Hackers may have leaked the Social Security Numbers of every American
engadget.com
engadget.com
I’d love to see a case like that. These data broker and credit bureau industries are obviously impossible to run safely and should be destroyed.
Not really. At that point it becomes an open question that both sides will furiously try to resolve in their favour.
What you're advocating (and I agree with) is biasing the odds in favour of the allegedly defrauded. For example, if you file an affadavit of identity theft with a credit bureau (or court), collections on that item are suspended for a fixed amount of time.
If someone steals your car and uses it to run over a pedestrian, both you and the pedestrian are victims. They're far more damaged. And you aren't at any fault, even if you e.g. didn't lock it or even left it with the keys in. It's still going to create a mess for you.
Fraud involving a stolen identity is similar. The defrauded is most damaged. But the person whose identity was used is also in a mess. Obviously, if a bank has a loan in your name it's going to need to talk to you to straighten things out. And the way it would prefer things be straightened out is also, obviously, that the loan be paid versus poofed. (And on the other side, there are also going to be people who borrowed money who claim they never did.)
If someone who looks nothing like me steals my passport and convinces someone to loan them a bunch of money, I'm not liable for that money, the person who loaned money to someone without checking the photo is just out of luck.
If the bank does the above, suddenly it's my problem for "getting my identity stolen".
Right. You're a victim. And you'll probably be involved in the process of investigating and resolving the manslaughter.
> If someone who looks nothing like me steals my passport and convinces someone to loan them a bunch of money, I'm not liable for that money
Right. But you're obviously going to be involved in sorting out that mess, even if that begins and ends with "fuck off."
> If the bank does the above, suddenly it's my problem for "getting my identity stolen"
How? If someone opens a credit line in my name in a foreign country, and I'm never contacted about it, it's not my problem. It only becomes my problem if they try to take my stuff.
Identity theft is in the same category, from the victim's perspective, as a bank error. If a bank mistakenly initiates foreclosure proceedings against me, that's their mistake. But it's my problem. That's the basic reality of the situation. (For a lower-level analog, if you accuse the wrong person of a crime to a police officer, that's your mistake. But it's their problem.)
What you're recognising is how much more powerful the bank is than you or me. Given how common identity theft is, they shouldn't be given the benefit of doubt they (or anyone else) would if they had a piece of paper purporting to promise something from us to them. But we have to recognise this isn't a return to the status quo; we're creating an exception.
If a bank mistakenly initiates foreclosure proceedings against me, and I do nothing, what happens?
Yes. That doesn't mean you won't have any inconvenience.
> If a bank mistakenly initiates foreclosure proceedings against me, and I do nothing, what happens?
You're describing seizure. If I walk into your home and steal something and you do nothing, what happens?
They do. When they file for e.g. foreclosure, they're submitting proof to competent authorities. You're disputing that proof because it's bad proof. But they--and the authorities--don't know that. It looks like regular proof. It's a conventional adversarial set-up. It's just incredibly unequal.
What I'm getting at is this isn't some weird switcheroo. It's how contracts work in general.
The degree of which the individual is victimized is a direct result of the bank's efforts to push all fault and responsibility to the person who had their information used for the fraud. I would argue that the bank is victimized by the fraudster and the bank chooses to transfer the fallout of the victimization to the individual.
Of course, the difference in your example and the identity use is that one is tangible and the other is not. If someone steals your car, you've lost your car. If someone 'steals' your identity, you haven't lost it.
> Obviously, if a bank has a loan in your name it's going to need to talk to you to straighten things out. And the way it would prefer things be straightened out is also, obviously, that the loan be paid versus poofed. (And on the other side, there are also going to be people who borrowed money who claim they never did.)
True, but it shouldn't be my responsibility to prove I didn't take a loan, but instead the bank's responsibility to prove that I did once I make the claim. If they don't like the work involved, then they should perform better due diligence before giving out money, or accept this risk as a cost of doing business.
Valid. Imagine it's a car you never use, didn't care for and won't replace. The inconvenience of being proximate to a crime is what I'm getting at.
