Scary fraud ensues when ID theft and usury collide
krebsonsecurity.com
krebsonsecurity.com
Even the term “identity theft” is slimy: deftly deflecting blame from the negligent bank, trying to draw an unrelated 3rd party into the mix by nominating him as the “theft victim.”
That sounds nice and all, but what would that actually look like in terms of legislation? Legally speaking you're already not responsible for fraudulent loans, and the onus is on the creditor to prove that the debt was actually yours.
The fix is straightforward: require evidence of the debt upfront, and if you're attempting to collect on debt you can't verify was agreed to by the person you're pursuing, damages are substantial (say, $1M per occurance). Make reporting of violations via the CFPB frictionless.
You will see debt originators rapidly standing up robust identity proofing systems (having customers come into a branch with their IDs), and asking Congress to legislate their implementation (Login.gov and similar for private enterprise, with the end game being a usable national ID system such that Estonia has [1]).
Tangentially, current risk management in this space between identity and finance sucks. I worked with someone to get liens off their Lexis Nexis Risk Solutions report (which mortgage originators use for compliance purposes with conventional mortgage underwriting guidelines as it relates to foreclosures and real estate fraud) that were on their report for almost 8 years in error. It took a CFPB complaint for Lexis Nexis to remove them with citations from an attorney to state statute, and this data isn't classified as consumer reporting, so it's almost impossible to obtain financial recourse/damages for these occurrences.
[1] https://privacyinternational.org/case-study/4737/id-systems-...
[1] https://news.ycombinator.com/item?id=29980189 (HN thread of the above link)
Totally agree.. but sending a debt validation letter is already pretty simple. In most cases you can send the scumbag collector a barely-modified form letter and that’s that. I’ve done this twice and it’s pretty painless, but in a perfect world, I wouldn’t be involved at all!
Banks need to be forced to stop considering
struct {
name,
address,
birthday,
ss_number,
other_public_info
}
…to be equivalent to a person, for the purpose of issuing loans. It’s total madness, and honestly I’m shocked that this kind of fraud isn’t even more common.That and
struct { acct_no, routing_no }
…is enough to withdraw money from my bank account thru ACH! Also lunacy. How are banks allowed to be so crappy?Legislation, plz.
Agree about ACH. The Fed's FedNow instant payment system due out next year should deprecate all that is trash about the ACH rails (switching to a push from a pull model being one of said deficiencies).
By that logic, other things that are antipatterns:
* most laws (do you think "the first 3 people you come across" would know the difference between murder and manslaughter?)
* programming APIs (ie. the trope of programmers having to search up usages for basic library functions)
* most basic life tasks (this can be literally anything. even how to cook. if your parents didn't teach you, and you couldn't search on the internet, most people would be toast).
Personally, I think the chances are much higher of getting a working definition, and toomuchtodo could probably have said 30 people without looking implausible.
At this point, you might be thinking that few don't know the precise definitions of manslaughter vs. murder, but consider this: most people (I suspect) at least have an understanding of the difference between manslaughter and murder, while not having the slightest idea of what sort of responses are available to them in the fraudulent loan scenario. Furthermore, while both probabilities are low, I doubt that the likelihood that your average person needs to know the difference between manslaughter and murder is close to the likelihood for being in the sort of situation being discussed here.
> Most basic life tasks (this can be literally anything. even how to cook. if your parents didn't teach you, and you couldn't search on the internet, most people would be toast).
It never occurred to me, until now, that the human race is perpetually at risk of extinction in one generation for this reason... but has there been one documented fatality, anywhere, at any time, from this cause?
Okay, what about if you want to renovate your house? Is the bureaucracy utterly out of control because you can't legally make modifications to your house without getting a permit from the city? Most people know they have to get a permit, and maybe that they need to go to city hall to get it, but good luck getting a permit without asking someone working there or looking it up the internet.
I suspect the vast majority of people aren’t going to add a major addition to their house without having someone to do the work who knows about permits, or actually knowing about it themselves. It’s like complaining about how few people know seamanship rules when most people don’t own or operate a boat.
In this day and age, is there a meaningful difference between those two? If someone got a call from a debt collector for a debt they weren't responsible for, don't you think they'd know to "look up how to do something"?
You won't even know what to search for if you don't know its something you can do - heck, given certain cultural contexts, you won't even know you can search for "what to do when" X happens.
And that goes back to the earlier point - unless your problem is something low-hanging on WikiHow, commercial/legal construct is such that you probably won't find the answer to your problem, and end up having to "hire an expert", assuming you have the money to do so. So, anti-patterns, yes, absolutely.
Indeed.
Should the average person need to know the difference between murder and manslaughter to avoid getting scammed into a murder charge?
Should the average programmer have to memorize every API they use to avoid creating the next Heartbleed?
And basic life skills is the literal opposite of your other examples...
While I think "legal system that everyone understands" is a laudable goal, there are too many edge cases and "bad" behaviors for that to be possible.
>Should the average programmer have to memorize every API they use to avoid creating the next Heartbleed?
