[HN Gopher] Identity thieves bypassed Experian security to view ...
___________________________________________________________________
Identity thieves bypassed Experian security to view credit reports
Author : picture
Score : 408 points
Date : 2023-01-09 14:14 UTC (8 hours ago)
(HTM) web link (krebsonsecurity.com)
(TXT) w3m dump (krebsonsecurity.com)
| agency wrote:
| I'm not surprised in the least bit. I keep my credit locked
| constantly since I've had my SSN leaked multiple times (by US
| government agencies). Every time I go to unfreeze it when I apply
| for credit at least one of the big 3 credit reporting agencies
| lets me unfreeze it without specifying the PIN I had to create
| when freezing.
|
| If there was any justice these companies would get the corporate
| death penalty.
| Loughla wrote:
| I froze mine years ago when the first leak of my SS# happened
| thanks to one of the stupid credit agencies.
|
| I was happy and secure in the knowledge that it was locked
| until I had to unlock it the first time. The password I set
| didn't work, as they had apparently changed the log-in system
| with no alert (also, now the stupid log-in sends us spam e-mail
| that we can't opt out of).
|
| I called them. I had my account unlocked, and the phone
| representative even gave me my own SS# within three minutes of
| being on the phone, and _by answering questions that were
| publicly available information_.
|
| It's an absolute fucking train wreck and I wish the system as a
| whole and the credit companies in particular were destroyed.
| Terretta wrote:
| > _... and by answering questions that were publicly
| available information._
|
| The 3 questions fraud check system everyone uses to
| performatively pretend to ensure you are who you are, can
| only draw the questions it asks from -- guess what --
| publicly available information.
|
| It's illogical on its face.
|
| // After identity theft, it gets worse, as thieves'
| fraudulent or real data will enter public records under your
| identity key, and now you can't pass your own check.
| rootusrootus wrote:
| PINs for freezes seems to be a thing of the past. I recently
| unfroze all of my credit reports momentarily so they could be
| accessed, and none of the big three asked for the PIN. They
| each have their own login and as soon as you authenticate to
| that, you're good.
| JumpCrisscross wrote:
| > _these companies would get the corporate death penalty_
|
| Would suggest replacing this in your vocabulary with "fines,"
| "license revocation" or "criminal penalties." Corporate death
| penalties, _i.e._ judicial dissolution or charter revocations,
| while a good slogan, don't make a lot of legal sense. As a
| result, I've found it in practice used to segregate activism
| and turnout operations (who like it) from rule and lawmaking
| influence (where it's not a serious concept).
|
| Massive fines, equal to market cap, or absolute liability,
| _e.g._ a $10k + legal expenses minimum owed to each person
| whose data leaked irrespective of actual damages, for example,
| are more specific and actually actionable.
| dylan604 wrote:
| I am not unsympathetic to your ultimate meaning. However...
|
| Take everyone's favorite whipping boy, Facebook/Meta, as the
| example corporation. At every turn, they have shown that they
| have prioritized greed vs community good. Any good they
| provide is only to further their pursuit of wanting more.
| Because they are so large, any upstart competitor with a
| total opposite ethos that might come about gets annihilated
| by the behemoth.
|
| If legal action were to give Meta the corporate death
| sentence preventing the company from operating and its execs
| from pivoting to somewhere else, then and only then could the
| competitors actually have a chance. So just because there's a
| death sentence for a corp doesn't mean the "people" lose as
| well.
| JumpCrisscross wrote:
| > _legal action were to give Meta the corporate death
| sentence preventing the company from operating and its
| execs from pivoting to somewhere else_
|
| Just do the second bit. The problem with judicial
| dissolution is corporations are a legal fiction. What you
| do with the people and assets is far, far more important.
| Ignoring the legal fiction to focus on those is my point.
| Take their stuff (fines). Force them to restructure (break-
| up). Limit their scope (corporate criminal penalties).
| Restrict their executives. "Corporate death penalty" is
| exactly non-specific enough to avoid specifying those
| prescriptions.
| dylan604 wrote:
| yes, but in coversation, are you going to list out those
| things every single time like that or are you going to do
| it once and then follow up with, "you know, the corporate
| death penalty?"
|
| i don't think it's nearly as non-specific as you think.
| if you ask people what a corp death penalty would be, my
| assumption would be that people would think of it as the
| corporation no longer existing. if you're saying that
| corps would just spin off assets as a new name, new corp
| charter, same people, same processes, then yes, that
| would be a valid concern. but we can at least state that
| once, and all agree upon it rather than continuing to
| repeat it like we're unable to understand the concept.
| JumpCrisscross wrote:
| > _ask people what a corp death penalty would be, my
| assumption would be that people would think of it as the
| corporation no longer existing_
|
| I mean, look at this thread. I'm not saying the impulse
| is wrong. But "corporate death penalty" seems to be a
| good way to take a discussion which _could_ lead to an
| outcome into one that won't. That's fine! People vent!
| But we shouldn't confuse venting with deliberating.
| dylan604 wrote:
| I just can't wrap my head around what your issue is here.
| Only lawyers talk like this. Are you a lawyer? People
| feel a corporation has committed such wrong doing that
| they should no longer exist. When that happens as an
| individual, it is known as the death penalty. Applying
| that same phrasing to a corporation comes with the same
| understanding. You're pedantry in this case are quite
| trite
| kelnos wrote:
| Not the person you're replying to, but I think the issue
| is that the individual vs. corporation analogy doesn't
| work. If you kill a person who has done bad things, you
| will indeed prevent that person from doing bad things in
| the future. If you kill a corporation (via legally
| dissolving its charter, the "corporate death penalty"),
| then you will not keep the individuals and investors
| associated with that corporation from doing bad things,
| as they will likely reorganize into a new entity and
| continue to do those bad things.
|
| I agree that there's an element of pedantry there, so if
| (as the GP suggested), someone is just venting and
| doesn't care about a specific outcome, saying "give them
| the corporate death penalty" is fine. But the downside is
| that if someone reads that, and looks up legal corporate
| dissolution, they might get the wrong idea that this sort
| of remedy will actually fix the problem. Or they might
| not even do any research, and just decide to start
| throwing around this term themselves, without really
| understanding what it means or what it does (and doesn't)
| accomplish.
|
| But I also agree that listing out other specific remedies
| (market-cap-sized fine, jailing executives, whatever) is
| long-winded and annoying, and maybe not really useful or
| relevant unless the discussion is actually about what
| specific remedies might be effective.
| r00fus wrote:
| I'd agree except for fines.
|
| If the fines are < the advantage to scoff the law, such a
| fine just puts a price tag that can be used in a cost-benefit
| calc for the company.
| atherton33 wrote:
| The fines should be to the shareholders. Ownership should be
| determined recursively to all actual humans. No trusts, no
| corporate owners, no funds.
