The Equifax disaster points to a much bigger problem
washingtonpost.com
washingtonpost.com
Yes, they should, but that's not what they are doing. They are doing the opposite. [1] It doesn't matter what the majority want Congress to do when they don't listen or care and instead do what their special interests tell them. The 'bigger problem' the article mentions is not that the laws are tilted towards the corporations. It's that they will continue to be tilted towards them due to corruption.
[1] http://www.latimes.com/business/lazarus/la-fi-lazarus-republ...
http://www.latimes.com/business/lazarus/la-fi-lazarus-republ...
> The FCRA Liability Harmonization Act is particularly noxious. Authored by Rep. Barry Loudermilk (R-Ga.), the bill would cap actual and statutory damages for class actions involving credit agencies at $500,000, and completely eliminate punitive damages.
Loudermilk said Friday that his bill “is aimed at curbing frivolous class action lawsuits against businesses under the Fair Credit Reporting Act,” which contains many of the rules for credit agencies.
Fortunately Wikipedia points us at Loudermilk's legislative history. We can see such gems as HR3441, which opponents say "creates a new definition of “joint employer” that strips workers of their legal recourse for wage theft or unfair labor practices when multiple employers jointly control labor conditions." http://democrats-edworkforce.house.gov/imo/media/doc/2017-09...
Or we can look at his campaign contributions: https://www.fec.gov/data/receipts/?two_year_transaction_peri...
"EXPERIAN NORTH AMERICA, INC POLITICAL ACTION COMMITTEE (EXPERIAN PAC)"
A clickthrough (this is a nice website, btw) shows the total Experian payments: https://www.fec.gov/data/committee/C00379768/
Only $285,000, unless I've missed an "all figures are in thousands" somewhere. That's a pretty cheap way of buying yourself some legislation.
"H.R.3330 - Ensuring Quality in the Unemployment Insurance Program (EQUIP) Act" = " To amend title III of the Social Security Act to permit States to conduct substance abuse risk assessments and targeted drug testing as a condition for the receipt of unemployment benefits, and for other purposes."
"H.R.3312 - Systemic Risk Designation Improvement Act of 2017" = something to do with Dodd-Frank
"H.R.3257 - Promote Accountability and Government Efficiency Ac" = screw over the civil service. "Notwithstanding any other provision of law, any employee in the civil service hired on or after the date that is 1 year after the date of enactment of this Act shall be hired on an at-will basis. Such an employee may be removed or suspended, without notice or right to appeal, from service by the head of the agency at which such employee is employed for good cause, bad cause, or no cause at all."
"No employee or applicant for employment in the civil service may be awarded by any court a remedy (including damages, costs, or attorney fees) under any of the provisions of law listed in paragraph (3) in a dollar amount that, in the aggregate, exceeds $50,000."
Then a bunch of stuff removing national labour relations law that would otherwise pre-empt state law; allowing concealed carry in DC by holders of other state licenses; something to do with marine mammal protection, probably removing it; and a change to labour law to require a majority of employees not just of union members in certain votes, presumably making strike action much harder.
People don't vote (less than 40% in that election). Make voting mandatory, like in Australia (or at least make it a national holiday), and require a certain amount of real political coverage in the media -- politicians would then better reflect the needs of the people.
> Cap political donations
> Reduce allotted time for campaigning to something like 2 months, and maybe have it publicly funded like Australia
> Use open source congressional redistricting algorithms
> Eliminate First Past the Post
> Eliminate straight ticket voting
All pretty nice ideas that mostly everyone that isn't in power can get behind
I do want to say that public funding also comes with its issues. Its the way most parties in Argentina fund themselves and because all of them do, all parties get to put their hand of the State coffers during elections. So much, they made an electoral reform to have another round of elections, just to be able to spend more money on pork.
There is no solution to funding political parties that wont screw someone. Its yet another example of diminishing the scope of government so they just steal less of it.
As well as a tradition of placing limits on free speech when appropriate.
Which is a larger threat to our country? Democratically elected officials not supporting the views of those that elected them? Or capping the amount of influence a single group can financially have?
