It's still easy for anyone to become you at Experian
krebsonsecurity.com
krebsonsecurity.com
TLDR A better national digital identity story makes this problem go away.
(responsible for customer IAM including identity proofing at a fintech, doing some lift for Login.gov independently as a citizen activist)
Just takes one person to leak the database, which is probably only a few TB compressed) for all of the US and fits on a single HDD/SDD.
I would be surprised if these DBs aren't already sold on the darknet. And this DB doesn't have to be super up to date b/c security questions often go back years.
Interpreting the DB should be easy to hardcode but even easier handled with an LLM.
So the protection afforded by these checks is IMO at best nominal.
My opinion: we should be able to visit a government office, get our picture and fingerprints matched, and then we can reset our email/password/2fa right there.
This might be somewhat true (it's certainly more expensive than not having security) but when your entire business is around making assurances based on people's identities, you'd assume that they'd put more effort into making their services secure. And if it's too expensive to do it securely, then maybe we should start to question whether such a service should even exist and deserves to store a lot of personal and private information.
It's notable this issue (verification by SSN) doesn't affect GDPR-land - the GDPR has fines of up to 4% of global turnover.
They should absolutely be fined and punished harshly even beyond that. If SBF can go to prison, so can the CISO of Experian.
How do we know it's malicious and not just regular incompetence? Hanlon's razor and all.
My question was related to this quote:
>the GDPR has fines of up to 4% of global turnover.
I was asking what GDPR has fines on. Does it have fines for incompetence? snthd claimed that "this issue (verification by SSN) doesn't affect GDPR-land" saying GDPR-land somehow prevents this with a specific fine. I'm wondering what the specific fine is that GDPR-land has that prevents this issue.
Plausible deniability allowing them to push as much significant risk of identity theft onto consumers instead of themselves where it should be.
Edit: Imagine this the other way around! Grandma gets scammed by someone pretending to be her bank. So the bank's identity got stolen. So now the real bank needs to fix it, provide more proof of identity to all customers and jump through all kinds of hoops to not owe grandma crazy amounts of money.
Well, we have no idea about that :)
In any case if it meant literally 'blaming the victim' it makes no sense at all, so either we give the benefit of assuming the poster is able to make coherent statements or we don't.
instutions should be respomsible for protecting themselves from fraud, they shouldn't need me to protect them from my identity being used in an unauthorized way.
It doesn't imply this second bit.
But another, more common scenario here is that I convince the bank that I'm you and get a credit card or loan from the bank. Now the bank is knocking on YOUR door asking you to pay them back for the cash they handed to some random person... but they're the ones who messed up by giving cash to a random person and not verifying that they are who they say they are!
You aren't really involved... the bank messed up by going "Oh you say you're Bob? Okay here you go!" Why is it your fault that they failed to accurately verify the identity of the person they gave THEIR money to? You didn't play any role in them deciding who to give their money, nor in their ID verification procedures.
No, I'm imagining a scenario where the things used to identify me to service providers is taken by someone.
> I also think your analogy of a "friend" isn't right...
I didn't mention a friend.
> you are the bank's PAYING customer... you pay them to secure your money and only give it to you!
I agree, but as per my analogy, the car's owner has had their car stolen.
> If they fail to provide the service they're offering to you... seems like they ought to be responsible for their failure.
As per my analogy, I'm not saying that the car shouldn't have been secured, nor that the storage provider shouldn't make the situation right via insurance etc. Only that the car owner is the one who is a victim of car theft.
> You aren't really involved... the bank messed up by going "Oh you say you're Bob? Okay here you go!" Why is it your fault that they failed to accurately verify the identity of the person they gave THEIR money to? You didn't play any role in them deciding who to give their money, nor in their ID verification procedures.
The bank being at fault doesn't mean the victim's identity wasn't stolen.
All of these objections seem to assume that if someone has something stolen, it was their fault. That's not true, and that assertion is what I'm objecting to.
I know it is pedantic but it is important to keep in mind because dumping the need to seek redress on the uninvolved third party is ridiculous, so we shouldn’t use language that plays into that point of view.
It's merely a tort (wrong). It never rises to the level of a crime. The few instances/places where slander is a crime in the US (historically or otherwise) are very problematic and subject to abuse.
Perhaps this specific kind of slander should be criminal, but it might be the only kind that should be. Not only would you need to justify that philosophically, but somehow convince legislators to make it that way (at the federal level, I should think).
It'd be a tough journey.
Agreed that getting legislators to do anything about it will be a pain, though.