> it shouldn't be my responsibility to prove I didn't take a loan, but instead the bank's responsibility to prove that I did once I make the claim
I know only one person who went through full-blow identity theft. Most of the consequence was in halting creditor actions. They weren't proving they didn't take out the loan as much as disqualifying attempts to seize their stuff. What made it stressful was there being no way to know when you're out of the woods.
The police will come after you and you will need to explain. But you still have your car.
A more fitting analogy: Imagine a bad actor buying a car that strongly resembles your own (same make, model, year, and color), then they convince the DMV to give them a duplicate of your license plate. In this analogy, the DMV is the bank.
The bad actor runs over a pedestrian. Sure, it may be a headache to prove that it wasn't actually your car, but once you do so, how much of the responsibility should you hold?
This is a good analogy. You shouldn’t hold any responsibility. But you’ll still have a problem that takes a lot of work to resolve. The impetus of resolving that falls to you.
That'd be evidence if it can be tied to the original debtor, no?
I don’t recall, I’d have to look in my records, why don’t you send me whatever proof you have and I’ll if I can find anything?
These are pretty slimy businesses, they should be treated as such.
As far as the question of if something is or isn't fraud, why would the context matter? As far as I know fraud has nothing to do with perjury or being under oath. If you intentionally lie to a debt collector in order to get out of a legitimate debt, I think that would fit the definition of fraud.
I am not sure I agree with that premise.
I would say there are literally no incentives to secure that data and no penalty for leaking it. Hence for profit businesses will never operate this securely.
I think it’s the same conclusion but a worthy distinction
This is what other countries are doing, this is a solved problem so identify theft shouldn't happen any more in any competently run country.
Individuals may occasionally be of interest in intelligence, but less than you think. Identity really comes from banking, law and medicine so that we don't give the wrong person money, drugs or put the wrong person in jail. It's low-level, procedural, civic stuff.
Beyond that there's a lot more dark, unwanted applications of identity and we forget how much it is a cultural artefact of the individualistic society we presently inhabit.
We do have plenty of nearly-good ways of _re_cognising_ a living person, if we have previously "cognised" them. Images, voices, faces, and various biological scans are all limited and likely to be defeated with coming technology.
So separating "trust" (as expected behaviour) from identity is a major challenge, and a most fascinating one. They are not the same thing.
[0] https://www.theguardian.com/uk/2005/nov/16/idcards.uksecurit...
[1] https://www.mirror.co.uk/news/uk-news/a-really-bad-idea-5656...
[2] https://www.theguardian.com/uk/2005/nov/17/idcards.immigrati...
Internet identifiers with private keys are unforgeable unless the certificate authority is compromised, so seems like she would be in favor of this.
There is no disadvantage with this compared to just having a public identifier with no private part (current SSN scheme in USA).
No I don't think she would approve of any zealous solutionism. Not that I personally drink tea with her, but from what I've read SR occupies that class of intellect that deals in philosophical fundamentals of human affairs high above the 'technician' who says "Oh we've solved this with new fangled thing X now". And I'd bet my comfiest boots on some "certificate authority" being compromised before the ink is dry on this comment. I mean... look at what the title of this thread is about. :)
Or, in other words, when you misplace your private key, you don't want to irrecoverably lose everything you have. Fortunately, the world isn't some nightmarish cryptocurrency dystopia - there are ways to prove you owned the lost credentials and keep the ownership of what you had. The flip side of it is that someone else can prove they own your stuff too, with enough effort.
This way it isn't a big deal if small businesses leak data, since they don't have the important parts, so they don't need to be regulated that hard.
There is, but it requires assymetric cryptography, so entities can verify you have access to the private key without having access themselves.
And that would be more technically sophisticated, and difficult to deploy, so I don't see it happening any time soon.
Could you imagine if we just treated knowing your email as being proof it was you in financial deals?
umm what? Private-Public key authentication exists.
I think it is not theoretically impossible, but it is we live in a world where these services are offered by race-to-the-bottom-of-the barrel providers (to merge a couple expressions).
