Experian Site Can Give Anyone Your Credit Freeze PIN
krebsonsecurity.com
krebsonsecurity.com
I know this will never actually happen, but I sincerely wish the Social Security Administration would publish a complete official database of real name to SSN mappings. It wouldn't impede their use as Social Security Numbers, but it would make it extremely obvious how inappropriate they are as a proof of identity. Maybe then we'd finally be forced to come up with something a bit less insane.
Erm... that's the entire fucking point of Experian. And yet they failed.
Experian is a free-market for-profit corporation.
Assume a credit rating agency can lower a lender's default rate from X% to X'% but introduces an additional Y% of fraudulent loans. If X - X' > Y, that's a good deal for lenders no matter what the absolute size of Y is.
Experian failed, but the system was designed to fail. You can already get all of this important info with this number, so there was little incentive to create a new system and ensure that every American participated in it. Their operation was also entrenched by government credit reporting acts, pretty much setting in stone how things are and preventing innovation. This was a pseudo-government 'industry', not a free market system with new startups frequently joining.
* Government Issued IDs -- Most situations. Police Tickets, Court issues, etc. etc. Usually your driver's license. This is effectively a security token, since its illegal to make illegitimate copies of a Government issued ID (although cryptography should be used in future ID efforts IMO)
* Tax PIN number and Last year's tax refund -- Pay taxes and do tax refunds. There's a ton of OTHER information you need to submit with your taxes to get it processed. The SSN is purely the "username" for your taxes, it isn't the "password".
----
In the free market? People use SSN as a password, because free market doesn't give a care about you or decent security practices. Or at least, Experian doesn't (and they're a free market actor)
For individuals, your TIN (Taxpayer Identification Number) defaults to your SSN, and you do not need the previous year's return to file taxes. Not sure where you are coming up with these imaginative claims, and I find it somewhat concerning how confident you feel in bureaucratic design decisions.
The government did NOT pick SSN's for ID. SSN cards used to have 'not to be used for identification purposes'. It was the private sector that appropriated SSN's as ID's. What the government failed in is adequately prohibiting and enforcing a prohibition of this type of use.
Identifying a person is one thing, proving you are that person is a completely different concept.
Given the prevalence of fraudulent tax returns and people working under fake SSNs to avoid taxes, I imagine the IRS would be very displeased with them if they were to do this. It's not just credit reporting agencies that need to reform their identification procedures, it's also government.
Which is exactly the problem. The IRS is relying on the fact that SSNs are sorta-kinda-secret. Unless the database gets leaked there's not much impetus for change.
If you think about it, there's virtually no purpose to a SSN without the IRS's current usage. The whole purpose of it is to track contributions into and benefit distributions out of the fund. The SSA tracks the benefit distributions, but the IRS's usage is squarely within the raison d'etre for the SSN existence in the first place. Releasing the mapping database would essentially break Social Security since they'd no longer have a working way of tracking contributions into the fund.
What it would prevent is the illusion that providing my SSN on demand is in any way an indication that I am in fact the human being attached to that number and not some third party.
I don't see a problem with the IRS continuing to use it as-is. I would have no more incentive to lie about my SSN than I currently do about my legal name or my mailing address, for example. In fact, I might have a significant disincentive if I knew that my boss, my HR manager, the auditor at the IRS, and anyone else who cared could spot check whether it matched what I told them all my name was. Besides, the IRS has been dealing with endless attempts at tax fraud for a century and a half now. One more awkward but plausible avenue for cheating is likely to be background noise against their existing caseload.
I wasn't saying that using SSNs they way they're currently used is a good system or even that it works halfway decently. I was saying your plan for the SSA to break the world would also fundamentally break the original purpose for the SSN and hurt themselves. The IRS and SSA need to get together and devise a better system for authenticating citizens and resident aliens before even contemplating taking that step.
What I'd like to see them do is get NIST involved and run it as a public challenge the way they have with the various encryption standards. Get competing strategies proposed and let cryptographers rip them to shreds until something acceptable is left over. Incidentally, we should also do the same thing with voting machines to create a standard which vendors can implement and sell to local election commissions.
> Besides, the IRS has been dealing with endless attempts at tax fraud for a century and a half now
Former Intuit employee here...not in tax, but I've worked with people who are and learned a lot about anti-fraud programs. Acting like this is an old problem is disingenuous. The advent of e-file has made the problem massively worse. Releasing the entire database would make it, turn, significantly worse. I can guarantee you that Intuit, H&R Block and the other online tax filing solutions have been in contact with Equifax to get the full list of (or full list of hashes of) SSNs that were compromised and that returns for those SSNs will undergo increased fraud scrutiny. Equifax only leaked around 1/3 of all SSNs, so your plan to release the full list would create far more than background noise.
