Our entire credit bureau system is broken
theverge.com
theverge.com
Here’s a scary fact: take your SSN and add 1 to it. That’s a valid SSN! There’s no checksums or any security features at all. If you were assigned a(n) SSN at birth, that new SSN has a high likelihood of even being someone born in the same hospital as you.
Could we have a memorizable public key and still have any meaningful level of security?
that way, I can decide how much I care about your 2 missed car loan payments 5 years ago and your disputed dry cleaning bill myself when offering you terms.
Why does my landlord need to know how much my student payments were ten years ago? Or what sort of car I drove then, and how long it took me to pay it off? Or that I once owed money to deplorable-sex-dungeon.com, or whatever other arbitrary thing they find offensive?
if I were* a creditor, I'd find it pretty valuable to know if a prospective lender was a deadbeat. just trying to find a middle ground here. my score is awful because I never borrow any money. i think that should be qualitatively different to a potential creditor than someone who doesn't pay their bills.
for some number of years that meant traveling (car rentals, hotels) was a huge effort. getting leases on apartments was easier because of references. a mortgage was possible in the seedy 2000s, but not any longer.
Things renters can and will do include not pay rent, incurring several months (or worse) while being evicted, trashing the house.. if they behave badly or just can't quite keep up with timely payments and you have to rollover to a new renter that is pretty expensive, too.
This isn't to say credit scores are perfect, but they are so effective a predictor of conscientiousness, insurance companies rely on them to predict someone's likelihood of a car accident - on average, they work.
Sure, could I deduce that $1200 a month is for your rent? And that $250 is your student debt repayment because you've been paying it for 10 years?
Anywho, there are different ways to present your credibility as a debt repayor without leaking too much. Not that I'd mind giving out detailed information, as long as they ask my permission first.
Apple is trying very had to do proper public-private key crypto, in a way where not even they have access to the keys, but that is also convenient for the user.
There's a reason, for example (this is the best example) you have to approve new iCloud Keychain devices from an existing device. Because that device re-encrypts the database with the private key of the new device.
Even that can cause problems as once someone forgets their password they may not be able to recover that keychain and by proxy other services. There are some trade-offs including an iCloud recovery key that is protected by HSMs that Apple Have with the complete inability to update their firmware - but that has other trade-offs such as they can't fix any bugs on those devices, etc.
I won't fully detail further I would suggest doing your own reading.
You may also wish to look at FIDO, in a sort of related unrelated way.
If (even) more of the contents of those boxes became valuable for easy impersonation and theft, the motivation for people to rummage would increase, and we would all likely pay a cost both in convenience and dollars for ordinary mail use.
Yeah, but get caught messing with mail and you can get royally screwed. I don't know of any other country where the Postal Service has its own cops with arrest powers, seems to be a pretty powerful deterrent.
For example:
http://www.birminghammail.co.uk/news/midlands-news/revealed-...
So people simply got lockable mailboxes and that works pretty well.
Post 9.11, the post office has been scanning the front and back of all mail delivered in the US. This is the corollary physical post anti-terrorism measure to scooping up all text messages and email metadata. Somebody realized that these scans could turned into a service where you can see what's in your postbox without having to visit it. Helpful if you don't get to the mailbox frequently or are traveling.
I signed up for the service and they used some sort of knowledge based question to verify I actually lived at the new address. Questions like "Which of the 4 addresses did you live at previously?" The IRS has tried to lock down their systems with questions like this and failed miserably. With the amount of data accumulated about us all, if somebody wants to dig up info on you, it's possible through a myriad of data broker services.
I failed the knowledge based identity test, I was asked to bring my ID to a post office. I think either they didn't have the right profile information for me, or were confusing the profile information for a prior occupant of my new address. My driver's license has a badge from the DMV showing that I had registered the new address with the DMV. This badge was delivered by mail to the new address. I presented this ID to the post office.
After all this, my request to join the Informed Delivery program was rejected. I have notification submitted with the post office of my change of address, I presented valid DMV ID that was not accepted despite it having been correctly updated with the DMV. While I was there, I was asked to show a second form of ID which was not indicated as a requirement on the program documentation. I've escalated a request for explanation to the US post office without answer.
While I agree the US post office could provide identity verification, they are definitely not geared to actually do so.
http://faq.usps.com/documents/Informed_Delivery_Sign_Up_Guid...
