Three Years in Identity Theft Hell
bloomberg.com
bloomberg.com
I remain hopeful that the full list of 140M SSNs will be posted in full. It's a rare opportunity: if that happens, the US will have no choice but to finally switch to a new system. One that doesn't rely on SSNs being private. That's the absurdity. It is easy to steal your identity because we have allowed it to be easy.
It's going to be difficult to switch to a new system, but the pain will be worth it. Imagine if the author could finally have peace of mind because nobody could impersonate him.
That is a fairytale, admittedly. It's always going to be possible to steal someone's identity if you're determined. But just look how trivial it is right now. Your driver's license plus the thief's photo is all they need. And it's possible to forge: they don't even need to swipe your physical one.
Those are “the keys to the kingdom,” said Bo Holland, CEO of AllClear ID, an identity-monitoring service. “Once you have somebody's name, social, birth date, and address, you can go and open new accounts.”
The SSN shouldn't be the critical key in that list.
The United States. I assure you that even though other countries have credit reporting, they do not use SSNs.
> will have no choice but to finally switch to a new system.
Really? I think they will just carry on unless and until the financial downside (losses from extending bad credit, or lawsuits from identity theft victims, or penalties from the federal government intervening directly) is shown to be really huge.
What I do not understand is why victims of this have not sued their banks over this yet. Suing should be the US couterbalance to this. People are innocent victims of fraudulent behaviour of their banks, and those banks are being robbed by thieves. Banks are supposed to guard their customers' money, which in this case they are clearly not doing. Maybe they do it unknowingly, or they are incompetent, but in the end those banks are behaving fraudulently too.
Identity theft is not just because of ssn or other unique semi secret numbers. It's part of it, yes, but the root cause is a combination of culture and lack of inventive (ie, identity theft is just not a big enough problem for actors to care).
More and more companies are insisting on customers signing binding arbitration clauses as a condition of doing business: car dealers, banks, airlines, you mention it. It's all very well to say, well, don't do business with them, when all the competition are doing the exact same thing. If you need, say, a new car, well, good luck getting one without signing most of your rights away, and this is no exaggeration.
Binding mandatory arbitration clauses mean that you cannot sue the company, and agree to accept the verdict of the arbitrator, for which there is no appeal, and who is generally hired by the company having the arbitration dispute and is therefore impartial /s.
I have read FTC field reports about vehicle warranty claims where one arbitration decision was so outlandish even the FTC wrote that it was irrational, and the vast majority were in favor of the dealer.
With a locked mailbox (which is the default) it becomes a hassle to steal an identity.
If I get a new credit card it's sent to the address I id'd for.
(Yes, I had an ID theft near-miss that involved a locked mail box in a locked stairwell. To me, the more obvious perpetrator seemed to be someone with access to the mail delivery pipeline, but the investigator I spoke certainly did not think terribly highly of the security of a locked mailbox)
Over here it's basically used for everything that needs authentication / signatures - taxes, banking etc.
Cannot do this with SSN.
They use ID cards with at least some features to make forging said ID cards more difficult, unlike the US SSN which is pretty much just a number on a piece of paper.
This is mainly an issue of authentification and as long as your credentials remain crappy/easy to guess/easy to forge (like the US SSN system), that long it will stay easy to game the system.
Imho this def con talk about birthing and killing virtual babies might also be quite relevant to the issue, tho it's not entirely focused on the US: https://www.youtube.com/watch?v=9FdHq3WfJgs
No, but many use systems which are not appreciably better than SSNs from a security and identity theft perspective.
Identity theft isn't something I hear about often here.
The ID is government issued, cheap to obtain in case of loss (30€ and a bit of waiting until the new one arrives) and contains a photo of you so it's of no particular value to someone who doesn't look like you.
IIRC identity theft isn't a huge problem in Germany but it exists, however most credit agencies offer options to lock down or delete data concerning such theft, I haven't interacted with any of them yet though.
In addition, each government service uses a different ID number and is forbidden from sharing information or using another service's ID number. So you have a fiscal number for taxes, a social security number for health things, an identity card number that only has meaning with the card itself. Your private (non-healthcare) insurance, your bank, and other private institutions can issue you their own number as well (or another kind of id key) but can not share them between themselves and cannot ask you to give them numbers of unrelated services. Citizens are responsible for forwarding themselves most information between separate services when needed.