It's a best practice to request proof of any outstanding debt before paying collections, and I've personally seen cases where friends have gotten out of a debt that went to collections simply by asking for proof, and when it wasn't provided, poof it went away.
I'm a sucker, and don't take advantage of this, but I don't blame anyone who does. Keep good records, and it won't be a problem!
Accordingly, up North an individual is only responsible for a few hundred dollar fee under fraudulent use of a credit card situation. i.e. even if you don't catch the billing errors fast enough to lock your card, you are generally not responsible for a criminals use of credit services without your knowledge.
When we were starting out, I made the mistake of paying for our IP lawyers dubious Lexis Nexsus subscription for a year, and then was hit 4 years later with a collection agents bill (initially we thought it was a scam)... because the former employee just kept using the service. Note, because I had initially agreed to pay for the journal subscription, my lawyer said it was cheaper to just pay them the $14k to get the matter settled (we were displeased as you could imagine.)
The lesson here, is be very careful about saying "yes" to things when you don't fully understand the consequences. There are unethical people that make their income from legal shenanigans pulled on new businesses.
Have a great day, =3
From what I read, the best thing you can do is freeze all credit reports and add a PIN to your tax efiling.
Related, any company offering monitoring should be required to pay for a serialized version. The 10-20 or so settlements that require monitoring in my lifetime have been useless because I already have it for a longer period.
As a kid twenty years ago, I was mildly bothered by it but imagined they must know what they are doing.
Looking back at near 40, with the hindsight of years, I'm flummoxed. Like, what the hell, who's absolutely terrible idea was this?
the serial number was sequential based on last name, you could essentially guess anyones student id if you had a couple of data points of last name : serial number
As far as I know no one used it for nefarious purposes, but it was a cool party trick to guess someone’s number.
It's a serial number, not a shared secret. It sounds like your college treated it as such.
The real problem with SSN is the prevalence of unintended usage.
IMHO, as the name suggests, the intended usage is for social security. We're not supposed to have Citizen ID numbers which is why the number has been shoe-horned into this role.
There is nothing more permanent than a temporary solution, and nothing more temporary than a permanent solution.
> Private sector use of the SSN is neither specifically authorized nor restricted. People are asked for an SSN at banks, video rental outlets, hospitals, etc., and may refuse to give it. However, the provider may, in turn, decline to furnish the product or service, leaving some to conclude they have no real choice.
> Throughout the history of the Social Security program, the SSN, originally intended to be used only to record Social Security earnings, has been adopted for other purposes, both governmental and private. The broad-based coverage of the Social Security program makes the SSN widely available and a convenient common data element for all record-keeping systems and data exchanges.
The bad idea was to try to convert a semi-public number into a secret identifier.
Back in the 80's, NYC had a program where the local police stations would lend you engravers so you could engrave your SSN on your TV, stereo, etc., so they could be returned if they were stolen and found. Probably also made pawn shops more reluctant to take them.
Guess it made sense at the time ;-)
But, to me, using SSN as a unique serial number feels correct. As somebody else mentioned, that's what it is - a serial number, not a shared secret. "Which John Smith are you?" is very similar to the VIN on a car answering "which Honda Civic?" SSN never proves that you are actually the John Smith you claim.
Before the Internet SSN was "presumed secret" but it became a tragedy of the commons. By 2000 it was the equivalent of your public key and should have been treated as such by institutions, never used as password like that bookstore did.
Student ID card would have been the right way to verify identity at a college; I'd forgotten the SID defaulted to SSN, which was also really lazy decision!
But they de facto are and have been for longer than they haven’t. At some point, it becomes an abdication of responsibility by the SSA, no matter how much they kvetch about it being “not their problem”.
The problem is the case for making a viable replacement for such usages.
(Information all from Hollywood.)
Other countries don't seem to have this problem? You can have my bank account number, driving licence number, passport number, national insurance number if you want?
For tax I would use my national insurance number and any form of photo ID to register for an online account, or you can do a paper form but I don't know how they verify identity if you're claiming a refund in that case.
