[HN Gopher] Identity thieves bypassed Experian security to view ...
       ___________________________________________________________________
        
       Identity thieves bypassed Experian security to view credit reports
        
       Author : picture
       Score  : 408 points
       Date   : 2023-01-09 14:14 UTC (8 hours ago)
        
 (HTM) web link (krebsonsecurity.com)
 (TXT) w3m dump (krebsonsecurity.com)
        
       | agency wrote:
       | I'm not surprised in the least bit. I keep my credit locked
       | constantly since I've had my SSN leaked multiple times (by US
       | government agencies). Every time I go to unfreeze it when I apply
       | for credit at least one of the big 3 credit reporting agencies
       | lets me unfreeze it without specifying the PIN I had to create
       | when freezing.
       | 
       | If there was any justice these companies would get the corporate
       | death penalty.
        
         | Loughla wrote:
         | I froze mine years ago when the first leak of my SS# happened
         | thanks to one of the stupid credit agencies.
         | 
         | I was happy and secure in the knowledge that it was locked
         | until I had to unlock it the first time. The password I set
         | didn't work, as they had apparently changed the log-in system
         | with no alert (also, now the stupid log-in sends us spam e-mail
         | that we can't opt out of).
         | 
         | I called them. I had my account unlocked, and the phone
         | representative even gave me my own SS# within three minutes of
         | being on the phone, and _by answering questions that were
         | publicly available information_.
         | 
         | It's an absolute fucking train wreck and I wish the system as a
         | whole and the credit companies in particular were destroyed.
        
           | Terretta wrote:
           | > _... and by answering questions that were publicly
           | available information._
           | 
           | The 3 questions fraud check system everyone uses to
           | performatively pretend to ensure you are who you are, can
           | only draw the questions it asks from -- guess what --
           | publicly available information.
           | 
           | It's illogical on its face.
           | 
           | // After identity theft, it gets worse, as thieves'
           | fraudulent or real data will enter public records under your
           | identity key, and now you can't pass your own check.
        
         | rootusrootus wrote:
         | PINs for freezes seems to be a thing of the past. I recently
         | unfroze all of my credit reports momentarily so they could be
         | accessed, and none of the big three asked for the PIN. They
         | each have their own login and as soon as you authenticate to
         | that, you're good.
        
         | JumpCrisscross wrote:
         | > _these companies would get the corporate death penalty_
         | 
         | Would suggest replacing this in your vocabulary with "fines,"
         | "license revocation" or "criminal penalties." Corporate death
         | penalties, _i.e._ judicial dissolution or charter revocations,
         | while a good slogan, don't make a lot of legal sense. As a
         | result, I've found it in practice used to segregate activism
         | and turnout operations (who like it) from rule and lawmaking
         | influence (where it's not a serious concept).
         | 
         | Massive fines, equal to market cap, or absolute liability,
         | _e.g._ a $10k + legal expenses minimum owed to each person
         | whose data leaked irrespective of actual damages, for example,
         | are more specific and actually actionable.
        
           | dylan604 wrote:
           | I am not unsympathetic to your ultimate meaning. However...
           | 
           | Take everyone's favorite whipping boy, Facebook/Meta, as the
           | example corporation. At every turn, they have shown that they
           | have prioritized greed vs community good. Any good they
           | provide is only to further their pursuit of wanting more.
           | Because they are so large, any upstart competitor with a
           | total opposite ethos that might come about gets annihilated
           | by the behemoth.
           | 
           | If legal action were to give Meta the corporate death
           | sentence preventing the company from operating and its execs
           | from pivoting to somewhere else, then and only then could the
           | competitors actually have a chance. So just because there's a
           | death sentence for a corp doesn't mean the "people" lose as
           | well.
        
             | JumpCrisscross wrote:
             | > _legal action were to give Meta the corporate death
             | sentence preventing the company from operating and its
             | execs from pivoting to somewhere else_
             | 
             | Just do the second bit. The problem with judicial
             | dissolution is corporations are a legal fiction. What you
             | do with the people and assets is far, far more important.
             | Ignoring the legal fiction to focus on those is my point.
             | Take their stuff (fines). Force them to restructure (break-
             | up). Limit their scope (corporate criminal penalties).
             | Restrict their executives. "Corporate death penalty" is
             | exactly non-specific enough to avoid specifying those
             | prescriptions.
        
               | dylan604 wrote:
               | yes, but in coversation, are you going to list out those
               | things every single time like that or are you going to do
               | it once and then follow up with, "you know, the corporate
               | death penalty?"
               | 
               | i don't think it's nearly as non-specific as you think.
               | if you ask people what a corp death penalty would be, my
               | assumption would be that people would think of it as the
               | corporation no longer existing. if you're saying that
               | corps would just spin off assets as a new name, new corp
               | charter, same people, same processes, then yes, that
               | would be a valid concern. but we can at least state that
               | once, and all agree upon it rather than continuing to
               | repeat it like we're unable to understand the concept.
        
               | JumpCrisscross wrote:
               | > _ask people what a corp death penalty would be, my
               | assumption would be that people would think of it as the
               | corporation no longer existing_
               | 
               | I mean, look at this thread. I'm not saying the impulse
               | is wrong. But "corporate death penalty" seems to be a
               | good way to take a discussion which _could_ lead to an
               | outcome into one that won't. That's fine! People vent!
               | But we shouldn't confuse venting with deliberating.
        
               | dylan604 wrote:
               | I just can't wrap my head around what your issue is here.
               | Only lawyers talk like this. Are you a lawyer? People
               | feel a corporation has committed such wrong doing that
               | they should no longer exist. When that happens as an
               | individual, it is known as the death penalty. Applying
               | that same phrasing to a corporation comes with the same
               | understanding. You're pedantry in this case are quite
               | trite
        
               | kelnos wrote:
               | Not the person you're replying to, but I think the issue
               | is that the individual vs. corporation analogy doesn't
               | work. If you kill a person who has done bad things, you
               | will indeed prevent that person from doing bad things in
               | the future. If you kill a corporation (via legally
               | dissolving its charter, the "corporate death penalty"),
               | then you will not keep the individuals and investors
               | associated with that corporation from doing bad things,
               | as they will likely reorganize into a new entity and
               | continue to do those bad things.
               | 
               | I agree that there's an element of pedantry there, so if
               | (as the GP suggested), someone is just venting and
               | doesn't care about a specific outcome, saying "give them
               | the corporate death penalty" is fine. But the downside is
               | that if someone reads that, and looks up legal corporate
               | dissolution, they might get the wrong idea that this sort
               | of remedy will actually fix the problem. Or they might
               | not even do any research, and just decide to start
               | throwing around this term themselves, without really
               | understanding what it means or what it does (and doesn't)
               | accomplish.
               | 
               | But I also agree that listing out other specific remedies
               | (market-cap-sized fine, jailing executives, whatever) is
               | long-winded and annoying, and maybe not really useful or
               | relevant unless the discussion is actually about what
               | specific remedies might be effective.
        
           | r00fus wrote:
           | I'd agree except for fines.
           | 
           | If the fines are < the advantage to scoff the law, such a
           | fine just puts a price tag that can be used in a cost-benefit
           | calc for the company.
        