|
| A strawman: Maybe proportion of ownership times current
| assets and all future income. Whatever fraction of their
| financial being is proportional to their share of the
| corporation is "dead".
|
| If you have X% ownership share, you are fined X% of all your
| current assets and X% of all future income.
|
| A message needs to be sent that it's not okay to invest in a
| company that is doing harm and then walk away from it. You're
| ethically and morally liable, the law should reflect that.
| nine_k wrote:
| I understand "corporate death penalty" as a dissolution of
| the corporation, likely with some cool down time for the
| execs found guilty when they cannot work as execs.
|
| No violence should be involved. Large layoffs resulting from
| that won't be pleasant one bit though.
| fragmede wrote:
| [flagged]
| dabraham1248 wrote:
| The theory is that, _once it becomes policy and happens a
| couple of times_, employees will pay attention to what
| their company is doing, and get out if they think they're
| in danger. It aligns individual morality with self
| interest, and will crater a company that starts sliding
| towards dissolution.
|
| Thus actual enforcement becomes almost a non-issue.
|
| I'm not sure I buy that the janitorial staff is supposed
| to keep up on the dark patterns in the sign up page, but
| that's the theory.
| anonymouskimmer wrote:
| To be consistent you'd have to be opposed to venture
| capital shutting down and selling off companies as well.
|
| To be fully consistent you'd have to be opposed to
| firings and layoffs in general (except as the result of a
| commission of a crime by the person so fired).
|
| I'd be happy with a corporate death penalty that resulted
| in the stockholders being wiped out, the executives (and
| possibly board) being fired and barred from the industry,
| and executive control of the company being taken over by
| someone like John J. Ray III. This would allow either a
| restructuring of the company or gradually winding it down
| in such a way that the non-executive employees and
| bondholders aren't screwed over.
| bastawhiz wrote:
| If I start a company with the express purpose of having
| it commit crimes, it will be shut down and everyone
| employed will be fired. That's not on the government,
| that's on me, the employer. So then where is the line
| that we draw that says how badly a company needs to
| behave or how many crimes it needs to commit to justify
| it being dissolved? We should not tolerate crime for the
| sake of the livelihoods of the henchmen. "The death star
| is bad, but think of how many people would be unemployed
| if we stopped them" is exactly the argument they want you
| to make.
| nisegami wrote:
| Violence is the only language the state knows.
| jazzyjackson wrote:
| I would suppose whoever is being _forced_ to terminate
| their employees is doing so under the threat of state
| violence (men with guns), but the employees being fired
| are not being threatened with any force, they 're just
| losing their job.
| JumpCrisscross wrote:
| > _dissolution of the corporation_
|
| Corporations are a legal fiction. What does dissolving the
| corporation mean? Revoking its charter? Then what happens
| to its assets? If you return them to shareholders, you've
| given a boon to its wealthiest, who can now re-organise it
| free of prior liabilities. If you liquidate them, you've
| delivered a junior fine, since with real fines the fine
| gets paid before creditors. If you take it, you've
| expropriated (also, fines with extra steps).
|
| In every case, what you want from a "corporate death
| penalty" is better effected with actual penalties. A
| market-cap sized fine is more specific and more actionable
| than a "corporate death penalty," which is why I suspect
| the latter is in circulation.
| soco wrote:
| I'm pretty confident it wouldn't come to layoffs. If Meta
| faced such a risk they would simply follow the rule.
| Remember how many times they threatened to leave EU?
| tomrod wrote:
| A corporate death penalty would be:
|
| (1) Dissolution as a viable entity in the US
|
| (2) All assets sold paid out to wronged parties before debt
| servicing or shareholders
|
| (3) All officers barred from holding political, non-profit,
| or corporate office at any level in the US states or
| territories, as well as removing the veil of corporate
| liability from officers. All technology and security
| employees have liens put in place to pay affected parties as
| well.
|
| When we mean death sentence, we mean it.
| ncphil wrote:
| Huh. So basically these guys got access to stuff that thousands
| of companies and governments who subscribe to Experian already
| have, but didn't pay for it. Color me outraged.
| tibbon wrote:
| Why isn't there more regulation on these? It seems something that
| 99.9% of voters would want to get behind. These credit report
| agencies horde data and then misuse it so frequently. It feels
| like there needs to be some accountability for misuse of data
| like this and breaches, especially when there's essentially no
| way to opt out and still function in society.
| xyst wrote:
| like the online tax return companies, their lobbyists push for
| minimal regulation
| int_19h wrote:
| In a representative democracy, it doesn't matter whether 99% of
| the voters are behind the issue. What matters is where that
| issue is in the overall stack ranking of "important" issues,
| where "important" is defined as "effective for the purposes of
| winning elections".
|
| Basically, when it comes to voting, is _this_ going to be the
| reason why you vote one way or the other? Or is it going to be
| the usual cocktail of taxes, abortion, immigration etc? If you
| have an opinion - no matter how strong - but they already have
| your vote, why should they care about it?
| SketchySeaBeast wrote:
| Every single report like this serves to make me feel sick and
| angry. These organizations are responsible for so much data that
| can literally ruin lives and they can't be bothered to think
| through their solutions. It's not but should be criminal.
| asah wrote:
| Specifically, personal penalties for the exec teams. Do this
| once, and they'll take 10x the level of care going forward.
| pwg wrote:
| > personal penalties for the exec teams.
|
| Yes, but the penalties have to be such that the exec does not
| simply view it as "cost of doing business" and mark it down
| as a business expense.
| thefurdrake wrote:
| 5% of their investment of the company per offense.
| asah wrote:
| good point - also can't be covered by an insurance policy
| or reimbursement or pay increase or special bonus.
|
| I guess we're arguing for non-financial penalties...
| bobkazamakis wrote:
| If security doesn't impact their bottom line, it's just another
| beautiful salary for the C suite to parachute off of.
| [deleted]
| gorbachev wrote:
| What's absolutely infuriating about this is that Brian Krebs has
| sounded the alarm about Experian's horrible security for a very
| long time, and Experian has done jack shit about their problems.
|
| This company needs to be shut down. It's incapable of
| safeguarding PII in a reasonable way.
| coldcode wrote:
| Until our government creates a law that makes the credit
| bureaus have to pay every time their security fails, nothing
| will happen. They don't have to care and probably laugh at all
| of us. But politicians are cheap to buy off and nothing
| changes. I am sure all 3 of them have huge legal teams anxious
| to slap you silly if you try to sue them.
| dboreham wrote:
| Ugh. "Identity Theft" is a term invented by the finance industry
| to victim-blame when their weak authentication mechanisms are
| compromised. We should instead talk about "Banks being defrauded
| by criminals due to lax procedures".
