Bank of the Underworld (2015)
theatlantic.com
theatlantic.com
If two thirds of Americans have had all of that information compromised from this one incident alone, why do we use it as authentication for anything? Shouldn't the SSN be replaced/assisted by a key pair?
No, the real problem is a liability one; loan companies should be held liable for each instance of fraud where they pursue the wrong person.
It would inconvenience SOME who don't live near a bank and shopping loan offers around will be harder than going on Quicken Loans, but it would also make it nearly impossible for the giant crime-rings that outside of the US to steal identities and open up credit cards.
On the other hand, opening a line of credit is something people do rarely enough that the extra time required for legitimate borrowers would be marginal.
Or asked differently: How do they handle that?
> Or asked differently: How do they handle that?
The same way the IRS handles it when you mail your taxes, they collect your social and some identifiers (banks tend to ask for driver's license, etc online).
I'm a bit surprised living in Switzerland, which has an image for those very discreet, secretive banks.
But you could not open an account with a local bank without showing your passport in person.
Even when I ran my own company and had the corporate account with a specific bank I had to show up at a branch in person showing my passport in order to open a pension account with the same bank.
This even applies for postal accounts.
Mailing a scan of your driving license would never fly. I don't think it would even be accepted as identification if you show up in person.
Obviously this would be more expensive for the consumer. I think if we can put a credit-freeze except for such applications in person, there would be people who go for it; I would.
Trying to do the whole thing in the private sector would result in everyone using Equifax as a "private key verification service".
Errm, that's not true.
(I should probably have written "some immigrants", because the situation is tediously complicated. Anyway, presumably you get to use the license as proof of right to work/rent etc?)
The religious reason is generally about seeing insurance and/or investment as gambling, as I understand it. I wouldn't call it that weird.
> Also utility bills are a valid proof of address for some reason.
Well, yes. A utility bill means that there's a highly-regulated company that is providing you a recurring service to that address, billing you at that address. If the electric company is billing you at a house, for providing electricity to that house, presumably that is your house. It doesn't seem especially unreasonable, it's going to be more up-to-date than the record of when the house was bought or when you started a lease, and it's cheaper than sending a government employee to verify. It doesn't have to be a hard, unfalsifiable proof; it only needs to be stronger evidence than writing down whatever address you like without any checks.
Utility bills are ordinary pieces of paper that can easily be forged.
Even if you have a genuine one, all it proves is that the address exists in enough of a way to have its own utility meter, and that the person you're dealing with has access to the mail there. That's not nothing, but it's not a lot. People may not be on the bill (subletters etc), or the bill may be paid by an absentee landlord, etc.
Conversely, the security is terribly vulnerable to social engineering, like SMS "2FA". I know because I had a month's disruption when someone managed to order a replacement phone line to my house and cut off my internet for a month.
It's not perfect, but I would say that in most cases it's better than nothing. It's a bit lacking for of subletters, but when I've needed proof-of-address, showing the signed lease has also been acceptable.
(I actually am in a month-to-month with no lease and with a roommate's name on the utility bill, so the last time I needed proof of address I needed something else. Can't now remember what it was.)
More trouble definitely, but not crazy hard. Some creditcard companies do it in those chip cards (others just put a readable ID on the chip, which is why you still see zoe gods printing chip cards). I know the government is generally less efficient than corporations, but they've got a massive budget. They should be able to figure out how to make an ID with a cryptographic signature that verifies itself and brings up a pre-registered photo on the computer of the person verifying you that's pulled from a government database. I don't really even want the government to have power, and I believe a national ID program like the one I'm proposing would do that in ways, so I'm fine with them failing to do this... I just don't understand why they haven't yet.
If minimizing privacy invasion, they could type info they're verifying in to get a yes/no instead of seeing whole thing. There's strategies for reducing abuse of such a service, too.
Consequently, all Federal identification documents are strictly voluntary (like passports), which means some significant fraction of the population will never have them.
Perhaps a PKI-based federated system should be deployed, even if adoption were on a state by state basis. I assume most states would adopt it, given the benefits we can think of ourselves.
Note that passports provide passable ones but not everyone has a passport.
If you desire an optional government-enforced ID scheme, Estonia provides some even to non-resident. You need to go to an Estonian embassy with a valid passport and for a sum ($200 IIRC) they'll give you a card and a USB card reader that allows to sign certificates in a way that is authenticated by the Estonian government.
They were started to keep of taxes and never meant to be used as IDs.
Was that because only 35 users were legitimate, or because the users - even if completely legitimate - were reluctant to risk potentially destroying their lives by admitting their identities to federal investigators?
My loss from the LR takedown was ~$600 and this is the first time I ever heard that any such recourse that was available.
In my personal experience, LR was easier to use and more widely accepted at the time than competing services. (namely PayPal)
This article focused a lot on the carding scene, which no doubt was heavily reliant on LR, but to paint all 1MM+ users of LR as carders is simply incorrect. As the article mentions, it was trivial to open an account (as easy as signing up for HN really) and many would do so to make a one-off payment.
>> According to Stapert, the U.S. government requested that he forfeit his fees for the case—insisting that the money Budovsky had paid him was tainted—a move that forced him to drop Budovsky as a client. (The Manhattan U.S. Attorney’s Office denies that the government petitioned Stapert to forfeit the fees.) Once on U.S. soil, Budovsky was assigned a court-appointed lawyer;
Challenging the US justice system in matters of legal (and even human) rights, more often than not, leads to dead ends.
One must assume registration was automated at this point, no? There's no shady business practice in this specifically.
And the USD is likely the greatest instrument by volume of the same types of transactions.
The transaction business will continue, as humans continue to trade for benefit. The cat and mouse game seems mostly about "authorities" overseeing and/or obtaining their share.
Again, an opportunity for p2p distributed, anonymous, and encrypted technology to allow humans to continue to trade that which they value.
Currency/money is based on trust/faith, so that would be the logical focal point.
Hypothetically, such development work would likely need to be conducted in jurisdictions that owe no allegiance to those authorities that do not wish for it to occur. Flavors of Cryptonomicon...
Fascinating.
Seems like a perfect fit and transaction cost would be worth it.
Lol!
I m not really how they gross 200 M USD in transactions at 1% and he is found with 2.5 M USD in his debit card.