Visiting the post office was easy. Getting them to accept my ID document was not.
I think if I had attempted to apply for this service at my old address, it would not have been a problem. I applied for this service around the 30 - 45 day mark after my move. I suspect the post office may be incorporating their historic data (which includes my old address) or possibly they are integrating their mailing system with DMV data (which may itself be out of date due to timing issues in data integration).
[1] (in German) https://de.wikipedia.org/wiki/Postident
It would also be useful if you could provide multiple keys and associate them with one or more databases: 'full identity' (public listing with name) or key ages (probably 18, 21, and whatever social security/etc ages are).
The latter thing would allow for sites that require 'adult' access without forcing them to request credit cards (not always of age) or personal ID. It might not even be part of the standard flow, but merely as part of establishing an adult is involved if there's a dispute.
PS: 'adult' also implies 'able to sign contract' (such as accept Terms of Service). Financial sites would obviously require the full legal name key.
That being said, people are unlikely to bother memorizing a 256-bit key, and even if they do they'll just type it into a shady form in a phishing email anyway. Better to just put it on a smartcard chip - it's proven technology that's been rolled out in other nations already.
You are thinking about this from the wrong direction. The problem isn't that the government hasn't provided a PKI, the problem is that social security numbers are being used for identification.
This was a serious fear when social security was originally created. For many years social security cards had the words "not for identification" printed on them. They contain no biometric data, not even a picture. Their purpose is not identification.
So the solution is obvious. Actually prohibit social security numbers from being used for identification. Don't allow creditors to even ask for them.
Then people will figure something else out on their own. Instead of a credit reporting agency existing at all, new credit applications could ask for your account numbers at existing creditors and then the new creditor can get your credit history directly from them. It would be straight forward to automate this -- and even require you to prove that you're the account holder by presenting your card from the other bank (or signing into its website if online).
There is no need for a national identification system. Having a bad one was the original problem. Replacing it with some differently bad one is no better.
That's still printed on them.
> Then people will figure something else out on their own. Instead of a credit reporting agency existing at all, new credit applications could ask for your account numbers at existing creditors and then the new creditor can get your credit history directly from them. It would be straight forward to automate this -- and even require you to prove that you're the account holder by presenting your card from the other bank (or signing into its website if online).
> There is no need for a national identification system.
This seems like wishful thinking to me.
The correct answer is correct regardless of who wants it to be.
Centralized identification is bad. There exists no competent, accountable, trustworthy party to administer it. It inherently gets abused to aggregate information about people that should be private. Monolithic systems are slow to adapt, allowing attackers to continuously outflank them.
When a bank needs to identify you, let them use your bank account number. When a doctor needs to identify you, let them use your patient ID number. And never the two shall meet.
Besides that, sometimes multiple entities do need to know who you are; how is it supposed to work if your insurer and your healthcare providers don't aren't able to match you up to one person?
It is possible to make things sufficiently mixed up that the entire consent-absent aggregation system falls apart. Prohibiting them from using social security numbers and otherwise not providing any alternative unique primary key would go a long way toward that end.
> Besides that, sometimes multiple entities do need to know who you are; how is it supposed to work if your insurer and your healthcare providers don't aren't able to match you up to one person?
You don't need a single global identifier for that. You can give your healthcare provider your insurance policy number.
Not really. Log onto Spokeo, look yourself up, and see how many errors there are -- but at the same time, how the data is "close enough" to be useful. All compiled without a single identifier like SSNs.
Q21: When did Social Security cards bear the legend "NOT FOR IDENTIFICATION"?
A: The first Social Security cards were issued starting in 1936, they did not have this legend. Beginning with the sixth design version of the card, issued starting in 1946, SSA added a legend to the bottom of the card reading "FOR SOCIAL SECURITY PURPOSES -- NOT FOR IDENTIFICATION." This legend was removed as part of the design changes for the 18th version of the card, issued beginning in 1972. The legend has not been on any new cards issued since 1972.
That's a subtle though crucial distinction.
The only non trivial element is how to sign the photo. I guess there must be a way to sign a degraded version of the picture so that even an average scan of the ID card would be verifiable. Or the card could contain a small, cheap, water resistant memory chip which contains the picture in digital format. Then you can have a high degree of confidence in this physical document.