           | atherton33 wrote:
           | The fines should be to the shareholders. Ownership should be
           | determined recursively to all actual humans. No trusts, no
           | corporate owners, no funds.
           | 
           | A strawman: Maybe proportion of ownership times current
           | assets and all future income. Whatever fraction of their
           | financial being is proportional to their share of the
           | corporation is "dead".
           | 
           | If you have X% ownership share, you are fined X% of all your
           | current assets and X% of all future income.
           | 
           | A message needs to be sent that it's not okay to invest in a
           | company that is doing harm and then walk away from it. You're
           | ethically and morally liable, the law should reflect that.
        
           | nine_k wrote:
           | I understand "corporate death penalty" as a dissolution of
           | the corporation, likely with some cool down time for the
           | execs found guilty when they cannot work as execs.
           | 
           | No violence should be involved. Large layoffs resulting from
           | that won't be pleasant one bit though.
        
             | fragmede wrote:
             | [flagged]
        
               | dabraham1248 wrote:
               | The theory is that, _once it becomes policy and happens a
               | couple of times_, employees will pay attention to what
               | their company is doing, and get out if they think they're
               | in danger. It aligns individual morality with self
               | interest, and will crater a company that starts sliding
               | towards dissolution.
               | 
               | Thus actual enforcement becomes almost a non-issue.
               | 
               | I'm not sure I buy that the janitorial staff is supposed
               | to keep up on the dark patterns in the sign up page, but
               | that's the theory.
        
               | anonymouskimmer wrote:
               | To be consistent you'd have to be opposed to venture
               | capital shutting down and selling off companies as well.
               | 
               | To be fully consistent you'd have to be opposed to
               | firings and layoffs in general (except as the result of a
               | commission of a crime by the person so fired).
               | 
               | I'd be happy with a corporate death penalty that resulted
               | in the stockholders being wiped out, the executives (and
               | possibly board) being fired and barred from the industry,
               | and executive control of the company being taken over by
               | someone like John J. Ray III. This would allow either a
               | restructuring of the company or gradually winding it down
               | in such a way that the non-executive employees and
               | bondholders aren't screwed over.
        
               | bastawhiz wrote:
               | If I start a company with the express purpose of having
               | it commit crimes, it will be shut down and everyone
               | employed will be fired. That's not on the government,
               | that's on me, the employer. So then where is the line
               | that we draw that says how badly a company needs to
               | behave or how many crimes it needs to commit to justify
               | it being dissolved? We should not tolerate crime for the
               | sake of the livelihoods of the henchmen. "The death star
               | is bad, but think of how many people would be unemployed
               | if we stopped them" is exactly the argument they want you
               | to make.
        
               | nisegami wrote:
               | Violence is the only language the state knows.
        
               | jazzyjackson wrote:
               | I would suppose whoever is being _forced_ to terminate
               | their employees is doing so under the threat of state
               | violence (men with guns), but the employees being fired
               | are not being threatened with any force, they 're just
               | losing their job.
        
             | JumpCrisscross wrote:
             | > _dissolution of the corporation_
             | 
             | Corporations are a legal fiction. What does dissolving the
             | corporation mean? Revoking its charter? Then what happens
             | to its assets? If you return them to shareholders, you've
             | given a boon to its wealthiest, who can now re-organise it
             | free of prior liabilities. If you liquidate them, you've
             | delivered a junior fine, since with real fines the fine
             | gets paid before creditors. If you take it, you've
             | expropriated (also, fines with extra steps).
             | 
             | In every case, what you want from a "corporate death
             | penalty" is better effected with actual penalties. A
             | market-cap sized fine is more specific and more actionable
             | than a "corporate death penalty," which is why I suspect
             | the latter is in circulation.
        
             | soco wrote:
             | I'm pretty confident it wouldn't come to layoffs. If Meta
             | faced such a risk they would simply follow the rule.
             | Remember how many times they threatened to leave EU?
        
           | tomrod wrote:
           | A corporate death penalty would be:
           | 
           | (1) Dissolution as a viable entity in the US
           | 
           | (2) All assets sold paid out to wronged parties before debt
           | servicing or shareholders
           | 
           | (3) All officers barred from holding political, non-profit,
           | or corporate office at any level in the US states or
           | territories, as well as removing the veil of corporate
           | liability from officers. All technology and security
           | employees have liens put in place to pay affected parties as
           | well.
           | 
           | When we mean death sentence, we mean it.
        
       | ncphil wrote:
       | Huh. So basically these guys got access to stuff that thousands
       | of companies and governments who subscribe to Experian already
       | have, but didn't pay for it. Color me outraged.
        
       | tibbon wrote:
       | Why isn't there more regulation on these? It seems something that
       | 99.9% of voters would want to get behind. These credit report
       | agencies horde data and then misuse it so frequently. It feels
       | like there needs to be some accountability for misuse of data
       | like this and breaches, especially when there's essentially no
       | way to opt out and still function in society.
        
         | xyst wrote:
         | like the online tax return companies, their lobbyists push for
         | minimal regulation
        
         | int_19h wrote:
         | In a representative democracy, it doesn't matter whether 99% of
         | the voters are behind the issue. What matters is where that
         | issue is in the overall stack ranking of "important" issues,
         | where "important" is defined as "effective for the purposes of
         | winning elections".
         | 
         | Basically, when it comes to voting, is _this_ going to be the
         | reason why you vote one way or the other? Or is it going to be
         | the usual cocktail of taxes, abortion, immigration etc? If you
         | have an opinion - no matter how strong - but they already have
         | your vote, why should they care about it?
        
       | SketchySeaBeast wrote:
       | Every single report like this serves to make me feel sick and
       | angry. These organizations are responsible for so much data that
       | can literally ruin lives and they can't be bothered to think
       | through their solutions. It's not but should be criminal.
        
         | asah wrote:
         | Specifically, personal penalties for the exec teams. Do this
         | once, and they'll take 10x the level of care going forward.
        
           | pwg wrote:
           | > personal penalties for the exec teams.
           | 
           | Yes, but the penalties have to be such that the exec does not
           | simply view it as "cost of doing business" and mark it down
           | as a business expense.
        
             | thefurdrake wrote:
             | 5% of their investment of the company per offense.
        
             | asah wrote:
             | good point - also can't be covered by an insurance policy
             | or reimbursement or pay increase or special bonus.
             | 
             | I guess we're arguing for non-financial penalties...
        
         | bobkazamakis wrote:
         | If security doesn't impact their bottom line, it's just another
         | beautiful salary for the C suite to parachute off of.
        
       | [deleted]
        
       | gorbachev wrote:
       | What's absolutely infuriating about this is that Brian Krebs has
       | sounded the alarm about Experian's horrible security for a very
       | long time, and Experian has done jack shit about their problems.
       | 
       | This company needs to be shut down. It's incapable of
       | safeguarding PII in a reasonable way.
        
         | coldcode wrote:
         | Until our government creates a law that makes the credit
         | bureaus have to pay every time their security fails, nothing
         | will happen. They don't have to care and probably laugh at all
         | of us. But politicians are cheap to buy off and nothing
         | changes. I am sure all 3 of them have huge legal teams anxious
         | to slap you silly if you try to sue them.
        
       | dboreham wrote:
       | Ugh. "Identity Theft" is a term invented by the finance industry
       | to victim-blame when their weak authentication mechanisms are
       | compromised. We should instead talk about "Banks being defrauded
       | by criminals due to lax procedures".
        
