How can they not be liable? How is this not negligence?
How can they not be liable? How is this not negligence?
My priority of problems is
* When fraud happens, banks can pass the pain and burden of proof onto consumers.
* Banks use insecure SSNs for authorization; some data is used for validating eligibility, authenticating the application, and authorizing the loan.
* There are minimal regulations on storing different classes of personal information (We need sarbanes-oxley for auditing/accountability of aggregated personal information).
If 1. was addressed, banks would have an incentive to fix 2., and force credit reporting agencies to improve 3.
I think it's no coincidence that the current state of affairs sits right at the sweet spot of these intersecting interests. And the problem is that the model requires an element of risk which is quite hard to control. Every now and then it flares up and becomes much bigger than they want. So we have incidents like this where the insecurities inherent in the system get exploited on a massive scale and the risk threatens to cross from profitable to massively unprofitable.
This goes from the transaction terminal to the bank's server room.
Europe has had chip cards for over 20 years. In the US, it was very recently implemented; only in the past year.
It wasn't that the US banks were occupying some "sweet spot" of retail transaction risk/reward; they simply didn't want to shell out the extra bucks to send people cards with chips in them. Neither merchant nor bank wanted to pay for chip-reading terminals. So, nobody budged until just the past year.
I don't know whether it was legislation, or perhaps the growing cost of credit card fraud (i.e. card skimmers, etc), but for whatever reason, it certainly wasn't a "sweet spot". We've had chip technology for 20+ years, they just didn't want to pay for it.
But ultimately I think its the people themselves that demand more security from their banks. E.g. Bank one introduces chip based cards and more people choose that bank because they want more security. Then gradually some atms start to be "chip only", and banks start to see the chipless ones get all the skimmers and accelerate their replacement to lower costs which forces business to atart getting more pos terminals with chips to meet the demand of people with cards that have mag strip disabled.
Having more security seems to be what everybody wants and benefits from, its just that europe has smaller players which accelerates market forces in that direction, and meybe because european consumers just want more security in general.
Here in the U.S. the next step is usually asking for the social security number. I called VISA/Citi to re-activate my card after traveling and they asked for the associated phone number with my account. Neither of these are especially secure, in my opinion.
Agreed. It still amazes me how prevalent credit card fraud is. Certainly that's preventable - if they want it to be. The problem is, the banks don't bear that cost, the consumer does. Even if the bank factors the loss into the cost of doing business, that still gets passed on to the consumer.
It is merchants (stores, internet sites) that bear the cost of fraud.
Merchants don't bear the cost, the consumer does. The merchant might not hand me a bill but that cost is embedded somewhere in the price.
The bottomline is the consumer pays. No matter how you cut it, the consumer always pays.
It is so strange.
What gives banks right to do that?
SSN can not be used as authorization, because it isn't secret information. And really, the same is true for credit card numbers; they're shared with too many parties to consider them secret.
It's my meta data. More valuable than phone meta data, and perhaps (to me) more valuable than my medical records. I have a relationship (as well as ethical and legal protections) with my doc. On the other hand, I've never met Equifax. They have no relationship with me other than to exploit my personal info. I never opted into that.
Yes. It lowers risk. But who benefits more? Who carries the risk? Me? Or them? It's the latter, yes. Yet we have no choice in the matter? That's not kosher.
We need to bury this nebulous "Identity Theft" and call out more clearly the two specific crimes that happened: 1. negligence (the entity that gave up the info) and 2. bank fraud. When you use these terms, the companies don't get a free pass. Just change the words and they're part of the mess.
It used to be called Bank fraud and it was the Banks problem. Now it's called Identity Theft and it's your problem.
[0] Some landlords require credit approval [1] Some jobs check credit
I was also very surprised to buy a car with cash, only to have a credit check required. It's a real thing. And according to this article, not required, but dealerships are confused by the language of the law and insist on running a credit check, anyway.
The system is rotten and (short of moving country) impossible to avoid.
There is no need to spread misinformation. While it is true that a hard inquiry will have a minor effect on your credit score (less than a 5 point hit), multiple hard credit inquiries from car dealerships or mortgage lenders within a period of 45 days only count as a single inquiry.
You're not at all disadvantaged by taking your business elsewhere, you're just making things up to furnish your dubious story.
That said, going in with a briefcase full of cash is going to cause a lot of other problems.
The dealership wanted to run a credit check if I were to pay with a personal check, but not if I paid with certified funds. I called my bank to have my debit card limit raised to $40,000 for 24 hours and paid for the car on my debit card with no credit check.
Or living suspiciously like a drug dealer (without money laundering).
Totally reasonable.
All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very similar to Google, et al. We aren't the consumer. They collect our personal information, vastly more than credit agencies. And the real customer are the advertisers who pay Google. The difference is, we probably trust Google more than Equifax (even before all of this).
A month ago, my mom said she wanted to start using Uber on her phone. I explained how to install it, and when she did (as well as the Lyft app for that matter) it wanted access to her camera, photos, contacts, a list of information on her phone. And she said fuck no. And refused to give permission. So she still uses cabs and pays cash.
The elements of negligence are:
1. Duty
2. Breach of Duty
3. Cause in Fact
4. Proximate Cause
5. Damages
You probably haven't suffered legally cognizable damages (yet). If and when you do, they might well be liable.
Don't want to be liable? Then don't store my data.
The main difference is that there is no magic number that any one can use to borrow money in your name. Lenders have to verify a person's identity using ID.
Further more, to get loan you don't have build up a score first. You could get a margage if you have never borrowed money in your life but have a stable income.
Same in the US, although it's a bit of a pain in the ass. It's my understanding, though, (correct me if I'm wrong!) that Germany is a bit less thrilled about credit than most other countries—even in Europe.
Article is in english: https://www.deutschepost.de/en/p/postident/identifizierungsv...
Is there a law allowing that?
Common sense suggests it should only be possible if user explicitly accepted "I agree that knowing my SSN is enough to prove it's me and I agree to be liable to any debts created with just my SSN presented".
But that's probably far too sensible European thinking.
I regularly keep hearing reports of how the US handling of money is basically medieval with some badly thought out insecure bits pasted on top. And some of that gets exported! It sucks that I need to own a credit card to be able to make international purchases on the internet. Why is there not an international version of iDEAL?
What you're saying is probably true in any country; but in reality imo it's way easier not to allow that to happen in the first place.
There's typically a single public entity that holds insolvency records within the legal framework. In some countries nobody can query it but yourself; you're therefore asked to submit a copy of your record in some occasions.
As for solvency, when you sign a lease or contract a mortgage, you're asked to submit proof of income.
(Someone mentioned Germany earlier, it's a terrible example in my opinion, Schufa isn't much different than the US credit agencies, albeit more accountable hopefully).
https://en.wikipedia.org/wiki/General_Data_Protection_Regula...