If the student aid system verifies identity by, for example, just validating that the applicants know a single 9-digit number that after the Equifax breach should be considered public information, that is a critical problem with their identity verification system and it should be patched.
I suspect the issue is similar here with the multi stakeholder problem here. The college needs as many paying students as possible, the workload of the staff should be as low as possible, the office giving out loans wants to have a low workload... All in all good scammers will serve all these needs and happily take the money in the process.
When someone tricks a bank in a way that harms you, the legal question governing your recovery from the bank is, “Did the bank act negligently, and did that negligence cause you harm?”
Unlike normal life, where “negligent” means “I didn’t enjoy it,” under the law there are several required elements that constitute negligence. One required element of negligence is that for a party’s negligence create liability, the alleged negligent party must have owed the harmed party a duty at the time of the breach of that duty.
Duty can arise in several ways according to state common and statutory law. For example, a doctor owes the duty of the standard of care to his patient. A driver owes the duty to drive the speed limit to other motorists. The question of whether duty exists in any situation is a complex question of law.
One thing that isn’t complicated, though: in every jurisdiction I’ve researched, a bank owes no duty to a non-customer.
This is why victims of identity fraud don’t sue the bank that granted fraudulent accounts: there is no negligence and will this be no recovery. (With the caveat that I’ve seen people who were harmed by a bank where they randomly happened to have an account… in this circumstance, duty can be ascribed to the bank because a banker-customer relationship in which duty is rooted exists).
Corollary: open an account at every major bank to establish a duty-relationship everywhere.
Poor startup idea of the day: Accounts-at-every-bank-as-a-Service.
> "Identity theft" is a term coined by banks to try to make it sound like random people should have to deal with the fallout of the banks' bad identity verification practices.
Wow, great point. I admit: I have been tricked by financial institutions to believe this term! Another (US military) term that is similarly misleading to me: "surgical strike". If they blow up the bus stop in your neighborhood with a cruise missile fired from 300km away... well, you won't ever feel safe in that neighborhood again... so the strike is certainly less than "surgical".The problem isn't the banks, the problem is that unlike Europe where in most countries it's commonplace for everyone to have a government-issued ID document, the US does not have that requirement and so companies of all sorts abuse documents not meant for that purpose like SSNs or driver licenses that can be trivially forged.
Banks can't invent security out of thin air when a significant part of the US population believes that mandating possession of one is a surefire way into a dictatorship or whatnot.
For example: https://www.reddit.com/r/Banking/comments/1csl00q/any_banks_...
Zero. Because FINCEN/KYC[0] laws in the US mandate identification for all customers.
Which means that at least 3% of the populations is "unbanked"[1]:
Some reasons a person might not have a bank account
include:
Lack of access via a nearby bank branch or mobile phone
Minimum balance fees
Distrust of the banking system, typically due to lack of transparency
regarding fees and deposit timing[1]
No access to government-issued ID, which is required to open a bank account
To avoid delinquent debts, such as creditors seizing the account in
judgements, or the government collecting back taxes or child support
[0] https://www.investopedia.com/terms/k/knowyourclient.asp[1] https://en.wikipedia.org/wiki/Unbanked
Edit: Fixed subject/verb agreement (laws/mandate)/fixed quote formatting.
https://www.bankhelp.gov/help-topics/bank-accounts/required-...
Add on top of that undocumented people or the issues surrounding the Native American population and their partial autonomy rights, and it becomes a mess very very quickly because it won't stay at "about three percent".
And then they have someone with an incomprehensible accent in a call center that probably also runs scam calls calling you up and asking for your password as part of their ordinary SOP.
They deploy fancy new tech like "verifying your voice" with some AI crap while simultaneously not allowing your password to have more than 8 characters. (Which must have two symbols but if one of them is ` you'll experience random spontaneous logouts).
There may be many causes of the disaster that is bank security, people not having ID is absolutely not part of it.
Quite often the impersonator had nothing to do with the collection of the identity itself. There are people that 'copy' things like insecure online information around identity, but there are also people that physically steal things like drivers licenses and birth certificates. This is the stage of a crime that I'd consider actual identity theft. After that you have black market information brokers. They didn't capture the identities in the first place. They don't directly use the information to impersonate others and yet they are still complicit in a crime. Then you have the final stage of impersonation fraud as you state.