         | dragonwriter wrote:
         | > "Identity Theft" is a term invented by the finance industry
         | to victim-blame
         | 
         | "Identity Theft" blames to the exploiter, instead of the
         | (possibly negligently) exploitable system; it is shifting
         | blame, but not principally to the victim.
         | 
         | > We should instead talk about "Banks being defrauded by
         | criminals due to lax procedures".
         | 
         | If we want to focus responsibility on the banks, we should
         | instrad talk about "Banks failing to safeguard customer funds",
         | or "Banks enabling criminals to steal customer funds."
        
           | janalsncm wrote:
           | Just so it's clear, if person A borrows money from bank B
           | under person C's name, person C will have to fix the problem.
           | And make no mistake, it's a huge problem. It will affect
           | person C's credit score and potentially cause loss of
           | property as bank B will hound person C for their money back.
           | This is in spite of the fact that there may be no
           | relationship between B and C or A and C. And then credit
           | reporting agencies D will happily report the lie from B, that
           | C owes money to B.
           | 
           | It's completely upside down. And good luck getting the local
           | police to fix the issue.
           | 
           | https://youtu.be/otU-1Il7GfM
        
       | li2uR3ce wrote:
       | I'm not surprised Experian's security is shit. Equafax proved
       | that there are basically no consequences. Here's some basic free
       | credit monitoring that you probably already had for free.
        
       | surume wrote:
       | This isn't the first time that a major Credit Bureau has had a
       | data leak, is it? Wasn't there a huge one a few years back?
        
         | exogenousdata wrote:
         | [dead]
        
         | berkle4455 wrote:
         | Experian and Equifax have security leaks all the time yeah
        
           | surume wrote:
           | "Identity thieves have been exploiting a glaring security
           | weakness in the website of Experian"
           | 
           | Shouldn't Experian have been thoroughly audited by the gov't
           | after the last major data breach? The above sounds pretty out
           | in the open, no?
        
             | lesuorac wrote:
             | > Shouldn't Experian have been thoroughly audited by the
             | gov't after the last major data breach?
             | 
             | That sounds pretty unconstitutional. Why would the USG
             | audit a private company for security?
        
               | AlotOfReading wrote:
               | It seems like it'd be a national security issue at the
               | very least. Those databases also contain an up-to-date
               | financial picture of government employees holding
               | security clearances. Even if clearance holders are
               | nominally supposed to remain above-board and
               | unsusceptible, I'm willing to bet that enough data mining
               | would allow decent targeting. The DoD is already
               | monitoring those employee's credit reports, so clearly
               | there must be _something_ actionable in them and it 's
               | quite likely they miss something.
        
               | thefurdrake wrote:
               | Which part of the Constitution is violated by the
               | government scanning a website's publicly-available,
               | advertised resources on the clearnet?
        
               | lesuorac wrote:
               | Unconstitutional just means it's not in the constitution.
               | My claim is that nowhere in the constitution does it
               | require the USG to audit a private company for security
               | (especially in conjunction with an after major data
               | breach clause).
        
               | thefurdrake wrote:
               | Yeah, I guess that ensuring foreign actors can't publicly
               | dump massive amounts of data on an arbitrary number of
               | american citizens to be used in economic warfare
               | definitely doesn't fall under any mandates that the US
               | government has...
        
               | lesuorac wrote:
               | Yeah, if it did you would've quoted it.
        
       | SPORTSCRYPO wrote:
       | [dead]
        
       | smarri wrote:
       | "you simply change the last part of the URL from "/acr/oow/" to
       | "/acr/report," and the site would display the consumer's full
       | credit report."
       | 
       | Unreal.
        
       | charles_f wrote:
       | > you simply change the last part of the URL from "/acr/oow/" to
       | "/acr/report," and the site would display the consumer's full
       | credit report.
       | 
       | Oh wow, that's one of the dumbest security hole I've seen so far.
       | That means you're either authenticated in the first screen, or
       | the second assumes that you are whom you say you are if you lend
       | on it. There's a clear lack of ethics from whomever built that,
       | whom either didn't care, or didn't know enough know enough to
       | excuse themselves from building it and ask for assistance.
       | 
       | I mean, this is not your regular system. Everyone is in there,
       | not that they have much of a choice, and it's their most
       | sensitive data, that you decide you're up to the task to protect.
       | 
       | I'm all for learning from your mistakes and I'm the first one to
       | screw up once in a while, and to admit that I am not a security
       | expert. But the size of this combined with how freaking dumb this
       | issue is... This is most likely gross negligence. In most of
       | other industries where people call themselves engineers, you
       | would be putting your own professional reputation on the line
       | when deciding you're up to the task. Then you would get in front
       | of am ethics commission and likely get your license suspended or
       | revoked.
        
         | xnorswap wrote:
         | It's just a classic IDOR, it's very easy to fall into with some
         | frameworks.
         | 
         | If you look, you see it everywhere. When stack-exchange rolled
         | out their CV feature they had a similar thing which leaked
         | everyone's email address regardless of the public profile
         | visibility or whether they had even used the CV feature.
        
           | bcrosby95 wrote:
           | I seem to recall github having this security hole in spades
           | about a decade ago.
        
         | bmitc wrote:
         | > There's a clear lack of ethics from whomever built that, whom
         | either didn't care, or didn't know enough know enough to excuse
         | themselves from building it and ask for assistance.
         | 
         | I highly doubt that Experian attracts the best and brightest.
         | And when you have a company that doesn't provide any features
         | to the consumers whose data they collect, control, and sell
         | except when sued, you get stuff like this.
        
         | mancerayder wrote:
         | These folks never did a basic penn test ? Unauthenticated
         | access to a different URL seems like a common thing to test
         | for.
        
           | acdha wrote:
           | That's ... optimistic in my experience. I've had reports
           | include breathless disclosures that our application was
           | leaking private information because robots.txt could be
           | accessed without authentication, or that we were disclosing
           | source code (front-end JavaScript).
           | 
           | Places which treat security as an audit checkbox are going to
           | try to outsource that work to save money and they're going to
           | get people who have enough skill to run a few basic tools but
           | not to reason about the results or do anything creative.
           | Experian seems highly likely to be on that side since they've
           | been able to avoid any significant penalties for past
           | negligence.
        
         | suzzer99 wrote:
         | I'm still struggling to think how this could have happened. I
         | wonder if it has something to do with interaction with
         | annualcreditreport.com?
         | 
         | Maybe originally the code had multiple levels of authenticating
         | the user: 1) we know who you are, but you haven't proven it
         | yet, and 2) you've proven it, now you can see everything.
         | 
         | But when they integrated with a 3rd party, which could have
         | been a decade or more after the original code was written, some
         | developer who didn't understand the code just lumped everyone
         | who came over from annualcreditreport.com into basket #2, even
         | though that user still had to go through the url flow to prove
         | themselves. Just a guess.
         | 
         | I don't think most non-programmers realize how often preventing
         | this kind of thing comes down to one developer making a stink
         | repeatedly to indifferent higher-ups. If that one developer is
         | incompetent or doesn't care, no one else does.
        