And there could be other usage of that card. Like if you make it a chip & pin so the card could become an unforgeable digital signature (physical signatures are absurdly unsecure too).
In fact, your US passport has that. Look for the biometric symbol on the front. It means there's a chip inside (not sure how to read off it) that includes your digitally signed identity details, including photo.
If you're willing to go the centralized route, then a minimalist ID card would just be a QR code that anyone can open and compare the official photo to you.
Whereas digital signing can be done in an offline, airtight system, as long as the public key is widely available.
"Just a qrcode" would be a weird and inconvenient format.
Other countries (Estonia, Spain, Belgium) have smartcard IDs. You can add a qrcode to that, but the primary data store can be secured (and accessed and updated) in much the same way a regular smartcard is, you can access it from your home with a regular card reader and the relevant access application. And of course the size is completely standard. And you can add contactless support to it if desirable.
Plus the US already has experience with these types of IDs: DoD has issued 17 million Common Access Cards.
https://play.google.com/store/apps/details?id=dexlab.eCL0WN&...
At one level it's a bit silly as many have passports and drivers licenses are (almost) a form of universal ID. On the other hand, I sympathize with the push against mandatory federal ID.
But, your point is still true. Americans have an irrational fear of a national ID .
- drive to the government office (cost of transit)
- typically during business hours (non-free for hourly employees)
- provide some backing ID (otherwise, what's to stop somebody claiming to be me/you). That might not be free.
Basically, anything that might disenfranchise a protected class of citizen is going to have a tough time getting bipartisan support. Look no further than state-wide voter ID programs - almost all originate in conservative, GOP-led states - and almost all are thinly veiled attempts to prevent poor and minorities from voting (those two groups are more likely to support Democrats).
- Washington and Oregon votes by mail for most/all elections (>95% mail ballot). No clue how they validate the sender, but you don't have to leave the house on election day.
- NC voters have to show an ID. But, just about any official-looking bill, bank statement, pay stub, or government document with voters name and address on it will do.
- Arizona similar to NC, but if no photo ID, must show 2 non-photo documents.
Americans have a rational fear of a national ID.
But what advantage is there in having the federal government do this, instead of just having a bank issue one when you open your account? You could even use the same card with multiple creditors, which gives them access to shared credit history. Then filing for bankruptcy is the same as throwing away your bank card.
A current problem in the US is that we have three for-profit companies doing that today, whom are only really accountable to each other (sort of) and their shareholders. Their customers are each other and banks; you whose data is actually at risk are not a customer of strong value to them directly.
Digital signatures are this just as much as any other cryptography:
You can put a gun to someone's head and force them to sign something, or observe their PIN and borrow their card while they're not looking, and the signature will match. Which means it is no solution to the problem where you claim there is a valid signature and they claim it isn't legitimate and the signature can't tell you who is telling the truth.
It's the possession of that primary key linking all of our data that is the security issue.
If you say "I'm bob smith with SSN 12345", then you gave them your id. You didnt' verify that you are in fact bob smith with SSN 12345.
Now they have to verify with some degree of certainty that you are. So they lookup your address, and send a regular paper mail describing what needs to be authorized, and you sign and return it (or call a number and enter a code, or visit a website, or whatever).
This kind of crude 2FA can still be circumvented by someone stalking you mailbox, but it's a lot better than nothing.
Now: what this requires is a mapping from name+ssn (or some unique identifier) to an up to date address. Having that has several other benefits when it comes to e.g. automatic voter registration etc.
There are obvious latency issues with this though and it would mostly be considered less than optimal today.
Make a national digital ID app. Applicants fill in a web form saying they want to have it. They enter their personal ID number (SSN or equivalent). The one time key for the digital ID is then sent to the mail address. The user installs the digital ID app on their smartphone/computer and enters the key from the mail.
Now they can use that app to 2FA anything: fill in their tax returns online, buy things online, send money to anyone else, login to their internet bank or any other website (by open API), manage social security and other systems, apply for schools etc. This must sound like science fiction in the US but it's been a reality for 5-10 years where I live.
I'm not sure what the fear is with a large central table having a number in one column and your name and address in the others.
That said -if you are afraid of federal/national systems (which is an entirely valid if not entirely rational position) then why have a federal tax authority, national passports etc? It seems like getting the worst of both worlds if you have to run authorities that obviously need to keep track of every living soul in the country whether they like it or not - but then not giving them the tools to do so.