A credit card application would similarly want a copy of photo ID and probably a proof of address (like a bank statement or utility bill).
There's nothing wrong with having the number, I have a national insurance number, I have Self-Assessment Tax Return numbers (I think it's unique each year), it's the secret bit I don't get.
No one on the left really cares that much -- they have their own sacred cows and causes of the year -- so nothing really changes.
I'm aware of and share the concerns about misuse (it has happened, see the tax ID debate in Germany), but what the fuck is that with "mark of the beast" relating to ID cards?!
Why couldn't the government use SSN to track people? There is no way to avoid tracking in situations where you need to identify yourself, regardless how you identify yourself, so why not make a robust way to identify yourself?
Revelation 13:16-17 King James Version 16 And he causeth all, both small and great, rich and poor, free and bond, to receive a mark in their right hand, or in their foreheads:
17 And that no man might buy or sell, save he that had the mark, or the name of the beast, or the number of his name.
I'd be happy to join a trillion-dollar class action lawsuit against whomever assembled this data without securing it.
A few years ago, Capital One credit cards wouldn't let us pay our bill online, which we had done for several years, unless we sent them a copy of both sides of our DL's! I called them and said no thanks and they said I would have to began paying through the mail. We paid off both cards and canceled them.
Have said all this, it's prob just a matter of time before my DL number is hacked by someone through some weakly secured site.
Right???
Around a year ago my identity was stolen (new CCs opened in my name). At that time I froze my credit on all 3 of the agencies. It's easy to turn it off/on with a switch so I have left it frozen. Its a good feeling knowing that no one can open a new CC in my name.
Another credit bureau says I don’t exist despite dozens of credit cards, 4 mortgages, and student debt. They need me to fax a copy of my license to prove I’m a real person.
So time to freeze:
- experian
- TransUnion
- equifax
- Chexsystems
Am I missing anything else?
Financial institutions in America prioritize convenience over security.
If they could push a button and use new identifiers, they'd do that today.
However, in reality that means cracking open 50 years of code and systems.
What else would you use though? (in the US)
I can't think of any broadly-existing alternatives. You could perhaps have people opt-in to a newly-created, cryptographically-secure ID replacement.
It ultimately falls to the government to provide a more robust solution.
In Europe, we use these as "root of trust" - either in physical form or in electronic form.
You aren't required to posses one in Europe either, but you get assigned a unique number at birth to identify you.
Of course life is hard without identification, but there is no law mandating that you get one, at least not in all EU countries maybe some of them do.
https://search.sunbiz.org/Inquiry/CorporationSearch/SearchRe...
Specifically one that flows past the CISO and prevents that role from being a firebreak to insulate the CEO.
Definitions: Government Identification Data includes Social Security Number. Bulk Extraction means any removal of data more than element by element. Unauthorized Third party means any person who the Company does not intend to grant access to. Intentionally Retaining means that a company chooses to ask clients to supply information which is then saved in a way accessible to the company for any reason in the future.
Law: Any company maintaining Government Identification Data must select someone as personally liable for the security of said data. If the company does not have a person who accepts personally liability, this liability transfers to the Chief Executive Officer of the company. In order for the liability to be considered transferred, the Company most keep on file a notarized copy of an affidavit accepting such liability Any company intentionally retaining any Government Identification Data must do so in a system that does not allow for Bulk Extraction by any Unauthorized Third Party. Failure to do so is considered Willful Negligence on the part of the company. Any company guilty of Willful Negligence herein described must forfeit the greater of 15% of their previous yearly revenue or 5 times the Gross Annual Compensation of the most compensated employee. In addition, whomever the company has selected as outlined above shall be incarcerated for no less than 12 months and no more than 60 months.
Its how the Elite are reacting to their data floating around is what should be focused on.