           | xnorswap wrote:
           | I don't know about this case, but a lot of the time this
           | class of vulnerability comes down to lack of Authorisation
           | rather than lack of Authentication.
           | 
           | So much effort is put into checking that people are who they
           | say they are (is Person X really Person X) , they forget to
           | check that they're authorised (is Person X actually supposed
           | to be accessing resource Y).
           | 
           | Given the URLs don't have the actual resource Identifier, it
           | means the resource ID will have been gathered from somewhere
           | else, typically one of three places:
           | 
           | 1. Cookies / Localstorage - Easily manipulated and should
           | never be treated as a secure place, it's easy to put simple
           | values here and forget that they still need to be validated /
           | checked server side, and that just because you have access to
           | /foo/Y you might not also have access to /bar/Y.
           | 
           | 2. Session - An ASP favourite, sticking something in a key
           | like Session["FolderID"] you might assume you've validated
           | and checked authorisation when you set the key, then later
           | re-use (deliberately or accidentally) the same key elsewhere
           | leaving it open for manipulation. And then you might assume
           | you don't need to re-check authorisation when you read the
           | key.
        
             | suzzer99 wrote:
             | The only way to write something super sensitive like this
             | imo is to have the back-end API that retrieves full credit
             | report be essentially hard-wired to a user access level of
             | "FULLY_VALIDATED".
             | 
             | That way no developer can come along five years later and
             | accidentally grant the wrong access level or show the
             | report to a not fully validated user. Put the security
             | check on or as close to the thing being accessed as
             | possible.
        
             | herpderperator wrote:
             | I wouldn't call the "session" concept an ASP favourite -
             | it's the industry standard for any backend web framework to
             | use a user session where the session key is stored as a
             | random cookie value and the actual key-value pairs are
             | stored on the backend somewhere.
        
               | xnorswap wrote:
               | That's fair, I associate it as an ASP favourite to mess
               | it up and cause all sorts of security holes with it!
               | 
               | Probably just a lot more inexperienced developers
               | treating it like a magic authenticated bag without enough
               | warnings about improper use in the documentation.
               | 
               | Also a very easy "go to" store via global variable in ASP
               | made it especially easy to use it as a go-to solution for
               | anything that you couldn't be bothered to properly store.
        
         | 8note wrote:
         | Credit agencies have no reason to care about their security wrt
         | your data. You aren't their customer, and they don't owe you
         | anything
        
         | ec109685 wrote:
         | This is where per-user level encryption of data should be used.
         | If your credit report on that site is encrypted and the keys
         | are only successfully derived by answering your security
         | questions, you've added another layer of security [1]. It also
         | prevents the situation where a hacker gets access to the box
         | doing the security check, and they can read everyone's data
         | versus just those users who are concurrently asking for their
         | reports.
         | 
         | Even simpler, this would be prevented if /acr/oow set a
         | decryption key as a cookie after validating the verification
         | data that was then used by /acr/report to decrypt your credit
         | report.
         | 
         | [1] Yes, it's possible to enumerate over all user's security
         | answers, so it's not perfect, but it ensures a simple mistake
         | with an if condition, doesn't release everyone's data.
        
         | vinceguidry wrote:
         | It's nineties-level internet security. Stuff like that was the
         | bread and butter of security researchers of that era.
        
           | NovemberWhiskey wrote:
           | I mean, sure, but nothing has changed since: "Broken Access
           | Control" is still #1 on the OWASP Top Ten for 2021.
        
           | contingencies wrote:
           | Closely related period fail: _/ receipt/<sequential-receipt-
           | number-here>.pdf_ = all customers full booking history and
           | personal data for all time.
        
         | jimhefferon wrote:
         | It seems like they owe us all compensatory damages. Big
         | damages.
         | 
         | I never really understood how they could take my information,
         | which presumably belongs to me, and then could use it to make
         | millions. How about my cut?
        
       | seanw444 wrote:
       | Why everything is tied to our SSN, I don't understand. Why we
       | allow private companies to manage our US social credit score, I
       | don't know either. There are a lot of things we've done here that
       | make no sense.
        
         | ncphil wrote:
         | ... because back in the 70s it was decided that disclosure
         | (a/k/a "transparency") was all we'd ask of private companies
         | (with exceptions, as in, some companies aren't even expected to
         | disclose). Who do you think _actually owns_ the U.S. Congress
         | anyway?
        
         | jmclnx wrote:
         | The main reason is "the mark of the devil", every time the US
         | Federal Gov. wanted to issues ID Cards, that came up. Just look
         | at the "Real ID" issues, but that is still not a useful ID for
         | everyone.
         | 
         | Also if you look at your Social Security Card, it states "Not
         | to be used for identification". But Companies, Univ and
         | everyone ignored that because they wanted a Unique Number. Not
         | may people realize the SSN is recycled as people die off.
         | 
         | I wish the US Gov would sue all Companies and Orgs that used
         | the SSN for ID purposes for trillions and return that amount to
         | people with Social Security Numbers.
        
           | catiopatio wrote:
           | No, the issue isn't religious irrationality -- it's
           | understanding the inherent dangers of a mandatory government
           | identification system and not wanting one.
           | 
           | Unfortunately, we have several anyway, but that's no reason
           | to accept a universal inescapable federal ID that we would
           | never be able to roll back.
           | 
           | > I wish the US Gov would sue all Companies and Orgs that
           | used the SSN for ID purposes for trillions and return that
           | amount to people with Social Security Numbers.
           | 
           | At least on that we agree. The SSN bas become a poor,
           | backdoor replacement for federal identification documents --
           | which is exactly what people were worried would happen, and
           | why they received the sop of "not for identification". That
           | didn't last long:
           | 
           | https://www.nytimes.com/1998/07/26/weekinreview/the-
           | nation-n...
        
             | reidjs wrote:
             | What's the downside of a universal federal ID?
        
               | supertrope wrote:
               | If nearly all choices and utterances are linked to the
               | same database and can be used against you in ways that
               | don't even exist today people will feel a strong chilling
               | effect. We have bankruptcy and privacy laws specifically
               | so the owners of these private ledgers and databases do
               | not entirely control our lives.
               | 
               | The issuer of an universal ID gains gatekeeping power.
               | Besides the danger of people getting excluded, children
               | and marginalized demographics won't have one.
               | 
               | Ironically widespread deployment of an ID can sometimes
               | lead to more fraud. Bureaucracies tend to confuse
               | identification, authentication, and authorization.
               | Possessing a scan of a passport is often accepted as
               | possessing the passport which is accepted as authority to
               | transact with that name. Through the transitive property
               | possessing a hacked .jpg can allow a fraudster to
               | transact as you. When businesses and bureaucracies are
               | not liable for fraud or their errors, they focus on the
               | ID tokens as a way to improve throughput instead of
               | assessing the legitimacy of the transaction in a holistic
               | manner.
        
       | landemva wrote:
       | The credit bureaus are moving in to work/payroll verification by
       | hoovering payroll data that US companies voluntarily give to
       | them. They sell access to data to people verifying income for
       | loan application, and law offices, and child support services.
       | 
       | I got job offer and told recruiter to put in writing that my
       | payroll data will not be released without a court subpoena. Am
       | waiting on response from recruiter. My outlook is that HR does
       | not care about employees if they purposefully leak this info.
       | 
       | Those concerned may want to ask their HR about payroll data
       | sharing.
       | 
       | https://www.experian.com/consumer-information/employment-inc...
       | 
       | https://theworknumber.com
        
         | d4mi3n wrote:
         | This can be more complicated in certain industries where a
         | relationship with a credit agency is otherwise required. I
         | worked at a fintech b2b lending company a while back that
         | worked closely with all the big agencies and I distinctly
         | recall that the company got favorable rates for opting in to
         | payroll sharing when negotiating rates for other services from
         | Experian.
         | 
         | It was sadly before my tenure at the company and I only became
         | aware of it much later, but I would not be surprised if
         | agencies are leveraging their other produces to incentivize
         | more companies to share this salary data.
         | 
         | In the meantime I'm going to continue exercising CCPA wherever
         | I can and hope we see some legislation or court cases at the
         | federal level to address some of these issues.
        