| dragonwriter wrote:
| > "Identity Theft" is a term invented by the finance industry
| to victim-blame
|
| "Identity Theft" blames to the exploiter, instead of the
| (possibly negligently) exploitable system; it is shifting
| blame, but not principally to the victim.
|
| > We should instead talk about "Banks being defrauded by
| criminals due to lax procedures".
|
| If we want to focus responsibility on the banks, we should
| instrad talk about "Banks failing to safeguard customer funds",
| or "Banks enabling criminals to steal customer funds."
| janalsncm wrote:
| Just so it's clear, if person A borrows money from bank B
| under person C's name, person C will have to fix the problem.
| And make no mistake, it's a huge problem. It will affect
| person C's credit score and potentially cause loss of
| property as bank B will hound person C for their money back.
| This is in spite of the fact that there may be no
| relationship between B and C or A and C. And then credit
| reporting agencies D will happily report the lie from B, that
| C owes money to B.
|
| It's completely upside down. And good luck getting the local
| police to fix the issue.
|
| https://youtu.be/otU-1Il7GfM
| li2uR3ce wrote:
| I'm not surprised Experian's security is shit. Equafax proved
| that there are basically no consequences. Here's some basic free
| credit monitoring that you probably already had for free.
| surume wrote:
| This isn't the first time that a major Credit Bureau has had a
| data leak, is it? Wasn't there a huge one a few years back?
| exogenousdata wrote:
| [dead]
| berkle4455 wrote:
| Experian and Equifax have security leaks all the time yeah
| surume wrote:
| "Identity thieves have been exploiting a glaring security
| weakness in the website of Experian"
|
| Shouldn't Experian have been thoroughly audited by the gov't
| after the last major data breach? The above sounds pretty out
| in the open, no?
| lesuorac wrote:
| > Shouldn't Experian have been thoroughly audited by the
| gov't after the last major data breach?
|
| That sounds pretty unconstitutional. Why would the USG
| audit a private company for security?
| AlotOfReading wrote:
| It seems like it'd be a national security issue at the
| very least. Those databases also contain an up-to-date
| financial picture of government employees holding
| security clearances. Even if clearance holders are
| nominally supposed to remain above-board and
| unsusceptible, I'm willing to bet that enough data mining
| would allow decent targeting. The DoD is already
| monitoring those employee's credit reports, so clearly
| there must be _something_ actionable in them and it 's
| quite likely they miss something.
| thefurdrake wrote:
| Which part of the Constitution is violated by the
| government scanning a website's publicly-available,
| advertised resources on the clearnet?
| lesuorac wrote:
| Unconstitutional just means it's not in the constitution.
| My claim is that nowhere in the constitution does it
| require the USG to audit a private company for security
| (especially in conjunction with an after major data
| breach clause).
| thefurdrake wrote:
| Yeah, I guess that ensuring foreign actors can't publicly
| dump massive amounts of data on an arbitrary number of
| american citizens to be used in economic warfare
| definitely doesn't fall under any mandates that the US
| government has...
| lesuorac wrote:
| Yeah, if it did you would've quoted it.
| SPORTSCRYPO wrote:
| [dead]
| smarri wrote:
| "you simply change the last part of the URL from "/acr/oow/" to
| "/acr/report," and the site would display the consumer's full
| credit report."
|
| Unreal.
| charles_f wrote:
| > you simply change the last part of the URL from "/acr/oow/" to
| "/acr/report," and the site would display the consumer's full
| credit report.
|
| Oh wow, that's one of the dumbest security hole I've seen so far.
| That means you're either authenticated in the first screen, or
| the second assumes that you are whom you say you are if you lend
| on it. There's a clear lack of ethics from whomever built that,
| whom either didn't care, or didn't know enough know enough to
| excuse themselves from building it and ask for assistance.
|
| I mean, this is not your regular system. Everyone is in there,
| not that they have much of a choice, and it's their most
| sensitive data, that you decide you're up to the task to protect.
|
| I'm all for learning from your mistakes and I'm the first one to
| screw up once in a while, and to admit that I am not a security
| expert. But the size of this combined with how freaking dumb this
| issue is... This is most likely gross negligence. In most of
| other industries where people call themselves engineers, you
| would be putting your own professional reputation on the line
| when deciding you're up to the task. Then you would get in front
| of am ethics commission and likely get your license suspended or
| revoked.
| xnorswap wrote:
| It's just a classic IDOR, it's very easy to fall into with some
| frameworks.
|
| If you look, you see it everywhere. When stack-exchange rolled
| out their CV feature they had a similar thing which leaked
| everyone's email address regardless of the public profile
| visibility or whether they had even used the CV feature.
| bcrosby95 wrote:
| I seem to recall github having this security hole in spades
| about a decade ago.
| bmitc wrote:
| > There's a clear lack of ethics from whomever built that, whom
| either didn't care, or didn't know enough know enough to excuse
| themselves from building it and ask for assistance.
|
| I highly doubt that Experian attracts the best and brightest.
| And when you have a company that doesn't provide any features
| to the consumers whose data they collect, control, and sell
| except when sued, you get stuff like this.
| mancerayder wrote:
| These folks never did a basic penn test ? Unauthenticated
| access to a different URL seems like a common thing to test
| for.
| acdha wrote:
| That's ... optimistic in my experience. I've had reports
| include breathless disclosures that our application was
| leaking private information because robots.txt could be
| accessed without authentication, or that we were disclosing
| source code (front-end JavaScript).
|
| Places which treat security as an audit checkbox are going to
| try to outsource that work to save money and they're going to
| get people who have enough skill to run a few basic tools but
| not to reason about the results or do anything creative.
| Experian seems highly likely to be on that side since they've
| been able to avoid any significant penalties for past
| negligence.
| suzzer99 wrote:
| I'm still struggling to think how this could have happened. I
| wonder if it has something to do with interaction with
| annualcreditreport.com?
|
| Maybe originally the code had multiple levels of authenticating
| the user: 1) we know who you are, but you haven't proven it
| yet, and 2) you've proven it, now you can see everything.
|
| But when they integrated with a 3rd party, which could have
| been a decade or more after the original code was written, some
| developer who didn't understand the code just lumped everyone
| who came over from annualcreditreport.com into basket #2, even
| though that user still had to go through the url flow to prove
| themselves. Just a guess.
|
| I don't think most non-programmers realize how often preventing
| this kind of thing comes down to one developer making a stink
| repeatedly to indifferent higher-ups. If that one developer is
| incompetent or doesn't care, no one else does.
| xnorswap wrote:
| I don't know about this case, but a lot of the time this
| class of vulnerability comes down to lack of Authorisation
| rather than lack of Authentication.