This is called libel. This person is a victim of a crime the credit reporting agency committed.
can you opt out? is there even a choice at all? where i live I can’t opt out of Experian or other credit rating services.
I'm pretty sure the OP was meaning that there's little point for the businesses that make use of the credit bureaus, if they can't be sure the bureau is accurate, rather than that consumers might be better off opting out (even if they could).
And your firm pays Experian/Equifax/etc. to GIVE information about you, e.g., automated employment verification.
I live in Switzerland, where this is the case. Even the government doesn't get this information. If the government thinks you're cheating on your taxes, they have to use warrants and follow the same procedures as for any other crime.
The only financial records accessible are records of legal debt collection actions ("Betreibungen"). Before offering someone credit, you can find out if other people had to sue them to collect.
Yet, even with so little information - without credit reporting agencies - everything works just fine.
FWIW, due to international pressure (things like FATCA), Swiss law was changed so that banks do report on international customers.
It definitely worked great for a lot of dictators, tax cheats and the sort… I think Switzerland is a great example of why complete privacy isn’t fair on ordinary taxpayers - it allows the ultra-rich to hide what they owe
The ironic thing is that one of those new hot spots, in addition to the usual suspects like Cyprus, the Caribbean, etc., is the USA. See https://www.washingtonpost.com/business/interactive/2021/wyo... for some juicy details.
Of course, privacy enabled the bankers to do shady things, but this wasn't the initial motivation. Swiss people value their privacy overall.
That said, yes, dictators and such were - and are - a problem. They aren't going to prosecute themselves, after all.
By the way, one of the top places unsavory types stash their cash is the US. FATCA is a one way street: US banks don't provide information on their international customers.
The problem was - and this rightfully pissed off a lot of countries - that Switzerland makes a distinction between tax evasion (you "forget" to mention those 5'000 franks extra income) and tax fraud, where you actually cook the books.
Tax evasion is not considered a crime and if you're caught you get fined and pay back taxes. Tax fraud is a crime and may land you ion jail.
So, in case of simple tax evasion a third country may not get the information requested since this is not a crime in both countries, which is a requirement for this.
With the automatic information exchange with other countries Switzerland is no more a prime destination to hide your illicit gains.
https://www.theguardian.com/world/2019/nov/14/the-great-amer...
> A South Dakotan trust changes all that: it protects assets from claims from ex-spouses, disgruntled business partners, creditors, litigious clients and pretty much anyone else. It won’t protect you from criminal prosecution, but it does prevent information on your assets from leaking out in a way that might spark interest from the police. And it shields your wealth from the government, since South Dakota has no income tax, no inheritance tax and no capital gains tax.
Make it completely legal and tort-free to lie about social security numbers anytime, anywhere, except when dealing directly with the government (i.e. filing your taxes).
That'll stop them being used, and right quick.
As a result, we have processes that ask for or require a social security number that aren't even related to the purpose for which it was created: Health care, loans, debt collection.
Notably, some citizens of certain religious sects, like the Amish, do not have social security numbers.
Some combination of name, address, birthdate, etc.
But the problem isn’t using the SSN as a semi-unique ID. It’s using it for that and also assuming it’s secret. SSN shouldn’t be any more secret than name or address (and shouldn’t be used to unlock or access accounts).
Plenty of countries have SSN-like numbers: https://en.wikipedia.org/wiki/National_identification_number
It's really not that special.
> But the problem isn’t using the SSN as a semi-unique ID. It’s using it for that and also assuming it’s secret. SSN shouldn’t be any more secret than name or address (and shouldn’t be used to unlock or access accounts).
Of course. Shouldn't it be trivial to sue any institution that uses SSN as a way to confirm your identity?
You’d think, yet here we are, with one of the big three credit agencies letting people steal/resteal accounts with nothing more than some public info.
*: except judges and juries, apparently
I've seen it more than once when working with health records: two people have the exact same SSN, but different sex. If I need to match records, I'll use SSN and birthdate, knowing even that's not immune to errors.
Fun story: many years ago, I worked on some consumer tax prep software. Specifically because of the Amish, the SSN field was optional. Imagine that - an Amish person using tax prep software.
While the government says that an SSN is not necessary to open a bank or credit card account, all the ones that I’ve encountered require it to proceed with the application, and the government doesn’t do any enforcement of that.
> Around 36 percent of the Swiss own their homes or apartments, the lowest rate in the West and well below the 70 percent average in the European Union, and the 67 percent in the United States. [1]
I’m sure there are many factors, but I would be less willing to finance someone’s large purchase without more information about their creditworthiness.
