Once scammers can't get access to the money the problem of bots in the classroom will mostly go away.
Once scammers can't get access to the money the problem of bots in the classroom will mostly go away.
Are these bots successfully completing FAFSA forms to the government?
And the government is successfully generating ISIRs to send to the schools?
If yes, then this is a federal ID verification issue.
If not, why are the schools sending aid payments sand ISIR? Or does CA run its own state-level aid programs that skip the federal forms completely (and botching the ID verification on their own)?
Or are all of these effectively stolen IDs? Where the FAFSA and ISIR are for real people (but people who aren't actually students)?
The article is missing a LOT of details, what a waste of time.
If the student aid system verifies identity by, for example, just validating that the applicants know a single 9-digit number that after the Equifax breach should be considered public information, that is a critical problem with their identity verification system and it should be patched.
> "Identity theft" is a term coined by banks to try to make it sound like random people should have to deal with the fallout of the banks' bad identity verification practices.
Wow, great point. I admit: I have been tricked by financial institutions to believe this term! Another (US military) term that is similarly misleading to me: "surgical strike". If they blow up the bus stop in your neighborhood with a cruise missile fired from 300km away... well, you won't ever feel safe in that neighborhood again... so the strike is certainly less than "surgical".The problem isn't the banks, the problem is that unlike Europe where in most countries it's commonplace for everyone to have a government-issued ID document, the US does not have that requirement and so companies of all sorts abuse documents not meant for that purpose like SSNs or driver licenses that can be trivially forged.
Banks can't invent security out of thin air when a significant part of the US population believes that mandating possession of one is a surefire way into a dictatorship or whatnot.
Add on top of that undocumented people or the issues surrounding the Native American population and their partial autonomy rights, and it becomes a mess very very quickly because it won't stay at "about three percent".
Zero. Because FINCEN/KYC[0] laws in the US mandate identification for all customers.
Which means that at least 3% of the populations is "unbanked"[1]:
Some reasons a person might not have a bank account
include:
Lack of access via a nearby bank branch or mobile phone
Minimum balance fees
Distrust of the banking system, typically due to lack of transparency
regarding fees and deposit timing[1]
No access to government-issued ID, which is required to open a bank account
To avoid delinquent debts, such as creditors seizing the account in
judgements, or the government collecting back taxes or child support
[0] https://www.investopedia.com/terms/k/knowyourclient.asp[1] https://en.wikipedia.org/wiki/Unbanked
Edit: Fixed subject/verb agreement (laws/mandate)/fixed quote formatting.
https://www.bankhelp.gov/help-topics/bank-accounts/required-...
For example: https://www.reddit.com/r/Banking/comments/1csl00q/any_banks_...
And then they have someone with an incomprehensible accent in a call center that probably also runs scam calls calling you up and asking for your password as part of their ordinary SOP.
They deploy fancy new tech like "verifying your voice" with some AI crap while simultaneously not allowing your password to have more than 8 characters. (Which must have two symbols but if one of them is ` you'll experience random spontaneous logouts).
There may be many causes of the disaster that is bank security, people not having ID is absolutely not part of it.
When someone tricks a bank in a way that harms you, the legal question governing your recovery from the bank is, “Did the bank act negligently, and did that negligence cause you harm?”
Unlike normal life, where “negligent” means “I didn’t enjoy it,” under the law there are several required elements that constitute negligence. One required element of negligence is that for a party’s negligence create liability, the alleged negligent party must have owed the harmed party a duty at the time of the breach of that duty.
Duty can arise in several ways according to state common and statutory law. For example, a doctor owes the duty of the standard of care to his patient. A driver owes the duty to drive the speed limit to other motorists. The question of whether duty exists in any situation is a complex question of law.
One thing that isn’t complicated, though: in every jurisdiction I’ve researched, a bank owes no duty to a non-customer.
This is why victims of identity fraud don’t sue the bank that granted fraudulent accounts: there is no negligence and will this be no recovery. (With the caveat that I’ve seen people who were harmed by a bank where they randomly happened to have an account… in this circumstance, duty can be ascribed to the bank because a banker-customer relationship in which duty is rooted exists).
Corollary: open an account at every major bank to establish a duty-relationship everywhere.
Poor startup idea of the day: Accounts-at-every-bank-as-a-Service.
I suspect the issue is similar here with the multi stakeholder problem here. The college needs as many paying students as possible, the workload of the staff should be as low as possible, the office giving out loans wants to have a low workload... All in all good scammers will serve all these needs and happily take the money in the process.
Quite often the impersonator had nothing to do with the collection of the identity itself. There are people that 'copy' things like insecure online information around identity, but there are also people that physically steal things like drivers licenses and birth certificates. This is the stage of a crime that I'd consider actual identity theft. After that you have black market information brokers. They didn't capture the identities in the first place. They don't directly use the information to impersonate others and yet they are still complicit in a crime. Then you have the final stage of impersonation fraud as you state.
Is it?
If I look at least somewhat like you, grab your ID, and stuff you in an incinerator then any ID system that does not take detailed biometrics will have no clue if I'm you or not.
