Experian’s credit freeze security is still a joke
krebsonsecurity.com
krebsonsecurity.com
I don’t want to have my information with these companies. Please let me not participate. It’s like every American was given a Chase Bank account at birth that we can’t close, it’s weird.
You don't need worry about your credit if you use cash and store it in a coffee tin, couch surf, and work under the table.
Credit reports are queried for many reasons, not only loans.
Everyday shopping happens with debit cards, bills are paid by wiring money.
When I came here, I "built credit" by paying everything by credit card and making sure to pay off the entire bill immediately to not incur any interest penalty, but when I read stuff like "always pay off the credit card with the highest APR first", my head's still spinning.
Business credits exist too of course, but I'd guess that the proportion of the population doing that is even less (and Germans are already much less likely to buy houses or apartments than people in the US).
Of course if you did have a credit somewhere, and you defaulted/didn't pay, it's bad, and there is a credit bureau tracking that and more ("SchuFa").
Nearly every “basic” transaction (like buying coffee) is done with what might appear as a “credit card”, but it is actually a debit card. Some people use “credit” for these daily sorts of purchase, but at least among the people I know, this is extremely rare.
The closer you are to 'living pay check to pay check' the easier it is to get you into this. And I suppose for some people it takes multiple larger purchases to get you into it. Popular culture, TV shows, Twitter nowadays etc. don't help and 'legitimatize' it (everyone's talking about it that way, so everyone must be doing it that way, so it's OK to do it that way).
You might be good at "paying it off at the end of the month". A lot of people easily slip into credit card hell that way, because they _can't_ pay it off at the end of the month, because they didn't realize how much of their credit they should really be using. Credit card says you have $2000? Let's spend $2000. At the end of the month I only have $1500 left in my account? Oh crap!
Personally I pay it off in sort of regular intervals, since it's all right there in my online banking. I've never waited for a "credit card bill", even when they still sent them to me in actual dead tree form.
I use my credit card for the purchase buffer the other mentioned, and I've set it to the exact amount is taken from my bank account on the due date.
I also track my expenses and categorize it, so I have a clear idea what's happening in the budget.
The points for regular spend, the sign up bonuses, and the interest savings (the average balance on my card ends up saving me interest on my mortgage) put me well ahead.
Credit cards are a solid because many (most?) people use them poorly, but it's certainly possible to use them wisely.
This sentence is the epitome of marketing brainwashing in the US. Not trying to single you out, as we all suffer it to different degrees here, but this sentence kind of puts it in such a nice little box.
What's a reward? What actions warrant such gifts? Why don't they just give you money instead of "points"? At any point, does the gameification of debt strike any of us as one of the most abhorrent MBA ideas in history? It's right up there on the list, sitting below indentured servitude and for-profit prisons.
This gets repeated, but it's not true everywhere. Some banks may not care or maybe it's harder in some countries. But for example in the UK I could easily revert a few £k the same day without issues. I'd love to read more about where the differences come from, but the blanket statement is not 100% correct.
It always depends, so do your own research, but as far as I understand, it is still considered decent general advice to tell people to prefer credit cards over debit cards. They will build credit, earn rewards, have excellent consumer protection from fraud, increase the distance between their purchases and the cash in their bank account, and so on.
"Credit card bills" also seem to be a regular part of everyday conversation here, in sitcoms, on Twitter...
You've been somewhat misinformed. You build credit by obtaining the credit line and just having it available for a long time, not by using it "as much as possible." Actually purchasing items with your credit card is not required.[1]
In fact, "maxing out" your credit cards (when your bill closes using 85%+ of your limit) actually can reduce your score (but only for the month(s) your cards are "maxed out.")
FICO scores aren't a black box, they publish exactly what they take into account - https://www.myfico.com/credit-education/whats-in-your-credit...
[1] with the caveat that some credit card issuers will close dormant accounts after a couple years.
Lenders get a raw copy of your report when you apply for credit, which contains things like credit account history (max limit, % of limit used, late payments if any, etc) and then run their own scoring algorithm on it. Those are black boxes.
In the UK, getting a credit card and using it regularly seems to be the common advice for building credit, which makes sense considering the scoring algorithms themselves aren't public (and differ by lender).
Pretty sure you need to make at least a $0.01 purchase for the purpose of having a payment, otherwise you won't have a payment history.
https://youtu.be/vsMydMDi3rI?t=2595
Now, if I shop online, I used to put it on a credit card. Now I generate a virtual debit card using an online service and pay with that. The logic is the same.
We later got some fraudulent charges on it, which got resolved for either of us, but for me the money was never gone (I had not paid the bill yet), while for my friend it took a while to get the money back on their account.
Another fun difference: When during our trip, waiters and cashiers would not just take the credit card, but walk away with it, we were horrified. In Germany, you never give your card away to anyone. You stick it in a terminal and type in your PIN.
I mean, it’s basically their only purpose in life (if you use it for the other purpose to purchase things ahead of your paycheck, that you don’t have the cash for already, you’re going to get yourself in trouble — 20% interest _hurts_)
Cash back/miles is another one.
For the cases that amex isn't accepted, all the major airline groups have a rewards card too (although BA's is an Amex), and most of the supermarkets have cashback cards in the 0.75-1% range.
Family restaurant means a chain like Applebees for those unfamiliar with the term.
The tablets are also a revenue-generating device as you can play games on them for a fee. They also have surveys so you can give feedback on the service, this has become somewhat controversial (see https://www.eater.com/2018/6/22/17492528/tablets-restaurants...).
Really depends.
If you know mostly college students, and younger, lower income people, yeah, most are paying with debit.
If your circle is high income and older, then it's mostly credit. Especially people who do frequent business travel.
In most nations the debt to income ratio for these things is also much stricter than in the USA, since they don't expect everyone to have 10k in credit card debt and 50k in student loans.
Financing can absolutely exist without a centralized credit rating system / data privacy nightmare.
Seems like a good system to me. You give people the "buffer" between your account and merchants but make it very hard for people to go into debt.
If you wanted to, you could have the credit card companies float you a purchase for almost 60 days without interest if you timed your charge and the payment right.
The real issue, I think, is the impact on your credit history for missing a payment entirely, i.e. not paying the minimum amount due. Even if it's $1, you need to pay all of it. That's the real penalty to worry about.
Should mention I make ~$300 a month in cash back by doing this and that’s my main motivation. I actually hate the idea of cash back as I realize it just adds cost to the system but I’m just one dude and the world has spoken on the matter so I may as well get what I can out of it.
It costs more to be poor.
Once upon a time, when cash back ran benefits were in the 6% range. I bought prepaid visas from a retail store. And ran them through some merchant account. About $50K went in a circle every day and I kept the spread of almost 4% if I recall. I had to pull some other accounting tricks to make sure it did not accrue tax liability in the process but it was actually fairly impressive once I hit a certain volume I knew I tripped the alarm with the credit card issuer. They changed their entire card benefits in a way that was obviously related to blocking the activity I was doing.
I take full advantage of all the credit card benefits though, as I think everyone should if they can.
That's definitely true. Time to reintroduce Scalzi's take on the subject:
> The reason that the rich were so rich, Vimes reasoned, was because they managed to spend less money.
