This is why I have my credit frozen with every agency, and all of my security question answers are plausible sounding, but entirely fake, answers stored in my password manager.
I'm not sure there is anything else we can do as consumers.
This is why I have my credit frozen with every agency, and all of my security question answers are plausible sounding, but entirely fake, answers stored in my password manager.
I'm not sure there is anything else we can do as consumers.
People asking them do need an explanation though, but no chance someone could guess one because it was plausible but wrong.
1) Wrong information
2) Information you don't know, like an estranged family member's birthday
I think the "random but actually meaningful" route is better. If you want it to get checked, grandma's name comes off fake name generator, not line noise from a CSPRNG.
A CSR is much more likely to expect correct or similar words than a correct or similar string of gibberish.
Correct Horse Battery Staple
WHat's your mothers maiden name?
Correct Horse Battery Staple
What's your favourite movie?
Correct Horse Battery Staple
They don't need to be plausible sounding, by the way, a random string of characters is fine.
Pet's name -> probably in your Instagram
Favorite color -> Hmm let's see what clothes you wear in your selfies
Street you lived on -> Hmm they probably already breached your credit report and the idiots at Experian leak all the streets you lived on without your consent
Had no idea, googled them… there’s some security theater that I don’t think anybody could have been reassured by.
> Select your favorite city:
> 1) Paris
> 2) New York
> 3) Banana
> 4) Beijing
Why do I have to tell a stranger over the phone my mother’s maiden name to confirm I own the account? That’s not my info to share, it’s my mother’s.
It's also, for many people, incredibly easy to find. People often keep their maiden names as a middle name, so if you can find someone's mother (relatively easy in the age of Facebook) it's not a far leap to figure it out from there. Even if they didn't keep their maiden name, finding it out is pretty simple by connecting the dots.
It made a bit more sense in the era before a majority of people started posting their private lives on the internet. These days it's a security disaster. Thankfully, the increasing popularity of non-traditional naming arrangements will probably do away with it soon.
Much better to use a 'plausible' answer like "Fielder" or "Pitt" or any random real last name.
Sounds plausible enough, but clearly a fake.
They seem to completely not notice that every individual and business would never know if another bank account existed in their name if it wasnt used in a different kind of crime or overdrawn forever.
there are plenty of people that just want access and dont do anything bad with it, aside frok the paradoxical standard of having access or impersonation to be bad
same is true of credit, although the original identity can see the extra credit line added, sometimes the phantom is a better steward of your credit than you are. Like “wow mixed lines of credit, paid on time! thanks undocumented person!”
Second, they need to make it illegal FIRST, or there would be no sanction evasion crime: if they don't act all naive and say "you cannot have an account here at all", then having an account would be fine... now the criminals need to cheat and lie, which they can be charged for.
Finally: not all crime will ever be punished and there's definitely a cost calculation: do we want to take fingerprints of all clients in banks to match them to a central id card database, to end up with criminals infiltrating the fingerprinting system anyway and everyone else having to do those dumb fingerprint checks for nothing ? Better keep it simple while the criming stays manageable.
The only cases where this doesn’t work are banking and airlines, which are required to check your government ID. Trello isn’t, and you can give them a burner forwarding email and fake name so this kind of thing doesn’t affect you.
You’d be surprised how much business you can conduct without providing your name. (pro tip: the “name” field in the credit card form is not matched against the cardholder.)
Also, make sure your CC billing address is a post box, so you’re not giving your residential address to everyone you transact with (the address/zip is matched).
I think it's a sort of option / depends on amount: some sites don't ask more than your card number and it works, some other you need to redo 5 times before they match properly. And anyway here you need to approve in the app like for a Google 2FA in Android.
Also, I have been asked to show ID with a card when making payment at plenty of retail establishments, just not necessarily restaurants.
Don't register to vote. It doesn't matter anyway unless you're in a swing state, and the idiots at the voting registration offices leak residential addresses.
This isn’t a prison, my location isn’t anyone’s business but my own.
Ron Swanson is parody; I am being sincere.
Private businesses on the other hand can f off. My credit card co can't come and handcuff me for not giving them an address to leak to 3rd party auto ads.
Simplification sure, but you started.
Courts enforcing notional rights weeks or months later can’t get you un-murdered in your sleep by home invaders. Did we all forget that swatting is a thing?
The place that you sleep is secret, and you should never tell it to anyone that isn’t an invited guest, especially not apps or the DMV. Every other data leak can nominally be mitigated with time, inconvenience, or expense, but violence to your person or your children cannot be un-done after the fact.
When the DMV leaks your info to all your stalkers and crooks on the internet and they come after you they won't find you there.