Is this not the case already? I know that it could be an incredible hassle to prove that you didn't take out the loan and that someone else has stolen your identity. (There's also the question of who has the onus of proof -- you or the bank.) But if it's a fraudulent loan and you could prove it was fraudulent (which I agree could be difficult to prove), can you be held responsible?
The simple answer to this is "no." Identity theft can take time and, occasionally, a small amount of money to clean up. This has a very real cost if you happen to be a person that has little of these resources. But you can never* be held responsible for a loan you didn't take out.
This is also the core reason why Equifax has not suffered many consequences: it's because the real world harm of their negligence simply wasn't that significant. I don't even know if there is any data to show that the number of identity thefts has increased in the wake of their breach.
*Unless I guess you receive a summons to a court date and don't show up and someone gets a default judgment against you. "Never," here, as usual, means "extremely rarely."
One thing I hate about massive corporations is that there's no semblance of accountability. I'm not looking for Hamurabi's law, but as long as companies can act with impunity in the face of the law we're in for a rough future :[
Amongst many things, recall how banks got away with a slap on the wrist for the whole Robo-Signing scandal. (see: https://en.wikipedia.org/wiki/2010_United_States_foreclosure...)
If an average individual had done this, they would face charges (and they should.) But mysteriously when it is done tens of thousands of times it somehow becomes legitimate. I'm a pretty liberal person but I am deeply disappointed in the previous US administration for not pursuing this scandal towards justice.
You'd think that crypto proponents would have learned after the first five major bitcoin breaches and millions of dollars of losses without recourse, that having trusted people with the power to change transaction history is a good thing.
Just issue public/private keys to citizens. They sign with their private key, banks verify with their public key. Anyone can request your public key from the Social Security Administration via API. Done.
The SSN acting both as the identifier and the password is the real problem, and throwing the blockchain into the mix just complicates things more.
We still need a central agency. It's the authentication method that is pathetically worthless.
Keybase is the only one getting this right, and people are now claiming they're ignoring security in order to do it. It would be a dumpster fire to trust government agencies to get the design requirements right.
https://eid.belgium.be/en/what-eid
For the last several decades, many of us Americans have become too skeptical about what government can do in terms of technology, even while it's completely true that government often gets it wrong.
There are very few government officials worldwide who truly know technology or how to effectively engage the real experts in an agile way rather than just government contractors. That seems to be the main problem to me.
Even in the US, the US Digital Service and 18F have done great work. And Canada has at least one backbencher MP who's a Linux and free software geek, asking legitimately knowledgeable questions in committees on topics like IPv6, copyright, and plenty of unrelated topics too.
Of course I realize those organizations and people are exceptions. But they, and the Belgian and Estonian examples, indicate what can be.
Maybe we can figure out how better to make technologists interested in serving in government, or working closely with it from the outside.
I'm holding out some hope that Estonia will be able convince their fellow EU member states to pick their game up now that they have the rotating presidency of the EU council [2].
But one thing Estonia has going for it (or working against it, depending on perspective) is its close proximity to a technologically advanced hostile nation. Estonia's rapid progress has been spurred in large part by the necessity of protecting itself from Russian cyberattacks, a Big Issue if I'm remembering the New Yorker article correctly.
[1] https://www.newyorker.com/magazine/2017/12/18/estonia-the-di...
[2] https://www.visitestonia.com/en/why-estonia/estonia-is-takin...