Claiming your $125 from Equifax is a “moral duty”
boingboing.net
boingboing.net
This is not to rag on boingboing in particular at all, this sort of language has become ubiquitous, but it's still incredibly frustrating. I have to wonder if "identity theft" represents one of the most effective bits of propaganda/doublespeak ever coined. The very wording flips around cause and effect and in turn responsibility. In reality people don't generally get their identities stolen, institutions/organizations fail to properly verify it. If someone claiming to be me applies for some financial service and the bank goes ahead and grants it, it's not that my "identity was stolen" it's that the bank/industry did a piss poor job of verifying it. It should be between them and the party that committed fraud, and if they go after me instead then they too should be punished for it as literal accessories to the fraud.
Instead we've ended up with this madness where parties A & B can do a transaction, and then party C can end up being pinned with it without ever having so much as a single interaction with A or B. There has been an internalized sense of helplessness and blame shifting that has allowed the industry to skate by something that we absolutely have the technology and economics to solve to a high degree. The article is not wrong that we should expend some effort to try to make sure that at least this minimal fine sticks a bit, but I resent having to be involved at all and having to give my info yet again to the guilty and having to buy into their root cursed fraud scheme and jump through their hoops.
What's really needed is a blanket law stating something along the lines that no unconnected 3rd party is ever liable for transactions between others, and that anyone who then goes after them for it is not only strictly liable for all expenses and damages but also minimum 3x punitive damages as well and some minimum flat level per incident too.
Right now, in the interest of increasing commerce, we're forcing everyone in society to bear the burden of this specific fraud and the benefits go to the lenders. If person A is being defrauded by person B pretending to be person C, then person C has no reason to be involved unless they aided person B.
This is placing the burden on consumers in a different way.
The burden is lifted from the rest of us who somehow got tasked with making sure lenders aren’t making errors with the risk of losing hours of our lives fixing someone else’s problem.
It’s ridiculous that after your child is born, you’re supposed to spend your time to place a credit freeze at the 3 credit bureaus. Transfer the liability of identity fraud to the lenders, and they will figure out the solutions in no time.
This feels like an idea that would benefit consumers and be a business opportunity targeted at creditors if we could only convince them this is their responsibility.
Each party is verified and the relationship is verified to ensure non-repudiation.
An identity verification system would require the individual establishing their identity with the credit agency and provide as much or as little credit establishing information.
When a B2C transaction is established, the customer would provide the business with a token identifying the credit profile they want to use and the business would request a credit chect with it to the agency, and if the business accepts the credit score they can both acknowledge to the credit agency they wish to do business.
First: No. The burden is on B to prove that C is A, the default should be that if they cannot quite definitively identify the counter party then tough cookies. And they need to do this while covering all expenses and time value with interest in the event they're mistaken.
Second: if only! Most identity theft is not even remotely subtle. It's people walking in with mediocre quality forged documents or minimal info literally hundreds or thousands of miles from any location C has ever visited in their lives. Or someone randomly claiming to be C via some simple 10 digit government number and an email address C has never used. Etc etc. It's not exactly mission impossible hacking-a-passport-and-wearing-full-3D-facial-prosthetics-and-voice-changer stuff we're talking about here. Standard "ID theft" is just from a financial party with all the incentives to push through acceptance as frictionlessly as possible and then simply hound whomever they can try to pin it on and feed them into "debt collection" systems until most people cave.
What the law needs to recognize is that everything about this should be literally criminal. The original criminal is the one who committed the original fraud. But everyone who goes along with it from then on out, every single 3rd party directly trying to steal money or time or whatever from the innocent victim, is an accessory to that fraud. All of them are involved, though as always they can seek (after paying their penalty) to shift expense/liability back up the chain if they can prove it. It's their fault for insufficiently verifying the original counter party, and then they've compounded it by seeking to defraud someone unrelated.
Party B thinks Party C owes them money.
Party C thinks they do not owe Party B money.
Party B sues Party C and shows (or not) by a preponderance of the evidence that Party C owes them money.
The onus is on Party B.