           | arcturus17 wrote:
           | I mean, from what you're saying, it's complicated in the
           | sense that the credit bureaus are exploiting their customer's
           | greed, because if the customer really cared about their own
           | employees, they would say no to the discounted rates, and
           | that would be the end of that. No?
        
             | d4mi3n wrote:
             | You're correct, but I believe this line of thinking is a
             | simplification. If you operate a public company and your
             | shareholders demand a return, odds are you'll have a board
             | that's going to force you to have specific policies. Some
             | of those policies are along the lines of "take any
             | discounts you can get on things that cause operational
             | expenses."
             | 
             | The only real way around this is having shareholders that
             | care about employee privacy, and I think _that_ will only
             | happen if these privacy issues impact the bottom line in
             | some way (difficulty hiring, increased costs, etc).
             | 
             | It's frustrating in that this behavior is cultural and
             | endemic to how businesses operate in the US. Change is
             | possible, but it requires support from more than just the
             | line of business employees and management.
        
               | arcturus17 wrote:
               | > but I believe this line of thinking is a simplification
               | 
               | Yea, sure. I wasn't meaning to take a hard moralist or
               | anti-system stance, when I say "the company is greedy" I
               | understand the company and its people are a cog in a
               | larger machine.
               | 
               | There is a simpler way out than waiting for a cultural
               | change to stop that practice, though: regulation.
               | 
               | I'm not entirely sure, but I doubt that here in Europe
               | it's so easy for companies to sell payroll data - if at
               | all legal. At any rate it sounds like an abhorrent
               | practice.
        
               | acdha wrote:
               | > If you operate a public company and your shareholders
               | demand a return, odds are you'll have a board that's
               | going to force you to have specific policies. Some of
               | those policies are along the lines of "take any discounts
               | you can get on things that cause operational expenses."
               | 
               | There's a lot of mythology around that, however: managers
               | are giving a large amount of discretion about business
               | decisions because it's extremely rare that there are no
               | trade-offs for any decision. For example, you could save
               | a lot of operational hosting expense by switching from
               | AWS to Bob's Bait Shack and Server Farm. In this case,
               | you could argue that the risk to employees is significant
               | and would potentially spill over to the company if leaked
               | information was used to compromise them.
        
         | rednerrus wrote:
         | https://www.reddit.com/r/overemployed/comments/v4y76m/how_to...
        
         | cptcobalt wrote:
         | Is this something that HR can typically & easily control with
         | the systems they use?
        
           | jrumbut wrote:
           | That depends on the systems they use. I appreciate the OP for
           | making at least one office give a moment's thought to it.
        
         | kccqzy wrote:
         | I happened to chat with HR when I did the opt-out. They
         | claimed, which I didn't believe, that most employees actually
         | benefit from it because they get streamlined approval for
         | personal loans and mortgages. I think it's just a way for them
         | to cut down on support requests from employees (like "Hey HR I
         | urgently need you to provide my last three pay stubs or
         | employment verification letters").
        
           | [deleted]
        
           | switch007 wrote:
           | Lol HR have an arsenal of excuses/bs on hand, always. "Most
           | employees actually benefit" Christ
        
         | mcculley wrote:
         | They should also ask their mortgage and auto loan provider. I
         | was running a consultancy when Paysa came online. We were
         | surprised to see it knew a lot about compensation and titles of
         | most of my employees. But not all of them. We found that the
         | common thread was employees who had recently applied for
         | loans/mortgages. They had submitted paystubs as part of the
         | application process which were then sold.
        
         | meesles wrote:
         | Unfortunately you won't stop the tide with simple data
         | practices. If they can't slurp up the the data automatically,
         | they have an army of people making phone calls to gather
         | employment data from other sources to add to their database.
         | 
         | We use them as a provider (unfortunately), and when they don't
         | have the data on hand we have to handle cases where it can take
         | a few days for them to call the business and confirm employment
         | directly with someone who works there. At that point, I don't
         | think where you work has a reasonable expectation of privacy
         | since you walk there, probably put it on your LinkedIn, talk
         | about it with friends/family, etc.
        
           | danuker wrote:
           | > put it on your LinkedIn
           | 
           | I stopped doing that when LinkedIn added their loginwall.
           | 
           | Clearly LinkedIn wants to harvest data while at the same time
           | making it difficult for others to do so, which would go
           | against my interest of making it public.
           | 
           | So I posted it on my own website. Goodbye to another
           | centralized point of failure/control.
        
           | notch656c wrote:
           | People are lazy. If they can't get the information a very
           | large portion of them will rubber stamp it or just ask you if
           | it's true, possibly to provide some evidence which they will
           | be to lazy to verify as authentic.
           | 
           | >it can take a few days for them to call the business and
           | confirm employment directly with someone who works there
           | 
           | If you hire out this kind of work, half the min wage slaves
           | getting screamed at with hot breath down their neck for "low
           | productivity" are gonna call once at most and likely not at
           | all and then check it off. Speaking as someone who has worked
           | at a call center along with the populace which was basically
           | people on work release/probation.
        
             | kevin_thibedeau wrote:
             | > If they can't get the information a very large portion of
             | them will rubber stamp it
             | 
             | They'll just toss your application out without a human ever
             | seeing it. You're clearly a noncompliant troublemaker and
             | not worth hiring.
        
               | notch656c wrote:
               | Most places don't do much vetting of your background
               | until you're hired. At which point it can be a lot of
               | work to offer to someone else, especially if it's been
               | more than a few days.
        
         | beembeem wrote:
         | Keep in mind that the large employers _pay_ Equifax _and_ give
         | them your pay data.
         | 
         | Equifax/TWN has a brilliant business model that should be
         | illegal. Get paid to collect data, then resell it.
        
         | starwind wrote:
         | You can freeze the worknumber so people running background
         | checks can't get information. When I changed jobs the company
         | ran a background check and they kinda freaked out cause they
         | couldn't get anything out of this database. I loved it.
        
           | landemva wrote:
           | I wonder if security of the payroll data lookup is even worse
           | than the credit report website. A 'freeze' may be worthless
           | if the data leaks are large. And a person making $18/hour to
           | do child support case management may interested in making
           | extra cash by looking up other people for a fee.
        
           | Scoundreller wrote:
           | Gartner has predicted by 2038, the average American will
           | spend 17 hours per day opting out of things they never opted
           | into.
        
             | bmitc wrote:
             | I can't tell if that's a real report or something from The
             | Onion.
        
             | hedora wrote:
             | Do they predict what percentage of trackers this continuous
             | coke-filled click-fest will actually disable?
        
               | TeMPOraL wrote:
               | They did not, because the number wasn't estimated by
               | adding up predicted time per tracker or service, but by
               | determining this is about the maximum the market can bear
               | - i.e. a steady state of the system.
               | 
               | Curiously, Stratfor also predicted 60% chance of the US
               | going to war with the EU before 2036, due to EU privacy
               | regulation threatening to shut down the increasingly
               | adtech-based US economy.
        