Want to get more people voting there are a few things that need to change
1. End First past the post... Anything is better, IRV, Alternative Vote, something else.
2. End 2 Party Gerrymandering, Parties should not have any control over distracting at all Should follow some other function like Zip Code, or Taxing Jurisdiction, or some other government function, not just for voting
3. Implement the Wyoming Rule for for congress
4. Pipe Dream... Put the federal government back into constitutional limits and reverse Wikard v Filburn or pass a law that renders it void
1-3 would do alot, #4 would do the most good
Election reform, (not election finance ) is needed but too many people focus on the money, the money is just a symptom of the problem, not the actual problem. Solve the underlying systemic issue with the voting process and the money becomes pointless and will dry up on its own
If you can't get people to voluntarily participate in democracy then you have a failed implementation of it.
Furthermore, the ability to not vote is a powerful and necessary option, as it's hard for those in power to imply that they have a mandate if <10% of the population actually participated in it.
I don't know what mandatory voting accomplishes except giving those in power the ability to say, "Tut tut! No complaining! You got your vote, after all."
What it does completely deal with is the voter registration question.
"Require" and "free press" don't go together unfortunately.
https://www.opensecrets.org/members-of-congress/pacs?cid=N00...
Well, the third parties haven't proven to be all that trustworthy, so suing your bank & credit-card firm(s) for releasing your information might be an interesting approach to take. If the CRAs have the source of their data cut to a trickle, they might start taking this seriously.
And not to defend Equifax, because how can you, but a lot of people make their living there and in general corporations deserve reasonable protection under the law just like individuals do. After all most of them are net positives for society: they provide employment, benefits, and many support their local communities in a variety of other ways.
Meaning that if they lose their court case, they can still continue to behave badly, and not face any additional fines once they hit that measly total.
Oh, and just in case that $500,000 might hit some small "mom-and-pop" credit reporting agency, the total damage that can be awarded (again IN TOTAL TO THE ENTIRE CLASS), is the lesser of $500,000 or 1% of the net worth of the person/corporation the suit is being brought against.
Meaning we are basically saying "you can't actually bring a suit against them that could cause them enough damage to actually change their shitty behavior"
Yes, but I would guess, more frivolous lawsuits are filed by corporations looking to silence critics or competition more so than ambulance chasers. They certainly have deeper pockets.
Hah. I'm not sure I would go that far.
I mean I hear you - corporations are important, as they're a great way for a group of people to accomplish something together - but if the most important thing you do for society is employment, you sound like a pretty shit corporation.
On the other hand, The New Deal did a lot of that. Hmmm.
The New Deal(s) did not really do the above. Although it really provided value in the form of infrastructure as well as employment to citizens it had to take money from people as well as borrow large amounts to do it.
Hating on corporations and trading them for the government as a pseudo-corporation is just as bad. Sounds like a comment dripping with naivety from a college history class as if it's a final 'gotchya' against someone who is looking at the situation from all avenues.
There are definitely corporations that provide employment, tax money, and/or charity work without generating monetary value (how long until Facebook actually sold anything?). But you're larger point is correct; those companies either don't last, or don't stay in that state.
The entire point of the New Deal was to provide employment first and foremost (then, why not do something possibly useful with those employees? Hence the infrastructure.)
> take money from people as well as borrow large amounts to do it.
How is this different from any other corporation? Every company I interact with - including the ones I don't pay - takes value from me; and most (if not all) have taken loans and/or investment. Usually it is money, and I get back something; but it's not like I gave Equifax my personal info [from which the took monetary value].
While yes, taxes ARE categorically different than prices (and bonds are different than stocks), you can still definitely adopt the perspective that they're how you pay for all the civilization supplied by the society you're a part of. And if you don't want to pay for those things, there's still ways to stop; and you don't even have to give up all the things you're getting for the price you're no longer paying.
I'm not hating on corporations. I'm saying that I would expect a corporation whose primary purpose is employment of people to do a poor overall job of adding value to society; at least compared to corporations with goals of delivering products or services.
It's not a question of "does this not produce value", it's a question of which kind of value is most produced.
...And I'm probably wrong anyway, because that's basically what temp agencies do.
