Until companies are held accountable for the negative externalities they are causing, this won’t end.
Until companies are held accountable for the negative externalities they are causing, this won’t end.
The law shouldn't be that someone else has to pay the costs, the law should be that you tell them to prove it was you that acted to open an account and they go pound sand if they can't do that.
> Libel is a method of defamation expressed by print, writing ... that is injurious to a person's reputation, ... or injures a person in his/her business or profession.
Might even be able to get punitive damages.
https://www.law.cornell.edu/wex/libel
Note, the person who "had their identity stolen" (that phrasing is an absurdity, twisted language designed to obscure and defraud the truth) was never a party to the deal. The only parties relevant here are the bank and the person that defrauded the bank. The only victim is the bank. Nobody here is arguing that this problem doesn't exist for real people, we're saying that it's insane that it even exists at all.
> (e) Limitation of liability
> ... no consumer may bring any action or proceeding in the nature of defamation, ... or negligence with respect to the reporting of information against any ... person who furnishes information to a consumer reporting agency ... except as to false information furnished with malice or willful intent to injure such consumer.
Sure, but I meant if they're reporting you to a credit agency for owing money or whatever. That is them publishing false information about you that will have negative consequences for you.
If a bank extends credit to someone without doing their due diligence, they’ve definitely been defrauded but that’s between them and the crook, not the person the crook was claiming to be.
Nordstrom was the only proactive party they called me immediately when they noticed someone filing out a credit card application in another state.
Unfortunately, the US government doesn't take identity theft seriously from a criminal prosecution perspective. At least not when it's affecting regular Americans.
More than 20 years later, I still have to pay for credit monitoring services because sometimes I’ll see stuff from the 1990s resurface and I have a backlog of documents that I have to deal with to get stuff straightened out.
When I moved to Seattle a few years ago, suddenly my credit report was empty. As in totally blank. I didn’t have any open credit cards at the time (personal choice; I’ve sense had a change of heart and have embraced trying to use credit cards to my advantage, always paying them off each month), but it showed nothing. Which was weird for a person in her 30s. This made renting an apartment difficult, despite having nearly double the required income. It turns out, when removing false claims off the report for the umpteenth time, everything was erased. I eventually got that sorted out but I still have no idea if my credit report is actually accurate, except that my score is in the 800s now thanks to said credit cards.
The only upside is that I’ve become so desensitized to the entire process that every time Equifax or some big database is hacked, I’m almost blasé about it. I’ve gone through this so many times, I know the drill. I know the time sink. I know the process. Whatever.
But insurance doesn’t solve that. It’ll cover the cost of the monitoring services and maybe some legal costs in the event you have to actually take something to court, but it won’t recover the time you have to deal with the insurer or the agencies themselves. In fact, I’d gladly pay a fee if it meant that not only would my shit be monitored, but someone would sit on the phone and submit all the paperwork on my behalf. Because that’s the part that is the most infuriating.
Being poor is incredibly expensive and exhausting.
That argument would only make sense in the U.S.
But I believe there are also lots of well-intentioned but bad regulations, and so they need to be considered carefully!
I don't think I accept that premise.
My argument is that the party that can actually do something about the fraud is the one that should feel the pain of dealing with it.
It's likely possible to quantify the effects, regulators could do that and strike a sensible balance between security requirements and so on.
It may harm the rich the most, in my opinion, since retailers wouldn’t as easily be able to trick you into a new credit card as part of the checkout process.
Poor people are more often in less stable living situations and it's easier to lose track of documentation. Not to mention unhoused people who don't have a safe place to keep track of things either and often don't have up to date identification in the first place. Also, with less access to the internet to do things remotely it's more common to need to take time off work to go to a physical branch which may be very far away, requiring taking multiple busses just to prove their identity.
Of course adding more security is important, but it has tradeoffs like this that harm the poor that need to be considered.
Going even further, nobody would actually complain if someone hijacked their identity and improved their credit score with good behavior!
This is probably much more common than people being framed or having issues proving their identity.
This falls under the general heading of "remote attestation" technology (as the person I am replying to probably already knows).
new account is in person only
Imagine a world where banks have to pay you for identity theft protection so that you're more "diligent" about not going to phishing websites.
That being said, none of the compromises described in the comment chain thus far required action on the part of the consumer; they all involved compromises of third-party companies. Like T-Mobile.
Since all those false reports ("identity thefts") are never willful on the part of banks and other lenders, there is almost no penalties that can be brought. The consumer bringing the most reasonable charge of libel against a credit bureau is specifically prohibited by this law, if the credit bureaus follow all of the rules (allowing people to see their reports, removing false info (good luck with that), etc.). If not a case of regulatory capture at the time, then at least this law needs to be updated given how important credit reports have become, how easy fraudsters can get your report tarnished, and how hard it is to get your reports corrected.
The only reason identity theft is a thing is because federal law[1] doesn't allow consumers to sue creditors or credit bureaus for inaccurate information about the consumer unless they were doing it out of malice.
If the law was changed to allow consumers to sue them for damages, you can bet that they will be far more diligent in verifying the identity of the person they're entering into a contract with.
0: https://help.id.me/hc/en-us/articles/360061369314-How-do-I-t...