This reminds me of a great Mitchell and Webb sketch. https://youtu.be/CS9ptA3Ya9E
I knew someone who had her identity stolen, she took all of the proper steps - going to the places to prove it wasn’t her, filed police reports, etc. and she still got arrested for various fraudulent activities like check kiting and theft by conversion. She ended up in jail for a weekend while relatives brought various forms of proof that there was already an ongoing investigation. She had a warrant out for her in another county that she didn’t know about.
While I agree with the premise that we should make security breaches as painful and expensive as possible for negligent parties such as Equifax, the manner of this claim feels completely off.
For starters, I have to submit information to a 3rd party, and that in fact will start a process that I, as a victim (potentially, at least) of Equifax's negligence, must complete. Moreover, even the actual damages I will be entitled to is quite unknown. I realize a lot of this is due to class action law, but it's still woefully insufficient.
Furthermore, reading through the fine print, at least according to other analysis I've read about it, you also have to enroll or already be enrolled in some kind of identity protection program (such as what Equifax offers themselves). So, I would to have to opt-in to a system I am trying to stay out of in the first place.
And why do I even have to confirm my info? If Equifax has it already, then they should reach out to me, as a victim of their negligence.
There is more, but these are the most glaring issues. I realize there's not a lot that can be done, but these factors give me a strong distaste for this and I think we are deluded in thinking this will actually amount to anything more than a slap on this wrist or even cost them much of anything. It's going to cost them up to $31 million based on people's claims. It likely won't cost them more by me filling out the claims, but it will cost me as I'll have to become further entrenched in a monitoring system that got us into this mess in the first place.
Straight forward.
[0]: https://www.equifaxbreachsettlement.com/admin/services/conne...
[1]: https://www.equifaxbreachsettlement.com/admin/services/conne...
It looks like, if your goals are a balance between receiving the settlement, privacy, and effort, the PDF (probably [2] if no minors were involved) is the way to go.
[1] https://www.equifaxbreachsettlement.com/file-a-claim
[2] https://www.equifaxbreachsettlement.com/admin/services/conne...
[3] https://www.equifaxbreachsettlement.com/admin/services/conne...
Multiple 3rd parties, at that; https://i.imgur.com/ARPFyFl.png
Last night those scripts were attempting to load from the form page, which is now currently 403 for me.
I would love to dedicate my $125 (assuming I am part of the breach, which is almost certain) to the pursuit of damage, and possibly incarceration, for the Equifax CEO and top executives at the company.
Give me a reputable law firm willing to take my donation, with clear use of proceedings. I bet thousands of people would love to spend that $125 this way.
A blog post? A mailing list? Else?
They will be giving away their "ID Patrol" product ($16.95/month) for four years, and charging the fund $813/each. Essentially the left hand is going to pay the right hand and it is considered a "fine."
Imagine a defective physical product went out. Then the company sent out repair kits. Those kits have a real cost to produce/ship/etc
It would still seem kind of silly that a company is sending me repair kits instead of money I can choose whether to invest in repairs or not, but so it goes
I would presume the law is a bit better in the physical world as making repair kits directly impacts your balance that you can’t use for anything else, at the least.
It's racketeering.
All the higher ups get plausible deniability and the headlines in the news, and nine out of ten people’s eyes will glaze over by the time you say conflict of interest.
I am asking “what is the logical reasoning behind the decision of the judge in this particular scenario”.
The situation may be unfair, but why specifically?
I wouldn't think the judge in the case can actually do anything in cases where the plaintiffs and defendants reach an accord, or at least the corruption needs to rise to a level higher than what is seen in this case.
https://www.ftc.gov/enforcement/cases-proceedings/refunds/eq...
This is a pure curiosity question, but I didn't think Equifax knew which numbers had and hadn't been leaked -- my impression was just that hackers got access to the full database. When the original announcement came out, wasn't there a big thing about how they were basically flipping a coin and returning a random result every time you checked if you were affected?
Are they really able to determine which social security numbers were stolen?
Edit: Question 12 on their FAQ says I can come back for more if there's damages in the future:
Edit: Nevermind, "to the best of my knowledge" the free-for-everyone Capital One CreditWise service qualifies.