> Take boots, for example. He earned thirty-eight dollars a month plus allowances. A really good pair of leather boots cost fifty dollars. But an affordable pair of boots, which were sort of OK for a season or two and then leaked like hell when the cardboard gave out, cost about ten dollars. Those were the kind of boots Vimes always bought, and wore until the soles were so thin that he could tell where he was in Ankh-Morpork on a foggy night by the feel of the cobbles.
> But the thing was that good boots lasted for years and years. A man who could afford fifty dollars had a pair of boots that’d still be keeping his feet dry in ten years’ time, while the poor man who could only afford cheap boots would have spent a hundred dollars on boots in the same time and would still have wet feet.
Careful with this though. The interest rules are very complex. One would think you pay the interest + penalty + balance in full and that's that, but no. Once the account goes into "charging interest" mode, it keeps charging interest on subsequent months even if you pay in full as long as there is a balance on the day of the cycle close (which if you're using the card, there always will be!)
The way out of that trap is, if you ever have a late payment, stop using that card entirely and pre-pay the entire balance (including charges not billed yet) before the close of the cycle. The goal is to get a statement with $0 balance. That will reset the account state to normal.
I'm not sure about that one. Maybe getting the balance to zero on any given day (not just cycle closing day) is enough to reset the account? I don't know.
But I know they'll keep charging interest every month even if you pay in full every month, once the account goes into that state due to a single delayed payment.
Looks like it's called residual interest? https://www.thepennyhoarder.com/debt/residual-interest/
Indeed! For very large payments I try to time them for the day after the close of the cycle, so I get those ~60 days of free deferral.
Also, I got a better exchange rate with my credit card than with cash from a bank or ATM.
On the other hand, I really liked that I payed for meals at the table instead of giving the card to the waiter, and that listed prices included tax.
That's not to say the US system doesn't have problems, it definetely does. But I wouldn't want a cash-only system either.
My US amex is usually only 0.1% more than current market rate and so better than any debit card I have by far.
In my experience, European countries are by far the worst when it comes to exchange rate and added fees. One hypothesis is that interchange fees are capped so credit card companies can't make as much from the merchants but even before that happened, I remember the fees being very high.
I just began teaching my kindergarten going son about money and some of the things he has learned watching us is very insightful. For all purposes, money for him is our phone. He has seen countless places where we pay with phone to buy things (using QR codes) and that has given him an impression that a phone can get anything from a store.
For me, in my own childhood days, money as in cash was easily understandable as a finite resource because once it’s given to someone, it cannot be taken back. So I learned just by watching that money carries a value and is limited. But just scanning a phone or card with no concept of finiteness will carry some repercussions I think in future.
Will be interesting to watch the future generation who might grow without concept of cash money.
Consumer culture in general means that it is very profitable for banks and payment processors to hand out credit cards like candy (with huge spending incentives), despite knowing that a ton of people are going to rack up debt that they will never be able to pay.
The overall credit system is also a lot larger than just credit cards. The country runs on cheap debt. Everything from houses, education, cars all the way to TVs and dresses is financed with long-term payments and low single digit interest rates. Most of what people earn goes towards paying for stuff they bought in the past rather than saving for something they might buy later.
Predatory loans are bad and governments do try to crack down on those. Going from "it's easy to get credit in the US" to "the US lets corporations steal from regular people" is a bit much.
1. The average American is considerably wealthier than the average European.
2. Cars are so expensive in Europe relative to America due to regulations/taxes/etc which are applied by governments (the alleged protectors of the people's welfare).
3. You've got causation backwards in regards to infrastructure, the US infrastructure is the way it is BECAUSE cars are cheaper, cars aren't cheap due to the needs of infrastructure.
If you pay your bill every month, then a credit card is like a debit card plus benefits like up to 20% of the purchase value in points, not to mention benefiting from the time value of money.
> benefiting from the time value of money
This is just nonsense. There is no additional gain from waiting till end of month till you pay.
As for your other point, if there were no benefit from floating money for 2 months, then there'd be no benefit from doing that an indefinite number of times, which conflicts with the time value of money, an established, mathematically basic concept.
Having lived in other countries, I actually missed the benefits that robust competition drives. Consumers in some countries are paying fees that went away 20+ years ago in the US.
And as grandparent says, the robust protections offered in the US are a huge plus to consumers. In other countries they aren’t so generous as to forgive fraud and the like.
What if you go bankrupt as a consumer in the US? Credit cards are scarily easy to come by in the US, which suggests to me that credit card issuers aren't worried about consumers potentially unable to pay them off. Which further suggests to me that it's not really the consumers being protected, but rather the credit card companies.
How does consumer bankruptcy work in the US? Raking in a lot of credit card debt, that you cannot afford, could make one liable for life.
You will have difficulty getting credit for 5-7 years. You may think "fine, I'll just pay as I go" but credit checks are often part of the approval process for an apartment lease, or applying for a job.
I'm not saying I agree with this. Landlords are ridiculously abusive, as a renter you will frequently be asked to pay a $300+ nonrefundable "application fee" before they will show you the lease document. They then can put whatever terms they want into the lease, understanding that many renters would not be able to afford another application fee.
The state recently limited security deposits to a single month, and do not permit taking more than one months rent up front. This was meant to help tenants avoid having to come up with more money, but of course landlords will simply mitigate the risk by not renting to some people at all or only for a higher monthly amount.
https://ag.ny.gov/sites/default/files/changes-in-nys-rent-la... "Capping Security Deposits • Landlords can only charge up to one month of rent for a security deposit or “advance payment.” This applies to all residential rentals, with a few exceptions, whether you have a lease or not. › This means that if you are moving into an apartment where the rent is $1500 a month, the most your landlord can charge for a security deposit is $1500. › This also means that your landlord may not charge you in advance for the last month’s rent if you are also paying a security deposit."
And then, your country tries to shame China for its "social score".
Comparing them directly in this way is not only disingenuous, it indirectly handwaves the objectively oppressive system China runs.
A poor credit file can show you are not organized or responsible.
Actually using much available credit is an indicator of someone in financial hardship who may be more likely to commit fraud or theft.
Surely that can't be legal?
If you buy something with a cc and the company for snow reason later does not fulfill it's obligations, the bank is liable. If you paid with cash or a debit card, you're on your own.
As a European I haven't as well. But that's because it's been the safe chip part of the card that's been used all my adult life and not the easily spoofed magnet stripe.
They are quite effective at stealing from Europeans just as well as they can steal from Americans, except Americans are not on the hook for the stolen funds whereas Europeans are.
Here's a Krebs on Security article that has pics of a shimmer found in Europe in 2015: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip...
There was 1.8 Billion in chip card fraud for cards issued in Europe in 2018, with the highest rates of fraud in France and the UK in Europe in 2018, although only 20% is at Point of Sale and 80% is online.
But the real difference vis-a-vis the US and Europe is not chips in cards but the massive epidemic of wholesale identify theft in the U.S. The vast majority (in terms of dollar amounts) of credit fraud in the US is part of identity theft, something the US suffers from due to lack of consistent ID cards and ID card enforcement - and very little todo with chip and pin technology.