The EU is federal in much the same way (independent states, we don't want the central EU government to meddle too much in state business etc) but then we made sure that the EU government doesn't have anything to do with individuals in the member states, they deal only with the member states themselves. I pay taxes to the EU only indirectly through my home country's tax - so there is no need for an EU tax authority to know who I am, and so on.
The analogous situation for the US would be there was no federal taxes collected from individuals, if states issued passports etc.
How would this even be remotely viable? Why would you expect people to be honest about their credit histories in cases where they had late payments or some sort of default?
Why would you expect people to not just give someone else's social security number?
In America this would be impossible though. People would cry about state's rights, sign of the beast, privacy, etc.
I don't understand this logic, so perhaps someone can help me out. Nearly all US citizens has a SSN or tax ID number that is tied to them at the federal level. The first is a pseudo-random (I use that term loosely) group of digits that is basically required for you to get anything accomplished in the US. There are no safeguards built in to the SSN, yet it is the most ubiquitous form of unique identification used in the US with no easy way to escape it. If yours gets compromised, you're screwed, and no one is willing to help you.
A driver's license is a step down from that. Most Americans will have a state drivers license or state issued ID. No, it's not federal, but you're still entered into a government database where the information can be shared nationally if needed.
On the other hand, a bonafide identification system with real safeguards to protect your identity would alleviate so many headaches, and it would be no more invasive than an SSN. What is the actual drawback to a national ID?
Lots of significant things use an SSN as a key - medical records, tax information, credit history, financial accounts. An SSN is one of the identifying things that the government definitely has access to. They could easily strong-arm their way around different agencies/companies with an SSN, so protection from government (in my eyes) is a non-argument.
A nationalized ID is supposed to protect us from unscrupulous 3rd parties. If you get someone's name and SSN, you can do a quick public records look up for an address. Confirm it with one company (say a cable co.) and you have unfettered access to that person's life.
I don't think the government could actually do worse than SSN as ID. It's a pseudo-random number with the person's place of birth and time of birth as "seeds". I already assume that Uncle Sam has (or at least access to) troves of data on me. So can they do me a favor and at least give me a half-assed ID system?
The United States is the largest initiator of war and conflict in the world. It is the largest state sponsor of terrorism. It has more air craft carriers than the next five nations combined. It has 1% of its population in prison, more than any other high income country in the world. In 2008, congress/the senate bailed out a terrible corrupt banking industry, allowing CEOs to get away with millions, without consequence, while Americans all over the country lost their homes due to outright fraud.
Distrust of the US government is by no means irrational.
Having a digital signature by a private key is a decent way to ensure that you are linked to the public key, if the recipient knows the identity of the public key, and the private key is hard to copy (i.e. not memorizable, not something you type in to a bunch of potentially compromised computers). One way to do this is like Estonia's e-ID, which includes such a private key in the gov't issued photo ID; but having such an ID in the first place seems anathema in US.
Websites can actually use this for proper citizen authentication (and non-repudiation). The integration has UX bugs, but at the end of the day, I am very happy that we have something much more secure than a US SSN.
It certainly has had help and encouragement from government mandates (SSN, drivers license/plate, monetary surveillance, etc), but even if those were eliminated it would continue just fine using its own primary keys.
As such, it can't really be top-down reformed much [0] except for correctly assigning liability for the fallout from its negligence. For instance, having to repudiate an incorrect debt from a libelous bank or surveillance company should entitle one to easily claim reimbursement for the expenses occurred (including time) to do so.
In the coming weeks we'll undoubtedly see calls to "reform" this system through the technical strengthening of the identifiers it assigns onto us. This is a recipe for rekindling belief in the authority of private surveillance as well as an invitation for it to invade even more aspects of our lives. This is not the direction we want to go!
[0] Of course we can all work on solving the problem from the bottom up by cloaking ourselves. Spend cash when possible, rotate your grocery psuedonyms often, etc.
Erm, what do you mean "we"? ;)
While I agree with you on all other points you mentioned, it's pretty clear to me that the voting public are _perfectly_ okay with the authority of both private and public surveillance, so long as it satisfies one or more of the following criteria:
* Reduces, or is thought to reduce, the cost of credit to the individual concerned. ("I'm okay with it, if it means I can trivially get access to credit because my credit score is good.")
