USA, 1986, the license number was my SSN. Every system used it to identify you: banks, doctors...
But things started to get weird. As other have already commented, everyone got confused, and let "Identity" = "Authorization".
Perhaps in a world of paper records, this system would have been ok. But always more transactions from remote locations. Many stores required you to write the last four digits of SSN on checks, or credit card slips, because they had no way of authorizing the transaction with your bank. Large vendors had these little modems that could dial up and talk to your bank, but small shops only had paper.
Anyway, it was in the banks' interest to roll out Point-Of-Sale transaction tech, because USA banking laws committed the bank to pay the vendor.
But fraud increased as the tech got faster. Someone noted that Social Security, by explicit law, cannot be used as ID in any situation that is not directly involving a Social Security pension or insurance.
The banks and medical systems rolled a lot of the shift away from SSN under their huge Y2K projects.
Here we are. Now they all ask for other publicly-available personal information, and still confuse ID with Auth.
My guess that this is misguided and muddled security thinking behind this, and is something that happens when the involved institutions do not have a coherent understanding of information security.
But knowing a persons name and social security number allows you to do all kind of misuse, i. e. identity theft. I have not lived in Sweden for 30 years, but I assume many things still work similar as here in Finland. Closing other people's credit cards and mobile phone subscriptions typically works by knowing the social security number. Ordering online without credit card and paying the bill (or not) after delivery, too.
Why do you need that exactly? If you are selling something, it's quite simple: if you receive the money, you provide the service -- if not, you don't.
The payment processor can use 2FA (this is actually done by a number of banks in Europe, when you enter the payment information, you get a text message with a code from your bank to confirm the transaction).
I think 3-D Secure is the protocol they use.
So no, I don't think there's any Equifax equivalent where a data leakage would enable stuff like this.
Thats how it should be done, except in the US there is no way to check against a national database of IDs, not even on the state level with DMVs. You literally trust the plastic card the person shows you and thats where the problems start. Online its even worse.
The major benefits compared to SSN authentication still are:
* It's a physical object, you have to be physically present to steal each one instead of getting a hundred million at a time.
* Most people would quickly notice that their card is gone, report it, and get it revoked. You only have between a few hours to a week to use it, not the next 50 years.
However, most of those scenarios have the added security that the CC or some necessary confirmation letter to sign is sent to the registered address of that id. So you'd also have to stalk my mailbox to actually get the credit card. This actually happens - so people use locked mail boxes to protect against this.
That is, even for this "manual" id method, there is 2fa in the form of regular mail, made possible by the fact that you can't use my id and give them your street address. When you show my id - they immediately know what address belongs to that id.
The 2fa app is driven by a separate company that only does identification service.
This makes the phone scam a lot more involved because you can impersonate someone on the phone but the mail makes it kind of 2fa. The credit card you tried to open in Bob's name will always be sent to the real address of Bob.
The bank didn't need to store much here - names and addresses they can lookup directly from the id number.