In practice it makes it sometimes tedious to auth at any of these services (you have to find your number in whatever mail you received or card you got issued) but it really makes it more difficult to impersonate another citizen, as you would at most gain access to one service, and it wouldn't help you access any other.
Or use the eID functionality, which is growing now that the old IDs are starting to expire.
A couple of weeks ago I had a friend over who used my WLAN to eID for some service (i think it was pre-paid CC? Neither of us can't remember at this point) over his android phone using some "AusweisApp2".
He ended up in a video chat with a lady who asked him to show his face/ID and swivel the ID in the light so she could see the reflections of the security features.
I was sitting next to that whole process thinking about how difficult it would be to put on a convincing facemask and create a matching fake ID that would pass a video inspection.
Shouldn't be that difficult, most certainly less difficult than trying to convince a postman in person by showing them a fake ID at an address matching the fake ID.
Rather, it's just very difficult compared to faking an SSN number on the internet.
The address in this case would be difficult since a lot of institutions pull your address from the local registry, so you can't convince them to not sent stuff to any victims address unless you manage to change their address in the registry too.
Ah, that’s the system you use when you don’t have any of the new eIDs, but one of the old ones.
That should be phased out by 2021
To confirm your income: Your yearly income tax sheet, a payslip or your contract of employment.
There is really no reason whatsoever for credit check and background check agencies to exist. All they do is ask for these papers anyway.
But think about America right now. Do you honestly think we could get national ID numbers? Could you imagine people being asked for a DNA swab or fingerprint to establish their identity? The blow black would be monstrous, and I don't think it'd be entirely unjustified. With 1% of our population incarcerated or on probation, with no national health care and being the largest state sponsor of terrorism in the world, there is good reason for Americans not to trust their government. Add in all the fundie religious people crying "sign of the beast" and Alex Jones followers yelling "national RFID chips" and you're stuck with a situation that cannot change.
Not necessarily. Not all states require an SSN in order to issue an ID.
> But think about America right now. Do you honestly think we could get national ID numbers?
Unfortunately (for all the reasons you mentioned and more), we're pretty close, as the REAL ID system is about to take effect.
That's going to be a huge problem for people living in the states that don't issue REAL IDs. It's also going to be a problem for legal immigrants and transgender people in every state.
I was under the impression that every single state requires an SSN to issue a driver's license or id card in order to track and enforce child support order across state lines.
Which states don't require an SSN to issue an ID?
Legal immigrants have passports, and ID cards/driver's licenses from their home country. I'm not sure what will require two forms of REAL ID compliant identification.
Nope. If they did, the impetus behind the REAL ID act wouldn't even be relevant, because illegal immigrants wouldn't be able to obtain a drivers' license or state ID.
> Which states don't require an SSN to issue an ID?
California is the biggest one, and in fact, California makes it illegal to discriminate against anyone who has a driver's license but cannot show legal residency.
Some states mark licenses as "not valid for identification" if they don't show legal residency, but it's usually subtle and easily overlooked or ignored. And the SSN isn't the only way to show legal residency, either.
> Legal immigrants have passports, and ID cards/driver's licenses from their home country.
For foreigners, passports are the only acceptable form of identification from foreign governments. Driver's licenses and other government IDs are not allowed, with the exception of driver's licenses from Canada.
Missourians have good reason to distrust the DMV, as they have been caught red handed illegally useing their databases in the recent past.
One shouldn't verify documents unless you're a member of the organization that issued them.
I remember needing to get a new SSN card once and it was creepy how easy it was.
The difference is probably that here those agencies aren't somehow trying to guarantee my identity. They just answer what credit rating my identity has.
In non insane countries, you are considered debt-free when you have no credit, not when you accumulate credits and pay them with one another.
I'm not sure how you think the American system works if you think that "debt-free" has any meaning other than "no balances or debts outstanding".
In Estonia I believe the system is based on public key cryptography (every national ID has a private key that is used for signing things).