The US has 24 B in credit fraud, the majority of which is identity theft, and the largest amounts related to entire bank accounts and fraudulent loans being taken out, lines of credit being issued in someone else's name, etc, and not some illegal transactions stolen at gas stations with intermediate devices.
“The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”
I'm betting the European cc fraud is mostly from residual magnetic stripes or online forms being used, not the chip usages. Do you have a specific breakdown?
If you enter your card in a compromised device, then you lose control over
1) how many transactions are being made
2) who you are paying
3) how much
Because the chip has no way of asking you for confirmation about the identity and amount of the transaction. There is no secure keypad entry connected to the chip or secure bus going out.
All you have is physical presence. The chip can prove to the input device that it is present, and the input device cam forward that proof to the bank. That is all the chip does. It does not prevent you from paying the wrong person, and it does not prevent you from paying the wrong amount. This is why compromised input devices are created, so that you can be charged the wrong amount and to the wrong party when you think you are buying gas.
The chip only guarantees physical presence. Checking the CVV is only when there is no presence and you are trying to milk the attack into an offline attack rather in addition to the MITM attack. Why are offline attacks also possible? Because vendors want to support online purchases, where there is no physical presence. But that' not the MITM attack I was describing.
Offline (card not present) transactions are a second issue, and indeed they are much larger (80-20) not present:present in terms of card fraud, but you don't need shimmers to conduct card not present fraud, although you can certainly use them for that.
Finally, not verifying CVV is not an abuse of the protocol, it's how you do a card not present transaction, which is also supported in the same payment protocol. It's not some weird form of protocol violation vendors are all mysteriously doing. It is not "doing it wrong".
For example, my Dutch card can only be used physically at an ATM using your PIN, or online by using a payment system like iDEAL for which you need bank login details + password (which is not stored on the card). It does not have a long card number like most US debit/credit cards.
But how is this specific to "credit" cards? Don't debit cards get the same protection? The point here is that in the US one needs to have "credit history" in order to do things like rent an apartment, which is not a thing in the EU.
As to security, the EU has largely gotten around the problem by implementing modern payment systems. In Poland no waiter will "disappear" with your card, they will bring a mobile terminal to the table, so that you can use your (contactless) card.
In fact, living in Poland currently, I can't remember the last time I used a physical card anywhere. For the last two years or so I've only been carrying my phone with me, no wallet at all.
With a credit card company it's always the card issuing company's problem to address.
That seems very backward. And as you might suppose, really isn't the case in the EU. Fraud is fraud, and it might take time, but you'll get your money back.
In the case of of CCs, there is an assumption that a certain portion of people will take high interest credit offered by the cards and that they will incur interest and have to pay that. The rates are often incredibly high, something like 20%+. To encourage more people to use these cards to increase the population and likihood people will be forced to pay these interests, CC companies offer incentives like cash back, no-interest periods to encourage borrowing behavior or misunderstanding of the boundary time for payments for at least one hefty interest payment, etc. They also offer an alternative to people who have difficulty receiving a loan for some item any other way.
Debit cards on the other hand are offered by traditional banks. Many of these are free and associated with free or nearly free accounts (usually requiring your regular income deposited or a minimum balance they can invest elsewhere while you let it sit idle). Banks are not incentivized for you to spend money. It's in their interest for your money to sit in your account theyre investing elsewhere or for them to charge you various service fees. They're less inclined to give you incentives and protections to use these cards.
If consumers get to a point of using credit cards in a responsible manner (essentially more people exploiting their benefits than CC providers exploiting them), you'll see these features and protections slowly peeled away. Many cards used to even offer price protection where if an item changed prices than the price point you purchased at, the CC company would refund you the difference. Obviously enough people took advantage of this vs the pool of people paying high interest that these features slowly peeled away. Time and value limits were introduced and tightened, card providers began to remove these, and now few if any cards provide this. This is one consumer feature/perk that used to exist that no longer exists because the normalized increasingly responsible use of cards by consumers. There are several more (rental protection, road side protection, flight delay protections, and a host of perks). Now you often have to pay a fee for a card that has such perks and need to be sure your spending rates are high enough to warrant the fee.
Payment systems aren't about payment systems and detecting fraud, they're about building complex systems people want to participate in under the assumption the complex system will at large extract wealth from the people using the system, not the other way around. Even something as trivial as just paying for exchange of services/good would be straightforward but it's not, it's gamed to pass risks, extract money, and transfer power.
Generally true, but I have suspected that banks have begun getting payments from the payment processors, however (Mastercard/Visa). Most recent time I created my checking account the bank nearly insisted that I have a debit card although I strongly preferred to have only ATM access with it. Additionally the largest banks have most certainly figured out squeezing fees from people for use of the debit cards.
And that's really the key difference between credit and debit.
With a debit card, if there is fraud, the money is gone from your checking account. You will get it back, but it will take time, and in the meantime you may be suffering from all kinds of unpleasant effects of having a suddenly and unexpectedly empty checking account.
With a credit card, if there is fraud, you have a debt on the books. You will get it removed, but it will take time, and in the meantime you still have all your money.
That's what card limits are for. Even on my high-level Visa Premier card, the limit is 1k per day, and there are also per-transaction and per month limits. I can increase it via my bank's app if i plan on making a big purchase with the card, so IMHO it's a good solution for that problem.
If you're protected from your credit card being used on a $5,000 purchase, why would you lower the credit limit below that?
https://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cr...
"If someone makes unauthorized transactions with your debit card number, but your card is not lost, you are not liable for those transactions if you report them within 60 days of your statement being sent to you."
I have never had my credit checked for an apartment.
I too only use my phone for most credit card transactions.
Here in Denmark we recently got an official digital drivers license. You verify your identity with the government issued 2FA system, scan the NFC chip in your (non-expired) passport, and you're golden. The digital license is as valid as the physical license.
Couple this with NFC payment being a requirement anywhere that takes payment, the banks having developed a way of transferring money between accounts in different banks instantly based on just a phone number, and the digital drivers license, there's never a need to have my wallet on me. At the moment I'm not even sure where it is -- it's somewhere in the apartment.
e.g.
https://www.moneyadviceservice.org.uk/en/articles/how-youre-...
No, they don't. It gets confusing because many banks do offer protections against debit card fraud, but that's entirely up to the bank and its terms of service (which of course they can change at any moment).
The credit card protections are by regulation, so you can count on them regardless of bank and the banks can't change them.
A debit card is a straight siphon into your bank account. The bank may or may not help in the case of fraud, depending how much they feel like retaining your business.
A credit card is a strong firewall between expenses and your money, both in implementation (it's a separate account after all) and regulation (you're not liable for fraudulent use).
So, in the USA always use credit cards. Avoid debit cards. I try to not have any debit cards (it can't be exploited if it doesn't exist) although lately it has been more difficult since banks insist on sending me debit cards I don't want. So I store them away, will never carry or use them.
What are you talking about? You do realize that credit cards exist everywhere at this point? You think that when someone pays by card in other parts of the world they maintain constant eye contact with their card, lest the person... skim the largely visible number?
The waiter comes to your table, presents you with the EPOS or tablet. You take it and either tap your card, or insert it and type your PIN. Then you hand the terminal back to the waiter.
