> Why don't they do [stronger authentication] for credit card requests? At a guess, it's because these stronger schemes are too inconvenient, and will drive away consumers who are trying to apply for credit.
> If that guess is correct, it suggests that the real solution is regulatory: make credit providers liable for the full damages, including ongoing inconvenience, suffered by victims of identity theft. SSNs are not the problem; authentication commensurate with the risk to all parties, including especially individuals, is.
Doesn't sound that hard to me...