Overall, your reply sounds like a comment arguing with an imaginary person you disagree with as if your imagined reality resembles the real thing. Try starting with a question next time, it'll help you figure out if what you think is going is actually what's going on.
And why exactly is it that the size of the lawsuit is a strong indicator of frivolity? I would expect the oppsosite, as a frivolous lawsuit business I believe my interests would lie in doing 100 lawsuits at 10,000 a year rather than one at a 1,000,000.
That's not a net positive to society in my eyes.
Why should someone whom is asking for money with no way to pay it back get the same preference as someone asking to borrow money who has a history of solid payments and has enough capital they could liquify to pay off at least 50% of the amount tomorrow?
I don't think that utility companies or landlords under report although I understand that it would be nice if they reported more for beginning creditors. The distinction for why they aren't included is that they aren't lending you money. You are only paying for their services as you use them. Once in default, they are effectively loaning to you at that point though with a balance to be paid. Do you think the IT technician whom invoiced you for $2500 in work should also report as well? [shrugs] Guess I don't want all balanced from whom provided me a service to be in a credit report for 7 years but I understand that is just me.
Has this ever even happened?
Not all 'republicans' and not all 'democrats' are the same.
Including terrorist supporter Pete King. http://www.washingtonpost.com/wp-dyn/content/article/2011/03...
Incidentally, it was introduced before the Equifax disaster ...
Because it has 13 Co-sponsors, all republicans and no democrats. https://www.congress.gov/bill/115th-congress/house-bill/2359...
Further, this was filed long before the breech, yet the piece tries to say that these representatives were doing it "despite" the breech was made public. Some of those listed may still be backing this, and it was (likely, I haven't read it myself) terrible legislation to begin with, but based on the evidence available, it is stretching to make the claims that the opinion piece does about them doing it "even as" the fallout from the breech is settling.
While I am glad they are covering the proposed legislation and bringing it to the publics attention, the piece is worded in a very weasely way.
Also, it is forbidden for information in this agency to be used for identifying purposes by banks and the like. This means considerably less risk for me as a citizen, and it also means the information is less valuable for hackers. Mortgage interest rates are currently 1-2 points less in The Netherlands than they are in the USA, so there's no correlation I can see between America's vampire capitalism credit model and cheaper loans.
Many Americans have so much debt that lenders are very interested in the whole picture when they consider making a new loan.
Old debt do drop off American credit reports, too. For most bad marks, they only stay on for 7 years (10 for bankruptcy). I don't know how long paid off loans are reported, but they generally have no negative impact (but might impact privacy). see this blog post http://blog.readyforzero.com/how-long-does-a-bad-mark-stay-o...
EDIT: Even though bad marks are supposed to stay on only for seven years, the industry is very scummy and will often try to keep the bad marks on your report longer, requiring you to take action sometimes to actually get it cleared off. The CRA's and debt collectors don't follow the law, and we certainly need better enforcement of the laws.
Much less prevalent than in the US. There are much fewer cash back/air miles/etc credit cards...actually, literally the only I'm sure exists is that for the department store De Bijenkorf. There may of course be more I haven't seen before.
Debit cards are the dominant payment method. Credit cards are most useful for things like hotels abroad, online shopping abroad (w/n Netherlands there is the iDeal payment system for online shopping). It's not uncommon to find shops that will not accept them.
That's the same as the US, except that here they expire after 7 years instead of five.
> Mortgage interest rates are currently 1-2 points less in The Netherlands than they are in the USA, so there's no correlation I can see between America's vampire capitalism credit model and cheaper loans.
That's a rather meaningless way to look at it, because there are a myriad of factors that affect aggregate mortgage rates, and credit ratings are just a tiny piece of it.
It's like saying "Well, they keep tell me that the world is getting warmer, but it's still pretty cold in my neighborhood".
It's worth nothing that though that this breach also affected some non-US citizens as well, most reports mentioned UK residents and Canadian residents as well.