The card never leaves your hand.
A lot of chain restaurants now use tablets to let you pay right at the table, and usually they support contactless payments.
Fast food restaurants have also started accepting contactless payments by and large, although it can be quite awkward in the drive thru.
Last time I visited it went like this:
1. I get a bill ($50 for example) and give the server my card
2. A card payment notification appears on my phone for the $50 payment with my bank
3. The receipt comes back with a tip field where I write $10 and sign
4. The server now updates the payment and a few days later when the payment clears, the amount has changed to $60
But what if the server chose to enter $20 instead of the $10 I specified? Do I have to keep the receipt and remember to go check that the cleared payment matches a few days later? How else would that be caught?
In the UK, you enter the tip on the card machine when you put your card in, so the payment is immediately taken and everything is clear. I really want to know why I shouldn't worry about the above scenario next time I cross the pond!
Additionally, I don’t worry about it thou because my past experience suggests I can reverse the charges if I call the credit card company fairly easily.
One thing to note about the US is that card processing fees are more than double what they are in the UK/EU. It allows CC companies to eat the costs of fraud more without passing it onto the consumer/business.
In that case, I need to go through my statement and remember that the $70 charge was supposed to be $60, or have the receipts and check it. That isn't something I have to do here, because it all happens at the same time.
Or are you saying that the penalty for the restaurant/server is high enough that this sort of thing just doesn't really happen much?
Same with stealing number. Yes it's kind of strange that most of the time the server just takes your card and disappears for a while, but I've never heard of a number being stolen from anybody I know. Of course, it does happen, but it's very rare.
Unless they have complicity with management, the risk over reward is too great to try this. If they kept the skim small to be unnoticed -- $3-5 on each check, perhaps -- it may still not add up to being worthwhile. Most people in the world are not criminal masterminds; I think sometimes engineers like us forget that others are not constantly looking for loopholes in everything. :)
Sure, they could. As long as you kept the receipt just show it to the credit card company and they'll reverse it. More importantly, I'd imagine the store would be heavily penalized, up to possibly losing their credit card contract which would leave them unable to accept payments if it's a recurring problem.
So, it doesn't really happen. In decades of eating out a lot, never seen it (and I'm the type who checks every line item in the credit card statement so I'd notice if anything is even a penny off). So no reason to worry about it.
> you enter the tip on the card machine when you put your card in
Personally I hate this so much, because I want to compute the tip and it's really uncomfortable to do so with the waiter staring at me. I want them to go away and give me time and peace to do the calculation.
As a software engineer, the idea of writing in my bad handwriting the tip and total and then someone who is probably in a hurry typing it in seems like a way to introduce more human error.
That's much less likely to happen with a terminal and, since most banks here send you instant payment notifications, you're likely to catch it immediately.
Obviously this system is working for billions of payments a year over there so it can't be too much of an issue! Next time I'm there, I'll not worry about it.
Can you point to a few examples of TVs or dresses being financed in the low single digits? I'm genuinely curious -- as an outsider, my impression of US credit was always one of a system that charged predatory interest. That impression is mostly based on seeing credit cards advertised at 15-25% APR, and hearing stories of student loans with interest rates that approached the double digits (for debt that's not dis-chargeable in bankruptcy, no less).
My point of reference are Switzerland and Germany, which have legal caps on interest rates around 10-13%. Credit agreements with higher interest rates are nullified, voiding all interest claims. As a result, the growing rate for unsecured debt is somewhere in the 8-10% region. (And, of course, significantly lower for secured debt, like mortgages or car leases.)
(I do have some reservations -- I'm guessing that only a small minority of cardholders attempt to churn their balance from card to card or pay it off before the end of the promotional period. 12-month lines of credit don't come for free, and if the expected average payoff wasn't worth it, credit card companies would probably stop running these promotions.)
Klarna offers a variety of payment methods. The 30-day factoring looks fine (3% charged to the merchant, no interest to buyers). But as far as I can tell, any financing they offer beyond 30 days comes with significant interest. Their product page for Ratenkauf [1] says "Es fallen Zinsen an." ("Interest is charged"). When I look at their demo store [2], they indicate a 10.43% APR for a €400 purchase paid over 12 months. This, of course, falls on the right side of the law and has a pretty small risk of ruining people -- still, I don't think there are many scenarios where you'll end up better off after paying 10% interest on anything.
[1] https://www.klarna.com/de/verkaeufer/produkte/ratenkauf/ [2] https://www.klarna.com/demo/de/de-DE/kp/p-sunglasses-de/. You'll have to add the sunglasses to your cart and proceed to checkout.
Until that happens, I'll take the 5% cash back, since it is preferable to 0% cash back while paying the same price.
Which, coincidentally, is the benchmark for "decent" credit card rewards.
Some cards will offer rewards on certain kinds of purchases, often up to 5%, but offering only 1%, or nothing for other purposes.
Since the average person only has a single credit card, the majority of cardholders produce more in interchange fees than they collect in rewards.
There's also some complicated accounting voodoo that I don't truly understand, that effectively means that banks can treat extended credit as a pseudo asset, plus, whenever alone is outstanding, it's value is added to the virtual money supply.
It is possible for an individual customer to get significantly more in rewards than interchange, but as this is a relatively small portion of customers, most issuers do not seem to care.
Every great once in a while I will run into a small business that doesn't take credit cards, or offers a discount for cash. But it's quite rare.
In the US, I'm sure people would scream and cry if the evil government tried to take their 2% rewards, even if it meant 3.5% lower prices. We don't like math very much over here -- as this thread is proving.
The merchant costs for processing the purchase of those products is baked into price though. The net effect is that the fees the merchant pays push your retail price up. You're not really getting a benefit if you get 2% back and the retail price is 2% higher to account for the merchants processing fees.
In the end, aside from the complicated consumer reward part, the amount that the credit card companies get isn't that different from the European system.
But the customer pays the merchant. It's all paid by the customer.
However actual businesses have overhead for dealing with physical cash as well. It is slower at the teller, needs to be manually counted and recounted, transported (sometimes with security) and so on. It is not clear whether real costs of handling money are greater or less than merchant fees.
If you don’t have any record: Great for Schufa, bad in the US.
There's a catch-22 if rules are so strict so that you can't get credit because you haven't had credit before, but in general "positive" credit reporting seems pretty beneficial.
I get that the flip side is the above can suck for businesses if consumers file bogus complaints but as a consumer I’m going to take advantage of every tool at my disposal. If I had paid with a debit card it would have been a big mess to fix.
This is quite humorously illustrated by a "That Mitchell and Webb Sound" skit: https://www.youtube.com/watch?v=CS9ptA3Ya9E
This. "Identity theft" shouldn't be a term. There's already a term for what's happening, it's called fraud, and it's perpetrated on the banks without involving the person whose identity was "stolen." Consumers shouldn't have to deal with the fallout from banks' fuckups, especially given the resources banks have available to avoid said fuckups.
This account would be able to attach a featureless debit card (using our national standard payment system "DanKort"), and have the same interest rate as the national Bank (so for now, slightly negative).
Employees of the national bank is already able to get accounts like this. So there is precedence.
