I remember a comment here on HN about how identity theft is the wrong name. Your wife and dog dont stop recognizing you. It is financial fraud and it really should be the entire responsibility of creditors to fix. The second you report it you should be able to have it sorted or be fully capable of suing them for defamation of your identity e.g. claiming you went on a credit card binge when you did not... We need an overhaul on privacy and our credit system. I am even much more concerned about the latter since it affects peoples lives much more dangerously.
> a surveillance technology that police and debt collectors use to track most of the United States’ 325 million inhabitants via their Social Security numbers, license plates, address histories, names and dates of birth. The mass-monitoring tech, called TLO, is a product of the Chicago-based credit reporting giant TransUnion, which last year had revenues of nearly $1.9 billion. One brochure for the service promises access to a startling amount of personal data drawn from myriad sources: more than 350 million Social Security numbers of dead and living Americans, 225 million employment histories and four billion address records. Add to that billions of vehicle registrations and call records and you have one of the largest commercial surveillance databases in existence.
> It’s used not just by cops but also by debt collectors and private companies carrying out background checks. Private investigators use it to track cheating spouses.
Honestly that this database exists at all is a serious problem in itself.
In my country such a database has existed for a long time. It's the national id database. It's controlled by national police. Everyone of us owns an eight digits number. As for me: identity is a right, not some secret that I want to hide. What doesn't make sense is that people are afraid of USA government having much needed data, while private organizations have them already.
How does your country handle authentication? The real problem is that in the United States, social security numbers and birthdates are used as private information for authorization with all the various financial and health institutions. I'm less afraid of them being public and mostly afraid of the fact that all these institutions treat that information as private.
In Germany, the combination (Name, Address, Date of Birth) is assumed to identify you uniquely.
For authentification you just show your ID card that contains both your name, date of birth, and your official address. If you move you have to notify authorities and get an official sticker on your ID card showing the new address. By law, everyone is required to own either an ID card or a passport to be able to identify yourself in front of police or a court.
Of course various governemnt agencies have their own identification numbers for you, for example you have a tax id that you will have to share with your bank, and another id for social security that you will have to share with your employer, etc. But those are just for reporting to various government databases and are never a form of authentification. You first prove who you are with your ID card, then you exchange id numbers for relevant systems.
(our IDs also have numbers, but you can get a new ID card as often as you want and nobody outside the government can do anything useful with it. We had some bad experiences with government databases, so it's now a number of unconnected smaller databases)
I'm in Czech Republic, but I guess the practice will be similar in Germany.
It depends on the degree of verification you need. You can just post a scan or a photo of your ID, you can send a small wire transfer because banks have to verify the account owner, there is an OpenID provider that offers authentication tied to the real world identity, a courier can come to your home to verify the ID or any combination of the methods.
Usually in the same way it's done everywhere else: name, date of birth, registered/current address, sometimes an additional pin/security question/etc, depending on who you're calling.
If it's official business you might be required to send an actual letter, though I doubt they ever check your signature unless you're suing them.
If it's online and state business (portal for unemployment stuff, state employee pension details, etc.), you usually have to provide your name and address first, which they then check against your registered address. They'll then send you a letter with a one-time password you can use to register your account.
Edit: Modern E-Business companies often require you to "verify" your identify by ways of Postident (you present your ID to a post office) or IDnow (you present your ID to a random guy via webcam who asks you to move it around so he can see all holograms, data, etc.) and can compare it to your picture in the webcam.
This is considered to be enough for financial transactions according to our current money laundering laws, so it's about the most though version you can go through.
To add to this: a lot of stuff just can't be done over phone or internet unless you use postident or IDnow. For example your first interaction with any financial institution is either in person or involves you waving your id card in front of a webcam according to their instructions.
Different country, but similar system here. Every person gets assigned a 11 digit personal id number at birth. That id-code then gets used as a identifier.
If you sign up for something, you just give them that number, and it will work as a unique identifier, they will know exactly that you are THAT John Smith, not that different John Smith
For something simple, like signing up for the grocery store customer card, it is enough to just say your name and number, for bigger things, like opening a bank account, you have to show your ID-card or passport.