|
| So much effort is put into checking that people are who they
| say they are (is Person X really Person X) , they forget to
| check that they're authorised (is Person X actually supposed
| to be accessing resource Y).
|
| Given the URLs don't have the actual resource Identifier, it
| means the resource ID will have been gathered from somewhere
| else, typically one of three places:
|
| 1. Cookies / Localstorage - Easily manipulated and should
| never be treated as a secure place, it's easy to put simple
| values here and forget that they still need to be validated /
| checked server side, and that just because you have access to
| /foo/Y you might not also have access to /bar/Y.
|
| 2. Session - An ASP favourite, sticking something in a key
| like Session["FolderID"] you might assume you've validated
| and checked authorisation when you set the key, then later
| re-use (deliberately or accidentally) the same key elsewhere
| leaving it open for manipulation. And then you might assume
| you don't need to re-check authorisation when you read the
| key.
| suzzer99 wrote:
| The only way to write something super sensitive like this
| imo is to have the back-end API that retrieves full credit
| report be essentially hard-wired to a user access level of
| "FULLY_VALIDATED".
|
| That way no developer can come along five years later and
| accidentally grant the wrong access level or show the
| report to a not fully validated user. Put the security
| check on or as close to the thing being accessed as
| possible.
| herpderperator wrote:
| I wouldn't call the "session" concept an ASP favourite -
| it's the industry standard for any backend web framework to
| use a user session where the session key is stored as a
| random cookie value and the actual key-value pairs are
| stored on the backend somewhere.
| xnorswap wrote:
| That's fair, I associate it as an ASP favourite to mess
| it up and cause all sorts of security holes with it!
|
| Probably just a lot more inexperienced developers
| treating it like a magic authenticated bag without enough
| warnings about improper use in the documentation.
|
| Also a very easy "go to" store via global variable in ASP
| made it especially easy to use it as a go-to solution for
| anything that you couldn't be bothered to properly store.
| 8note wrote:
| Credit agencies have no reason to care about their security wrt
| your data. You aren't their customer, and they don't owe you
| anything
| ec109685 wrote:
| This is where per-user level encryption of data should be used.
| If your credit report on that site is encrypted and the keys
| are only successfully derived by answering your security
| questions, you've added another layer of security [1]. It also
| prevents the situation where a hacker gets access to the box
| doing the security check, and they can read everyone's data
| versus just those users who are concurrently asking for their
| reports.
|
| Even simpler, this would be prevented if /acr/oow set a
| decryption key as a cookie after validating the verification
| data that was then used by /acr/report to decrypt your credit
| report.
|
| [1] Yes, it's possible to enumerate over all user's security
| answers, so it's not perfect, but it ensures a simple mistake
| with an if condition, doesn't release everyone's data.
| vinceguidry wrote:
| It's nineties-level internet security. Stuff like that was the
| bread and butter of security researchers of that era.
| NovemberWhiskey wrote:
| I mean, sure, but nothing has changed since: "Broken Access
| Control" is still #1 on the OWASP Top Ten for 2021.
| contingencies wrote:
| Closely related period fail: _/ receipt/<sequential-receipt-
| number-here>.pdf_ = all customers full booking history and
| personal data for all time.
| jimhefferon wrote:
| It seems like they owe us all compensatory damages. Big
| damages.
|
| I never really understood how they could take my information,
| which presumably belongs to me, and then could use it to make
| millions. How about my cut?
| seanw444 wrote:
| Why everything is tied to our SSN, I don't understand. Why we
| allow private companies to manage our US social credit score, I
| don't know either. There are a lot of things we've done here that
| make no sense.
| ncphil wrote:
| ... because back in the 70s it was decided that disclosure
| (a/k/a "transparency") was all we'd ask of private companies
| (with exceptions, as in, some companies aren't even expected to
| disclose). Who do you think _actually owns_ the U.S. Congress
| anyway?
| jmclnx wrote:
| The main reason is "the mark of the devil", every time the US
| Federal Gov. wanted to issues ID Cards, that came up. Just look
| at the "Real ID" issues, but that is still not a useful ID for
| everyone.
|
| Also if you look at your Social Security Card, it states "Not
| to be used for identification". But Companies, Univ and
| everyone ignored that because they wanted a Unique Number. Not
| may people realize the SSN is recycled as people die off.
|
| I wish the US Gov would sue all Companies and Orgs that used
| the SSN for ID purposes for trillions and return that amount to
| people with Social Security Numbers.
| catiopatio wrote:
| No, the issue isn't religious irrationality -- it's
| understanding the inherent dangers of a mandatory government
| identification system and not wanting one.
|
| Unfortunately, we have several anyway, but that's no reason
| to accept a universal inescapable federal ID that we would
| never be able to roll back.
|
| > I wish the US Gov would sue all Companies and Orgs that
| used the SSN for ID purposes for trillions and return that
| amount to people with Social Security Numbers.
|
| At least on that we agree. The SSN bas become a poor,
| backdoor replacement for federal identification documents --
| which is exactly what people were worried would happen, and
| why they received the sop of "not for identification". That
| didn't last long:
|
| https://www.nytimes.com/1998/07/26/weekinreview/the-
| nation-n...
| reidjs wrote:
| What's the downside of a universal federal ID?
| supertrope wrote:
| If nearly all choices and utterances are linked to the
| same database and can be used against you in ways that
| don't even exist today people will feel a strong chilling
| effect. We have bankruptcy and privacy laws specifically
| so the owners of these private ledgers and databases do
| not entirely control our lives.
|
| The issuer of an universal ID gains gatekeeping power.
| Besides the danger of people getting excluded, children
| and marginalized demographics won't have one.
|
| Ironically widespread deployment of an ID can sometimes
| lead to more fraud. Bureaucracies tend to confuse
| identification, authentication, and authorization.
| Possessing a scan of a passport is often accepted as
| possessing the passport which is accepted as authority to
| transact with that name. Through the transitive property
| possessing a hacked .jpg can allow a fraudster to
| transact as you. When businesses and bureaucracies are
| not liable for fraud or their errors, they focus on the
| ID tokens as a way to improve throughput instead of
| assessing the legitimacy of the transaction in a holistic
| manner.
| landemva wrote:
| The credit bureaus are moving in to work/payroll verification by
| hoovering payroll data that US companies voluntarily give to
| them. They sell access to data to people verifying income for
| loan application, and law offices, and child support services.
|
| I got job offer and told recruiter to put in writing that my
| payroll data will not be released without a court subpoena. Am
| waiting on response from recruiter. My outlook is that HR does
| not care about employees if they purposefully leak this info.
|
| Those concerned may want to ask their HR about payroll data
| sharing.
|
| https://www.experian.com/consumer-information/employment-inc...