This is obviously not a particular attractive not sophisticated "product", but it is awfully hard to hurt yourself with, and will have all the functionality that allows you to function in a modern society.
Make banking a choice, and force the banks to make sufficiently attractive products to convince me to participate willingly.
Actually quite some interesting thoughts within this book.
How does “giving everyone an account in the national bank at birth” correspond to making a choice? How about, instead, you give people the option to open an account with the national bank? That sounds more like a choice.
Instead, I have spent 6+ hours on the phone with them over the last 3 months. I have faxed the requested information 3 times and mailed it once and nothing has been resolved. I've given up. I recently had to have my credit checked for home purchase and I simply told the lenders that I would not be working with them if they could not use Experian or Transunion to verify my credit.
The most insanely infuriating thing about all of is was that when Equifax got hacked, I immediately froze my wife's and my own credit with Equifax. At the time, they required you to create a unique 16 digit key to manage your freeze. They have apparently done away with that, so even though I own the key and can give it to them, it means nothing to them. My wifes account has no issues.
My account will be frozen for life at Equifax, I don't care to waste any more time with them and I the credit system in the US with a passion.
I’ve never been lucky enough to be compensated with such a service. But it wouldn’t surprise me if they were so helpful that they even auto-enroll you in another (paid) year at the end of your free trial!
One also wonders why reforming the credit bureaus is not a bipartisan priority in Washington. Congress is apparently only interested in fighting over the issues that nobody can agree on. Don’t hold your breath for any progress fixing systems that anyone except a lobbyist can clearly point to as broken.
The problems might get some attention if the corporate media chose to hype them, but guess who buys a bunch of advertisements on their news channels?
And one solution might be to simply create a statutory strict liability of $1000 per consumer per breach. The (possiblity of) class action lawsuits would do the rest to encourage correct behavior.
(It might encourage cover-ups as well, but you could penalize that, and incentivize and protect whistleblowing and well-intentioned security research.)
The problem with these situations is that liability would induce bankruptcy by a factor of a thousand. If one of these companies screws up, likely they did so for each of their customers, who each have their own customers. Plausibly millions of people, for vendors that aren't exactly Google-sized. So for any non-trivial damages they're out of business and you get three cents on the dollar of your indemnity because so did everybody else. Which is all but worthless. It doesn't even give them much incentive to not screw up, because they're only paying 3% of the damages before they file bankruptcy and start over, which itself only happens if they're unlucky. Plenty of companies would be willing to take those odds and they'll still be the ones with the lowest price.
The only way for them to cover the full amount is to buy insurance, but then you have the liability on the wrong party again and they lose the entire incentive to avoid screwing up. We might like to believe that insurance companies have some magic to reduce claims, but mostly they don't and they just spread the cost of the liability across all their customers.
So really all you're asking for is a law that forces you to pay extra in order to buy insurance. But can't you already buy insurance from an ordinary liability insurance company instead of the vendor?
Then you're hoping that the insurance company's checklist does more good than the overhead in enforcing it costs.
Those type of guidelines generally fall into three categories.
The first is the ones that are sensible and cost effective, but mostly those are the ones that everybody does regardless. You might marginally increase the number of people who do these things. This is where the possible benefit comes from.
The second is the ones that are just ridiculous nonsense. Things insurance companies require because they're fallible entities. The typical "install antivirus on Linux servers" checkbox. It has no benefit but it has a cost and the cost offsets the benefit of the useful measures. The insurance company has minimal incentive not to do this, especially if insurance is required by law, because the cost is being paid by somebody else.
The third are measures that are marginally effective but not cost effective. They do a little and cost a lot. Insurance companies love these because they do marginally reduce the number of claims and the cost is hidden, but it still gets passed on to the customer (you), and the cost exceeds the benefit. It's a deadweight loss to you but the insurance company has a perverse incentive to require it.
When you put them all together you're lucky if you break even.
For example, take an action which makes everybody spend an hour of their time. Disposing snail mail for example. Lets say there's 300M people in USA. Lets say only 100M of them are affected. Lets also be charitable and say that an hour of their time is worth $10. That's a 1B damage right away. It is a Fukushima level damage.
I don't have a solution, but it is disturbing that we allow actors capable of causing such damage just go do their business, take risks, and if risks don't work out - just file for bankruptcy and suffer essentially no consequences
Some of these have decent solutions. We want people to recycle aluminum cans, so we have a deposit which you get back when you take the can to the recycling machine. If you're too lazy to do that, now it's a means for the homeless to make a buck, you don't get your deposit back, and the cans still get recycled.
For other things the solution isn't obvious. You could require anyone who wants to operate in these industries to post a massive bond of their own money to pay the claims if there are any, but that's just asking for market consolidation. You end up with an abusive monopoly or possibly even nobody willing to offer a product in the market at all. The cure is worse than the disease.
In some sense what you need is the opposite. If there are a thousand competitors then there is no one company who can breach a hundred million users. Moreover, there is plenty of competition, so companies that get breached have to worry about reputational harm and customers switching to a competitor. Then you would expect the companies with good long-term records to take over.
And then we're back to the problem with credit reporting agencies. The problem is that the victim has no way to opt out of the system.
One solid solution would be to eliminate social security numbers whatsoever and otherwise put them out of business. The entire credit system is just a zero-sum bidding war anyway. Making it harder for everyone to get credit only reduces the bidding war for housing and makes it more affordable to everyone.
It struck me how reflexively cynical I have become, that reading this question surprised me.
I hope my answer doesn't come off as snarky, but sincerely, there's a lot of good information here: https://duckduckgo.com/?q=credit+bureau+lobbyists&ia=web
This is a classic “concentrated benefits, disperse costs” problem that is really hard to solve in society. The three credit bureaus have a huge incentive to maintain the status quo, while millions of people have a small incentive to change it. The three credit bureaus are going to fight a lot harder to maintain the system than everyone else will fight to reform it.
It is the same thing you see with our tax system. For individuals, it just isn’t worth it to try to change the system. The effort would cost more than the gain, but the overall cost to society is great.
> The best part about this lax authentication process is
> that one can enter any email address to retrieve the
> PIN — it doesn’t need to be tied to an existing account
> at Equifax. Also, when the PIN is retrieved, Equifax
> doesn’t bother notifying any other email addresses
> already on file for that consumer.
Hang on, so the attacker doesn't even need to break into somebody's email account first, they can just guess the questions and put in their own email address?! This is insane.I don't know what the best solution to this will look like, or if society will ever try to implement one. A lot of people are against having a Federal ID. A private solution will have its own set of problems.
The good news is, its the responsibility of the place that's issuing the credit to do due diligence of confirming an identity. If someone steals your private details and gets approved for a line of credit using them, life will suck for a bit while you sort it out, but you'll never actually owe that money (no matter what the debt collectors tell you).
https://billhunt.dev/blog/2020/12/18/federal-policy-recs/#4-... (“Federal IT Policy Recommendations: 2021-2024, 4. Solve Identity Once and for All”)
(disclosure: I am not Bill, just running with their recommendations)
An personal example I had a few years ago was signing a cellphone contract online. The postal employee delivered the sim card after verifying my identiy at the door (you can't get phone contracts without ID around here).