[1] https://www.nytimes.com/2023/11/06/realestate/zurich-switzer...
In Germany there is Campact for example which usually crosses 200K signatures per petition, if something like this doesn't exist in the US then I think someone with money should create it or promote an existing solution like OpenPetition to enough recurring signers
I did some Googling and it didn't seem like there's an easy option.
Imagine if they were like password manager apps? We could evaluate all of them, choose what we wanted, and migrate whenever something happened.
As a business? Sure, report to the ones you want to
I don't think that "increased competition" will work here. We are not customers of the credit bureaus. We are the product. The customers are lenders and other people who need your information. From the lenders' perspective, this is all working out fine, largely because the onus for "identity theft" is placed on members of the public as individuals rather than on lenders to accurately verify applicants' identities before extending credit. As many people have pointed out before, "identity theft" is a misnomer designed to pass the buck onto individuals. Ideally, it should be the lenders' responsibility to prevent criminals from misusing your information and to make things right whenever a criminal tries to use your information fraudulently, but right now the onus is placed on individuals.
A better solution would be to have higher standards for identity verification by lenders. That would shift the burden onto lenders to actually verify people's identity before extending credit. Some lenders actually do a pretty good job of verifying people's identities before extending credit in my experience, while others just seem to accept the information given uncritically (as far as I can tell!). High industry-wide standards should help solve this (either voluntarily or mandated by law).
Without it (also without a sufficiently high number), most avenues to housing are cut off
I tried contacting every retailer. Only Magazine Luiza seem to have acknowledged the fraud and issued a warning but to no avail, as I am still receiving invoices from them.
I contacted the local police and issued a boletim de ocorrência (which I am not quite sure how to translate) that describes the problem and how I was unable to apply countermeasures.
I am expecting fallout from this. I am really anxious about this whole situation and how I am utterly powerless in protecting my identity.
However, HIGHLY unlikely they issue a card in your name and purchase stuff in your name online. If they have a card with them, they’ll go to physical stores and leave with the product with them immediately.
Typically (as I said above) they have purchased a stolen CC number online and are using it until it gets blocked or run out of balance/limit.
In any case, there’s zero fallout for you, the victim. These retailers are used to this (0,5% of transactions turn into fraud), so they’ll eventually figure out it’s fraud and they know it wasn’t you. They know you’re a victim too.
[0] https://registrato.bcb.gov.br/registrato/
Edit with the link
As tmcz26 said, it's very unlikely they issued a card on your name, but if that happened, contact the bank's ombudsman AND report it to the Central Bank, as they failed the KYC process.
Typically the item is resold for half the price and it’s spoken for. It’s not like they buy to resell later. If they make the fraud they already have a buyer
> I tried contacting every retailer. Try to reach out to the ombudsman (ouvidoria) and explain your case. Even if they don't actually solve the problem, you documented that you tried to friendly resolve the issue.
> I am expecting fallout from this.
Very worst case scenario, the retailers will send the fraudulent invoices to collection agencies and might report you to the credit bureaus. Don't ever pay any cent toward this fraudulent debt. Don't negotiate. The only option is the debt going away as it is fraudulent. It's their money that's on the hook and paying it shifts the responsibilities to you.
Once it hits the credit bureaus, as you already have a Boletim de Ocorrência, and proof of contacting the companies (protocol numbers + dates), i.e. documentation, sue them and ask for damages. It's a simple and common suit that both the credit bureaus and the retailers will want to settle. Make them pay for your time. They don't have any proof that it was your person that made those transactions.
> I am utterly powerless in protecting my identity.
Yeah, but the thing is, if the retailers, banks, credit cards, etc. really wanted to avoid fraud, every purchase/subscription would require the same level of protection as a real estate transaction. Everything signed, in-person meetings, upfront payments, banks, lawyers, notaries, cryptographic signatures (hey, we have e-CPF and nobody uses it!). But as you see, 100% fraud avoidance means friction, and no sane retail business likes friction. It's a business decision on their end. They accept risk so they can take your money easier.
If however it’s a credit purchase (personal loan, crediário, etc) then it might go to collections, then this advice works.
Online purchases though are 80% credit card and 15% Pix/Boleto so it’s unlikely they got a loan just to buy stuff. If they can get a loan, they’ll get the cash itself and run.
Edit: on a Credit Card transaction the burden of evidence is on the merchant. THEY have to prove it was you.