|
| https://theworknumber.com
| d4mi3n wrote:
| This can be more complicated in certain industries where a
| relationship with a credit agency is otherwise required. I
| worked at a fintech b2b lending company a while back that
| worked closely with all the big agencies and I distinctly
| recall that the company got favorable rates for opting in to
| payroll sharing when negotiating rates for other services from
| Experian.
|
| It was sadly before my tenure at the company and I only became
| aware of it much later, but I would not be surprised if
| agencies are leveraging their other produces to incentivize
| more companies to share this salary data.
|
| In the meantime I'm going to continue exercising CCPA wherever
| I can and hope we see some legislation or court cases at the
| federal level to address some of these issues.
| arcturus17 wrote:
| I mean, from what you're saying, it's complicated in the
| sense that the credit bureaus are exploiting their customer's
| greed, because if the customer really cared about their own
| employees, they would say no to the discounted rates, and
| that would be the end of that. No?
| d4mi3n wrote:
| You're correct, but I believe this line of thinking is a
| simplification. If you operate a public company and your
| shareholders demand a return, odds are you'll have a board
| that's going to force you to have specific policies. Some
| of those policies are along the lines of "take any
| discounts you can get on things that cause operational
| expenses."
|
| The only real way around this is having shareholders that
| care about employee privacy, and I think _that_ will only
| happen if these privacy issues impact the bottom line in
| some way (difficulty hiring, increased costs, etc).
|
| It's frustrating in that this behavior is cultural and
| endemic to how businesses operate in the US. Change is
| possible, but it requires support from more than just the
| line of business employees and management.
| arcturus17 wrote:
| > but I believe this line of thinking is a simplification
|
| Yea, sure. I wasn't meaning to take a hard moralist or
| anti-system stance, when I say "the company is greedy" I
| understand the company and its people are a cog in a
| larger machine.
|
| There is a simpler way out than waiting for a cultural
| change to stop that practice, though: regulation.
|
| I'm not entirely sure, but I doubt that here in Europe
| it's so easy for companies to sell payroll data - if at
| all legal. At any rate it sounds like an abhorrent
| practice.
| acdha wrote:
| > If you operate a public company and your shareholders
| demand a return, odds are you'll have a board that's
| going to force you to have specific policies. Some of
| those policies are along the lines of "take any discounts
| you can get on things that cause operational expenses."
|
| There's a lot of mythology around that, however: managers
| are giving a large amount of discretion about business
| decisions because it's extremely rare that there are no
| trade-offs for any decision. For example, you could save
| a lot of operational hosting expense by switching from
| AWS to Bob's Bait Shack and Server Farm. In this case,
| you could argue that the risk to employees is significant
| and would potentially spill over to the company if leaked
| information was used to compromise them.
| rednerrus wrote:
| https://www.reddit.com/r/overemployed/comments/v4y76m/how_to...
| cptcobalt wrote:
| Is this something that HR can typically & easily control with
| the systems they use?
| jrumbut wrote:
| That depends on the systems they use. I appreciate the OP for
| making at least one office give a moment's thought to it.
| kccqzy wrote:
| I happened to chat with HR when I did the opt-out. They
| claimed, which I didn't believe, that most employees actually
| benefit from it because they get streamlined approval for
| personal loans and mortgages. I think it's just a way for them
| to cut down on support requests from employees (like "Hey HR I
| urgently need you to provide my last three pay stubs or
| employment verification letters").
| [deleted]
| switch007 wrote:
| Lol HR have an arsenal of excuses/bs on hand, always. "Most
| employees actually benefit" Christ
| mcculley wrote:
| They should also ask their mortgage and auto loan provider. I
| was running a consultancy when Paysa came online. We were
| surprised to see it knew a lot about compensation and titles of
| most of my employees. But not all of them. We found that the
| common thread was employees who had recently applied for
| loans/mortgages. They had submitted paystubs as part of the
| application process which were then sold.
| meesles wrote:
| Unfortunately you won't stop the tide with simple data
| practices. If they can't slurp up the the data automatically,
| they have an army of people making phone calls to gather
| employment data from other sources to add to their database.
|
| We use them as a provider (unfortunately), and when they don't
| have the data on hand we have to handle cases where it can take
| a few days for them to call the business and confirm employment
| directly with someone who works there. At that point, I don't
| think where you work has a reasonable expectation of privacy
| since you walk there, probably put it on your LinkedIn, talk
| about it with friends/family, etc.
| danuker wrote:
| > put it on your LinkedIn
|
| I stopped doing that when LinkedIn added their loginwall.
|
| Clearly LinkedIn wants to harvest data while at the same time
| making it difficult for others to do so, which would go
| against my interest of making it public.
|
| So I posted it on my own website. Goodbye to another
| centralized point of failure/control.
| notch656c wrote:
| People are lazy. If they can't get the information a very
| large portion of them will rubber stamp it or just ask you if
| it's true, possibly to provide some evidence which they will
| be to lazy to verify as authentic.
|
| >it can take a few days for them to call the business and
| confirm employment directly with someone who works there
|
| If you hire out this kind of work, half the min wage slaves
| getting screamed at with hot breath down their neck for "low
| productivity" are gonna call once at most and likely not at
| all and then check it off. Speaking as someone who has worked
| at a call center along with the populace which was basically
| people on work release/probation.
| kevin_thibedeau wrote:
| > If they can't get the information a very large portion of
| them will rubber stamp it
|
| They'll just toss your application out without a human ever
| seeing it. You're clearly a noncompliant troublemaker and
| not worth hiring.
| notch656c wrote:
| Most places don't do much vetting of your background
| until you're hired. At which point it can be a lot of
| work to offer to someone else, especially if it's been
| more than a few days.
| beembeem wrote:
| Keep in mind that the large employers _pay_ Equifax _and_ give
| them your pay data.
|
| Equifax/TWN has a brilliant business model that should be
| illegal. Get paid to collect data, then resell it.
| starwind wrote:
| You can freeze the worknumber so people running background
| checks can't get information. When I changed jobs the company
| ran a background check and they kinda freaked out cause they
| couldn't get anything out of this database. I loved it.
| landemva wrote:
| I wonder if security of the payroll data lookup is even worse
| than the credit report website. A 'freeze' may be worthless
| if the data leaks are large. And a person making $18/hour to
| do child support case management may interested in making
| extra cash by looking up other people for a fee.
| Scoundreller wrote:
| Gartner has predicted by 2038, the average American will
| spend 17 hours per day opting out of things they never opted
| into.
| bmitc wrote:
| I can't tell if that's a real report or something from The
| Onion.
| hedora wrote:
| Do they predict what percentage of trackers this continuous
| coke-filled click-fest will actually disable?
| TeMPOraL wrote:
| They did not, because the number wasn't estimated by
| adding up predicted time per tracker or service, but by
| determining this is about the maximum the market can bear
| - i.e. a steady state of the system.