For the higher levels one has to go to the postal office, and it includes a bit more paperwork. These are only used for higher sums, mine was for a bigger leasing contract for my company.
Changing the law to require that banks prove beyond a reasonable doubt that they entered into a contract with you. The burden should be on the bank/creditor to prove that they extended a line of credit to you. It shouldn't be up to you to prove that you didn't.
I mean, imagine if you could hold any company liable for fraud if you received a phishing email that appeared to be from them.
Even the phrase "identity theft" is a misleading attempt to shift the blame, as humorously depicted in this Mitchell & Webb comedy sketch: https://www.youtube.com/watch?v=CS9ptA3Ya9E
You want a line of credit? You have to go into a physical location, get photographed, maybe a fingerprint scan. Ideally, we centralize the data.
This serves several goals: 1) It provides a huge resource bank for fraud detection. On the small scale, you can flip the records to law enforcement as soon as someone says that their identity was stolen. On a big scale, you could identify serial fraudsters-- if the same guy applies at 12 banks under 12 names, a red flag needs to go off as soon as he steps into bank No. 13.
2) It makes applying for credit a serious, conscious thing that discourages frivolous use. The Klarna/Affirm style "instant credit" disappears. I think there are many people who will be better with their money just because of the shame of going into a bank and admitting they need another credit line.
3) You have an opportunity for direct intervention. Applying for credit may be a crisis signal-- maybe te guy taking your picture has some basic training and guidance to ask "are you undergoing financial abuse by a spouse?" or "you know that you're buying into a classic 419 scam?"
My friend did this. We made a bet. I called his bank and, when challenged for the answers, laughed and said I'd mashed my keyboard and that it's all gibberish. I got through and won a free drink.
Like if they ask for a city, then give a city. If they ask for a name, give a name. Etc.
Yikes.
Big bank?
If the bank wasn't able to view the answers in plain text, the security questions would not be able to serve their intended purpose.
Security questions are not a password.
The theory behind this implementation is that probably no one other than you knows what the amount of the mortgage you took out in 1999 is or the size of the car loan you took out in 2015. So in theory it confirms that you are the person who the credit report belongs to. In practice it gets tricky because there are plenty of people who have super boring credit files (e.g. they only have a credit card and have never had a loan). With that kind of user you end up in the situation where the questions either ask about information that can probably be gleaned from public records or the answers end up being “none of the above.” For those users specifically it is a pretty useless solution. I remember signing up for Credit Monitoring and thinking that anyone with a passing knowledge of my life could answer the questions.
It turns out that verifying that someone is who they say they are without needing to see a valid ID is a hard problem to solve.
Is it a great solution no, but before data breaches became so common it was a somewhat reasonable solution. In today’s world though I would agree that it is a pretty terrible solution, but I don’t know how you would solve that without requiring notarization from a trusted third party that the person is for sure who they say they are.
There's a reason they tell you to never use an ATM at DEFCON...
One of the three removed the freeze by me just calling and asking, never providing a PIN.
One of the three was alright. I set the PIN to something of my choosing. I had to call, provide all my info and then the PIN to remove it.
The state of credit freezing across the three big companies is an absolute joke.
Unless, that is, you subscribe to Experian’s heavily-marketed and confusingly-worded “CreditLock” service, which charges between $14.99 and $24.99 a month"
It's great to see theyre taking the knowledge that being hacked doesn't matter and putting it to good use
However, all the information I was providing to set the alert, or remove it, is the exact information that any lender would receive on their application. The system if so horribly broken security-wise, I am shocked there aren't more accounts being opened left and right by people who got them from applications emailed to thousands of lenders over the years.
Reputable lender is something like an honest car salesman. Often consumers deal with middlemen and brokers that aren’t bearing the cost of fraudulent transaction.
Isn’t it what partially what caused financial crisis of 2008? Loans were given to people with no income and one, two or even three existing mortgages. Everyone’s incentive was to earn the commission and sell it further misrepresenting low grade bonds as high grade.
Am I wrong?
I'm, to put it mildly, not happy, and I've no confidence it's not going to get reset again tomorrow.
Yes, I use a complex randomly generated password.
They do send an email to your previous address on the account notifying you of the fact though, which is the one silver lining.
And a lot more than the credit bureau know those two pieces of information.
Honestly, the US really needs a government run public key ID service. The government in providing passports and drivers’ licenses is already doing identity verification. If along with your passport they would allow you to register a public key that people could use to verify your identity, it would be a huge help.
"Starting October 1, 2021 (originally scheduled for October 1, 2020 but was postponed a year due to a global coronavirus pandemic[6]), every air traveler will need a REAL ID–compliant license or another acceptable form of identification (such as a U.S. passport, U.S. passport card, U.S. military card, or DHS trusted traveler card, e.g. Global Entry, NEXUS, SENTRI, FAST) for domestic air travel."
Apparently the government is gravely concerned that terrorists might fly from Boise to Twin Falls, so we need to make them generate at least 3 to 4 forged documents, to force them to get the super duper secure drivers license.
I'd go find links on RealID, and the resistance to that, but it should be an easy query away. RealID made it the responsibility of the states, and people still didn't want it. As I understand it, mainly because it was just a proxy for a federal ID.
In Europe, it's common place to be able to subscribe to loans, or similar contracts online. However, the legislation is VERY strict about requiring very tough MFA-authentication.
Say for example you would want to subscribe to a new credit card. You would either have to go personally to do it (which means they can verify your identity), or you can do it from your Online portal. HOWEVER, if you choose to do entirely online, you HAVE to use your phone as a 2nd factor to authorize the operation.
I'm not saying there's no identity theft. There absolutely is. But they are extremely strict about authenticating each and every (considerable) move.
I guess what I'm trying to say is, a PKI for the US. government is not necessary (in fact, given the time and resistance it took to deploy SECURE ID, I'd say it's dead in the waters right now), and would only require legislators not in the bed with credit card companies, to setup and enforce strict rules for authenticating orders / proceedings.
Passports have an rfid chip inside them that does something like receive a challenge and respond with a signature over a hash of the passports biographical data combined with the challenge, along with the public key corresponding to the signing key, and a certificate signed by a government key to confirm the signing key is legit.
The government public keys are published, so anybody can verify that someone who claims to have possession of a particular passport really does. The weak point is that as far as I can tell the revocation list is not public, so you can't distiguish between a stolen and not stolen passport.
The reframing of the banks being defrauded as the problem/theft of the "identity" of the name mentioned by the criminal when defrauding the bank is a pretty creative and slimy way of a bank de-risking themselves.
Someone didn't steal my identity. Someone took money from you claiming to be me. That's a you problem, not a me problem.
This is quite humorously illustrated by a "That Mitchell and Webb Sound" skit: https://www.youtube.com/watch?v=CS9ptA3Ya9E
But still, it does manage to get abused. Unfaithful relatives / spouses / colleagues / etc. can manage to get hold of your password and device, take out loans or buy stuff, and you're 100% in the jam for it. We get cases from time to time where people are basically held accountable for hundreds of thousands in credit/consumer debt, because someone used their signatures to take out those loans. And probably 99 / 100 times, they lose in court, against the banks.