* Prevents, or is thought to prevent, the risk of terrorist action or harm to children.
* Is limited to "others" (poor people, immigrants, other races, etc.).
We also need to know every time our credit is accessed and updated, not monthly like current reports, realtime.
This right should be in the digital Bill of Rights that need to happen as well that you should be able to protect yourself in the case of a breach at no cost to you.
Blockchain seems like the direction, but with how slow we move in everything legislatively, we need something now that allows freezing to be free, fast and easy.
The three credit bureaus, because they are in a fixed market and not truly in a competitive fair market with a privileged position, they got lazy just like the ratings agencies during housing crash. Lack of focus on their core missions due to no competitive threats.
Unfreezing? The whole point is to delay access, it can't be fast or it defeats the purpose. "They" have everything they need to unfreeze (otherwise why would freezing be necessary), so the only real protection you have is to forcibly delay access until you can prevent it.
> TransUnion and Equifax said they are always assessing new ways to secure consumer credit data, an area that is tightly regulated by governments around the world.
https://www.reuters.com/article/us-canada-blockchain-credit/...
The irony aside, it seems like the exact sort of thing a blockchain is good for: verifying transactions with a high degree of anonymity among parties that fundamentally do not trust each other. If I say I've had transactions that I say I have, I should be able to send you a code for you to verify it. There's no reason why I shouldn't have to consent for my private financial information to be disclosed to strangers in the first place.
Also, FWIW you do have to consent for someone to run a credit check on you.
Going on a tangent, Apple has made the same mistake with TouchID.
I think that's one of the motivations (if not the primary one) to add the feature to disable TouchID from the lock screen via Emergency SOS:
https://www.macrumors.com/2017/08/17/ios-11-emergency-sos-di...
Joe/Jill Public won't use a passcode on their phone, because it's too much hassle. But they WILL enable TouchID, thus rising the bar for random phone thieves/hackers.
This is what concerns me most as we move from this to implementing solutions. We now have a glut of technology companies, some large and trusted, and many that will be created specifically to address this, that will permute the risk factors an pitfalls of such a business infinitely. One hundred companies doing credit bureau things means 100 places you'll have to put your sensitive info, 100 places that will have some different vulnerability, and 100 more targets on your attack surface.
Granted, one of these solutions may be sound, viable, secure, and advantageous to consumers. But the extant bureaus and any company that comes in to compete is a business, needs to make money, and will resist competition, will resist security over profit, and will never capitulate to a better competing solution until their last dollar is raised and spent.
If anybody still uses SSNs for authentication afterwards, they are grossly negligent.
For example in czech republic:
- everyboby has "birth number", which is more or less equivalent of SSN except it in clearly encodes gender and for most people also DOB.
- corporations and any entity that is licensed for trade (including sole proprietorships) have "ICO" (which somewhat funilly translates into "personal identification number"), in essence it is equivalent to US's EIN.
- any entity which directly deals with tax office has DIC (tax identification number), which for natural persons is "CZ" + birth number and for other entities is "CZ" + ICO, same string is also an EU-wide VAT ID.
Once you start a bussiness or even own part of non-tradeable public company (which includes things like homeowners association) all three of these numbers are readily available in various open access government registries, together with first and last name and usually with registered address and thus nobody uses knowledge of one of these numbers as serious authenticator (but from time to time it is used as kind of filter for who given bussiness is willing to deal with).
That's why it's more important than ever that we support and implement new important initiatives like that of Tim Berner Lee's. He wants a platform that gives users control of their data. Very good idea IMO.
Of course then you have regulatory capture to deal with but nothing is perfect
I am also sceptic with regards to corporations having the data but government owning it doesn't make it much better.
In Denmark you mostly need to get access to one place in the system and you potentially have access to the data across the different verticals, Danish system is also SSN based.
The biggest problem though is what is the alternative to a credit bureau system?
I've never been asked for it as an authenticator though.
What are you asked for as an authenticator? Do you have a drivers' license number, or a tax identification number, or a birth certificate number, or a passport number, or some other national identification item?
A consistently formatted identifier that's unique to every person in the country just seems like it would be too tempting for businesses not to use.
Here's the Gov advice for online services: https://www.gov.uk/government/publications/identity-proofing...
Here's how they examine ID: https://www.gov.uk/government/publications/recognising-fraud...