There's no legal footing, but they will try.
If I said to your employer, "I'm pretty sure judge2020 is a wanted criminal," and they actually fired you over it, you should be able to successfully sue me for lost wages (or if you sued your company, they should in turn be able to go after me).
In both instances they said to lock my credit, and provide free credit monitoring for a year.
I find this egregiously insufficient to the point where I think we need more regulation in this space. They should provide lifelong credit monitoring and full insurance on any financial fraud that now occurs on my behalf, as well as immediate presumptive financial compensation.
That aside, the root cause here is that identity in the U.S. is a dumpster fire. We have no distinction between unique identifier (SSN) and secret (also SSN). Every other security question is just another version of the same factor type (something you know) which is easily accessible to scammers.
There is quite literally no agreed upon way to prove you are who you say you are.
We need DMVs to begin issuing IDs that are physical with digital capabilities, like credit cards. We need the equivalent of Apple/Android Pay for identity online. We need to mandate that banks support digital IDs. And we need strict enforcement for people who misuse a digital ID.
I believe that the consequence of ignoring this problem is at least tens of billions of dollars in GDP annually lost to fraud. And perhaps more importantly, it’s an insidious erosion of our status as a country of laws.
The problem is that there is a very vocal segment that views such things as "government overreach" through to the literal mark of the devil.
And then there are the challenges of issuing them. There are states (the same states, typically, who shut down voting locations in working class areas and defund their DMVs) who will fight tooth and nail about having to implement this in a way that is free to all.
There's absolutely no straw man. Among other reasons, things like this are exactly why there is opposition in some segments.
You've literally argued "You're making a strawman by describing what I think!" You're against it because overreach and abuse. I say a segment is against it because of reasons including that. Maybe less of a hair trigger is needed.
Sure, technically there is a sliver of actual people out there worried about "mark of the devil". I'd still say it's a straw man to use that to characterize general opposition.
> You've literally argued "You're making a strawman by describing what I think!"
Uh, not at all. I accept that the government wants to be able to identify citizens. I'm not calling this government overreach. What I have a problem with is the ongoing failure to pass any corresponding laws that prohibit companies from abusing these identification systems to build limitless privately-owned completely-unaccountable surveillance databases. These abuses need to be stopped first, rather than brushing off the problems we're already suffering and giving even more to the surveillance industry.
As I said, pass a US GDPR that gives me the right to opt out of most of the surveillance industry, lets me drastically curtail and audit the parts I don't completely opt out of, and make sure any new types of identity attestation are still refutable in the legal system, and I am generally on board with stronger identification through something like a smart card.
And how will all this magically work online? Answer: you'll have to provide whatever digital secret gives you access, just the way you provide your SSN now. Which means your digital secret will be in all the same online places where your SSN is now, vulnerable to the same kind of hacking. How does this fix anything?
Loads of ways to do digital attestation but they all involve some 3rd party being the trusted source of truth. Typically this would be the DMV or other government branch and at this point a few red flags start to go off: dmv isn't known for it's competence and I'm not really thrilled about them getting hit to confirm my identity for pornhub.
This is a REALLY hard problem to solve unless you take a "privacy must be sacrificed for the greater good" mentality.
Some countries already have national ID systems that use cryptography like this to secure identify oneself online, such as Estonia: https://en.wikipedia.org/wiki/Estonian_identity_card#Electro...
Also, the Estonia system apparently includes keys allowing the manufacturer to perform card operations. How do I know that won't get hijacked?
One neat thing about systems like this is that the card itself can perform a cryptographic computation that proves its own "ID", without communicating its private key to the connected computer/phone. So even if your computer was compromised, the ID card connected to it still can't be copied. The card is simple enough that there is less attack surface (as compared to an entire computer), so it's much less likely be be hacked, even if it's connected to a hacked device. Though mistakes do happen, since no system is perfect. So if a vulnerability is discovered, new cards might need to be issued.
Granted, an attacker on your computer (controlling it remotely) could just wait until you log in to your bank via smartcard and then quickly pull all your money out... you need a more complex solution to fix that problem (like cryptocurrency hardware wallets use; they have a little screen that shows the proposed transaction, and you have to physically push a button to confirm it, and then it does another cryptographic operation to authorize that particular transaction).
However, the smart card system does prevent an attacker from simply buying a database dump of email addresses, passwords, SSNs, etc. and using that to get into your bank account.
It's unbelievable
https://qbix.com/blog/2021/01/25/no-way-to-prevent-this-says...
https://qbix.com/blog/2023/06/12/no-way-to-prevent-this-says...