Wow, that's really user-friendly, I wish it would be handled like that in Germany too.
Instead, German registration offices are selling citizen registration data in bulk to most interested parties and they couldn't even tell you to whom [0].
People can opt out of that process, by handing in a written objection with their initial registration, tho barely anybody actually does that because barely anybody is aware of their data being sold in the first place.
These are implemented as biometric two factor auth. So you show your id card, scan your finger print and validate via a code received to the registered mobile device on sms
(1) https://www.google.com.sg/amp/m.timesofindia.com/business/in...
And in a delightful catch-22, Aadhaar is essentially a requirement for obtaining a cell phone.
You can bypass this with some other documents and providing a landline that they verify within a week, but it's incredibly cumbersome.
I don't know what the rules were back then for moving to Canada, but you could stay 180 days at a time back then.
I'm glad they can make discresionary decisions like that for special circumstances, such as someone who clearly can't have an ID or passport yet.
Mind if I ask, did they ask for your passport?
It's the same in the US too. The problem in the article is that the person had a legitimate driver's license issued in the stolen name with his own picture on it.
It's not just a simple as "he had the SSN".
+ Getting a mortgage as an identity thief? Fine. Easy to pay him a visit.
+ Getting a car? No. That's dumb. You can buy a car if you have the money.
+ Getting a bank account? Fine. Just force banks to disallow people to go below zero for several years (or forever). Replace all credit cards by debit cards.
That's basically the situation in the Netherlands for most part. Identity still gets stolen, but the impact is minimal.
This argument doesn't not follow logically. It's like saying you shouldn't lock your house because if somebody really wants to get in, they will do it.
As a result you have the equivalent of dozens of people trying to pick the lock of your door every day, and the law can't do much to stop it. That requires you to pay f*ing attention to the quality of your lock.
But it would no longer provide security if every person in the country had a copy of your key.
Of course, this isn't something I suggest you do. It's certainly not practical for most people. I mention it only to show that there are varied security needs. On this particular subject, my credit has been frozen since the OPM breech.
the day you get robbed, it will absolutely make a difference for whoever insure your house and its content.
It's pretty great to live here. The only crime in my area is growing weed and that's now legal.
The argument that it is ok, because anyway if somebody wanted it really hard they would find a way to get my personal details, is illogical.
SSN is fine, what we need is the right for our credit to always be frozen and anyone who grants credit outside of our approval is liable for the loss. We also just need to bite the bullet and make chip and pin mandatory everywhere.
We don't need to make identity theft impossible just reasonably hard. Other nations seem to have it figured out.
This means everyone in the US has to accept national ID.
(It could theoretically be done at state level but it would be a huge hassle compared to national, and your tax authority and others are already national and need to know every person that lives in the country).
Basically you need to trust the federal government to solve your ID problem. And if the answer to that is "Whoa that won't happen, people won't accept national anything" then the simple answer is you'll keep being subjected to ID theft.
Why is chip & pin a bullet to bite? Isn't that just better for all parties involved?
Sadly, just 'issued without approval' is a bit too wide a definition. You need to deal with 'john' helping others fraudulently impersonating 'john'. In that case, the bank should not be liable.
In general, I see potential for a weird type of coorperation. They verify identities for credit providers for a fee. In return, this coorperation takes on the liability of wrongly verifying identities.
Question is, given the importance of such a coorperation, how much regulation is needed? At what point is there so much regulation required that it is better left as a government-run service?
Of course the government will never let a good crisis go to waste. Instead, we will all get chips under our skin that can't be removed that will be passively scanned by the authorities everywhere we go.
The entire problem is that people started using SSN as a shared secret, but it was classic password reuse. Use the same secret every fucking where.
No. If you want to establish trust, use a random secret for each new trust relationship.
If you want to establish identity ask the identity providers what kind of anti-forgery guarantees they provide. Oh, nothing, you say!? Then don't use that provider.
Banks are trying to use easy to forge things to make sure they won't lose money. Sounds like stupidity. So they limit their stupidity (hence you can't just register for a credit card online, otherwise bored Russian teenagers would have already bankrupted them).
They shouldn't even ask for it.
