14 ms·
Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and
by hrehhf 9y ago
Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank.
Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit reporting agencies inflicting this upon Alice. BigBank is the victim who lost money, and BigBank bears the responsibility for making the mistake of giving out a loan in Alice's name. The Fraudster committed a crime against BigBank, not against Alice. It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice.
The idea that Alice was victimized by Fraudster is a concept being perpetuated by the credit reporting agencies as a way to absolve themselves of responsibility, and place the burden upon the consumer, and to avoid realistic identity-verifiction which might slow or complicate the practice of issuing large amounts of debt to the general public.
- Simon_says 9y agoThis is very clearly what's going on. Fraud is uncommon enough and the cost of fraud to the banks is smaller than the cost of reducing the velocity of money and loan-making, so the problem will never get fixed so long as it depends on the banks to initiate the fix.
- adrr 9y agoWork at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.
- fweespeech 9y agoBanks carry the risk like they do for credit cards, consumers carry $100 of the risk and the risk to their credit rating.
- wolco 9y agoChange the way checks are issued/redeemed. Right now the customer is on the hook for 7 years because a check isn't cleared until it goes back to the bank that issued the check . The customer thinks by seeing the money in the account the check was good and can clear a sale. The reality is the bank can take that money back if it is later determined to be false/fake.
- adrr 9y agoPaper checks are going away. Some of the online banks don't even support them. ACH allows only 60 days to claw back the money(disputes) and with same day clearing requirement we can get rid of 2 day holds.
- pfranz 9y agoWhat are they being replaced with? Yeah, as a young renter I went years without using a check. When buying a home last year I had various inspectors during the process. After buying, I've had electricians, plumbers, contractors, locksmiths, and other consultants. I think one gave me a bill and accepted credit card. The rest preferred checks (to be fair, I didn't seek other forms). I've tried all sorts of p2p methods over the years. All of the banks are too confusing, obscure, or too limited (i.e. only within their bank). Paypal and credit cards charge a not-insignificant fee. Venmo or Square Cash work fine if your group of friends accept them--but more than half the time, they don't for me. I often do ACH transfers between my own accounts, but the first time I set it up a cringe a little bit and cross my fingers. It sucks waiting the 2 or 3 days waiting to see something. I can't see small businesses accepting ACH as payment because they want something in hand. If we had the setup I've heard about in Britain or Europe, I can see checks going away, but with as much churn as I've seen in this space in the 20 years since Paypal, nothing seems to stick.
- thanksgiving 9y agoFor some, it might be walmart. Previously, on hn https://news.ycombinator.com/item?id=8361329 https://news.ycombinator.com/item?id=8361329
- hyperpape 9y agoI've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those authorizations to each other. Individuals who need more flexibility could opt out or do something more complicated, at the cost of some risk. There's some cost to this, but I still suspect quite a few people would accept it.
- ac29 9y ago>carrying official ID It's probably not hard to forge a social security card and birth certificate if you have the relevant information. From there, a state ID (or maybe even passport) should be possible to get. I don't believe there is any biometric security on either. A determined identity thief might go that far.
- rphlx 9y agoThe thief would have to physically resemble the victim's photo, height, age, gender, etc, which is some added defense in depth. For instance it would be hard for most males to pass themselves off as a typical female.
- munin 9y ago> The thief would have to physically resemble the victim's photo Why? Show up to a government station with your birth certificate, SSN, some telephone and utility bills, and they'll take the thiefs picture and put it on an identity card with your name on it.
- zo1 9y agoThat sounds incredibly bad for a first-world country. If that was the case, I'd argue that the entire country is in collapse. As you then have no control over foreigners impersonating locals and manipulating something as serious as elections, never-mind bank-fraud. Edit: Point being, this needs to be fixed ASAP if you are to move your country into the future. Fix the regulatory/state hurdles that prevent it from happening, and get yourselves National Identification that's secure. Things will flow positively from there.
- zo1 9y agoVerify that person's biometrics against the national database? I know that's what's happening in South Africa, a third-world country: http://www.htxt.co.za/2015/09/16/this-is-how-banks-and-home-affairs-smartcards-will-use-fingerprint-id/ http://www.htxt.co.za/2015/09/16/this-is-how-banks-and-home-...