|
| Curiously, Stratfor also predicted 60% chance of the US
| going to war with the EU before 2036, due to EU privacy
| regulation threatening to shut down the increasingly
| adtech-based US economy.
| thechao wrote:
| This _serious_ analysis is stupider than the entire plot
| of Idiocracy.
| toomuchtodo wrote:
| "How to freeze your work number"
|
| https://news.ycombinator.com/item?id=33212195
| MerelyMortal wrote:
| I would do the verification over email as that means they
| didn't typo whatever email you gave them (easier to typo an
| email address rather than a phone number).
| [deleted]
| josephcsible wrote:
| > I got job offer and told recruiter to put in writing that my
| payroll data will not be released without a court subpoena.
|
| Doesn't this kind of demand usually just result in you not
| getting the job?
| nkrisc wrote:
| Yeah, probably more often than not. But if you've got in-
| demand skills and can afford to be choosy, then go for it if
| it's important to you.
| landemva wrote:
| Not all companies give out payroll data. Better to learn now
| if finance/HR doesn't protect their employees and to decline
| the offer. Lack of qualified applicants ... or people have
| had enough. I do not consent.
| dwardu wrote:
| It would be a bullet dodged if so
| ipython wrote:
| I strongly suspect this was more widely exploited than what's
| being let on. I have received hundreds of Medicare robocalls
| where the caller was suspiciously able to suss out a fake dossier
| - even though street addresses and names would be plausible, but
| the birthday and SSN were fake.
|
| I would definitely investigate this further to see if this
| knowledge was in the hands of criminals/scammers who were selling
| access for $$ over the past few years.
| davidkuennen wrote:
| It still boggles my mind how much you can do with another persons
| SSN in the US. It's like a password for your life in plain text.
| Crazy.
| sofixa wrote:
| It's interesting seeing the American credit model malfunction so
| badly so often (massive data leaks, crappy gaming of the system -
| even today i read on HN not to pay off your mortgage if you don't
| have any other loans or it might tank your credit score).
|
| As with a couple of other things, it's basically the only
| developed country with this model (useless for-profit middlemen
| for no good reason), it really sucks for the average consumer,
| yet there is no actual change coming. Why? Is it American
| exceptionalism refusing to acknowledge that there are better ways
| used elsewhere? Is it free market "absolutism" hoping the market
| will fix itself?
| user3939382 wrote:
| > Why? Is it American exceptionalism
|
| Because our government is completely corrupt and doesn't
| represent the interests of the People, at all. It serves and is
| beholden to large corporate interests, chief among them banks
| and financial institutions. In a just system that represented
| our interests Equifax would be forbidden from compiling
| consumer data after what they did.
| seniorThrowaway wrote:
| Exactly, and the best part is it is all out in the open but
| the majority of people either don't understand or don't care.
| The corporations openly write legislation via their
| lobbyists, huge bills that congress themselves don't even
| fully read let alone write. I've just about given up hope
| that this will ever change.
| user3939382 wrote:
| The 2014 Princeton study
| https://doi.org/10.1017/S1537592714001595 highlighted
| https://i.imgur.com/eH6YcWn.png what a corrupt sham our
| "democracy" has become.
| jollyllama wrote:
| It's not really malfunctioning, in my opinion. It's more or
| less designed to violate individual privacy and offer as many
| people access as efficiently as possible.
|
| Neither free market absolutism nor exceptionalism are the
| reason that it's designed this way. At least, not in the way
| that I think you mean it. Rather, it's because the current
| economy of the USA is an inflationary credit economy. It's a
| very un-free market; a great example is education. The
| government subsidizes loans which drive up the price, and put
| people in debt so that they are more desperate to take jobs.
| [deleted]
| lesuorac wrote:
| I mean, a credit report is only useful if it actually tells
| me about _your_ credit worthiness.
|
| Sure, some Elon Musk guy might have enough credit worthiness
| to make a $44 billion purchase. But are _you_ Elon Musk or
| just some guy impersonating Elon Musk? Fraud may not be
| rampant enough currently but if Experian/etc continue to help
| fraudsters it will just keep getting worse.
| jimbob45 wrote:
| Are you able to offer a better system that is/was working in
| another developed country?
| sofixa wrote:
| I can tell you about the system here in France - when you
| apply for a loan, the bank asks for some information (your
| salary, marriage status, kids, etc.) from you to see what
| you're capable of to spend monthly, and checks with the
| national bank what loans you have/had, and if you've
| defaulted on any of them. That's it, they don't need to know
| more, and the national bank doesn't keep track of everything,
| only very basic loan information (and of course they have no
| for profit motive), and nobody outside of a bank where you're
| applying for a loan uses this information to define your
| worthiness as a tenant or employee.
| aantix wrote:
| But why not?
|
| Failure of paying back a loan prior - why would I want them
| as a tenant?
|
| If you had a friend that failed to pay back loans, would
| you want to make a future loan to them?
| toomuchtodo wrote:
| Depends on the terms. People change, situations change.
| It's a big reason why finance firms in the US are
| attempting to move away from the three CRAs to cashflow
| underwriting; it turns out credit scores aren't a great
| forward looking proxy for repayment ability.
| astura wrote:
| >even today i read on HN not to pay off your mortgage if you
| don't have any other loans or it might tank your credit score
|
| Only when it drops off your report, which is 10 years after you
| pay it off.
|
| If you were so concerned about having a line of credit on your
| record then open up a credit card and don't use it, no reason
| to pay thousands of dollars in interest to avoid an abstract
| fear of "tanking your credit score."
|
| >it really sucks for the average consumer, yet there is no
| actual change coming
|
| I am an average consumer. The credit system is great for me!
| I'm able to demonstrate my responsibility and as a result I'm
| able to obtain a large amount of credit products at very low
| cost as well as pay less for insurance. I guess you can argue
| that the government should be providing this service rather
| than private companies or there should be more regulations
| around security, but the system only "really sucks" for people
| who take out loans and don't repay them.
| hedora wrote:
| Funny story:
|
| Rocket mortgage fraudulantly tanked our credit score and
| refused to fix it. The other bank's underwriting department
| looked at it, shrugged, and honored the mortgage office's
| request for an override to give us the best available rate.
|
| IMO, Credit ratings are theater.
| [deleted]
| mrguyorama wrote:
| I had $60k in the bank and was paying $12k down on a used
| car that cost $28k and would be worth $30k the second I had
| the keys (the dealership seemed to low ball it a little,
| probably because they were a new volvo dealership with one
| GTI on the lot they had for like a couple months that they
| needed to get rid of), but no, they still needed to check
| my credit, which at the time did not exist, and still
| required me to sign up to $2k interest payments over a 5
| year loan that would have been more profitable if I never
| paid a cent and they could reposes the collateral.