               | thechao wrote:
               | This _serious_ analysis is stupider than the entire plot
               | of Idiocracy.
        
           | toomuchtodo wrote:
           | "How to freeze your work number"
           | 
           | https://news.ycombinator.com/item?id=33212195
        
             | MerelyMortal wrote:
             | I would do the verification over email as that means they
             | didn't typo whatever email you gave them (easier to typo an
             | email address rather than a phone number).
        
           | [deleted]
        
         | josephcsible wrote:
         | > I got job offer and told recruiter to put in writing that my
         | payroll data will not be released without a court subpoena.
         | 
         | Doesn't this kind of demand usually just result in you not
         | getting the job?
        
           | nkrisc wrote:
           | Yeah, probably more often than not. But if you've got in-
           | demand skills and can afford to be choosy, then go for it if
           | it's important to you.
        
           | landemva wrote:
           | Not all companies give out payroll data. Better to learn now
           | if finance/HR doesn't protect their employees and to decline
           | the offer. Lack of qualified applicants ... or people have
           | had enough. I do not consent.
        
           | dwardu wrote:
           | It would be a bullet dodged if so
        
       | ipython wrote:
       | I strongly suspect this was more widely exploited than what's
       | being let on. I have received hundreds of Medicare robocalls
       | where the caller was suspiciously able to suss out a fake dossier
       | - even though street addresses and names would be plausible, but
       | the birthday and SSN were fake.
       | 
       | I would definitely investigate this further to see if this
       | knowledge was in the hands of criminals/scammers who were selling
       | access for $$ over the past few years.
        
       | davidkuennen wrote:
       | It still boggles my mind how much you can do with another persons
       | SSN in the US. It's like a password for your life in plain text.
       | Crazy.
        
       | sofixa wrote:
       | It's interesting seeing the American credit model malfunction so
       | badly so often (massive data leaks, crappy gaming of the system -
       | even today i read on HN not to pay off your mortgage if you don't
       | have any other loans or it might tank your credit score).
       | 
       | As with a couple of other things, it's basically the only
       | developed country with this model (useless for-profit middlemen
       | for no good reason), it really sucks for the average consumer,
       | yet there is no actual change coming. Why? Is it American
       | exceptionalism refusing to acknowledge that there are better ways
       | used elsewhere? Is it free market "absolutism" hoping the market
       | will fix itself?
        
         | user3939382 wrote:
         | > Why? Is it American exceptionalism
         | 
         | Because our government is completely corrupt and doesn't
         | represent the interests of the People, at all. It serves and is
         | beholden to large corporate interests, chief among them banks
         | and financial institutions. In a just system that represented
         | our interests Equifax would be forbidden from compiling
         | consumer data after what they did.
        
           | seniorThrowaway wrote:
           | Exactly, and the best part is it is all out in the open but
           | the majority of people either don't understand or don't care.
           | The corporations openly write legislation via their
           | lobbyists, huge bills that congress themselves don't even
           | fully read let alone write. I've just about given up hope
           | that this will ever change.
        
             | user3939382 wrote:
             | The 2014 Princeton study
             | https://doi.org/10.1017/S1537592714001595 highlighted
             | https://i.imgur.com/eH6YcWn.png what a corrupt sham our
             | "democracy" has become.
        
         | jollyllama wrote:
         | It's not really malfunctioning, in my opinion. It's more or
         | less designed to violate individual privacy and offer as many
         | people access as efficiently as possible.
         | 
         | Neither free market absolutism nor exceptionalism are the
         | reason that it's designed this way. At least, not in the way
         | that I think you mean it. Rather, it's because the current
         | economy of the USA is an inflationary credit economy. It's a
         | very un-free market; a great example is education. The
         | government subsidizes loans which drive up the price, and put
         | people in debt so that they are more desperate to take jobs.
        
           | [deleted]
        
           | lesuorac wrote:
           | I mean, a credit report is only useful if it actually tells
           | me about _your_ credit worthiness.
           | 
           | Sure, some Elon Musk guy might have enough credit worthiness
           | to make a $44 billion purchase. But are _you_ Elon Musk or
           | just some guy impersonating Elon Musk? Fraud may not be
           | rampant enough currently but if Experian/etc continue to help
           | fraudsters it will just keep getting worse.
        
         | jimbob45 wrote:
         | Are you able to offer a better system that is/was working in
         | another developed country?
        
           | sofixa wrote:
           | I can tell you about the system here in France - when you
           | apply for a loan, the bank asks for some information (your
           | salary, marriage status, kids, etc.) from you to see what
           | you're capable of to spend monthly, and checks with the
           | national bank what loans you have/had, and if you've
           | defaulted on any of them. That's it, they don't need to know
           | more, and the national bank doesn't keep track of everything,
           | only very basic loan information (and of course they have no
           | for profit motive), and nobody outside of a bank where you're
           | applying for a loan uses this information to define your
           | worthiness as a tenant or employee.
        
             | aantix wrote:
             | But why not?
             | 
             | Failure of paying back a loan prior - why would I want them
             | as a tenant?
             | 
             | If you had a friend that failed to pay back loans, would
             | you want to make a future loan to them?
        
               | toomuchtodo wrote:
               | Depends on the terms. People change, situations change.
               | It's a big reason why finance firms in the US are
               | attempting to move away from the three CRAs to cashflow
               | underwriting; it turns out credit scores aren't a great
               | forward looking proxy for repayment ability.
        
         | astura wrote:
         | >even today i read on HN not to pay off your mortgage if you
         | don't have any other loans or it might tank your credit score
         | 
         | Only when it drops off your report, which is 10 years after you
         | pay it off.
         | 
         | If you were so concerned about having a line of credit on your
         | record then open up a credit card and don't use it, no reason
         | to pay thousands of dollars in interest to avoid an abstract
         | fear of "tanking your credit score."
         | 
         | >it really sucks for the average consumer, yet there is no
         | actual change coming
         | 
         | I am an average consumer. The credit system is great for me!
         | I'm able to demonstrate my responsibility and as a result I'm
         | able to obtain a large amount of credit products at very low
         | cost as well as pay less for insurance. I guess you can argue
         | that the government should be providing this service rather
         | than private companies or there should be more regulations
         | around security, but the system only "really sucks" for people
         | who take out loans and don't repay them.
        
           | hedora wrote:
           | Funny story:
           | 
           | Rocket mortgage fraudulantly tanked our credit score and
           | refused to fix it. The other bank's underwriting department
           | looked at it, shrugged, and honored the mortgage office's
           | request for an override to give us the best available rate.
           | 
           | IMO, Credit ratings are theater.
        
             | [deleted]
        
             | mrguyorama wrote:
             | I had $60k in the bank and was paying $12k down on a used
             | car that cost $28k and would be worth $30k the second I had
             | the keys (the dealership seemed to low ball it a little,
             | probably because they were a new volvo dealership with one
             | GTI on the lot they had for like a couple months that they
             | needed to get rid of), but no, they still needed to check
             | my credit, which at the time did not exist, and still
             | required me to sign up to $2k interest payments over a 5
             | year loan that would have been more profitable if I never
             | paid a cent and they could reposes the collateral.
             | 
             | I know there are contrived ways I could have killed the
             | value of the vehicle before the loan was done and they
             | couldn't recoup it, but like, come on. My credit report was
             | BLANK. It was never needed in the first place.
        