- Simon_says 9y agoThe big architectural flaw is that when I as a consumer prove my identity to company A, that gives company A enough information to impersonate me to company B. Or equivalently, it can give a rogue employee at company A that power, or anybody who hacks company A's database. The solution is asymmetric cryptography, wherein identity is tied to a public/private keypair, and I can prove I have the corresponding private key without giving the other party the ability to impersonate me. Ideally, the government wouldn't know my private key, either, rather they would just give their own attestation that a given public key is owned by a person with a given name, DoB, SSN, and biometrics. Along similar lines, any financial account would have its own keypair, with moving money out of the account requiring signing with the private key. The state of cryptography today is way too obtuse for this to work right now, but I think it could be made more user friendly with specialized hardware to hold the keys and perform the encryption. The idea that SSNs are secret, but we hand it out to half a dozen organizations is absolutely ludicrous.
- MarkPNeyer 9y agoExactly. Eve lies to bob, and tells Bob she's Alice. Bob asks Claire, who says Yes, that's Alice." Bob gives Eve money, and Eve runs off. This should not be Alice's fault, responsibility to solve, or problem to deal with. It is, because Bob is much, much more politically powerful than he ought to be.
- adrr 9y agoBigbank is the only one in your scenario that actually has monetary loss since they lent out the money and most likely will never get it back. In identity theft, the company has the financial loss. FBI won't investigate unless its over 250k in losses as well.
- MikeGale 9y agoPretty twisted world where provable financial loss is the only or main measure.
- deleted 9y ago[deleted]
- TheCondor 9y agoYou certainly can quantify the monetary losses to Alice too. When her credit rating is shit and she buys a car or home, the banks are expert at placing those rates and can tell you exactly how much more she pays. What is more difficult is calculating the loss of what she doesn't even do due to bad credit, like she might not be able to rent the same apartment, she might not even try to buy a car. She may not have to pay that bank loan back but that doesn't clear her credit up immediately.
- Spooky23 9y agoFraud isn't limited to credit. My dad had someone open a savings account in his name and transfer a significant amount of money via ACH. He only found out because he got a welcome or from the bank! The police investigator told him that the particular fraud that he was a victim to was impacting >500 people and >$5M
- hansjorg 9y agohttps://www.youtube.com/watch?v=-c57WKxeELY https://www.youtube.com/watch?v=-c57WKxeELY
- odins_caribou88 9y agovery well said!!
- toufka 9y agoPrecisely. In no way was Alice's identity stolen - that's tautologically impossible. Rather, the bank was defrauded by the criminal - Alice is of not a party to whether or not the bank recovers from its own loss. Alice's ownership is entirely unaffected, though the bank's internal processes might not reflect that - again, their problem, not Alice's. Further - this rat race, where I have to give ever more intimate details about myself to verify who I am, "for my own protection", seems to only ratchet away my privacy until there is nothing about me left unpublic. Facebook, Banks, Airbnb, Credit Card companies, Telephony companies have ALL given me that line when I resist providing SSN, DoB, or whatever mine-able nugget they're looking for this month. Every time I give out a new kind of private information it inevitably leaks - defeating their point of having asked me - all the while my privacy is left scorched while they move on unconcerned to the next piece of my private life. It's uncomfortable.
- mattmanser 9y agoI've worked a bit in the industry and around the industry, the worrying thing for me is that it doesn't seem to be working for anyone apart from equifax/experian/call credit. I have separately worked with one of those companies with a client and their IT staff were utterly incompetent (I won't say which). Loads of different sites, lots of little fiefdoms, utterly inconsistent security policies on each site, blaming everyone but themselves because only half their sites could access a video on a major commercial video provider (not-youtube). We ended up having to host it on AWS cloudfront as none of them had blocked it yet. Their sharepoint could only host a 50mb file, which made their CEO look like a blockhead in the 20 min high def video. Utterly incapable of hosting a simple video file so all their staff could access it in 2010. I've also worked with a company one of those companies acquired for $100 million+, holding millions of people's personal details in the UK, with some very sensitive data. Some of the worst IT engineering I have ever seen, a bunch of tools written by the worst out-sourced IT teams I have ever seen (if you've ever worked with C#, these idiots made a project per .cs file. Yes, PER CS FILE. They also wrote the worst SQL I have ever seen, all of the stored procedures seemed to be duplicated but the duplicates had op_ before them. I eventually realised the op_ stood for optimized! They were still terrible and half the program used one set of SQL, the other half the optimised. Whenever I re-wrote one of these 'optimised' queries, I usually knocked it from seconds to milliseconds. Outsourcers in the naughties really did suck that bad, young 'uns). We've given up huge amounts of privacy, but the scores are utter bullshit and the 2008 crash show what a load of nonsense they are. A friend even told me at uni he'd got a £1000 loan out to get a good credit rating. You just put the money in an account, pay the capital off every month, lose a little bit of interest and in 2 years you have a shiny credit rating even though it means zilch. equifax/experian/call credit basically get given all our personal spending habits for free, sell it on to everyone else for crazy money, don't add anything to the economy and as far as i can tell, are a huge security hole. EDIT: Another anecdote on how incompetent these people are, a couple of years ago someone used my details to scam a few free phones. I got alerted to it when I started receiving insurance contracts for those phones in the post. The phone companies sorted it pronto, almost immediately admitting they'd been scammed, but I wanted to make sure my credit rating hadn't been trashed. In the UK these agencies must provide you with a credit report for a nominal fee so you can check for incorrect details, so I applied to the big 3. One of them accused me of trying to hack their system because I'd forgotten a security question, eventually told me to fuck off after passing through various layers, then sent me a letter saying they'd detected a hacker trying to access my details. No, you idiots, that was me. Still never got my report from them. Yes, they still use security questions.