Saying identity is intrinsic is tantamount to saying "I am that I am". I mean, that's cool and all, but that tells me nothing about who you actually are.
There is nothing intrinsic about your name for example. This can and does change for people.
Again, same with location where you live.
We spend our entire lives grown up and getting old, so how we look adapts.
Then you get down to bio markers like fingerprints or dna, but these are recent inventions when it comes to human identification and take a fair bit of technology to use successfully.
I was curious, because I (living in central Europe) could not think of a single case of identity theft in my social circles or a prominent case I ever heard of.
> Compare this to Europe, where every resident has an eID containing a keypair and X.509 certificate signed by the government containing their personal details.
Woah. First, on HN I keep seeing this term "Europe". Europe is 50 countries. Please try to be more specific. Did you mean EU? If yes, then my question: Really? All 27 EU nations support and actually use this identity programme with financial institutions? I never heard about it. And, just saying that it exists isn't enough. Do normies use it (like your parents & grandparents)?[1]https://commission.europa.eu/strategy-and-policy/priorities-...
The iOS app is surprisingly decent. She could still request the old, paper-only id but this one could be also used to pay for local ordinances straight from her phone, and it's less cumbersome than the SPID-based[1] authentication.
[1]https://it-m-wikipedia-org.translate.goog/wiki/SPID?_x_tr_sl...
The first time I had a chance to use was just some months ago, when I could activate a SIM-card online through and my smartphone reading out my ID-card via NFC. I pay daily via NFC, but it's the first time ever I had to use the chip in my ID-Card, despite it having one for 15 years now. Laws and regulations are good in theory, but reality can be often quite a bit different.
Only if you assume that anyone who works for a SEC regulated company[0], applies for a California driver's license[1], current and former US Military personnel[2] healthcare workers, teachers, real estate agents, child care providers and others[3] are either "criminals" or "tourists."
If so, into which bucket would you place CA driver's license applicants? Criminals? How about US Military personnel? Tourists?
Please do elucidate.
[0] https://www.law.cornell.edu/cfr/text/17/240.17f-2
[1] https://www.dmv.ca.gov/portal/vehicle-industry-services/occu...
[2] https://www.law.cornell.edu/uscode/text/8/1440f
[3] https://blog.certifixlivescan.com/state-by-state-guide-to-fi...
But you wouldn't know anything about that, would you Ivan, especially since many (most?) Americans don't have a passport.
Are your papers in order, Ivan? It would be a shame if you ended up in a Siberian gulag, eh?
Also I always thought that it is weird, having to take driving exams to get an ID and calling an ID a "driver's license".
A proper national ID and strong privacy laws would be obvious policy wins, but that would require competent lawmakers.
In my lifetime, the most consequential federal legislation has been the DMCA (1998), the Patriot Act (2001), and Obamacare (2010), which effectively marked the end of meaningful legislative power and the handoff of governance to the executive branch.
One of those two is as of last week or so required to board a flight in the USA.
Apparently people associate it with the authoritarianism of 1984 even though mandatory ID existed in 1948 when the novel was written.
Coincidentally and/or anecdotally I've never had my identity stolen.
But there’re tons of scams involving stealing your personal id and security codes. It’s wide spread from Belgium to Estonia.
I think the current solution is to have users scan a QR code, if they are on a different device than the one with their authenticator app. I haven't hear of anyone with the hardware token being scammed though, but most of the people who have the hardware version, do so because we don't even trust an app on our phone.
But yes, there are PLENTY of cases of identity theft even in countries with electronic identification solutions.
One thing the US could do, but won't, is have an account registered with the federal and state governments. Any money coming from the government should ONLY go to that account and it changing it should require a thorough identity validation.
It is not identity theft. It is identity fraud.
Implying that you can lose your identity to someone is a way to shift blame from the banks or whatever entity being defrauded.
Often, posters on HN engage in pedophilia, tax evasion and satanic rituals. This is even more likely if you allow just anyone to create an account.
That's ridiculous, right? Because I provide no evidence for my statement whatsoever. And yet, I manage to paint every HN user with that broad brush.
It's an example of 'reductio ad absurdum'. If you have any evidence that your hypothesis is any more valid than mine, please do provide it. Otherwise, you're just smearing people without any reason except to validate your world view.
I don't know about evidence, but logically your example is bad. One is talking about specifically fraud issues, and their most likely cause. You're just generally talking about people.
SIM card swaps have been reportedly repeatedly, as being a social engineering hack. Often the exchange has been done via gift cards or crypto. More than one such hack resulted in millions being stolen.
Your attack dog response is quite unwarranted. Why are you so upset at a generic comment, indicating that fraudulent identity verification can be done on both ends?
Do you imagine that university admissions employees are perfect, uncorruptible? Is this some weird, US political minefield?
You didn't say that financial aid administrators were being "socially engineered. Nor did you say that they had their SIMs swapped. Rather, you said[0]:
"Often issues such as this are the result of people involved in the verification process, being bribed or taking cash for approvals."