           | barbecue_sauce wrote:
           | Why do you consider yourself an average consumer?
        
             | runarberg wrote:
             | I would love to see some data about this but it wouldn't
             | surprise me if many USA residents don't have a credit score
             | at all, or if they do, it is very minimal. Given how many
             | are underbanked, I wouldn't be surprised if the average
             | credit score is heavily skewed by the people gaming it.
             | 
             | Anecdotally, neither me nor my partner have a credit score.
             | I know several people where I'm living that are permanent
             | renters/get owner financed loans, buy used cars with cash
             | (or are simply given old cars, or don't have a car at all).
             | 
             | I did a superficial search and found some census data
             | (https://www.census.gov/data/datasets/time-
             | series/demo/cps/cp...) but I have no idea how to read it.
             | 
             | Edit: Looks like my suspicions have some merit:
             | 
             | > 22% of Americans do not have a credit score. Half of this
             | percentage has a stale credit score that makes it
             | impossible to generate a valid FICO score while the other
             | half do not have any credit file with any of the three
             | credit bureaus--Equifax, Experian, and TransUnion.
             | 
             | > 18% of Americans have credit scores that fall in the
             | 580-669 range of "fair." those in the fair range are
             | considered sub-prime and have lower chances of qualifying
             | for a loan or getting better interest rates.
             | 
             | https://comparecamp.com/credit-score-statistics/
        
           | runarberg wrote:
           | I posted on my sibling that 22% of Americans have no credit
           | and of the ones that do have credit, 18% have a subpar credit
           | score. That sums up to over a third of Americans that the
           | credit system is either working poorly or not working at all.
           | 
           | Maybe you are indeed an "average consumer" (whatever that
           | means) but if you are, then the credit system is heavily
           | skewed in your favor, with many "non-average consumers"
           | falling by the wayside.
        
           | toast0 wrote:
           | > Only when it drops off your report, which is 10 years after
           | you pay it off.
           | 
           | I haven't seen what happens at 10 years, but there's
           | definitely an effect after about a year; mine dropped 50
           | points, which isn't really tanking, but could switch you into
           | a different risk category depending on where you started.
           | Finishing up my car payments didn't help either.
        
             | staringback wrote:
             | Credit Karma isn't a real score.
        
               | toast0 wrote:
               | Who said anything about them? This is on scores reported
               | in my online banking.
        
               | staringback wrote:
               | Then your online banking is using the same fake score as
               | Credit Karma (usually called VantageScore or something
               | like that)
               | 
               | If you actually want to get the score that lenders use,
               | experian.com will give you your FICO 8 score. This score
               | considers all accounts open the same until they have been
               | closed for 10 years.
        
               | toast0 wrote:
               | One of my banks says:
               | 
               | > The FICO(r) Score pulled on [date] is the FICO(r) Score
               | 8 based on Experian data, and is the same score that
               | [name of institution] uses, along with other information,
               | to manage your account.
               | 
               | Another says:
               | 
               | > The score provided here is FICO(r) Score 8, which is
               | based on TransUnion(r) data and may differ from other
               | FICO(r) Scores. Variations may also occur when your score
               | is based on data from another consumer reporting agency
               | or calculated at a different time. [name of institution]
               | and other lenders may use different scores and other
               | information in credit decisions.
               | 
               | I'm not going to intentionally interact with Experian
               | directly, unless I have to, so not going to compare
               | there. From what I recall, when I last opened a loan and
               | they disclosed the scores, they were within spitting
               | distance of what I was seeing from my banks at the time.
               | 
               | Now maybe FICO 8 score means something different than
               | FICO Score 8; these guys like to be deceiving, and maybe
               | some banks give the VantageScore, but mine seem to give a
               | FICO Score 8.
        
           | icedchai wrote:
           | Paying off your mortgage won't "tank" your score.
           | 
           | I paid off my mortgage almost 15 years ago. I have zero debt,
           | no car loans or anything, and pay off my credit cards in full
           | every month. My credit lines are barely utilized (single
           | digit percentage.) My score seems to vary from 790 to 810.
        
             | SoftTalker wrote:
             | Using credit cards and paying them off is keeping ytour
             | score up.
             | 
             | If you have no debt and pay cash as you go for your
             | expenses, you will eventually drop because the credit
             | bureaus will have no recent data to compute a score.
        
         | ufmace wrote:
         | We should remember the reason why it was created - to replace
         | decisions for approvals on loans, mortgages, apartment rentals
         | etc being made by low-level individuals for a variety of
         | arbitrary reasons. Many places made such decisions based on
         | personal connections, class, race, and other such things. AFAIK
         | most other places still use such systems. Replacing that with a
         | system where everybody's worthiness and terms for such things
         | is determined algorithmically based on numeric data is a great
         | move towards equality.
        
         | ndsipa_pomu wrote:
         | There's a bunch of people making money from it and that usually
         | takes precedence over whether it is fit for purpose in other
         | ways.
        
           | thinkmassive wrote:
           | Yep, think of credit score as a rating of how likely a debtor
           | will be profitable to creditors over the long term.
        
         | tau255 wrote:
         | I find it kinda similar to:
         | 
         | -USA tax system where Turbofax created a niche for itself and
         | fights hard to keep the system as convoluted as it can be to
         | detriment of everyone
         | 
         | -USA healthcare insurance system where insurance companies do
         | the same
         | 
         | Seems like best way to profit is to become a parasite that does
         | not fix the problem but just defends the current situation.
        
         | randommuser wrote:
         | Does anyone have good resources on what other non us countries
         | do? Asking as an American curious/wanting to learn more.
        
           | worksonmine wrote:
           | I don't have any resources to share but in my country the
           | bank looks at my income - expenses then checks if I've
           | defaulted on any debts. My limited understanding of the US
           | system is that everyone has (often several) credit cards to
           | build the necessary credit score. Here owning a credit card
           | is for people drowning in debt who struggle to pay bills on
           | time or in rare cases new money flexing their amex black,
           | which is also shunned upon.
           | 
           | I've always thought the US system was super weird and
           | backwards forcing debt on people. We don't have credit cards
           | from every big chain and don't get harassed into signing up
           | for cards in the mall, it's just not a thing.
           | 
           | We have the same safeguards you have, but we prove it with
           | sensible spending instead of getting debt just to prove that
           | we can pay it in time.
        
             | Nifty3929 wrote:
             | "looks at my income - expenses then checks if I've
             | defaulted on any debts" - This is basically what we do in
             | the US as well. But HOW do they do this in your country?
             | 
             | In the US, the loan originators look at year-end tax forms
             | or recent pay stubs to verify income. They look at credit
             | reports from e.g. Experian to verify defaults and other
             | debt information.
        
           | hungryforcodes wrote:
           | Google is your friend...
        
           | technion wrote:
           | Australian here. When I apply for rentals I just went to my
           | online banking and took a screenshots of the deposits.
           | 
           | It's been years since I had my mortgage approved but I
           | vaguely recall the process being very similar.
        