A full list might not even be necessary — a form that would allow you to trade some basic details for an SSN might be enough to scare various agencies straight. At least that way isn't quite as iterable.
Honestly, this doesn't even sound all that implausible to me as long as some sort of sufficient warning was built into the announcement to give organizations a way to build alternatives. Say two years. After that, levy major fines against anyone who's not compliant with certain very basic security standards.
The biggest hurdle here isn't going to be backlash as much as it is comprehension. Just like with net neutrality and encryption, most lawmakers are going to have a hard time understanding why SSNs as secrets aren't a good thing, and they'll have to be convinced.
"The first hurdle for instantly revealing anyone’s freeze PIN is to provide the person’s name, address, date of birth and Social Security number (all data that has been jeopardized in breaches 100 times over — including in the recent Equifax breach — and that is broadly for sale in the cybercrime underground).
After that, one just needs to input an email address to receive the PIN and swear that the information is true and belongs to the submitter. I’m certain this warning would deter all but the bravest of identity thieves!"
SSN is not a secret. End of story.
I am not actually sure that I've seen a bigger display of ineptitude. I suspect there's going to be academic research papers published about this and studied for years to come. I'm not big on conspiracy theories, but I could understand someone believing this is deliberate incompetence. I'm not even sure I could fault them for believing that.
I don't have the answers. But, just because I'm not an MD doesn't mean I can't point out an obviously broken arm. This is a problem and it does need fixing.
At this point, it's reached the level of absurd. Not even a great author could have come up with a better storyline. This has reached the point of being surreal. If I weren't witnessing this, I'd have trouble believing it - it's that bad.
At this point, I'm having trouble thinking of something they haven't screwed up. This has more twists than a soap opera.
In many places, if you want to get a small, revolving line of credit it’s considered perfectly normal to spend weeks validating your identity, including one or more in-person visits by a financial official. Can you imagine doing this in modern America? The economy would shrink by whole percentage points overnight.
We’ve made a deal with the devil, and this is how we pay.
Maybe it's better, in the long term, to suffer that shrinkage? I'm absolutely not an economist, so I don't really know. Maybe we are in a credit bubble and it needs to pop?
Could we absorb the negative drop in the economy without there being riots in the street? Would it be better in the long run?
We've reduced those over here by figuring out how to batch-precompute most of the needed work, with a generally low error rate.
In France for example there's no SSN used by banks, there's no Credit score either. How do people get mortgages? Bank do their research, ask for your paystubs and other documents, it's simply due diligence.
Due diligence can take you pretty far, for instance for mortgages, probably the biggest loan a person needs in life: current mortgage fixed interest rate are around 1.3% - 1.8% for long duration[1]. You get this without the existence of a credit score. In 2008, there wasn't any wave of people loosing their home because their mortgage was approved too easily and they suddenly weren't able to pay back, so something must be done right.
As an other commenter mentions, you might not be able to get your mortgage approved in a minute on a smartphone app ... But who wants this anyways? In a house/car buying process, this isn't the most time consuming task anyways, and certainly not the one you should approach lightly.
It's true that in the US, opening Credit cards is much more common, but even there, I'm not sure why a couple weeks of wait is much of a big deal, the bank already takes one to 2 weeks to send you the credit card by mail.
[1] http://www.meilleurtaux.com/credit-immobilier/barometre-des-...
Edit: also, comparing nominal interest rates is meaningless, you have to compare the spread vs. the risk-free rate for the given currency.
I don't know how it works in France, but other countries have a "bad payer" database. You get added to it when you're behind with your payments, and get removed from it when you're no longer behind. All lenders check that database.
I'm still annoyed by this entire debacle but I'm not sure what the correct solution for a lost PIN should be.
Krebs gives an answer in the article and I think I agree:
> I understand if people who place freezes on their credit files are prone to misplacing the PIN provided by the bureaus that is needed to unlock or thaw a freeze. This is human nature, and the bureaus should absolutely have a reliable process to recover this PIN. However, the information should be sent via snail mail to the address on the credit record, not via email to any old email address.
Until we have a way to guarantee our electronic identity to the government (e.g. an RSA key registry so that I can sign a message like "I am $name and $email is my email"), physical delivery is the best option.
What would happen when that address is incorrect or outdated?
Getting a notarized copy of an ID and proof of address and mailing it in isn't too terrible of a hoop for poor people (who aren't so poor that an organization that cares about credit ratings is considering lending to them) to jump though. It doesn't scale well and provides a substantial hurdle for monetizing ID information.
If it's outdated, then it simply goes to your old address. If you moved, the Post Office will forward mail addressed to you at your old address to your new address.
https://www.identityguard.com/news-insights/beware-change-ad...
Two things I do: monitory my credit reports regularly and give nonsensical answers to the security questions.