Currently fraud is held back by law enforcement. Which is triggered by fraud detection. Which is triggered when the wrong person gets a call from a collections agency.
And this chain of events is too long, but since there's no global (national) system to check if someone is a professional scam artist or a regular bloke, that's what banks are left with.
Seems like an opportunity to force the hand. I, like you, imagine such an action would induce systemic change.
Maybe.
Impossible. A large part of the American people is obsessed with "the government is going to oppress us all". National IDs or anything similarly working are therefore a big no-go.
If you could solve this problem, you could presumably also solve the gun debate to a large degree.
And it would help if individual making the faulty decision to extend credit lost all their commissions for the week. It should be a blight on their record, with more than 5 instances causing them to lose their jobs. And CEO of the worst offending company gets a hefty fine.
Maybe that would focus the industry on solving this problem.
So it would a "Credit ID," Passport Number, DL #, or something related. What's the difference, it will need to be stored next all your stuff, awaiting to be stolen. Now the banks eat the small % caused by fraud (cost of doing biz), your life is hell, but not theirs.
Scan your iris before getting the new loan isn't going to happen either, too costly and slow. If they ever do that online, they'll find a way to recreate that based on your existing scan, stored at the future Experian.
Identity theft in Europe is extremely rare. It is possible to do something in your name, sure, but it does not happen nowhere near as often and damage is limited compared to ssn system.
Not gonna happen, banks for now will rather swallow the relatively low loses due to fraud.
In USA you sign a piece of paper (pre-approved loan), or login online and the loan money is deposited in your account within a few days. All automated. So far it works out for them, if fraud loses increase, the banks, not us, will choose the next method. And Congress will approve it within weeks.
It should not be a passport number or driver's license number. It should be the original, physical passport or driver's license that you present in person. The physical object is much harder to steal or copy, and can be revoked.
You should not be able to open credit lines or accounts with a business without appearing at least once in person first.
The national ID also has an embedded smart card usable for authentication but for some reason using that has never took off.
Video is just another form of photo copy, so how would that work?
All in all this process makes it much much harder to steal an identity. Also, once you report your ID card stolen, its serial number will be blacklisted preventing it from being used. Add to this that there is a snail mail address on your cards which will typically be used to send login information such as passwords and PINS
Also, please don't use terms like "steal an identity", that is how banks frame things in order to make it appear that they are not responsible. Banks don't employ reliable authentication, thus they get defrauded by imposters--nothing is ever stolen from those who the importers pretend to be, it's only between the bank and the imposter, noone else is a party to that fraudulent transaction.
For now, it remains somewhat secure in practice and will hopefully bye augmented by use of cryptography already available in many IDs (though, as other comments note, not widely used in some countries)
>The SSN shouldn't be the critical key in that list.
Nothing in that list is secret.
Why only 14-year-olds and younger?
Just look what many other countries do.
(You also can have a certificate on it, but they missed an opportunity and didn't make it default, you have to ask for and pay extra for that. Would have been a chance to widely roll out certificates of the standard necessary to legally replace signatures, instead of other crap that has been proposed as a replacement sigh)
Also, how is the reliability of the 2FA device established? If there were some claim before a court that you authorized some sort of transaction, what would they have to demonstrate to prove your liability? What will the court do if you question whether the numbers generated by the 2FA device are actually cryptographically random?
For illustration, when I'm logging in, I get the option to login with my password, OR to login with 2 factors. When the second factor is optional, it doesn't provide much defense. Some select services require the second factor, but its very few. Until very recently, the second factor was SMS, which is rather easy to fool.
Also, as far as I know, Digid isn't related at all to banking. Instead, you need to show ID (passport or ID-card, drivers license does not suffice in this case) to open an account with a bank. After that, each bank has their own system.
I absolutely hope this happens too...
... but I have a feeling all of the banks and agencies involved will find a way to plug their ears more and pretend nothing is wrong.
They will look at how costly and complex it is to create a halfway decent identity system (even though it's really not hard, other countries do it just fine with digital and physical keys/tokens).
And they will just continue to push the burden of ID theft onto consumers, rather than their businesses.
I would do this with the information:
1. Write a script to webscrape sites like LinkedIn to find out if a name/address/ssn key could be tied to people like doctors, engineers and whoever else might have sufficient disposable income.