I'm not sure why you modified my original argument. Is having impossible-to-use-from-muscle memory APIs totally fine unless they lead to security vulnerabilities?
>And basic life skills is the literal opposite of your other examples...
in what way? because you assume most people know how to cook? that's because it's knowledge that parents pass down because you need it daily, not because society engineered it to fail safe or whatever.
This is not the issue here. The issue here is whether there is a better way to handle the problem of fraudulent loans facilitated by identity theft.
Are they actually going to get rid of ACH though? It's all pointless if they still have ACH for legacy reasons. Take our EMV implementation. Not only do we have "chip and signature" if the chip fails to read three times most readers just fall back to mag stripe.
Congratulations, you just outlawed uncollateralised lending to everyone but the super rich.
The core idea is sound. But link the payout to actual costs and damages.
Come to think of it, except for medical bills, I really don't know what an uncollateralized loan would be for and which I'd consider a net-positive. And before you come back to me with medical bills: Fix your health insurance system and that problem goes away...
Treat it as you suggest: a KYC/AML failure. Public reporting requirements. Liability to the injured (for actual damages). And, if a pattern emerges, license restriction and eventually revocation.
A $1mm mandatory penalty will force lenders to settle. (Nobody will spend $100k proving they properly made a $25k loan with a $1mm penalty if they’re wrong or unconvincing.) When customers know that, you get adverse selection. That would shut down the market.
I know brothers who share a passport and driving license, and do just one lot of taxes between them.
Tightening up identify verification laws will further exclude these people, and may be a net loss for the nation.
And why would you live under someone else's identity? Isn't it identity theft?
You obviously have no idea what you are talking about. Perhaps "Europe" to you only refers to some rich Scandinavian countries?
In Eastern Europe ID cards are frequently issued solely on the basis of witness statements, fraud is very common.
There are probably hundreds of thousands of "fraudulently" issued European passports in circulation. If you go walk near embassies in Chisinau, you'll be approached a plenty of people offering to help you procure one.
Even the UK has struggled with this https://www.bbc.com/news/uk-58876645
>And why would you live under someone else's identity? Isn't it identity theft?
Because you don't have your own, there are a plenty of Europeans who have never even had a birth certificate (or lost theirs).
Because yours comes with the wrong nationality, a semipermanent black mark that prevents you from seeking normal employment.
I don't think this is a problem at all, the whole concept of borders and citizenships is poisonous.
Of course it's not only Eastern Europe, of course Greece and Italy have struggled with this too.
You have no idea what you are talking about. I am not talking about Cyprus here.
Here's an article describing a small slice of it https://www.vice.com/en/article/akwe34/romania-has-allegedly...
> you might dislike the way its possible to acquire passport
I don't, I firmly believe that this is a good thing.
>Your claim like its s massive problem on the grand scale of things in Europe is propaganda.
I don't claim that it is a problem at all. I'm just saying that you were being ridiculous when you said
> Its time for Americans do the European and developed world thing and use IDs with proper identification methods
Europe is far from having this figured out.
The wider surveillance issue should be addressed with a GDPR equivalent. What bona fide use do they have for knowing my identity and analyzing my individual purchases? None!
FWIW you can usually get the sale prices by asking the cashier to swipe the "store card" or periodically getting a new nym.
Plenty of reasons, some more legit than others, but there are a large number of people in this position.
I really wish that someone would seriously propose a voting reform act which would basically be the national equivalent of “motor voter registration” except for anyone, at no cost, and either with widespread offices or free transportation (to cover the poor, old, blind, etc.). Get rid of every possible excuse for not having ID and then we can clean up so many screwy processes which rely on a patchwork of paperwork to handle different situations, no two agencies with identical requirements.
That’s fairly deep in “the administration doesn’t want to.” territory. Granted, Germany isn’t as sparsely populated as the US in some regions, but for example we have pop-up admin posts. Effectively a bus that comes visit every few weeks, clerks pop up an admin office where you can do all the tasks, including getting an ID card. That’s not unfeasible, even in comparatively sparsely populated regions.
No, it's describing real things which have happened in the U.S. — for example, in 2015 the state of Alabama closed a number of DMV offices in predominantly black counties. They reversed that in 2017 after outcry and some investigations, but it's not like that's a one-time concern which will never go away. Here's a story from last year with similar concerns (note that this doesn't need to be intended maliciously to have an uneven impact):
https://www.pewtrusts.org/en/research-and-analysis/blogs/sta...
That's why I'd like to avoid the issue entirely by having strong legal protections and guaranteed funding. The kind of pop-up you mentioned would be a great solution in rural cases, as would other possibilities like some kind of shared infrastructure with the post office or other government agencies where you could have a trusted third-party take an official picture and seal all of the provided material, etc. The idea would be to pair a voter ID requirement with a guarantee that ID would be free and easily available to categorically remove this class of concern.
If you want to say that ID documents should be something that's much less painful for individuals to acquire (and should be free!), completely agreed.
But the idea that a modern society can function without a safe identification system is somewhat far fetched to me.