And then of course there is this:
SIM swapping - someone can just steal your SIM and then get into a lot of accounts
https://www.bloomberg.com/news/features/2023-08-04/teen-game...
Amazon - someone can just take over your account
https://www.reddit.com/r/cybersecurity/comments/hsj4x8/my_am...
Apple and Amazon together, they can take over ALL YOUR ACCOUNTS (the most terrifying read):
https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking...
I recommend to everyone to use a email alias at gmail or a similar service, different once for every site, instead of your actual email, as the login to Amazon and other services. That way the attackers can't guess your actual login, let alone your password.
That's criminal-grade negligence.
In my head I am interpreting the law like this: Credit Reporting Company negligence "interferes" with a person being able to obtain a loan.
IANAL either, but it seems the losses suffered from ID fraud are only recoverable via this.
This sounds like it was used to get a vehicle - which are fairly trackable things. How did the ordeal unfold and conclude?
I wonder if Ford in particular is more susceptible?
In any event, I’ve no idea whether a law enforcement eventually looked into it. But the sense I got was no one was going to do a damn thing.
(Oh and Progressive, because they got insurance for the vehicle in my name and also didn’t pay that. But it was 1000x less dollars, literally, so when I told the debt collector “lol not mine” they just went away).
Credit freezes are a joke, because if you have a person's credit report, you have enough information to cancel the freeze, even if you can't temporarily thaw it. Still, maybe it's better than nothing, so might as well. But it's then a pain if you need to interact with the credit system; some of the bureaux have such poor systems that your accounts will regularly not work; anyway, credit issuers don't tend to tell you what bureau they'll pull from until after they pull, so may as well unlock the big 3 before you do anything; and batch all your credit increase requests together.
Once I got back in I saw credit pulls and immediately contacted the companies to figure out the car dealership in question, then called them to let them know that they should under no circumstances sell that car.
And the form to get that settlement meant giving some random authority more personal information than these companies even have.
I would keep going too.
You try to sign up correctly, then it emails the fake persons email for permission? How does that make any sense.
"Hello scammer, John Doe would like to access his Equifax account. Do you want to give him permission?"
I agree the Experian way is not good either, but how is the above handled?
They already have the well-shared data that determines much of your life. Signing up is so you can glimpse it too.
I can speak for Experian. If you already registered the account, and someone else knows your SSN and the answers to the credit bureau security questions, then _they_ get to register your account. You as the person who originally registered will get an email that your email address changed.
Supposedly the thinking is that they want to make it impossible for someone to truly be locked out of accessing their own Experian account, so they just let you do these stealth registrations as long as you can answer all the security questions. Clearly they need a better solution.
No individual in a personal capacity ever wanted to do business with Experian, like they wanted to buy an iPhone or something. You're introduced to the unpleasant fact of its existence at some point. They don't have anything you want, you're the product from the start, and you don't have to walk into their net, you're probably born in it.
Things that deal in you.
They make money from you, indirectly.
You have no business or social relation with them.
You didn't vote for them.
They have immense power to harm you.
You have no recourse.
You may not even know they exist.
Until recently this was the preserve of a few government agencies that had a very narrow focus on a few "persons of interest". Today it is every dime store startup in "big data", search, spammers, social network, and the entire grubby, yellow maggoty underbelly of "surveillance capitalism" and all the mushrooms that grow on it.
So far the promised "benefits" of this have never materialised. Will we be able to keep pretending "nobody cares" as public awareness, and governments' will to enact legislation grows? At some point surely "credit agencies" and their ilk will essentially be outlawed under a dozen different digital rights acts.
First of all, $25/month for an Experian product? I can't possibly fathom how anything they provide can be worth even 1/100th of that. That price just absolutely blows my mind.
But worst of all, they proudly say it is $0.00 and have the pay button the most prominent. How many people get roped into this? They are just slime all the way down.
In contrast, I lost my drivers license and in order to get a new one I had to go the DMV in person and put my thumb print on a biometric scanner which pulls up my picture for the DMV person to look at before they authorize the request. I can also file an affidavit of identity theft with a police report attached and they will give me a new license and A NEW DRIVERS LICENSE NUMBER. The federal government trying to shoehorn an unconstitutional universal identity system into social security is the source of all this nonsense.
How does the state have your fingerprints on file?
It's a basic requirement in California to get any form of ID.
I wish I could put a permanent fraud alert on my credit accounts, but would probably have to hire a lawyer or something.