I don't think most people feel it is unfair or immoral to release "unfavorable" information. If one didn't pay back a credit card, most reasonable people think, "OK that's true and on my report. My bad." What people think it is deeply wrong is for a fraudster to get a loan from a bank, the fraudster does not pay, and the bank libels them by sending a false report to the credit agency saying they defaulted on the loan. This agency and bank have no penalties for propagating the libel/slander and this libel will hurt the person in many ways. Everyone knows that getting this libel to stop is very difficult and the credit agencies and banks don't care about fixing the errors. The run-a-rounds people go through are legendary. People fear getting libeled by banks and other issuers of credit, so much so many buy insurance for "peace of mind". The credit reporting agencies are like Ticketmaster, a company set up to take the heat and misdirect the anger when some other entity is screwing you. Ticketmaster plays front man for the concert promoters/venues/bands whereas the credit agencies play front man for the banks.
I feel your overall argument, and you should know your idea here is not exactly accurate. For instance, in Europe there are actually laws against unfavorable information.
I am not a lawyer, this is not legal advice. Before deciding to blackmail, you should consult a qualified attorney in the appropriate jurisdiction.
While blackmail is a specific case of extortion where unfavorable information is released, what the agencies do by requiring you to pay for protection(the freezing of your credit)seems to qualify as extortion.
"What Is Extortion?
Most states define extortion as the gaining of property or money by almost any kind of force, or threat of 1) violence, 2) property damage, 3) harm to reputation, or 4) unfavorable government action."
I think you could make a case for number 3 - gaining money for threat of harm to reputation. Your credit score is very much your financial reputation.
source: http://criminal.findlaw.com/criminal-charges/extortion.html
https://en.wikipedia.org/wiki/Racketeer_Influenced_and_Corru...
One could argue the disclosure timing and executive stock sales (pre-disclosure) could constitute investor/securities fraud, as well.
Unfortunately, there's no law I'm aware of that's going to help you here - although there /possibly/ should be a law governing ownership of someone else's private data, that's not currently the case, as far as I know (IANAL). It's also not immediately obvious to me how you'd construct such a law without causing problems for many other areas of the financial system.
Whether Jeff Sessions thinks so is another story.
That's incorrect. CRAs can only release information to others if the requester has "permissible purpose". Under ordinary circumstances, that means you've asked the requester for some sort of service that allows them to pull your credit report.
The purpose of a freeze is to prevent someone from trying to impersonate you and use your credit file. If you just want to be paranoid about it (or "proactive" if you prefer) then you can pay to have your file frozen and unlocked on demand. If you're already a victim of identity theft or legitimately expect to be, then you can get the freeze for free, I believe.
This is a nice idea. In practice the keys would have to be accessible via some kind of password to make them usable to ordinary people. And then those passwords would need to be re-settable via email or phone. There are security issues with that I guess, but we'd probably be better-off than we are now.
And what happens when someone loses their encryption key? This happens often enough with house keys that there are entire businesses set up for emergency locksmith services.
DigitalLocksmith.io (YC S2018)
Jokes aside, this is why combining accessible and strong cryptography is hard. Certainly not impossible but hard. And historically, not at all within the competency of companies like Equifax.
But presumably the credit agencies would need the key as well, to enable those resets and so they can add to the records, which probably negates much of the benefit.
But no matter what you do the CRA has to be able to write to the data, and read from it to give it to third parties, and be able to reset passwords. AFAIK that requires that they have the keys to decrypt the data.
That is the single _biggest_ problem facing the human species.
A 3 minute intro to GDPR for those unfamiliar: https://youtu.be/n5WJOncaHt4
How is that worse?
Revoking keys is great but doesn't help after they've given full access.
There is multiple layers of security at play here, including seperated logging entities such that there is no traffic that isn't logged, always leaving a paper trail of what services was used by the adversary. If you want to gain access to impersonate someone, there are others a significantly more effective ways utilizing social engineering. Not to say it's easy, because you need to obtain an official card (sygesikringsbevis), then use that to request a new passport with your photo, hope they do not have old photos in record, then use the passport to change address and then order NemId key card, and hope the person is not reading the mail and text about a new card being send.
That's true in a lot of infosec, but in identification, you can revoke everything and wait for meat-space verification to start again.