For remote authentication, you use the ID-card for secure Internet banking, signing contracts digitally, voting, etc
(I'm probably from another country, since my such number doesn't have eight digits.)
There are three ways to authenticate myself, none of which is knowing that magic number. Many institutions choose to do it simpler and more convenient, which is then their problem if anything untoward happens.
(BTW: None of the authentication mechanisms are available to minors, which fits in well with another aspect of the law: If an adult or a legal person enters into an agreement with a minor and something goes wrong, that's not the minor's problem.)
Norway has a public number as well. It is used in part as identity, and for taxes and all that stuff. As far as identifacation goes:
1. Picture ID. For me, it is my passport or immigration card, and some folks have their pictures on their bank card as well, which works for ID.
2. For online transactions of various sorts and sometimes doing things at the bank, I have a little device that gives me numbers. This is issued from the bank, but is a national system. I use it along with my ID number and a password of my own choosing. This is done for things like purchases, banking, government websites that store my information (medical stuff, for example), the secure mailbox (government documents and things like that), and a doctor-patient thing.
3. Sometimes, a service will sent a SMS code as well as or instead of some of the above.
I think things like income and tax information are public here and I think your address is as well (I can't remember). There is also quite a bit more trust in the government as well.
How come no one has sued them (at least in small claims court) for gross negligence?
Anyhow, around here businesses request your consent to copy/scan/store your gov issued id card. So I guess defrauding them is about as hard as getting into a club with a fake id. (But there wasn't really a need for that, as few years ago enterprising individuals paid a homeless guy for his id card and managed to buy more than a hundred thousand SIM cards with it, so there are other issues when it comes to security.)
> What doesn't make sense is that people are afraid of USA government having much needed data,
You just need one "bad apple" or some technical hiccups and suddenly the personal data of almost all of your citizens can reach other governments' hands. After an event like this one (https://en.wikipedia.org/wiki/Office_of_Personnel_Management...) advocating for extensive data collection by a government entity is poor folly.
Please see my reply bellow, I didn’t say that I approve of private entities collecting data, it’s just that governments are a lot more powerful compared to companies. Just to give an easy example, an entity like the US government can have me extradited and imprisoned in the US even though I have never set foot on that side of the Atlantic while companies like FB or Google can’t, for the moment.
It is equal folly to have it in commercial or gov control. The more people and more comprehensive it is, the more incentive to hack it or abuse it.
The bigger problem is that the TLO is an adversary database -- it is a record of information about the enemy, i.e. the debtor, the citizen. Automated licence plate readers are standardized on repo cars now. Of course, they are collecting location data about all cars. Police are also widely deploying ALPR. You don't really have location privacy in America any more, even if you don't have cell phone.
I didn’t say I approve of commercial data hoarding, quite the contrary, it’s just that, for the moment at least, those companies can’t put someone in jail (or worse) based on that collected data, the way a government can.
I think it might actually be worse, because the govt is constrained in collecting some data, but they can query company databases where it is collected (either on a fee basis or a third party record search). This is the case with the cell phone location database in the US.
my favorite example: a US person setting up their own personal account on the US Social Security Administration's website must provide sufficient authentication information.
and where Social Security get this authentication information about each person? Equifax!
I’m pretty much sure that if I were to do something that might be seen as illegal by the US government my country’s government (NATO and EU member) would do pretty much nothing and feed me to them, no questions asked.
I'd say, "Vote for the people you distrust the least, and watch them like a hawk." You can't trust anyone with power, because they will use the power you give them to get more; why would we want to give them the tools to do that if they don't absolutely need them? Governments haven't needed to know all my purchases, my movements, my financial details, who I talk to, what news I read --- none of this is necessary to make and enforce sensible laws, provide for national defense, or coordinate international and intranational trade. They want this data so they have more control, i.e. power.
What doesn't make sense is that people are afraid of USA government having much needed data, while private organizations have them already.
History teaches us that governments have to be treated according to different rules. Private companies didn't murder 100,000,000+ of their own customers in the last century alone. It took governments to do that.