2. I would take out loans in their name. If I have to be there in person, I would go from city to city and find people I could easily get dirt on, like people that might be here illegally. I would then cut them in for a piece of the loan and then move onto a random city in a 200 mile radius.
3. Move away after I get away with enough to live on for the rest of my life.
4. Hell I might just sell the rest of the information and scripts to other people who lack scruples.
Neglecting all of that you do realize that International wire transfers do exist right?
Australia, NZ, Singapore, most EU countries all have instant person-to-person transfers with little to no fees and supported via the government. 500 euro can be gone like that. Poof. But it's all within the same country. And when it's within the same country, it's traceable, reversible and enforceable by law.
So the 1-3 business days isn't where the protection is at. It's the way we mark and track transactions. The real danger, is SWIFT transfers. Once that money leaves the country, it's very unlikely you'll ever see it again.
[1]: http://penguindreams.org/blog/the-american-banking-system-is...
Banks send a constant stream of credit card offers through the mail and pay people to use credit cards (with rewards). Stores are always trying to get you to sign up for their credit cards and offering big discounts if you do, and car dealerships offer special deals - but only if you agree to finance your car. People might want more credit, but lets be honest - the financial industry is doing everything it can to shovel debt onto the American public.
Imagine if a loan shark went door to door in a neighborhood paying residents $500 to take one of his loans. That seems almost cartoonishly evil, but that's more or less what the financial industry does. And it's not hard to see why - the average credit card has an annual interest rate of 15%. Even after you factor in things rewards and people who don't pay, you're still looking at a very nice rate of return.
It's hard to see how identity theft isn't directly linked to financial institutions trying to make credit as easily available and as widespread as possible. Instead of viewing identity theft as a high price to pay for the convenience we want, it should be viewed as yet another terrible consequence of the financial industry's efforts to push as much debt onto Americans as they can.
> In an economic system where U.S.
> consumers carry $12.73 trillion in
> household debt, you shouldn’t be able
> to just call up, say “it wasn't me,”
> and leave thousands of dollars in
> obligations by the wayside.
Yes, you should, and the banks should be the ones left holding the bag. The author did nothing wrong, and was victimized by the banks' incompetence at adequate fraud checks.I've not been stopped at EU airports for awhile but I am still not 100% sure if my name is on the Interpol blacklist still. The process of clearing your name is totally opaque. A helpful officer at London MET assured me to undertake the work to do it.
The amount of times I've had to explain the very concept of "identity theft" to enforcement is just crazy. And sadly I don't think they fully understand it most of the time.
I'm a little afraid to travel to eastern Europe, since this "advance fee" for a VW fraud in my name is particularly common there and I am tired of receiving threats. Sigh....
This would be the final say in any credit accounts, accounts not listed here are not legal debt (ie they cannot be collected or sued for)
You can still use SSN for identification but authorization would require more. I imagine maybe a few different levels of security:
1. Password (or list of passwords) you can set/change in person at any post office. The company adding the credit account would need this password to register the debt.
2. Yubikey or other auth token you can register at the post office to create one time passwords for companies creating credit accounts.
3. Every new credit account requires physical confirmation at the post office.
Then just setup really good cameras (maybe face scanner or biometric scanner) at every post office and make it like a 10 year felony to impersonate someone at the post office. The scammers will be out of the system very quickly.
So, the banks here are pretty annoying, opening an account is a lengthily process.
Convenience trumps security in the US.
Perhaps if it was easier to do that, there would be less of the predatory lending that created such a crippling burden of debt.
I think that one of the reasons is that the US does not have a central government registry of all the people.
In Austria, we have the „Melderegister“. Every person that stays in Austria is required to register the address of their current residence. Your name and address is always in this registry, from the day you are born until you die (foreigners residing in Austria are also required to register).
Everything relies on this registry — voting rights, taxes, etc.
I think that Banks can check this register to verify your address. So even if an identity thief is successful in applying for a credit card, that credit card would be mailed to the victims actual address, so the identity thief would have to intercept postal mail as well.