Credit reporting agencies and financial service providers should be required to use a government provided identity provider (Login.gov is getting there; it’s currently only offering identity services to federal agencies and select state and local governments) or in person proofing with government IDs to verify identity. If they don’t, they are entirely liable for the transaction(s) and related losses, instead of rolling the dice with security question voodoo and foisting the liability on consumers.
Solve digital identity and you solve identity fraud.
There's absolutely no reason why banks can't do something similar (actually more stringent) when extending a line of credit. The PATRIOT act in the US requires banks to verify the identity of those trying to open an account or secure a mortgage loan, so requiring something similar for lines of credit shouldn't be out of the question.
The root cause of the issue is the law I referenced in the comment[1] that started this subthread. If consumers were able to sue banks and credit bureaus for false information, then banks would have much more incentive to be more diligent. Right now, they can offer "identify theft protection" service where the consumer has to pay them instead. That doesn't give them incentive to be more diligent, and, quite possibly, has the opposite effect.
That's just good vertical integration.
Banks could easily require one to show multiple forms of identification in person at one of their branches in order to apply for credit.
Are you really just handwaving being able to make fake passports or fake government issued identification cards, as if that is basically the same as just knowing someone’s SSN and a couple other pieces of information about them? What a ridiculous argument. ID cards are required to have multiple security features to prevent reproduction without highly specialized equipment, to prevent altering or tampering with existing cards, and to have multiple ways of detecting counterfeiting or altering of cards. There is no “what’s next” because identification cards are already incredibly secure.
The person I was responding to mentioned "multiple forms of identification". At the moment (and I could be wrong) some of these valid forms of identification are things that can be bootstrapped, faked or social-engineered into getting relatively easily. E.g. municipal bills, driver's licenses, birth certificates issued from hospitals, etc. (e.g. look at here for UK https://www.hsbc.co.uk/help/banking-made-easy/help-us-identi... ). Once you get one of those, you can with effort start acquiring more and more of those other ones. And they would all be 100% legitimate and not fake, which is the crux of the "identity theft" problem, as you can't prove who you are even with real documents as the other person has real ones too! I guess I used the term "fake" in my original response a bit loosely.
Point is, we're skirting around the real issue. We have no "chain of proof" or "evidence" from the time you were born to the point in time that you have to start using your identity for formal things. It's all based on layers and layers of multiple people, possibly incorrectly, "vouching" for you by saying you are who you say you are.
Even with secure identification cards, there is still a huge potential for fraud which happens a lot even in countries that have national ID cards. E.g. https://www.timeslive.co.za/news/south-africa/2020-08-28-hom...
Then, when the “real” person asserted the falsehood of your identity, regardless of your real ID cards, it would still be easily provable that you were not the real person. For instance the real person could have their parents verify their identities and certify that the birth certificate you both have a copy of is legitimately tied to the real person and not you. Unlike now, where you can just walk away from some fake accounts and internet information, there is biometric data linking you to multiple serious crimes.
Is it something that could happen, and probably does? Sure. Is it something that would happen even 1% as often as identity theft related financial crimes happen under the current system? Absolutely not. It feels like the current problem is banks being robbed because they are storing their money in a cabinet next to the glass front door, and you are arguing that if banks build vaults and security systems that bank robbers will just bring huge industrial drills with diamond coted bits to break into the vault over multiple hours while bypassing the security system. Sure, they could do that, but bank robberies will still drop to almost nothing compared to before.
Basically multiple layers of regulation in the form of consumer protection laws that put the onus on businesses to be accountable for what they do. You can't blame the victim for having their identity stolen just because they chose T-Mobile over a competitor, or expect them to fight the case in court (which most people won't do because it's too expensive).
A lot of incidents get reported to the state attorney general offices that the customers reside in, as well, but that is less convenient to keep an eye on since there are 50 of them.
These don't really make the news because there are just too many of them to keep up with. One of my clients recently had to send breach notifications to all their customers and it did not even make the local papers. This is a town of 20k people where nothing ever happens and apparently that wasn't enough to waste ink on.
The takeaway here is that there is infinite work available for security incident responders, if you are looking for a change of pace.
These corporations already expect to have a data breach. They call it "cost of doing business". And USA let's every company do this.
You could get your identity stolen from many different places. Just because your location data was leaked, doesn't mean T-Mobile should be on the hook carte blanche for any identify theft you face in the future.
Can you really not see this leading to massive fraud?
Cell phone companies ask for social security numbers (SSNs) to do a credit check when opening post-paid accounts. Most people don't know any better, so the give out their SSNs. The companies can just delete the SSN after they use it once, but they don't. That should be on them. If I was a company, I would not want to take on any more responsibility than necessary. These companies decided to take on the responsibility, so it is on them.
The “fraud” you imagine would require both that a company is negligent with someone’s data, exposing them to the risk of identity theft, and that the same person is the victim of identity theft in a totally unrelated way or unrelated reason. That isn’t guilty until proven innocent, because it is proven that the company was negligent and did allow data to be leaked. If it makes you feel better, we could just fine them $10,000 for each person’s data that was leaked right off the bat, and then hold that for all future claims where those people end up having their identity stolen.