Is there something else I’m missing that’s only temporary?
And if Experian knew who was viewing our info inappropriately, they'd know it's not us -- and stop it. Instead their lame system assumes that anyone who has minimal information about us _is_ us.
I have stuff like credit wise, karma, etc... have not seen weird/unknown accounts so hopefully I'm good.
Giving the backing of the state over their actions. Move from being accountable to government to _being_ the government. And the competency of giant public bureaucracies!
Here in the Netherlands it works exactly the opposite: the best 'rating' is to not be in the system at all. When you get a loan, the amount and monthly payments are registered. This registration is removed once you have paid back the loan.
When you ask your bank for a loan, they basically look at two things: how much is your income and how much are your current financial obligations (i.e. existing loans). Cost of living is subtracted from your monthly income, as well as the monthly payments of your existing loans (from the national debt registry). What's left is how much (additional) monthly payment you can afford. If the monthly payment for your newly requested loan is above this number it will be refused.
As such there is no such thing as a good or bad rating, only what you can and cannot afford.
> how much is your income and how much are your current financial obligations
This doesn't work if your income doesn't show up in the government's system. For example, if your income comes from illegal activity. Crime is bad and you shouldn't do it, but crime is an economy and some people really don't have a better option. If your income comes from criminal activity, getting boxed out of the consumer financial system isn't helping you towards any avenue where crime is no longer the best option.
It's not a government system. Banks will typically ask for a payslip.
> For example, if your income comes from illegal activity.
You think banks are going to give you a loan if your income is from criminal activity? That's cute. Banks are required to report suspicious activity and the last thing they want is even the appearance of being involved in money laundering. It's a problem for certain professions, like sex workers (which is a perfectly legal occupation here) as they mostly get paid in cash and often deposit large amounts of it they are an obvious channel for money laundering and as such they have a hard time just getting a bank account, never mind getting a loan.
I admit to misunderstanding but I fail to see how this diminishes my point.
> You think banks are going to give you a loan if your income is from criminal activity? That's cute.
That's exactly what I'm saying. The above approach systemically blackballs anyone who lacks a better avenue to a reliable income.
That's a failure that exists in both the American system and the Danish one. My point is this: In the American one, it's a byproduct of AML law, which could easily be changed to allow banks to ignore small-time cases (with conditions, of course). In the Danish system, the blocker is inbuilt - it can't be regulated away without fundamental changes to the design of the system. Adding a "proceeds from criminal activity" box doesn't work great. Ask Al Capone.
Petty criminals don't pose enough of a threat to society for it to be worthwhile to block them out of basic, low-risk financial services like checking accounts and debit-backed credit cards. Barring them from those services doesn't discourage the illegal activity. It does more to lock them into their current socioeconomic status.
How do you propose a third party can establish your ability AND desire to pay back a loan, i.e., determine how much risk there is in lending to you?
> As such there is no such thing as a good or bad rating, only what you can and cannot afford.
This is a completely naive line of thinking. Maybe you CAN afford a loan, but WILL you pay it back? Ah, you might say, the bank will remember that and refuse to loan you money next time. Congratulations, you've invented a system of credit worthiness.
Ability is simply by asking for a recent payslip. For things like mortgages they usually ask for a signed statement from the employer as well (they declare that if employee continues to function as (s)he has been they have no intention to end their employment).
Desire doesn’t really factor into it. If you don’t pay your debt they will get their money one way or the other. Personal bankruptcy is not a thing over here, you cannot walk away from debt.
> Maybe you CAN afford a loan, but WILL you pay it back?
Of course you will, you have little choice. Worst case they get a judge to simply take it out of your paycheck.
Why, going through such trials, ex opere operantis, might just sour a 'true believer' in the "invisible hand" on the whole novus ordo seclorum.*
Hahahhahahaha! Urghk, briefly part-swallowed my tongue from laughter, excuse me...
* As the undoubtedly distinguished graduates of Yale SOM, for example, might phrase it
What even is the CISO doing? Sitting on her thumbs for a year?
Why even have laws or fines if they're so toothless?
From tiny little mom-and-pop shops, to FAANG giants, nobody is giving me the opportunity to say "NO that's NOT me!". And though it's a "verification" email, typically account is usable and vast majority of functionality is allowed even without verification. So I get to vicariously and angrily "enjoy" the follow-up emails and updates while the users gamble, purchase, sell, review, invest, write, game et cetera using my email address.
Boo to this, I tell ya, boo!