|
| I know there are contrived ways I could have killed the
| value of the vehicle before the loan was done and they
| couldn't recoup it, but like, come on. My credit report was
| BLANK. It was never needed in the first place.
| barbecue_sauce wrote:
| Why do you consider yourself an average consumer?
| runarberg wrote:
| I would love to see some data about this but it wouldn't
| surprise me if many USA residents don't have a credit score
| at all, or if they do, it is very minimal. Given how many
| are underbanked, I wouldn't be surprised if the average
| credit score is heavily skewed by the people gaming it.
|
| Anecdotally, neither me nor my partner have a credit score.
| I know several people where I'm living that are permanent
| renters/get owner financed loans, buy used cars with cash
| (or are simply given old cars, or don't have a car at all).
|
| I did a superficial search and found some census data
| (https://www.census.gov/data/datasets/time-
| series/demo/cps/cp...) but I have no idea how to read it.
|
| Edit: Looks like my suspicions have some merit:
|
| > 22% of Americans do not have a credit score. Half of this
| percentage has a stale credit score that makes it
| impossible to generate a valid FICO score while the other
| half do not have any credit file with any of the three
| credit bureaus--Equifax, Experian, and TransUnion.
|
| > 18% of Americans have credit scores that fall in the
| 580-669 range of "fair." those in the fair range are
| considered sub-prime and have lower chances of qualifying
| for a loan or getting better interest rates.
|
| https://comparecamp.com/credit-score-statistics/
| runarberg wrote:
| I posted on my sibling that 22% of Americans have no credit
| and of the ones that do have credit, 18% have a subpar credit
| score. That sums up to over a third of Americans that the
| credit system is either working poorly or not working at all.
|
| Maybe you are indeed an "average consumer" (whatever that
| means) but if you are, then the credit system is heavily
| skewed in your favor, with many "non-average consumers"
| falling by the wayside.
| toast0 wrote:
| > Only when it drops off your report, which is 10 years after
| you pay it off.
|
| I haven't seen what happens at 10 years, but there's
| definitely an effect after about a year; mine dropped 50
| points, which isn't really tanking, but could switch you into
| a different risk category depending on where you started.
| Finishing up my car payments didn't help either.
| staringback wrote:
| Credit Karma isn't a real score.
| toast0 wrote:
| Who said anything about them? This is on scores reported
| in my online banking.
| staringback wrote:
| Then your online banking is using the same fake score as
| Credit Karma (usually called VantageScore or something
| like that)
|
| If you actually want to get the score that lenders use,
| experian.com will give you your FICO 8 score. This score
| considers all accounts open the same until they have been
| closed for 10 years.
| toast0 wrote:
| One of my banks says:
|
| > The FICO(r) Score pulled on [date] is the FICO(r) Score
| 8 based on Experian data, and is the same score that
| [name of institution] uses, along with other information,
| to manage your account.
|
| Another says:
|
| > The score provided here is FICO(r) Score 8, which is
| based on TransUnion(r) data and may differ from other
| FICO(r) Scores. Variations may also occur when your score
| is based on data from another consumer reporting agency
| or calculated at a different time. [name of institution]
| and other lenders may use different scores and other
| information in credit decisions.
|
| I'm not going to intentionally interact with Experian
| directly, unless I have to, so not going to compare
| there. From what I recall, when I last opened a loan and
| they disclosed the scores, they were within spitting
| distance of what I was seeing from my banks at the time.
|
| Now maybe FICO 8 score means something different than
| FICO Score 8; these guys like to be deceiving, and maybe
| some banks give the VantageScore, but mine seem to give a
| FICO Score 8.
| icedchai wrote:
| Paying off your mortgage won't "tank" your score.
|
| I paid off my mortgage almost 15 years ago. I have zero debt,
| no car loans or anything, and pay off my credit cards in full
| every month. My credit lines are barely utilized (single
| digit percentage.) My score seems to vary from 790 to 810.
| SoftTalker wrote:
| Using credit cards and paying them off is keeping ytour
| score up.
|
| If you have no debt and pay cash as you go for your
| expenses, you will eventually drop because the credit
| bureaus will have no recent data to compute a score.
| ufmace wrote:
| We should remember the reason why it was created - to replace
| decisions for approvals on loans, mortgages, apartment rentals
| etc being made by low-level individuals for a variety of
| arbitrary reasons. Many places made such decisions based on
| personal connections, class, race, and other such things. AFAIK
| most other places still use such systems. Replacing that with a
| system where everybody's worthiness and terms for such things
| is determined algorithmically based on numeric data is a great
| move towards equality.
| ndsipa_pomu wrote:
| There's a bunch of people making money from it and that usually
| takes precedence over whether it is fit for purpose in other
| ways.
| thinkmassive wrote:
| Yep, think of credit score as a rating of how likely a debtor
| will be profitable to creditors over the long term.
| tau255 wrote:
| I find it kinda similar to:
|
| -USA tax system where Turbofax created a niche for itself and
| fights hard to keep the system as convoluted as it can be to
| detriment of everyone
|
| -USA healthcare insurance system where insurance companies do
| the same
|
| Seems like best way to profit is to become a parasite that does
| not fix the problem but just defends the current situation.
| randommuser wrote:
| Does anyone have good resources on what other non us countries
| do? Asking as an American curious/wanting to learn more.
| worksonmine wrote:
| I don't have any resources to share but in my country the
| bank looks at my income - expenses then checks if I've
| defaulted on any debts. My limited understanding of the US
| system is that everyone has (often several) credit cards to
| build the necessary credit score. Here owning a credit card
| is for people drowning in debt who struggle to pay bills on
| time or in rare cases new money flexing their amex black,
| which is also shunned upon.
|
| I've always thought the US system was super weird and
| backwards forcing debt on people. We don't have credit cards
| from every big chain and don't get harassed into signing up
| for cards in the mall, it's just not a thing.
|
| We have the same safeguards you have, but we prove it with
| sensible spending instead of getting debt just to prove that
| we can pay it in time.
| Nifty3929 wrote:
| "looks at my income - expenses then checks if I've
| defaulted on any debts" - This is basically what we do in
| the US as well. But HOW do they do this in your country?
|
| In the US, the loan originators look at year-end tax forms
| or recent pay stubs to verify income. They look at credit
| reports from e.g. Experian to verify defaults and other
| debt information.
| hungryforcodes wrote:
| Google is your friend...
| technion wrote:
| Australian here. When I apply for rentals I just went to my
| online banking and took a screenshots of the deposits.
|
| It's been years since I had my mortgage approved but I
| vaguely recall the process being very similar.
