> It’s used not just by cops but also by debt collectors and private companies carrying out background checks. Private investigators use it to track cheating spouses.
Honestly that this database exists at all is a serious problem in itself.
There are three ways to authenticate myself, none of which is knowing that magic number. Many institutions choose to do it simpler and more convenient, which is then their problem if anything untoward happens.
(BTW: None of the authentication mechanisms are available to minors, which fits in well with another aspect of the law: If an adult or a legal person enters into an agreement with a minor and something goes wrong, that's not the minor's problem.)
Also companies don't treat your ID number as lavishly as in the US where you have them printing them gratuitously into easily stealable documents.
For authentification you just show your ID card that contains both your name, date of birth, and your official address. If you move you have to notify authorities and get an official sticker on your ID card showing the new address. By law, everyone is required to own either an ID card or a passport to be able to identify yourself in front of police or a court.
Of course various governemnt agencies have their own identification numbers for you, for example you have a tax id that you will have to share with your bank, and another id for social security that you will have to share with your employer, etc. But those are just for reporting to various government databases and are never a form of authentification. You first prove who you are with your ID card, then you exchange id numbers for relevant systems.
(our IDs also have numbers, but you can get a new ID card as often as you want and nobody outside the government can do anything useful with it. We had some bad experiences with government databases, so it's now a number of unconnected smaller databases)
It depends on the degree of verification you need. You can just post a scan or a photo of your ID, you can send a small wire transfer because banks have to verify the account owner, there is an OpenID provider that offers authentication tied to the real world identity, a courier can come to your home to verify the ID or any combination of the methods.
Usually in the same way it's done everywhere else: name, date of birth, registered/current address, sometimes an additional pin/security question/etc, depending on who you're calling.
If it's official business you might be required to send an actual letter, though I doubt they ever check your signature unless you're suing them.
If it's online and state business (portal for unemployment stuff, state employee pension details, etc.), you usually have to provide your name and address first, which they then check against your registered address. They'll then send you a letter with a one-time password you can use to register your account.
Edit: Modern E-Business companies often require you to "verify" your identify by ways of Postident (you present your ID to a post office) or IDnow (you present your ID to a random guy via webcam who asks you to move it around so he can see all holograms, data, etc.) and can compare it to your picture in the webcam.
This is considered to be enough for financial transactions according to our current money laundering laws, so it's about the most though version you can go through.
Norway has a public number as well. It is used in part as identity, and for taxes and all that stuff. As far as identifacation goes:
1. Picture ID. For me, it is my passport or immigration card, and some folks have their pictures on their bank card as well, which works for ID.
2. For online transactions of various sorts and sometimes doing things at the bank, I have a little device that gives me numbers. This is issued from the bank, but is a national system. I use it along with my ID number and a password of my own choosing. This is done for things like purchases, banking, government websites that store my information (medical stuff, for example), the secure mailbox (government documents and things like that), and a doctor-patient thing.
3. Sometimes, a service will sent a SMS code as well as or instead of some of the above.
I think things like income and tax information are public here and I think your address is as well (I can't remember). There is also quite a bit more trust in the government as well.
Anyhow, around here businesses request your consent to copy/scan/store your gov issued id card. So I guess defrauding them is about as hard as getting into a club with a fake id. (But there wasn't really a need for that, as few years ago enterprising individuals paid a homeless guy for his id card and managed to buy more than a hundred thousand SIM cards with it, so there are other issues when it comes to security.)
You just need one "bad apple" or some technical hiccups and suddenly the personal data of almost all of your citizens can reach other governments' hands. After an event like this one (https://en.wikipedia.org/wiki/Office_of_Personnel_Management...) advocating for extensive data collection by a government entity is poor folly.
The bigger problem is that the TLO is an adversary database -- it is a record of information about the enemy, i.e. the debtor, the citizen. Automated licence plate readers are standardized on repo cars now. Of course, they are collecting location data about all cars. Police are also widely deploying ALPR. You don't really have location privacy in America any more, even if you don't have cell phone.
my favorite example: a US person setting up their own personal account on the US Social Security Administration's website must provide sufficient authentication information.
and where Social Security get this authentication information about each person? Equifax!
[0] see https://www.ssa.gov/hlp/mySSA/df-idverification.html
The problem here is not which type of organisation holds the data; it's the fact that individual humans are involved in using it.
Same reason you'd worry more about a 200-pound drunk guy than you would a toddler, if they both came at you with an axe.
History teaches us that governments have to be treated according to different rules. Private companies didn't murder 100,000,000+ of their own customers in the last century alone. It took governments to do that.
Government is/will be the first/last institution that can defend you and your identity.
Vote the people you trust.
In healthcare hospital staff typically works around this by using "Mr twelve" - 1212121212 - which is syntactically correct with the correct checksum, but not identifying an individual.
“I’m not clear why you think it’s my identity that was stolen, rather than your money.”
It's not identity theft, it's financial fraud.
It's not stealing music, it's copying music.
It's not buying ebooks, it's leasing them.
It's crazy how easily we (and journalists above all) accept semantic distortions of reality, and forget what's actually going on.
Infringement of or on the person.
If someone "steals" your identity, and then shows up at the bank and withdraws your money, the bank will be on the hook for that loss, not you.
There are superficial barriers and hoops in place which make the chances of you not getting your money back non-zero. Not to mention, it will at the very minimum inconvenience you and waste your time.
Credit cards are less problematic in this area, but when it's a bank account / debit card, there tend to be fairly agressive deadlines for identifying the fraudulent activity and contesting it as well as arbitrary processes, forms, and reviews unique to each the bank.
In the interim you don't have the funds - for many people living paycheck to paycheck this can be a catastrophic situation.
I recently had to go through this process with a debit card someone on the other side of the country had fraudulently charged $500 to. Due to my being in the midst of leaving for a long bout of travel, it was a nightmare to get the protest documented on time, and my bank suddenly required all sorts of exceptional identifying documents they never require in the course of regular business, requiring me to jump through a number of additional hoops like accessing my safe deposit box to retrieve my passport - when I wasn't even in the same state at the time. It all just added more delays to the process.
As far as I could tell, the bank was treating me as the potential criminal. They were operating under the assumption that I, the victim, am actually the perpetrator attempting to commit fraud. Through this lens, the process being frustrating and inconvenient to the customer appears advantageous, as it all increases the odds of them failing/giving up.
Someone using your card isn't the main problem with "identity" theft. That's a minor issue. If it's more than a few hundred bucks you'll notice immediately.
Someone getting a loan or a social security card benefits or health insurance or tax refund or committing a felony in your name is the major issue, which can run your life with you not even knowing for possibly years.
In other news, it seems the NYTimes has managed to use the phrase "regulatory capture" three whole times so far in 2018![1] Woo hoo! We'll be addressing this in no time at all. Right after rolling back copyright extension. And tech innovating better fora support for constructive public discussion. RSN. Maybe next week? :/ Sigh. [1] https://www.nytimes.com/search?endDate=20181031&query=%22reg... But yes, it is possible to push on these things. History is contingent. And no one ever promised bootstrapping a civilization was quick or easy or monotonic.
I just realized that upon reading your comment.
From the old world, the word infringement was used. People do or have a thing they are not supposed to, basically.
No theft occurred because no loss of property happened. Thus, the other word.
I would wonder about examples of infringement back when information was much less fluid. Identities are one such example.
This could be infringment of the person, again setting modern language and examples aside.
Money was moved from the bank via fraudulent behavior.