Is it?
If I look at least somewhat like you, grab your ID, and stuff you in an incinerator then any ID system that does not take detailed biometrics will have no clue if I'm you or not.
Saying identity is intrinsic is tantamount to saying "I am that I am". I mean, that's cool and all, but that tells me nothing about who you actually are.
There is nothing intrinsic about your name for example. This can and does change for people.
Again, same with location where you live.
We spend our entire lives grown up and getting old, so how we look adapts.
Then you get down to bio markers like fingerprints or dna, but these are recent inventions when it comes to human identification and take a fair bit of technology to use successfully.
I was curious, because I (living in central Europe) could not think of a single case of identity theft in my social circles or a prominent case I ever heard of.
A proper national ID and strong privacy laws would be obvious policy wins, but that would require competent lawmakers.
In my lifetime, the most consequential federal legislation has been the DMCA (1998), the Patriot Act (2001), and Obamacare (2010), which effectively marked the end of meaningful legislative power and the handoff of governance to the executive branch.
Apparently people associate it with the authoritarianism of 1984 even though mandatory ID existed in 1948 when the novel was written.
Coincidentally and/or anecdotally I've never had my identity stolen.
One of those two is as of last week or so required to board a flight in the USA.
> Compare this to Europe, where every resident has an eID containing a keypair and X.509 certificate signed by the government containing their personal details.
Woah. First, on HN I keep seeing this term "Europe". Europe is 50 countries. Please try to be more specific. Did you mean EU? If yes, then my question: Really? All 27 EU nations support and actually use this identity programme with financial institutions? I never heard about it. And, just saying that it exists isn't enough. Do normies use it (like your parents & grandparents)?The first time I had a chance to use was just some months ago, when I could activate a SIM-card online through and my smartphone reading out my ID-card via NFC. I pay daily via NFC, but it's the first time ever I had to use the chip in my ID-Card, despite it having one for 15 years now. Laws and regulations are good in theory, but reality can be often quite a bit different.
Only if you assume that anyone who works for a SEC regulated company[0], applies for a California driver's license[1], current and former US Military personnel[2] healthcare workers, teachers, real estate agents, child care providers and others[3] are either "criminals" or "tourists."
If so, into which bucket would you place CA driver's license applicants? Criminals? How about US Military personnel? Tourists?
Please do elucidate.
[0] https://www.law.cornell.edu/cfr/text/17/240.17f-2
[1] https://www.dmv.ca.gov/portal/vehicle-industry-services/occu...
[2] https://www.law.cornell.edu/uscode/text/8/1440f
[3] https://blog.certifixlivescan.com/state-by-state-guide-to-fi...
But you wouldn't know anything about that, would you Ivan, especially since many (most?) Americans don't have a passport.
Are your papers in order, Ivan? It would be a shame if you ended up in a Siberian gulag, eh?
Also I always thought that it is weird, having to take driving exams to get an ID and calling an ID a "driver's license".
[1]https://commission.europa.eu/strategy-and-policy/priorities-...
The iOS app is surprisingly decent. She could still request the old, paper-only id but this one could be also used to pay for local ordinances straight from her phone, and it's less cumbersome than the SPID-based[1] authentication.
[1]https://it-m-wikipedia-org.translate.goog/wiki/SPID?_x_tr_sl...
It is not identity theft. It is identity fraud.
Implying that you can lose your identity to someone is a way to shift blame from the banks or whatever entity being defrauded.
But there’re tons of scams involving stealing your personal id and security codes. It’s wide spread from Belgium to Estonia.
I think the current solution is to have users scan a QR code, if they are on a different device than the one with their authenticator app. I haven't hear of anyone with the hardware token being scammed though, but most of the people who have the hardware version, do so because we don't even trust an app on our phone.
But yes, there are PLENTY of cases of identity theft even in countries with electronic identification solutions.
One thing the US could do, but won't, is have an account registered with the federal and state governments. Any money coming from the government should ONLY go to that account and it changing it should require a thorough identity validation.