So many problems that I read about in the US (using utiliy bills to proof you are a resident, registering to vote) just sound like a clumsy workaround to the fact that there is no „Melderegister“.
One can decide to not work (get a tax number), not drive (get a drivers license), not travel (get a passport), not get free healthcare (get a medicare card), not vote (evade census'). Unlike most countries, one doesn't need to register or let anyone know where you live, and there is no national service (conscription).
It also has very little identity fraud.
also, how would one get around the problem for homeless people or people without a permanent residency?
And, if you happen to forget it, they will unlock it if you can cough up the very information supposedly compromised in the equifax leak anyway.
Wait, what? Any more reading on this?
Don't know if that change is live, however.
Going to take the liberty of adding to this because the imprecision might cause some people to develop a poor model of how financial institutions work: you don't have a "credit account." You have a few firms which have partial views of your "credit history", sourced by reports from some firms you've previously done business with before. What a freeze does is that those firms (CRAs) who could disclose your credit history to a bank will, instead, report to the bank "That file is frozen."
How is this different from your mental model? Because credit decision is between a financial institution and a bank -- they don't have to ask anyone else's permission, including the CRA, to lend you money. They also don't have to "respect" a freeze on your file; it's purely advisory. It may deter _some_ banks from issuing you _some_ credit but it will likely not deter _all_ banks from issuing you _all_ credit products.
How does the system differentiate between someone showing up and doing something in your name vs you actually showing up and doing something negative?
[edit: spelling]
(They generally don't ask for payments till the end.)
143M accounts - lets just say 2% are rich/active enough to consider freezes. That's almost $3M over the course of say a week - for each such agency.
If enough folks write their congress critters asking for "make freeze/unfreezing free of change to everyone", maybe they will do something useful for once.
The only way someone can open a new bank account, credit card or loan in your name under the freeze is if they A) have the credit-bureau-specific PIN to lift the freeze, or B) the account was somehow opened without doing any kind of credit check.
The banks kicked him back and he tried forging checks from others (not me).
I filed the reports with the police. And checked my credit. Nothing serious happened as he seems to have been pretty much thwarted by most places he went.
But then he got caught when he was pulled over for having a brake light out.
All in all I suffered no real harm from this guy. Seems like for the most part the system works...
You just got lucky and caught it early.
I've been curious about the real-world impacts of identity theft for quite some time. In the article linked, the author's only obvious losses were a) on the home mortgage (couldn't cosign; worse rate) and b) at the airport, with TSA (which I don't get; how did his credit rating have an impact on the secondary security screening?).
It's unclear to me why I should care that much about identity theft, or what a thief can do. I'm not saying it wouldn't be a huge hassle to get calls from scammed creditors or be unable to obtain consumer credit, but I am fortunate enough not to need credit and I already have the credit cards and bank accounts I need.
There is the whole IRS fraudulent return thing, which could be quite tedious to sort out and meantime would take real money. But that's about all I can think of unless you need consumer credit.
> It's unclear to me... what a thief can do.
Um... well... how about anything you can do with your identity, except it's someone else? Do you really not understand why that's a bad thing?
Hmm, I don't know, to be honest. That hadn't occurred to me.
> I think you understand perfectly well the problems identity theft can cause, but you're just being intentionally obtuse.
Huh? No, I was asking a question. Why would someone be intentionally obtuse about something like this? I can't figure out how my comment was misinterpreted, but it certainly was. I apologize for my lack of clarity in the original post.
> Um... well... how about anything you can do with your identity, except it's someone else? Do you really not understand why that's a bad thing?
"Anything you can do" isn't very clear, hence my desire to understand the threat better. Assuming I have no need for consumer credit (like, actual loans), it's just not clear to me in which cases a bad credit score can be a problem. Auto insurance had not occurred to me, so thanks for that example.
Once again, I think you may have misinterpreted my comment in some manner. Do people really troll each other over, like, identity theft? Weird. But I wasn't. :)
That person is never helpful to the discussion.
A single anecdote of good fortune carries exactly as much weight as a single anecdote of misfortune.
It feels shitty when someone else gets the points for something you submitted earlier, but life isn't always fair, and as long as you keep submitting good content and making good comments, things even out in the end.