         | nicolas_t wrote:
         | I disagree with the better ways used elsewhere, as a French
         | citizen who has worked abroad all his life, I can barely get
         | anything. When I came back to France for a year due to my
         | father's health issue, it was difficult getting an apartment
         | because I had proof of income for more than 3 years in France
         | (the current income I was declaring of 150k usd a year working
         | remotely from France didn't count). People in France who have a
         | CDI (permanent contract) can easily get mortgages and
         | everything but entrepreneurs, people on fixed term contracts,
         | etc... have a very hard time getting anything.
         | 
         | With a US social security number that I got as a student and
         | good management of my credit card accounts that I kept since, I
         | have a good US credit score and can easily get a mortgage in
         | the US. Of course, it's possible to game it, but you can also
         | get a very decent score by just managing your finances well.
         | 
         | So from my perspective, I think the US system works much
         | better. Does it have issues? Yes, there's data leaks, there is
         | some gaming of the system (by the way, paying off the mortgage
         | won't tank the credit score, it'll lower it yes by a few
         | points, but that's mostly inconsequential)
        
           | mancerayder wrote:
           | > I disagree with the better ways used elsewhere, as a French
           | citizen who has worked abroad all his life, I can barely get
           | anything. When I came back to France for a year due to my
           | father's health issue, it was difficult getting an apartment
           | because I had proof of income for more than 3 years in France
           | (the current income I was declaring of 150k usd a year
           | working remotely from France didn't count). P
           | 
           | Do bank savings count for anything?
        
           | mixmastamyk wrote:
           | "Working remotely from" means long term you'll be paying
           | taxes there. Which should be proof, and if not should be
           | fixed. Having to wait a year or three is probably fine for a
           | mortgage, no?
        
             | giraffe_lady wrote:
             | French bureaucracy is infamous for a reason and it's not
             | just the state itself. A CDI is a certain type of
             | employment contract, and a CDI is a CDI and everything else
             | isn't, and a CDI is required for almost any significant
             | loan. Workarounds are possible for smaller loans IF you
             | have a personal relationship with the bank officer
             | servicing that area. But if you didn't grow up there, or
             | don't normally bank there, or they're suspicious of your
             | race or tattoos, or were your bully in high school or or
             | or. This sort of thing is more or less exactly what the
             | credit reporting setup was meant to eliminate.
             | 
             | It doesn't matter what it "should be" proof of or what a
             | reasonable person could infer from this income or
             | documentation of it. If you don't have a CDI, which even
             | many full-time employed people don't, you're in a hard
             | spot.
        
               | mixmastamyk wrote:
               | Again, I don't see anything here that requires a third-
               | party as intermediate. If you have a system broken in
               | another way, go right ahead and fix that. But it is not
               | sufficient justification for incredibly bad actors such
               | as Experian et al to exist.
        
       | galoisscobi wrote:
       | Ugh, annoyingly Experian was the hardest one to do a credit
       | freeze on. A few weeks ago, I was able to easily do a credit
       | freeze on other bureaus but Experian wanted me to call them
       | during business hours so I put it off. It might not help much but
       | I'll plan on doing the credit freeze with them today.
        
       | twinkletwinkle_ wrote:
       | Without going into too much detail, I once encountered an
       | Experian identity verification question on behalf of someone
       | else. This person was an Uber driver making ~$20,000 per year.
       | 
       | The question was: "According to our records, you purchased or
       | leased one of the following vehicles in the previous year. Which
       | vehicle do you currently own?"
       | 
       | A. Maserati Granturismo
       | 
       | B. Ferrari 458 Italia
       | 
       | C. Aston Martin Lagonda
       | 
       | D. Honda Accord
       | 
       | So... 2 Italian supercars, another supercar with only 200 ever
       | produced, or a mass market sedan.
       | 
       | Bonus - of the 4 questions, you only needed to answer 1 correctly
       | to pass the check.
        
       | EricE wrote:
       | A reminder that if you haven't frozen your credit with the three
       | credit agencies - it's a great time to do so!
        
       | tantalor wrote:
       | This is a really poorly written article. It goes on and on about
       | poor security and how much the credit agencies should not be
       | trusted, but it never says why this disclosure is harmful or why
       | anyone should care.
       | 
       | To say "identify thieves do this" implies "this is harmful" is a
       | post-hoc fallacy.
        
         | ThaDood wrote:
         | I mean, I might be generalizing here but I think the target
         | audience for Krebs is usually security minded individuals who
         | probably don't need an explanation as to why having your credit
         | information leaked is bad.
        
         | projektfu wrote:
         | At the beginning of the article he mentions that Telegram
         | channels where attackers discuss methods have been sharing the
         | method, as part of their plans to steal money from people. If
         | the red team wants it, it's probably worth their while.
        
       | twobitshifter wrote:
       | How much value do the credit agencies add beyond what could be
       | obtained by knowing income, location, number of dependents, and
       | current debt/liabilities?
       | 
       | verifying identity is another matter, but I'd expect what you put
       | on the credit application to be the data that explains the
       | defensible reasons to not give a loan, without needing a magic
       | credit score.
        
         | anonymouskimmer wrote:
         | "How much value do the credit agencies add beyond what could be
         | obtained by knowing income, location, number of dependents, and
         | current debt/liabilities?"
         | 
         | Theoretically they verify these numbers. Otherwise people would
         | lie. Presumably, in the credit score calculation, they also
         | have actuarial tables that allow calculating the odds of delay
         | or default for each person.
        
       | Phemist wrote:
       | Meanwhile, UK Gov project One Login will use cloud services
       | architectured by Experian:
       | 
       | https://www.publictechnology.net/articles/news/government-pl...
        
       | janalsncm wrote:
       | The whole concept of "identity theft" is a concoction meant to
       | pass blame on to consumers rather than creditors. If a bank gives
       | away money to a person pretending to be you, that shouldn't be
       | your problem. The bank screwed up. Your "identity" wasn't stolen,
       | the bank didn't do basic due diligence and now they're looking to
       | pass the blame on to you.
       | 
       | https://youtu.be/CS9ptA3Ya9E
        
       | [deleted]
        
       | [deleted]
        
       | DontchaKnowit wrote:
       | Always thought Experian was a disgustingly juicy target and it
       | was just a matter of time before something like this happened
        
       | alberth wrote:
       | Naive question: what harm can come from someone having your
       | credit record?
       | 
       | Companies all the time do hard inquiries to access your credit
       | record.
       | 
       | EDIT: don't get me wrong, it's not good this was able to be done.
       | But what's the actual impact though?
        
         | downrightmike wrote:
         | Fun one is they buy a motorcycle and insurance and keep
         | charging it to you and you have to fight with the insurance
         | companies to clear the debt.
        
         | tantalor wrote:
         | Came here to ask this. The article doesn't say why this is a
         | bad thing.
         | 
         | At best it implies poor security by the credit agencies might
         | increase the risk that "identity thieves will ruin your
         | financial future" but it doesn't say how access to a credit
         | report will do this.
         | 
         | Guessing: something in the report (what exactly?) might make
         | taking out bogus loans easier by selecting the most vulnerable
         | victims (why?)
        
         | mynameisvlad wrote:
         | Identity verification questions are generally based on public
         | records along with the credit report information. Some
         | questions might not be detailed in the report (like how much a
         | specific loan's monthly payments are) but others would
         | definitely be included, like the name of a creditor on file.
        
       ___________________________________________________________________
       (page generated 2023-01-09 23:01 UTC)