They aren't calling for changes in companies, cause companies are proactively running to them with "new services" to protect them and their families and well paid servant class (ie the exec class) who are all quite clueless and constantly get into all kinds of cyber trouble. Google "cyber concierge" services.
awk 'BEGIN{for(i=0;i<=999999999;i++)printf"%03d-%02d-%04d\n",i/1000000,i/10000%100,i%10000}'I mention it because I have little hope in going after the scammers legally or playing cleanup later.
is it just the usual "the US government is catastrophically compromised by the private data monetisation industry"?
What the heck business model explains a video production company owning personal data for practically every American? I feel like there is a lot more than meets the eye on this one.
... or a lot less than meets the eye
And where are ssns posted “publicly”?
No one checks who uses that number? How is that even a thing?
...thus making them available to the the only group left without easy access.
My larger point being that it's time to shift our concern from privacy - to disproportionate privacy.
It isn't randos who routinely harm/exploit us with our own data but those in power.
I suggest that equal privacy would serve us far better than privacy laws that target us and few else.
For equal privacy, the default starts out somewhere near: If you can see mine, I can see yours. If you're going to restrict just us, 1) you need to openly+clearly justify it and 2) the restrictions need to sunset.
We presently go law by law, and we have a bloody fight for each one with the final result typically varying between ineffective and counterproductive.
Eventually the system works as intended; we get exhausted and give up. This is the present state of affairs pretty much all over - and has been for a very long time. There's little reason to believe a different result is soon to manifest.
leaking all SSNs makes relying on SSNs as authentication unfeasible,
the only way to stop SSNs being authentication token is to give everyone access to them, but yes that can cause short term troubles
The concept of having SSN is de facto wrong, there are situations where one needs to identify oneself unambiguously
I went to another country, and what I found is that to get a monthly bus pass I had to fill out a form that asked for:
Full Name + Gender + Date of birth + Place of birth + Mother's Maiden name + Mother's DOB + Mother's place of birth
(and so on) I forgot the exact details, but it was ludicrously intrusive. Mother's maiden name? Really??? I did not even know some of that info and filled it out with educated guesses. It is not like they were able to check ...
all that information is just an unreliable SSN
Good! When Congress Critter's little blond granddaughter gets pwned (someone takes her identity), maybe Congress will get real serious about really punishing these Companies when a breach happens.
But we know what will really happen in this scenario, the Company will get funding (bailout) from the Feds, the CEO will resign with millions of USD, the CEO will become a lobbyist.
And in reality, the granddaughter will get special treatment from the Company due to who she is.
what does an imaginary young woman's hair color have to do with cybersecurity?
Notice you didn't question what the gender of the grandchild.
LOL. Congressman Danny Davis' grandson was murdered by someone who wanted his shoes and Congress didn't even care enough to yawn.
Someone put the right 10 digits into a webform? What could we do! They stole your identity!
No, you just didn't want to force someone to walk into a bank to apply in person because that would cost more and reduce your new applicant rate.
https://www.fox32chicago.com/news/2-sentenced-to-prison-for-...
So while a punishment might exist for something, that doesn't preclude trying to prevent the crime form occurring in the first place. This isn't easy work, and of course, it won't work 100% of the time, but it doesn't mean we stop trying to reduce the number.
And not just in a "An eye for an eye makes the whole world blind" kind of way.
Yes, economic sanctions. Withhold money and make markets unavailable until local law enforcement addresses it.
Man, the internet sucks these days.
I can appreciate the superficial aspect of it - if we're going to overcome racism, we should stop focusing on race. This of course is ignorant to the reality that if we stop talking about race and racism, racism will just go unchecked. Which is of course what (some/many/most?) of those people want.
Unfortunately, I don't think we will overcome racism until everyone wants to overcome racism. More unfortunately, I don't think everyone wants to overcome racism, this seems obvious.
The bigger tragedy is, trying to force-feed "don't be racist" to society just makes some people dig their heels in more, making things worse instead of better. Finally, the biggest tragedy of all is how predictable this outcome is, using force and anger as a tool to change the thoughts and actions of a person/group is generally quite ineffective.
As if SSN wasn't already the most insecure form of identification on the planet. Maybe now we can stop pretending it's a valid form of identification.