The banks will argue that if they were held responsible for such actions, the modern fast-tracked system would halt to a grind. It'd be like in the old days where you needed to show up in person, with all your financials, and carefully go through everything just to get a small-ish loan.
Same for withdrawals. Some couples will use individual accounts as a convention but they are each entitled to drain the other’s, whether or not their name is on it.
In response to your comment, I think that the Norwegian system is inferior in the respect of the end-consumer having the final responsibility. I think that if the bank had final responsibility for any credit fraud, the fast-tracked system would hiccup perhaps, but not grind to a halt. Fintech is evolving rapidly and a new innovation could satisfy both fast banking and keep incentives correctly aligned between banks <-> consumers.
The same company, which may at times make false claims about you, is in possession of a service / technology they claim can detect those false claims.
Why is it not libel when these companies make false claims about me? Especially when they advertise that they have the ability to detect such false claims? "Pay us and we will not make false claims about you" they say. "Pay us and we'll double check with you before making claims we believe to be suspicious about you."
Freezes and thaws are free. Your credit report, and any scoring mechanisms (FICO), should be available to consumers at any time free of charge. Credit monitoring products should be outlawed. Failures to safeguard citizen data (Equifax) or to promptly remove inaccurate data should incur steep financial penalties.
[1] https://www.govtrack.us/congress/members ("Use GovTrack to find out who represents you in Congress, what bills they have sponsored, and how they voted.")
Any solution must suck less than current government and private credit reporting agency systems.
[1] https://www.hud.gov/program_offices/housing/sfh/caivrs ("The Credit Alert Verification Reporting System (CAIVRS) is a Federal interagency database that contains the following: Delinquent debt information from the Departments of Housing and Urban Development, Agriculture, Education, and Veterans Affairs and the Small Business Administration.")
Sidenote: The above systems is ripe for overhaul by the US Digital Service. It is a pathetically old mainframe system with limited operational hours (and takes federal holidays off), when it could be a PostgreSQL database (or similar relational db) with an API.
Once upon a time governments in places with credit reference agencies (so particularly the UK and US for this story) noticed that this is a lot of power with not very much responsibility and they ought to fix that. So what they said was, you must let people see this data you know about them, for a small statutory fee. No option, that's what you have to do now if you want to stay in business.
This actually terrified the CRAs, because they imagined everybody is going to send off their fee, and it costs more for this enormous unwieldy corporation to respond than they're allowed to charge, so if everybody does this the company goes bankrupt.
But internally at Experian somebody says - Aha! The law doesn't require us to explain what the credit data means. So if you pay your fee you will get stuff that's incomprehsible to lay people not because we're deliberately obfuscating it, but because to us maybe "day 60 late ratio" has an obvious and very specific meaning but to a consumer it's noise. Obviously an expert could write a book about how to decode the statutory report, but we can instead offer a product that costs more than this fee but includes friendly explanations and translation. If we set the pricing right on this product, we make a profit while also warding off the statutory reports we dread.
And that project actually worked. As of ten years ago lots of people worried about their credit would cheerfully pay a CRA money to find out what the problem was. The division doing that grew enormously within Experian and other CRAs copied this idea.
In fact popular culture made things that didn't exist in one country (e.g. the numeric FICO score from the US) part of what consumers expected to learn in other countries, and so Experian UK actually has (or had when I worked for them) people who make up the formula for an arbitrary score number, even though creditors in the UK don't use this - so it's as meaningless as your Hacker News "karma" score.
Then somebody had another bright idea, what if we give this product which apparently people value, away for free, and then for a fee attach it to credit offers like new credit cards? We funnel card companies the exact customer profile they were looking for, they save acquisition costs, the customer gets the new credit they wanted, everybody is happy and we're richer. So that's what happens today.
Checked your credit lately?
IMMEDIATELY view the information contained in your file
Get it straight from the source
View information that is already available to lenders, insurance companies and prospective employers.
Secure on-line access for 30 days
Easy to read, "navigable" format
Only $8.00!!
Furthermore, adding more regulations and more requirement fixes issue short term, but does not address it long term. Even if regulations you suggested are enacted, I am afraid that it won’t take long until they are misused, abused and misinterpret again.
Rather than adding more requirements or stipulating more penalties and burdening regulators with defining right security protocols and mechanisms, it should be reworked into something that allows more competition and more control and forces bad actors fail fast and be replaced. Also it should be actionable at the consumer level.
My ideas are: 1. CRA must explicitly get permission from a person to keep their financial history. 2. Consumer has a right to “be forgotten by an agency” and the agency must abide within, lets say, 30-60 days. Also a said agency is required to send the customer or another agency of consumer choosing an authenticated copy of existing credit history. Similar to phone number porting. 3. Collateral. CRA must maintain a collateral fund to be used to pay penalties to consumer in case their information gets stolen. The size of the fund is a function of number of consumers the agency is keeping history for.
It does make it harder for new players to enter the market, but on the other hand: - they have something to risk - security evolves, and consumer pressures would make CRA evolve their system as well. If a CRA uses md5 to hash password, get hacked, first, they will loose money in their collateral fund, second, consumers will leave them and they essentially be out of business.
If you could fix a bad credit score by wiring Experian $50, that would be extortion.
Something they know is potentially dubious is negatively affecting your score but you need to subscribe to their service to have it actively reviewed.
This is a cost center for them, not a profit center. Their core business would be compromised if you could just bribe them to fix your credit score.
Isn't that just a protection racket?
"Nice credit score, it would be a shame if something happened to it."
I've sat in on calls from consumers to a CRA when I worked there. The typical thrust of the call is that the caller believes they are a good person and so the records of them doing stuff creditors won't approve of should be purged, the CS agent explains that they can purge anything if the consumer sends them proof it is wrong, for example if the record says somebody went to County Court and secured a judgement against them for £800 then a letter from the court saying "Whoops, our bad, we wrote Michael Smith, 43 from Leicester in this judgement but we meant somebody else entirely" will get that erased from their record. But just calling and moaning about how you really wanted to buy a new car but your credit is bad doesn't change anything.
I didn't see any sign there was a way to short cut any of this by paying for credit reports. I guess if you don't remember all the times you didn't pay your bills then a web site that lists them is handy? But that seems like that's on you.
I actually had reports from all the big CRAs in my country, and the best ones (with the most comprehensive coverage, so, Experian, who also happened to be my employer at the time) basically just say this guy seems to pay for some basic utillities and he pays on time. And that's it. The worst ones are like "This guy exists, and we don't have good data so shrug".
The best way to begin "fixing" your credit? Which all of these companies will recommend, but it's no big secret at all? Register to vote.
Creditors prefer to lend to people who actually exist. Governments don't want people who don't exist voting. So register to vote and immediately confidence that you're actually a real person, with a postal address, shoots up.
The next step is easy for me but apparently lots of people find it almost impossible. Pay bills! Got a phone? Agree to pay the phone company to use the phone and then... actually pay them for it. Again, your credit worthiness shoots up because creditors want to get paid, and showing you have some idea how to actually do that part is a good sign.