And if the keys are ID related you can easily revoke it. You can't revoke a SSN, fingerprint, DNA, or a face scan.
Isn't that what this was addressing? The attacker has to get both your password and one-time codes before you change either. All the ID related stuff is used like usernames, not keys.
If an attacker does get both, you presumably go in to a government office, have your fingerprints taken, choose a new password, and get given a new set of codes.
While having the populace in general be security aware would be a great thing, it's barely possible to get them to do even basic shit like not putting credit card numbers and other secret information into an email and sending it to anyone who asks nicely.
Educating people on why 'healthy security habits' and 'key rotation' doesn't mean locking the front door and hanging their housekeys differently is pretty much a non-starter.
That's basic UX. If you make the experience shitty, people will avoid it. No amount of experts waving their hands wildly will help that.
If you can't wrap up your healthy habits and your key rotation in a simple device/card/whatnot that people can carry around and use just like a key, your security measures have already failed.
"Because I said so" doesn't work on kids, it sure as heck doesn't work on adults.
That's doubtful, especially as technology becomes increasingly ubiquitous. For systems like SS force users to use it so opting out isn't currently even an option.
> If you can't wrap up your healthy habits and your key rotation in a simple device/card/whatnot that people can carry around and use just like a key, your security measures have already failed.
Who said we won't?
Seat belts were also avoided for a long time but eventually people have realized they're a good idea.
I take it, then, you were not around in the 80s :) People did not "realize" seatbelts are a good idea. We made people wear seatbelts, using quite draconian laws and relentless PR.
> Who said we won't? [... wrap security habits into a handy device]
You'll have to explain to me how that jives with your idea of decentralizing data and access control. A key/security device will need to be manufactured - and there are only a few commercial entitites that can and/or will do that. And if you think they won't centralize key management, I admire your optimism.
I was not around in the 80s, but I know that campaigns to support seat belts and the potential outcomes of not doing so had eventually gotten people to be much more careful.
Regarding devices, things like the Ledger or Trezor Bitcoin wallets could easily be adapted to allow users to control their own data securely and simply. There's no reason end users need to understand what's going on in the background. They just know you have a secure usb device you use to authenticate yourself.
If you can solve the UX problems associated with those, you'll win a lot of praise.
To be clear, even something as simple as contactless payment/transit cards are still too difficult for many people to manage.
I had to physically take a wireless payment terminal out of a taxi driver's hands when he insisted on trying to do a contactless payment by taking the card in one hand, the reader in the other, and then as if he were playing a game of 'slap', slapping the credit card against the terminal and then immedidately pulling it back up and away. He repeated this several times, cursing each time the terminal displayed the message 'Read Error'.
I've repeatedly seen people of all ages: try to press contactless cards against screens, wave cards back and forth at varying distances from the reader, and all manner of other behaviors. And we're talking with basic cards that have no option for input here.
Key rotation that requires installing software, using a computer, etc - it's all going to be far too complex for many to understand.
Key rotation doesn't need to be so complex if the afore mentioned hardware devices are built correctly.
Overall I hope security-absolutists like me can work with more socially in-touch people like you to build solutions that can become mainstream.
If you want to have some idea of the challenges - read reddit's Tales from Tech Support[1] subreddit. For a non-IT focus, the Just Rolled Into the Shop[2] subreddit has a similar theme - that people refuse to read instructions, educate themselves, or even listen to basic instructions on things.
Better still - do a 'ride along' with someone who does hands-on IT support for a few weeks.
I suspect the only way we will get it if Apple decides to make an ID platform that integrates with the iPhone.
[1] https://www.reddit.com/r/talesfromtechsupport [2] https://www.reddit.com/r/Justrolledintotheshop/
[1] is better because it's real stories.
A report-book was written by Ralph Nader called Unsafe at any speed, talking about motor accidents which prompted some outcry and political action that ended with the seatbelt legislation and other safety features.
Some time after the book was published, it was shown to have inaccuracies and wrong statistics.
https://www.nytimes.com/2015/11/27/automobiles/50-years-ago-...
If you have to have many accounts to access government services people are just going to use the same password for all of them and never rotate them. A single authentication service used by all gov't services would be a huge gain for security.