* owner of account doesn't pay, service sells the debt to collection agency, and they come after you because it matches your email and profile.
* owner of account subscribes to something unsavoury or does something illicit, which is now traceable to you
* given email is a big part of the incredibly ridiculous and overly pervasive tracking economy and profiling of the interwebs, your profile will now be even more annoying then before and be associated with things you don't want them to be.
Etc. Or just, to your point, one day they'll realize their mistake and be mad at YOU (because people aren't generally good at taking responsibility :) and now it's a thing.
I should mention I have a dozen email accounts of various degrees of protectiveness. Thia happens, annoyingly, to my most private address that I have never ever once used for business or signed up for anything, only for friends and family. So among everything else I'm peeved that my pristine email and identity is being polutted by other crap.
And again... The reason this frustrates me, is this should.not.be.and.issue in any sane world. If you're sending verification email it should have a No option. Anything else is grossly neglible or evil or both.
Over years, I've received peoples private medical bills; been subscribed to dating sites of various degrees of sketchiness; my email has been used to register with government agencies in countries of various degrees of sketchiness too; signed up for gaming, gambling, Crypto, banking, nft, investing, and so on - many things where my comfort level for mistakes and mistaken identity and Confusion and incorrect systems of record, is lower than "some kiddie signed me up for blizzard.net" :-/
That of course doesn't make it any less annoying, but it would at least stop an actor from using an account that is associated to your email.
https://www.theregister.com/2022/02/15/missouri_html_hacking...
It wasn't thrown out by a judge. The governor still maintains that the reporter "hacked" and violated state law but the prosecutor's office declined to pursue the case.
The only mechanism you have to alert the person usurping your email identity that there is an issue is to trigger the phone call verification 3 times per day, preferably around 4am.
If you call the phone support, it will give you robots until playing a pre-recorded message telling you to physically mail a legal request including copies of your ID etc.
https://www.consumerfinance.gov/complaint/
https://www.youtube.com/watch?v=9CWbc6pekd8&t=1310s ("We have a complaint database, we collect information, and are always eager for information" -- FTC Chair Lina Khan at Y Combinator)
1. That exposes me to MORE involvement with this service, not less, and potentially legal culpability. Risk may be small but impact is large and benefit is neglible, so math doesn't work out for me.
2. It requires MORE effort on my part. For a poor design and error made by not me.
If it were once every 5 years, maybe.
When it's weekly, it's just an annoyance.
Sometimes when I'm really angry, I just write to their gdpr or compliance officer with a stern better and links to various sections of the law and their obligations. Doesn't accomplish much but makes me feel better :-)
But overall, it's a systemic issue, and given we are on hacker news, I'd say it's OUR systemic issue caused by us :-/
I still get email from AT&T for John Notreallyme who I believe is in his 80s and lives in Montana. He signed up in-store and I got emailed all of his details.
I got the first email that asked me to confirm my email address. Obviously I did not do that.
It makes no difference. I don’t know why they bothered.
I get tons of email intended for the other "first last"s in this world.
Most memorable are an employment offer as an environmental engineer in New Zealand, the results of an environmental survey for some commercial real estate development in Houston, TX, and bankruptcy papers from an attorney in British Columbia, CA.
I regularly get reminders for dental visits in Oklahoma, purchase orders for machinery in Germany, and course registrations for some person who works in my industry and was easily searchable online.
It is not so intrusive to be problematic, and is mildly interesting.
I had it when someone (or likely his partner) with the same (somewhat uncommon!) firstname.lastname@gmail.com used my email. I started digging and it turned out we both were/are PhD students, just totally different fields. Must have something to do with the name. I was happy that via the faculty site I found his "real" email. Nearly send him a really weird post card, I had only his postal address...
In the other case I must have simply experimented with first initial/middle initial/last name, and that worked.
One is a minister in the Boston area, so it's not hard to recognize her inbound emails.
Don't be too quick to assume this. Likely the email account is one of many spammers gathered from a data breach.
Reset the password. I even change the username to "spam" or something too, poison as much of the associated data as I can. PITA I know, it happens to me regularly.
I sat silently for a bit while the financial advisor finished his talking point. Then I spoke up. I don't remember exactly what I said but the other guy with my name sat there with a scared / dumbfounded expression on his face while the financial advisor calmly asked me to leave.
I told him I would leave as soon as they promised to remove my email address.
One could create an account, hail rides and add their own payment method while still being associated with someone else's email. Ride recipes would then be sent to someone else's email where the receiving party could add or increase a tip through an unauthenticated link and have it charged to the riders credit card.