| nicolas_t wrote:
| I disagree with the better ways used elsewhere, as a French
| citizen who has worked abroad all his life, I can barely get
| anything. When I came back to France for a year due to my
| father's health issue, it was difficult getting an apartment
| because I had proof of income for more than 3 years in France
| (the current income I was declaring of 150k usd a year working
| remotely from France didn't count). People in France who have a
| CDI (permanent contract) can easily get mortgages and
| everything but entrepreneurs, people on fixed term contracts,
| etc... have a very hard time getting anything.
|
| With a US social security number that I got as a student and
| good management of my credit card accounts that I kept since, I
| have a good US credit score and can easily get a mortgage in
| the US. Of course, it's possible to game it, but you can also
| get a very decent score by just managing your finances well.
|
| So from my perspective, I think the US system works much
| better. Does it have issues? Yes, there's data leaks, there is
| some gaming of the system (by the way, paying off the mortgage
| won't tank the credit score, it'll lower it yes by a few
| points, but that's mostly inconsequential)
| mancerayder wrote:
| > I disagree with the better ways used elsewhere, as a French
| citizen who has worked abroad all his life, I can barely get
| anything. When I came back to France for a year due to my
| father's health issue, it was difficult getting an apartment
| because I had proof of income for more than 3 years in France
| (the current income I was declaring of 150k usd a year
| working remotely from France didn't count). P
|
| Do bank savings count for anything?
| mixmastamyk wrote:
| "Working remotely from" means long term you'll be paying
| taxes there. Which should be proof, and if not should be
| fixed. Having to wait a year or three is probably fine for a
| mortgage, no?
| giraffe_lady wrote:
| French bureaucracy is infamous for a reason and it's not
| just the state itself. A CDI is a certain type of
| employment contract, and a CDI is a CDI and everything else
| isn't, and a CDI is required for almost any significant
| loan. Workarounds are possible for smaller loans IF you
| have a personal relationship with the bank officer
| servicing that area. But if you didn't grow up there, or
| don't normally bank there, or they're suspicious of your
| race or tattoos, or were your bully in high school or or
| or. This sort of thing is more or less exactly what the
| credit reporting setup was meant to eliminate.
|
| It doesn't matter what it "should be" proof of or what a
| reasonable person could infer from this income or
| documentation of it. If you don't have a CDI, which even
| many full-time employed people don't, you're in a hard
| spot.
| mixmastamyk wrote:
| Again, I don't see anything here that requires a third-
| party as intermediate. If you have a system broken in
| another way, go right ahead and fix that. But it is not
| sufficient justification for incredibly bad actors such
| as Experian et al to exist.
| galoisscobi wrote:
| Ugh, annoyingly Experian was the hardest one to do a credit
| freeze on. A few weeks ago, I was able to easily do a credit
| freeze on other bureaus but Experian wanted me to call them
| during business hours so I put it off. It might not help much but
| I'll plan on doing the credit freeze with them today.
| twinkletwinkle_ wrote:
| Without going into too much detail, I once encountered an
| Experian identity verification question on behalf of someone
| else. This person was an Uber driver making ~$20,000 per year.
|
| The question was: "According to our records, you purchased or
| leased one of the following vehicles in the previous year. Which
| vehicle do you currently own?"
|
| A. Maserati Granturismo
|
| B. Ferrari 458 Italia
|
| C. Aston Martin Lagonda
|
| D. Honda Accord
|
| So... 2 Italian supercars, another supercar with only 200 ever
| produced, or a mass market sedan.
|
| Bonus - of the 4 questions, you only needed to answer 1 correctly
| to pass the check.
| EricE wrote:
| A reminder that if you haven't frozen your credit with the three
| credit agencies - it's a great time to do so!
| tantalor wrote:
| This is a really poorly written article. It goes on and on about
| poor security and how much the credit agencies should not be
| trusted, but it never says why this disclosure is harmful or why
| anyone should care.
|
| To say "identify thieves do this" implies "this is harmful" is a
| post-hoc fallacy.
| ThaDood wrote:
| I mean, I might be generalizing here but I think the target
| audience for Krebs is usually security minded individuals who
| probably don't need an explanation as to why having your credit
| information leaked is bad.
| projektfu wrote:
| At the beginning of the article he mentions that Telegram
| channels where attackers discuss methods have been sharing the
| method, as part of their plans to steal money from people. If
| the red team wants it, it's probably worth their while.
| twobitshifter wrote:
| How much value do the credit agencies add beyond what could be
| obtained by knowing income, location, number of dependents, and
| current debt/liabilities?
|
| verifying identity is another matter, but I'd expect what you put
| on the credit application to be the data that explains the
| defensible reasons to not give a loan, without needing a magic
| credit score.
| anonymouskimmer wrote:
| "How much value do the credit agencies add beyond what could be
| obtained by knowing income, location, number of dependents, and
| current debt/liabilities?"
|
| Theoretically they verify these numbers. Otherwise people would
| lie. Presumably, in the credit score calculation, they also
| have actuarial tables that allow calculating the odds of delay
| or default for each person.
| Phemist wrote:
| Meanwhile, UK Gov project One Login will use cloud services
| architectured by Experian:
|
| https://www.publictechnology.net/articles/news/government-pl...
| janalsncm wrote:
| The whole concept of "identity theft" is a concoction meant to
| pass blame on to consumers rather than creditors. If a bank gives
| away money to a person pretending to be you, that shouldn't be
| your problem. The bank screwed up. Your "identity" wasn't stolen,
| the bank didn't do basic due diligence and now they're looking to
| pass the blame on to you.
|
| https://youtu.be/CS9ptA3Ya9E
| [deleted]
| [deleted]
| DontchaKnowit wrote:
| Always thought Experian was a disgustingly juicy target and it
| was just a matter of time before something like this happened
| alberth wrote:
| Naive question: what harm can come from someone having your
| credit record?
|
| Companies all the time do hard inquiries to access your credit
| record.
|
| EDIT: don't get me wrong, it's not good this was able to be done.
| But what's the actual impact though?
| downrightmike wrote:
| Fun one is they buy a motorcycle and insurance and keep
| charging it to you and you have to fight with the insurance
| companies to clear the debt.
| tantalor wrote:
| Came here to ask this. The article doesn't say why this is a
| bad thing.
|
| At best it implies poor security by the credit agencies might
| increase the risk that "identity thieves will ruin your
| financial future" but it doesn't say how access to a credit
| report will do this.
|
| Guessing: something in the report (what exactly?) might make
| taking out bogus loans easier by selecting the most vulnerable
| victims (why?)
| mynameisvlad wrote:
| Identity verification questions are generally based on public
| records along with the credit report information. Some
| questions might not be detailed in the report (like how much a
| specific loan's monthly payments are) but others would
| definitely be included, like the name of a creditor on file.
___________________________________________________________________
(page generated 2023-01-09 23:01 UTC)