Reliable financial data is hard for marketing companies to gather about individuals, CreditKarma solves that problem.
If you read their privacy policy and ToS you'll learn they are able to sell your data as part of all the free services they provide you.
So my choices are let a 3rd party pay the credit agency for that info and I get nothing, or let CK pay the credit agency for that info and I get something for free.
Sounds like CK is still the better deal.
different cards (banks) have relationships with different credit unions, if you have a diverse portfolio of cards, you can get more reliable data than CK direct from the Credit Union for free (or for the annual fee of your card)
Credit Karma tries to sell you services based on your credit.
Companies like Credit Karma or even companies like Facebook and Google don’t sell your data. They sell access to you based on the data they have.
The distinction makes a big difference. If a law is passed saying that a company is not allowed to give out your data, it doesn’t really hurt companies.
They did a MASSIVE campaign around the Tax Filings and many people simply 'opted in' because they had CreditKarma and it was Free, without realizing what they were trading away for 'Free'.
Also, I suggest billing Equihax for time spent changing emails, phone numbers, etc to make your identity less susceptible ("the time you spent remedying fraud, identity theft, or other misuse of your personal information caused by the data breach, or purchasing credit monitoring or freezing credit reports, up to 20 total hours at $25 per hour.")
My credit is self monitored. Any credit/contract taken out claiming association with my public identifiers (eg name, SSN, etc) but without legal notice to my longstanding address of record is prima facie invalid. So I review all of the junk mail that comes into my mailbox, which does cost actual time, primarily due to the negligent operations of these ambient-authority-demanding surveillance shitheads.
https://equifaxbreachsettlement.com
You put in your last name and the last 6 digits of your SSN (not full SSN), it tells you if you were impacted, you give your full contact info, select the option for $125, it gives you an option for check or gift card, and done.
Legally it requires that you already have some form of credit monitoring, which from other comments here seems that many credit cards already include (mine do, e.g. Capital One).
But... I'm kind of amazed it's so easy. This really ought to be done by everyone who already has a credit card that provides free credit monitoring. I never thought I'd get to have a little feeling of personally holding Equifax accountable in a small way, but here we are. :)
If you scroll down and click "Find out if your information is impacted" that's where you put in the last 6 digits of your SSN and it tells you, and then brings you straight to the form if you're eligible.
I'm not sure what will happen if you file your claim but you weren't affected... it might just be ignored then?
Can you share the docket numbers of people getting $8k default judgements?
https://blog.legalist.com/i-won-8-000-from-equifax-in-small-...
This is a guide to taking them to small claims. I haven't followed any of these so I don't know how valid they are.
https://myradvocate.com/Your%20Guide%20to%20Sue%20Equifax%20...
I certainly had a lot of time wasted trying to figure out what to do and then taking more actions to protect from possible consequences of their screw up.
Yes its articles are somewhat fun to read, but when posting to HN, just post the real article, which is always linked in the website.
https://slate.com/technology/2019/07/equifax-settlement-mone...
I don't think it's hard for anyone to claim 10hrs on this. Just reading the news/basic research over the last 1.5 years can quickly reach 10hrs.
For me, I also signed up for credit monitoring a month after the breach announcement and have since been getting spammed every week with various credit alerts. If I spent 10 min on each mail and got 1 email/week over the last 1.5 years that would be 13 hours of pondering credit spam.
1) If the public trust doesn't reach 50% of voting shares then what difference will it make?
2) If the public trust does reach 50%, then it's no longer a for-profit company, but rather full socialist government/public control of the economy
Fines are fine -- they reduce the value of shares and therefore the bottom line. They just need to consistently outweigh the potential profits from bad behavior.
If fines are too low, the solution isn't to find another fix -- it's just to raise fines more.
If you have 10% of shares and two other organizations have 45% each, and those two organizations have a conflict, you get to choose which of those two organizations has control over the company. Those organizations are both incentivized to make your needs a priority in order to secure your votes. In this situation no single group can choose the destiny of the company without the assistance of one of the other groups.
https://secure.equifaxbreachsettlement.com/en/claim
and let them sort it out.