Calling this tax fraud is... I guess true, but kind of odd and silly.
Two people making $X/2 will in almost all cases pay more taxes while receiving fewer benefits than one person making $X. If you wanted to pay fewer taxes, you wouldn't use this scheme except in a few strange edge cases. I don't think the brothers are sharing a passport, a driver's license, and tax filings in order to reduce their tax bill...
(Reading between the lines, since you didn't seem to pick up on it: one of the brothers is an undocumented immigrant. The goal is not tax minimization... the two brothers are paying more taxes while receiving fewer benefits in order to avoid deportation of the undocumented brother.)
Quite sure most people, the vast majority of people would rather this be tightened up just for the fact that they don't want to have others living under their identity.
As for brothers sharing a passport, I doubt that these laws would affect them the same way, especially if they're twins and pass for each other. But then, just because they can do so, doesn't mean that they should.
That would force a number of other changes, and I think they would mostly be positive. Those whose businesses depend on high-volume easy credit may disagree.
I wonder if this can be bypassed by a warrant canary (or repayment canary)? Basically instead of having creditors report that you defaulted on your debts, creditors will just report whether you opened/closed a line of credit, and whether you're current on it. If you aren't current, then the algorithm assumes you're delinquent. Since you can't compel speech (first amendment), you'll have a very hard time forcing companies to do something.
Not necessarily a common problem, but this kind of stuff can pop up in surprising ways where the victim is left cleaning up the mess of the financial institutions involved.
It would be very easy to verify and confirm for a bank.
This should be the end of the story. If bank would've been on a hook - they'd look way more carefully on it.
And also on-point, when are management and coders going to realize that much data should be treated as toxic waste and destroyed, rather than kept forever, just in case we might want it?
This guy had an ID theft, prevented it from going forward, but the payday lender had his info in their DB, and so the second time around somehow actually authorized the bogus loan. If they hadn't stored the info from this person who would NEVER deliberately be a customer, the bogus loan would not have happened.
And all that trouble caused so some thief could net a measly $1000.
Only then might we get a financial system which is robust against ID theft. While the costs are externalized to countless individuals, nothing will change.
How did the company get duped into making the loan? If the answer is something like "we treated an SSN as identification", that company should lose the right to be a credit issuer.
If Equifax issues a report saying that I owe X, and I contact them with proof that this was a fraudulent loan, and they continue issuing that report... how is this not criminal libel?
The typical individual is not engaged in the political process, and if they pay attention to this subject, they do so for an ephemeral amount of time. Individual voter's anger has no consequence.
Our system is optimized to privatize gains and socialize losses.
Curiously, political pushes for reform never advocate for getting rid of the corrupt laws, but rather creating a whole new regulatory regime whose corporate giveaways will only become apparent down the line.
I know that courts move slowly and judges are often depressingly technological illiterate, but I have absolute confidence that I could put together an incredibly convincing panel of experts who would define "reasonable procedures" in a way that would run wholly afoul of the SOP of the major credit reporting agencies.
By my quick non-attorney reading I think you'll be arguing under 1681o, and still stuck showing actual financial damages for having been denied a loan or whatever. Point being they've legislated themselves out of the straightforward tort of libel by 1681h (e).
While medical providers do seem to take this to ludicrous, my understanding is that there's an underlaying common law principle concerning actions taken on behalf of someone in an emergency, and it's not just medical providers to whom this applies.
When my partner was pregnant, the OBGYN's office would send us small little bills despite us having paid our copay's. The bills ranged from $40-$200 and did not indicate what the bill was for, listing it as something generic "misc services" for instance. I called down there once and asked what the bill was for and the person I spoke to could not tell me. So, I didn't pay any of them switched OBGYN's.
Second story, the partner had incredible stomach pain... we ended up in the ER, paid the co-pay, etc. A couple months later I get a bill for 1k for seeing an out of network doctor. I call the insurance company and ask if that's correct and this is what they told me: That the hospital had a habit of sending out fraudulent bills, and that they had a legal settlement with them that they weren't even allowed to contact the patients directly.
It was literally just a cash grab.
> Held: Only a plaintiff concretely harmed by a defendant’s violation of the Fair Credit Reporting Act has Article III standing to seek damages against that private defendant in federal court.
Per the Court, this means something like you were provably denied credit on the basis of the incorrect reporting, and you either didn't have an opportunity to explain yourself or your explanation was not accepted in favor of the information from the credit reporting agency's information. This is a very, very high bar to clear and is made even more difficult by the fact that almost any agreement of substance includes a mandatory binding arbitration clause. Thus, you don't even get the chance to go to court.
(Many businesses lauded here on Hacker News have such clauses, so even the "good" entrepreneurs can't resist taking away rights to the courthouse from their users.)
More coverage and links to the decision at SCOTUSblog: https://www.scotusblog.com/case-files/cases/transunion-llc-v...
Partly because there is also some procedure for challenging credit reports. I'm going to try and find the blog post about it...
Is it really just a simple as an ACH transfer?