- Spooky23 9y agoClearly, both the bank and the individual are victims of the crime. Generally speaking, the impact to the customer is usually greater, as bank business model aren't dependent on every loan being repaid. Consumers stand to lose money directly and lose the opportunity to access capital. The credit agency or anyone else who has a breach is usually a negligent third party.
- ticviking 9y agoThey are victims of very different things though. The bank is a victim of fraud. The individual is a victim of impersonation by the borrower, and slander by the bank and credit agencies.
- uiri 9y agoNot sure how the individual is victimised by the fraudster here. If the bank had a 100% success rate at detecting fraud with no false positives and no false negatives, then the individual wouldn't need to know and likely would never find out about the impersonation attempt. The individual is victimised by the bank and the credit reporting agencies by their spread of misinformation.
- zAy0LfpBZLC8mAC 9y agoThe individual isn't in any way a victim of the crime. A bank used some information presented to them to conclude that they were dealing with Alice when that information was objectively not sufficient to justify that conclusion. That has absolutely nothing to do with Alice. Alice is victimized in the next step by the bank when the bank claims that it somehow is Alice's responsibility that they took someone else for Alice.
- perlpimp 9y agoIn some countries when you sign out a loan and a card you get picture snapped. but then this measure would stick banks with loans and not the consumer.
- jameshart 9y agoWhat Alice is the victim of is slander, not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation. The credit agencies then go ahead and repeat that slander.
- njarboe 9y agoThis is a great description of what is going on with "identity theft". I don't usually like changing the name of something to try to push an agenda, but calling "identity theft" "bank slander" would be good idea.
- sjg007 9y agoSo presumably a class action law suit against the reporters for slander? Might depend on specifics of the law... Maybe it's time for a better credit reporting agency startup.
- mycall 9y agoEspecially if a very large class action law suit was started from this. Calling all identity thief peeps....
- sowbug 9y agoYou mean slander by banks, not slander of banks. The term you propose is ambiguous.
- mywittyname 9y agoWow, I learned a ton from this comment. I would have never come up with this on my own.
- zAy0LfpBZLC8mAC 9y agoWell, yes, Alice is the victim of slander, and the bank is a victim of fraud. But the important point is that neither of those imply that Alice is responsible for anything.
- tssva 9y agoThe credit agencies report what has been told to them by BigBank. Once the fraud is detected BigBank should update them that Alice does not in fact have a $10,000 loan with them and it would then be removed from Alice's report. If the loan has been determined to be fraudulent and it has not removed from her credit report, BigBank is victimizing her not the credit agencies.
- discreditable 9y ago"Now back when I worked in banking, if someone went to Barclays, pretended to be me, borrowed £10,000 and legged it, that was "impersonation", and it was the bank's money that had been stolen, not my identity. How did things change?" https://www.lightbluetouchpaper.org/2017/08/26/is-the-city-force-corrupt-or-just-clueless/ https://www.lightbluetouchpaper.org/2017/08/26/is-the-city-f...