I know a lot about them. I know their shipping address in the UK. I know that they order inexpensive club attire, online Dominoe's delivery, and have a specific gym membership.
I am shocked that Google offers no way to disentangle my email address from this person's. A more malicious person than I could easily take advantage of all of this personal information.
There's probably a single digit number of people with my initial and surname in the world, and I still get order confirmations for one of them, car promotions for another and am on some sort of targeted B2B spam list for a third to my Gmail address in that format. I quite like the order confirmations tbf, most of them are for a fish and chip shop I actually used to get food at when I was a kid and my grandparents lived nearby so they're oddly nostalgic
https://support.google.com/mail/thread/125577450/gmail-and-g...
https://www.quora.com/What-is-the-difference-between-gmail.c...
https://www.gmass.co/blog/domains-gmail-com-googlemail-com-a...
I live in NY.
1. Freeze all your credit with experian, equifax and transunion
2. Opt out of them selling your info: https://consumerprivacy.experian.com/ https://myprivacy.equifax.com/opt-in-opt-out/personal-info https://service.transunion.com/dss/ccpa_optout.page
All free. 1 of them tries to upsell hard but can do all for free. I think a law passed in 2019 ish forcing it to be free.
Just had to deal with this for the first time in the last two weeks when someone tried to open a fraudulent account in my name... Interestingly, this happens for the first time in my life 2 months after I had to write down all my personal information to get a 0% APR credit card from a jeweler store...
It should be a default frozen system, not a default open system.
Now granted, it’s possible that the attacker won’t change your email address first, in which case I’m not sure if you get an email stating that your credit was unfrozen. But it’s likely they’ll change it in order to make it harder for you to mitigate the damage in a timely manner.
We've encountered an error Sorry, this service is not currently offered to residents of your state. If you need further assistance, you can call Consumer Care at 1-866-295-6801 during our regular business hours 9 A.M. to 9 P.M. ET Monday to Friday, and 9 A.M. to 6 P.M. ET Saturday and Sunday except holidays.
Oh man, actually looks like Equifax's entire website is down? Ouch.
1. All your mortgage, credit inquiries and bank account names
2. All your previous addesses and perevious employers
3. Your MONTHLY salary and combined comp per yer going back to 20XX when I came to the US.
4. Dates of employment per employer, bonus, overtime, RSU comp
Does Experian and Transunion have that too, and can we block that as well?
The credit agencies however offer you a real and valuable service. Without credit history it’s impossible to get credit. It’s also harder to get jobs and to rent. So while it’s creepy, at the very least you gain some demonstrable advantage and benefit.
The data brokers and vendors however collect without your permission or knowledge, compile much deeper profiles of you as a human being and what you do and enjoy, along with these other details, and sell it for a profit you never get a share of.
Perhaps one day we will have a functioning legislative branch and from it will come a real privacy bill. I’m hopeful it’ll be better informed than the EU ones by taking lessons learned. But I hope for a lot of stuff, like world peace and cures for cancer.
I think I generally agree that this is a reasonable service, however the main reason you can’t get credit without a credit history is these services exist that can provide credit history to lenders. It is bizarre to think that loans would not exist without these services.
And technically, you can get many loans today without a credit score. For example, there are bank statement mortgage loans, but they have caveats like:
- you will go through manual underwriting and will likely need to show records of payment history on any existing debts, including utilities, insurance, rent, etc
- They will likely need the contact information for each one of your previous debts to verify it manually
- When they run a quote, you will typically be considered at the lowest credit score possible for that program - typically 620 for a conventional loan or 500 for FHA. This means you'll be getting the worst rate possible
- You'll likely need a 20% down payment, depending on if any of the PMI automated underwriting systems even give you a quote with such a low "fake" credit score. The lender might ask for more of a down payment depending on their own risk assessment.
- The lender (or whoever buys your loan) will report your new account to the bureaus, giving you a score.
You work at a big company. Your employer is choosing to sell this information to credit bureaus.
I first learned about this practice in the mid-2000s. Like you, I was quite surprised, but they didn't have any data on my own income or assets yet, and I resolved never to work for an employer that would engage in this type of business practice.
I think employers should be legally required to disclose and obtain written consent to sell your income data, but beyond that point, it's really on you to decide what employment arrangements you are willing or unwilling to accept. It's sad that you had to find out this way given how easy it would be for these employers to just disclose it upfront. I'd recommend looking for a different employer.