Fighting that is fighting progress due to fear. And blanketly decrying "centralization" of data because of the fear that it may get lost doesn't address the problems. We should move our society forward, but we should do it while solving the individual security concerns piecemeal and as they happen.
As it happens, IIRC, circa 2000, US schools and universities had to change their databases and systems to not use SSN's as student IDs because of identity theft problems extending from this very core problem.
The US through law must deleverage SSNs and make them public-safe, and promote/mandate a real PKI non-profit system for authentication and authorization for the greater good.
So, instead we have an extremely crappy national ID in form of SSN cards, but I'm fairly certain that same crowd would also be happy to end social security - so at least they're consistent.
With current technology there's no technical or practical (other than inertia) reason federal services couldn't use state IDs. There's only 50 states, not N states. A 50-case switch wouldn't be that bad. ID requirements between states aren't so disparate that you couldn't get a good enough mapping.
The biggest hurdle to ANY effective ID system for individual people is that ID is a composite key. There are many Joe Smiths in the US. There are many Joe Smiths in a state. There are probably a handful of Joe smiths with the same birth date. There are possibly multiple Joe Smiths born on the same day that look similar and share a zip code.
People don't have unique identifiers other than DNA and even then if you don't do a good job processing it you're not guaranteed accuracy and I don't think we're at a point where we trust any .gov with that level of info about us.
So far we've been able to squeak by with just using really ugly composite keys.
And yes, State + State ID is a decent substitute for a national ID. Because it is a national ID. Except that some states will implement it in the shittiest way possible, and so we end up with even more of a lowest common denominator than if the states negotiated a standard.
And one could reasonably make the case that in this day and age, IDs fall under the Commerce Clause.
Here's the ugly truth: People are objecting to a national ID because it's an easy-to-parrot talking point. The rational objections are on thin ground. (Basically, the downsides are already existing anyways, we're just not getting the upsides. Because ideological purity. Yes, I mean you, ACLU)
- Applying for university
- Managing my student loan
- Registering a company
- Delivering taxes
- Changing health provider options
All online (various different services). This is in Norway. Actually the electronic state ID systems supports multiple identity providers, I mostly use the one from my bank. Which them also covers all my banking needs.
And if the USA had national ID it would be used to harass BME citizens ala Sherif Joe
Look, when the ACLU is against national IDs you have to at least admit that the idea is worth discussing. https://www.aclu.org/other/5-problems-national-id-cards
They represent both the best (a strong belief in an ideal of humanity, and a fervent desire to make the world a fair and open place) and the worst (ideological purity über alles) of the left.
And I say that as a card-carrying ACLU member :)
any company extending credit or charging a customer should be required to reach a level of proof required by law, to the point I would think that above a certain level of credit it requires a notary or such.
I'm not really sure the protocol is up to the job, while theoretically it would appear possible to secure data on the internet, the reality seems to be that the complexity of the systems involved means there is no reliable solution.
They seem pretty capable, so far, of keeping their own collected data secured.
Not trying to stick up for Google here, but, like MS, there seems to not be a real breach there.
A lot of people are making the assumption that digital information can be somehow protected when in fact it seems the opposite assumption is more likely to be correct--any information in digital form accessible on a network will be compromised. It's just a matter of time and not even a very long time in most cases.
What if we take this as a starting assumption for information management? I think this leads you to a different way of thinking of information protection, specifically that we need to come up with ways to extend the time that private information remains protected. For example, what prevents us from having physical "information wallets" that we carry around with us and unlock only on demand and in return for specific services? This sounds a lot like an iPhone. Why don't we put things like medical records in them?
I think the technology to do this is already on the horizon, especially if you assume that the information that people truly need to protect (e.g., financial records) is not that large.
I mean, there are circumstances where it'd work. But the requirements for verification and chain of custody would limit usefulness, I think.
It could probably extract DNA in real time from your sweat or breath.
But then DNA will become just another identifier, because we'll be able to synthesize it too, and then amplify it again, use it to trick the machine, and so forth.
EDIT: leaving the error, but real time PCR is actually a lab technique. I meant basically super fast sequencing