Now, if you're trying to persuade somebody to lend you Ferrari 488 money on a Fiat Uno income, those two basic tips won't get you there. You're going to need to learn how to manage exactly the right levels of debt, what's recorded and what isn't, lots of tricks. But I assure you that you aren't going to learn that stuff by paying a CRA, because it's like learning how to clip out of bounds in a video game, the designers of the game don't even understand it well.
If you suppose that paying for credit monitoring will cause them to catch mistakes somehow, you'd need to show that.
If your assumption is that the CRAs don't care about mistakes unless you're paying them you need to think again, the value the CRAs had before any of this existed was that they could give a lender valuable intelligence about whether you might pay them. Lenders pay them for that, if the intelligence is often bogus the lender is wasting their money.
Is that not the value proposition of credit monitoring?
Which is the exact same as what the law already requires (if you ask, free once per year in the US I believe) them to do, but of course the law doesn't require a snazzy web site with animated dials and explanatory videos.
If you're the sort of person who found it easier to get a few hours of exercise every week once they had a device telling them "You've only done 14 minutes of exercise today. That's not on track", then a credit monitoring service might be just the thing you need to actually pay off those cards on time and get your credit back into shape. But if you didn't buy that Fitbit, but did the same exercises, you'd get just as fit - and if you didn't buy credit monitoring but looked after your credit you'd find it easier to qualify for more credit.
So, having the monitoring might cause you to catch mistakes somebody made, and if you do you can inform them of the problem and they'll fix it (if you have documentary evidence) but it doesn't really change their actions compared to people who don't buy monitoring.
If you're thinking, wait, then why do they give you free credit monitoring when a big company loses your data? The answer is, because CRAs had existing sales people in those big companies, and when the big companies wanted to buy something to give peace of mind to people whose data they'd lost, "free credit monitoring" was on offer. Selling them something that actually helps is trickier, and what does it really mean exactly to actually help anyway?
I worked on a product like that, but it wasn't an easy sell. And for most users it seems exactly like it doesn't do anything. Like owning a Carbon Monoxide alarm. It seems to be working, but it doesn't actually go off, because you don't actually have a Carbon Monoxide leak, so... It's unclear what the online equivalent of the reassuring "I have power and am working" LED is, let alone the "Push to test" button. But outfits like Experian are aware that some kind of actual "Do bad guys actually have my stolen data and if so what do they have?" service is a better fit for those "data loss => free credit report" scenarios which is why they acquired the company I worked for when we were doing this.
> Originally and often still specifically, racketeering refers to an organized criminal act in which the perpetrators fraudulently offer a service that will not be put into effect, offer a service to solve a nonexistent problem, or offer a service that solves a problem that would not exist without the racket.
Since I’m seeing a lot of confusion about how credit reporting is done and how credit monitoring services work let me break it down a bit. Let's say you are getting a new credit card with Chase Bank. When you apply for that credit card Chase does a hard inquiry on your credit report to decide if you are elligible for that card and what credit limit they are going to give you. If they then issue you a card they then report to the credit bureaus that you opened a new line of credit with them and the limit on that line of credit.
If you have credit monitoring you would get 2 notifications. You would get a notification that a hard inquiry was made on your credit report and a second saying a new line of credit was issued to you. The point of credit monitoring isn't for the bureau to catch mistakes but for you to be aware of activity that could negatively impact your credit score. The bureau has no way of knowing if something was legitimate or not since they only have the information that was reported to them. Credit monitoring does however let you know something major happened to your credit which means you now have the ability to respond to that knowledge.
There are 2 important things to remember, all 3 credit bureaus are legally required to give you 1 free credit report per year at your request. You can get it online from https://www.annualcreditreport.com/index.action or the FTC has instructions https://www.consumer.ftc.gov/articles/0155-free-credit-repor... if you want to request it by mail. I have heard a lot of people suggest that consumers should space out requesting the 3 free credit reports so they get one about every 4 months and use that as a form of credit monitoring. It isn't completely fullproof since lenders aren't required to report to all bureaus so something could show up on only 1 report and not the other 2. The second important thing to know is that bureaus are legally required to allow consumers to dispute items on their credit report. The FTC has a sample dispute letter you can use to file a dispute, but some if not all of the bureaus have ways to file disputes online. As someone else in this thread mentioned these disputes generally require some sort of evidence that the reported item is incorrect.
So say I get a credit monitoring alert that says my address has changed because some creditor reported my information incorrectly. Regardless of any other steps I should get that resolved with the creditor because it will probably keep causing issues. But I could then file a dispute with the credit bureau(s) saying that the address is incorrect which would probably require a bill or something to prove my current address (similar to how some state DMVs prove you are a resident).
I feel pretty sure they can probably pinky-promise that they really are inquiring about the right person and still do at least a soft inquiry.
- Every single one is answerable by reference to my Facebook page and a few old area phonebooks [remember when most people used to list their name, phone number, and home address for the world to see? ah yes. good times.]
- And they usually tell me I'm wrong, which would make me suspicious that I was a victim of identity theft, except that the answers I give usually match the data in the report I eventually receive.
I fill them out, screenshot the form and keep that screenshot in an encrypted file that I keep backups of. Not even text searchable that way.
Also completely ridiculous I have to do any of this.
Ah what?
Total mess and they seem to have little to no incentive to fix/improve anything
> Minors are attractive targets for identity theft. Because they’re young, they have clean credit reports, and most don't discover the theft until they reach adulthood.
https://www.buzzfeednews.com/article/leticiamiranda/what-hap...
Children Credit Freeze Pages:
• Equifax - https://assets.equifax.com/assets/personal/Minor_Freeze_Requ...
• Experian - https://www.experian.com/freeze/form-minor-freeze.html
• TransUnion - https://www.transunion.com/credit-freeze
Source: https://www.nytimes.com/2018/12/28/your-money/credit-freeze-...
Oh well, the other agencies unlock so it just takes a little talking whenever I need to run a credit check explaining equifax is jacked up.
I am pretty confident he or she is not going to maintain a list of acceptable passphrases left by former tenants for the purpose of authenticating credit check phone calls 10 years later.
> We help you store all your financial data, including your free credit reports, in your secure vault. When you control your data it's easy to make the right credit decisions and get access to the best offers.
I think they meant that they want to store "a copy of" all my financial data. That's one more copy. How do I control my data in this scenario?
Edit: Changing from SV to startup.
Remember - you're the product, not the customer of the credit agencies. You aren't a first party in that relationship - it's a service about you, not a service for you - which is why the agency's interests are not remotely aligned with yours.
The only way to make it aligned with yours is through regulation, which forces your concerns to be taken into account. Unfortunately, in the valley, that's a dirty word.
Because there's a lot of barriers to entry to collecting your financial data, and any industry with lots of barriers to entry, the costs of which are lessened at scale will result in a monopoly, or duopoly, or something of the sort.
> Why are they privatized?
Because we don't have any laws against them existing, and they are providing a valuable service to creditors, landlords, and employers.
> What are the checks and balances to keep them incentivized?
There are a few legislative ones, but there aren't really enough of them.
Experian offers a boost product where you authorize them to monitor your electric bills, etc ..once I did ... gave them permission to do so my Experian credit rating went up to the same number (a point or two off) then the other two. What a racket!!!