In Sweden all citizens get a unique 12 digit number at birth (where the last char is a checksum). It is used for identification and you can call the tax agency to find the ID of everyone. For the public sector it is a great value as a primary key but increasingly shops have started asking for it too. This means a lot of information is easy to aggregate from multiple sources and build profiles of people. I guess most people don't care.
We have the same thing here in the UK (national insurance numbers) but one key difference to the US seems to be that we rarely need to disclose ours. You use it for tax related activities and that's all. I'm pretty sure if a shop asked for it most people would say no, because no one knows their own without looking it up, but also because it'd be really weird.
Regarding @pkz comment about Swedish citizen numbers if you are in sweden and don't have one it is a nightmare getting anything accomplished - utilities, broadband etc, even if you are paying Swedish tax. Despite being EU members that federalization model fails if you don't have that number
This is true. Not having one makes regular life increasingly difficult. In many cases I am pretty sure it boils down to system designers actually not considering there could be customers without one. Software won't work without the ID number to connect data to.
In healthcare hospital staff typically works around this by using "Mr twelve" - 1212121212 - which is syntactically correct with the correct checksum, but not identifying an individual.
> It's not buying ebooks, it's leasing them.
I mostly agree, though in some cases you do own them in a format that is reasonable. In other cases some ebooks are open on github as well under Creative Commons.
It's definitely a brilliant smokescreen. The credit agencies/banks/insurance companies that fail to secure your personal data can blame you and call you a victim instead of admitting negligence...
There are superficial barriers and hoops in place which make the chances of you not getting your money back non-zero. Not to mention, it will at the very minimum inconvenience you and waste your time.
Credit cards are less problematic in this area, but when it's a bank account / debit card, there tend to be fairly agressive deadlines for identifying the fraudulent activity and contesting it as well as arbitrary processes, forms, and reviews unique to each the bank.
In the interim you don't have the funds - for many people living paycheck to paycheck this can be a catastrophic situation.
I recently had to go through this process with a debit card someone on the other side of the country had fraudulently charged $500 to. Due to my being in the midst of leaving for a long bout of travel, it was a nightmare to get the protest documented on time, and my bank suddenly required all sorts of exceptional identifying documents they never require in the course of regular business, requiring me to jump through a number of additional hoops like accessing my safe deposit box to retrieve my passport - when I wasn't even in the same state at the time. It all just added more delays to the process.
As far as I could tell, the bank was treating me as the potential criminal. They were operating under the assumption that I, the victim, am actually the perpetrator attempting to commit fraud. Through this lens, the process being frustrating and inconvenient to the customer appears advantageous, as it all increases the odds of them failing/giving up.
Your bank was just trying to figure out which of two internet strangers not in your home territory was the real you.
Someone using your card isn't the main problem with "identity" theft. That's a minor issue. If it's more than a few hundred bucks you'll notice immediately.
Someone getting a loan or a social security card benefits or health insurance or tax refund or committing a felony in your name is the major issue, which can run your life with you not even knowing for possibly years.
I've had issues like this multiple times. But have never felt like I had to prove my innocence. I recommend using a smaller bank. It's a lot harder to mistreat your customers when you know their face.
Fraud? So the suggestion is the old state of law was preferable, from a public policy perspective? Before "identity theft" was created? Created by a process that was described, if I'm remembering the right bill correctly, as industry lobbyists standing in the hallway outside the Congressional committee room on their phones - stepping into the hall to call their clients back to ask what else they would like, and then cycling back through the room to add it? Hmm... could be. ;)
In other news, it seems the NYTimes has managed to use the phrase "regulatory capture" three whole times so far in 2018![1] Woo hoo! We'll be addressing this in no time at all. Right after rolling back copyright extension. And tech innovating better fora support for constructive public discussion. RSN. Maybe next week? :/ Sigh.
[1] https://www.nytimes.com/search?endDate=20181031&query=%22reg... But yes, it is possible to push on these things. History is contingent. And no one ever promised bootstrapping a civilization was quick or easy or monotonic.