- zAy0LfpBZLC8mAC 9y agoBrilliant Mitchell and Webb from the comments there: https://www.youtube.com/watch?v=CS9ptA3Ya9E https://www.youtube.com/watch?v=CS9ptA3Ya9E
- redm 9y agoThis argument is akin to splitting hairs. The fraudster who applied for the loan against BigBank was at fault. The BigBank accepted the Fraud and reported it to the credit agency. The Credit Bureau reports/includes the data provided by BigBank; it's what they do. If there is a dispute between what BigBank says and what Alice says, it's not necessarily so easy to resolve, and that's the position the Credit Bureau has to deal with. To absolve the fraudster of the primary fault is ridiculous. That said, this is the problem with difficulties in identity verification, we all want privacy and security at the same time. While they are not mutually exclusive, having both is much more complicated than one or the other.
- g051051 9y ago> It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice. Credit Reporting agencies report the data passed to them by companies such as banks. In your scenario BigBank thinks it's given a loan to Alice, and when they don't get repaid, report that to the CRAs. Alice is a victim of the thief because her identity was appropriated to secure the funds. BigBank is a victim of the thief because they were defrauded. The CRA is a victim because they were just reporting the information that was provided to them in good faith by their customer BigBank. So saying that the CRAs are "victimizing" Alice is completely false. Alice bears the burden and risk of clearing her name, just as a victim of car theft bears the burdens of reporting the crime, getting another vehicle, dealing with the any outstanding loans, etc. These burdens are inflicted by the thief, not the bank or CRA. > perpetuated by the credit reporting agencies as a way to absolve themselves of responsibility, [...] and to avoid realistic identity-verifiction which might slow or complicate the practice of issuing large amounts of debt to the general public. This completely misunderstands the role of a CRA. The CRA doesn't have to verify identity, it's up to the credit grantor to ensure they are dealing with the person they think they are.
- zAy0LfpBZLC8mAC 9y agoYour comparison is bullshit. I have control over how I secure my car from being stolen. It's complete nonsense to equate that to me being responsible for a bank's failure to protect themselves against fraud where I have no power whatsoever to influence how the bank secures itself against fraudulent loan applications.
- g051051 9y agoYour statement is nonsense. Regardless of your efforts, the best you can ever hope for is to minimize the chance of your car being stolen. You can never prevent it completely. If your car is stolen in spite of your best efforts, are you at fault? Do you still have to deal with the consequences as a victim of that theft?
- zAy0LfpBZLC8mAC 9y ago
- emiliobumachar 9y agoAgreed. Thought experiment: suppose instead that Fraudster convinced Alice that he represented BigBank, and so Alice was duped and gave her money to Fraudster thinking she was depositing into BigBank. The only thing she could expect from BigBank was politeness while explaining to her that she was duped. If it's a very friendly bank, she may tie up a manager for a couple hours, but that's it. If she keeps coming back, she'll soon be escorted out by security, or the cops. Now, what if she started falsely telling others that BigBank took her money, and that significantly affected BigBank's reputation? Are we talking jail time, or just civil penalties?
- dlubarov 9y ago> Are we talking jail time, or just civil penalties? Jail time could be a possibility depending on jurisdiction. In the US, a handful of states have criminal defamation statutes - https://en.wikipedia.org/wiki/Defamation#Criminal_defamation_3 https://en.wikipedia.org/wiki/Defamation#Criminal_defamation...
- dragonwriter 9y ago> Now, what if she started falsely telling others that BigBank took her money, and that significantly affected BigBank's reputation? Are we talking jail time, or just civil penalties? Probably not jail time, and perhaps not civil penalties. Even civil defamation in US law generally requires knowing falsehood or reckless disregard for the truth, not just mere falsehood, and criminal defamation, where it exists, tends to have high . Unless the bank had provided concrete evidence so solid that it was unreasonable for her not to believe their denial of responsibility, there likely be no legal wrongdoing.
- sowbug 9y agoAn even more analogous experiment would have Alice take out a mortgage with BigBank, then receive a fake notice of debt reassignment to BiggerBank, which is actually Mallory. Alice makes mortgage payments to Mallory for many months. Now BigBank is wondering why Alice fell behind on her mortgage. Who's the victim?
- devotedtoneu 9y ago
- swat535 9y agoThis may damage Alice's reputation temporarily however, once the bank determines that it has been defrauded, it should make the loan information inaccurate. I believe the Fair Credit Reporting Act allows Alice to remove inaccurate information from the report?