That might well be the case here. But unless you actually have even a shred of evidence (do you? if so, please provide it), you're painting thousands of people with the same broad brush.>Do you imagine that university admissions employees are perfect, uncorruptible? Is this some weird, US political minefield?
I do not. But I also don't make completely unsupported accusations/attacks against random strangers as you did. Not a "political minefield" at all. You were just talking out of your ass and I called you on it. Full stop.
My statement is entirely valid in this context.
Social engineering attacks are a well known method to hack, and masquerading as others is indeed a hack.
Is this (as the headline suggests) more of a problem in California? Does California have particularly generous and vulnerable financial aid?
https://www.csac.ca.gov/college-financial-aid-and-safety-for...
Fraud is still fraud.
https://www.dmv.ca.gov/portal/driver-licenses-identification...
Similarly, there are mechanisms that allow victims of crimes to seek help from the police without fear of deportation.
Makes sense to me. I'm much more worried about road safety and crime than people coming to the US then paying payroll and sales taxes, but not being able to claim federal benefits.
Which is well and good, but then the original question still applies: how do the bots manage to get past all these requirements?
Other than completely unsecured private loans how the hell are 18 year olds getting cash for their student loans?
I'm curious how that even happens, it's pretty hard to get actual cash back after the banks send the money to the school on your behalf.
Let's say in 10-15 years they'll have robots that can pass for humans as well. Then what? How are you going to tell who's a real human?
(Isaac Asimov, _The Caves of Steel_.)
Schools have another problem with "ghost students" in general which is that there's a lot of other stuff going on at schools that depend on real students being there. Vendors, club activities, sporting/social events, nearby bars and restaurants etc. There's an entire ecosystem on and around campus which is created or supported by real students. All that non-classroom stuff helps make the school more attractive to students and often directly generates income for the school as well, but little of it would exist or be worthwhile if the campus is a ghost town.
At that time, you could drop classes in the first two weeks for a full refund.
- If you're working/raising a kid/whatever, you don't necessarily have the time to drop into classes that might be full. There is likely a non-zero number of people who see their preferred section is full and don't move beyond that (people taking one-off classes, or slowly working through a professional certificate).
- That's a lot of extra mental bandwidth for all involved. Yeah, it works, but life would be better if it wasn't the norm.
Also, decent human beings care about things that are unjust/immoral/unethical regardless if it affects them or not.
That kind of immoral act? You might not be as decent a person as you might think.
I guess the tax payers money? Otherwise they would have nipped this in the bud.
> Also, decent human beings care about things that are unjust/immoral/unethical regardless if it affects them or not.
Decent people are sometimes quite far between, most people would never lift a finger even an inch if they don't have anything to gain personally.
Personally, I haven't found that to be the case. If you've got sources that say otherwise I'd be interested in seeing them.
What involved party shouldn’t care?
There's some truth to this if the people in charge of the process are not the ones paying.
I've seen gratuitous waste in government due to indifference. It can happen in the private sector too.
I don't think this is a correct model of the situation. As far as I know, it isn't the case that there's a fixed budget for student loan disbursals and all of it will go to some school or other unless it gets stolen. Rather, if more people ask for student loans, more money gets disbursed, and if fewer people ask for loans, less money gets disbursed. So the amount of money the school gets wouldn't be affected.
not necessarily
And loan fraud just drives up the cost of loans for everybody else.
And the overhead of fighting this eats into school resources, driving up the tuition that's forcing the loan in the first place.
And as a professor/instructor, that's money that could go to funding more tenured positions (vs adjunct spots or other "non-permanent" teachers).
So, sure, without putting much thought into it, an individual might not care. But after any thought at all, one should see that fraud drives up the cost for all of us.
Not if they continue to ignore it, because once again, it's not their money being sent to scammers.
> And loan fraud just drives up the cost of loans for everybody else.
Doesn't sound like a problem for the involved parties.
> So, sure, without putting much thought into it, an individual might not care. But after any thought at all, one should see that fraud drives up the cost for all of us.
You might care. I might care. But I guarantee that the involved parties do not care for even three seconds of their day about it. They have much more important things to think about, such as what color of the ballons for their kids next birthday party.
yes -- based on real life interaction with real low-level accounting middle class bureaucrats in California, I agree that most of the people who are professionals in Federal student aid do not personally care about this bigger system. More importantly they care about their own paychecks, which most of them use to buy things for their own family events.
Key word: "popular."
A dean's most important question: "How are we gonna pay the bills?"
Well, if the number of ghost students in a department's popular class just doubled and eventually get dropped from the roll, that means the number of bona fide students completing that class also went down.
If you're the professor of that class, you want to make it crystal clear to the dean that this is an otherwise popular class getting hit by a scam, and not a class that's organically becoming less popular year over year.
Communicating this distinction to the dean is paramount-- the prof's pay and job stability depends on the scam being addressed for next quarter/semester. And those concerns bubble up from dept dean up the administration.
I mean, as I write this I start to wonder the opposite of you-- how could anyone in this chain of authority not prioritize addressing this issue?
Many students use their F.A. to pay for groceries or rent.
Turning it into company store credit is a really bad idea.