- goialoq 9y ago"Mitchell & Webb Sound - Identity Theft" https://www.youtube.com/watch?v=CS9ptA3Ya9E https://www.youtube.com/watch?v=CS9ptA3Ya9E
- danjoc 9y ago>It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice. I think you're confused. It's BigBank that's falsely placing a debt burden on Alice. The credit reporting agencies are only reporting what they are told. Imagine if Alice doesn't care about her own credit worthiness. Let's say she has no debt, and no intention of acquiring debt. What happens if criminal tricks BigBank? They say, "Alice, you owe us this money." Alice tells BigBank, "No, prove it or pound sand." What happens then? BigBank goes to the court and tries to get a judgment against Alice for the money owed. If Alice isn't aware of the proceeding, the judge will grant BigBank's request, and now Alice will owe BigBank the money stolen by criminal. BigBank's poor authentication and the judicial branch are the ones doing the real harm to Alice. If anything, the credit reporting agencies are providing value to Alice by warning her before BigBank goes after her in a secret proceeding and makes the debt hers.
- mycall 9y agoIt isn't BigBank warning her.. it is the collection agencies, but that's just semantics.
- danjoc 9y agoThat's exactly the point. BigBank isn't going to warn anyone. It's just going to seek judgement, or sell the debt to shady collectors and write off the difference. https://www.nytimes.com/interactive/2014/08/15/magazine/bad-paper-debt-collector.html https://www.nytimes.com/interactive/2014/08/15/magazine/bad-... Think about the credit reporting agencies as a rather sloppy "master list" of who owes who money. It seems what is needed are stiff penalties for banks and collection agencies who falsely claim they are owed money. Until then, you can't live in peace. Someone is going to claim you owe them money if you have any money yourself.
- shimon 9y agoWhat actually happens: 1. Alice does have debt, and does intend to acquire debt in the future, like most people. The presence of this fraudulent debt in her credit report makes credit more expensive and hard to get. 2. Before filing suit and going to court, BigBank makes persistent but usually polite attempts to collect. But when she says "that wasn't me" they don't believe her, because lots of deadbeats say that sort of thing too. 3. Perhaps BigBank sells the debt to a collection agency, which is far more aggressive and (willfully?) ignorant of laws regulating how and when they can contact Alice. Perhaps they call Alice's employer, threaten to garnish her wages (even if they legally can't), or lie about Alice's ability to contest the debt. 4. If Alice is determined enough to keep fighting and go to court, she has still sunk significant time and money into fighting this. It's unlikely she'll be compensated fairly for that. I agree the credit reporting agency is in some ways helping Alice, and would add that these agencies probably do reduce the rate of fraud overall. But they also have a responsibility to do a good job minimizing errors. We can't expect them to never make a mistake, but they should have some skin in the game when their inaccuracies hurt a credit applicant.
- deleted 9y ago[deleted]
- mgalka 9y agoAgree with your point on Experian absolving itself, but there are many scenarios in which Alice is also the victom of the thief. With enough info about someone, you can steal digital assets too.
- lorenzorhoades 9y agoIf it was on the BigBank to always prove that their identity was indeed stolen, it would quickly become unmanageable. People would commit fraud in the opposite direction, by getting a huge loan from some a bank and claiming that their identity is stolen. I'm sure it would be easier than stealing someones identity to do it, and it would obviously involve some necessary actions to avoid being caught but this would drive loan rates through the roof for the average citizen to make up for all the fraud occurring. I agree with you ideologically, but in practicality i do not believe it would work.
- benchaney 9y agoIn that case banks would just have to verify who they were giving money to before they start handing out loans. That doesn't sound particularly unmanagable to me.
- caf 9y agoThis would obviously drive the BigBank to collect some better evidence that the person applying for the loan is who they say they are, which is exactly the incentives we want here.
- gmac 9y agoThere's a nice comedy sketch on this point by Mitchell & Webb: https://m.youtube.com/watch?v=CS9ptA3Ya9E https://m.youtube.com/watch?v=CS9ptA3Ya9E
- amygdyl 9y agoI wish I could remember details, but a cofounder or single digit employee of a acquisition Equifax made, elected to forgo their earn out, because they were opposed to working in any capacity for Equifax. I think that they were somehow bullied into revealing their reasoning, to escape penalties in contract (which in any event were unlawful in the UK, I heard this from a employment attorney friend who has super reported cases, ie those which established new law). They were immediately snapped up by a startup in VA. Equifax managed to suppress their credit file completely. Preventing them from even renting a apartment for at least a year, and I believe it was a year before they had been even recognised by a US reporting agency and could open and operate a checking account. This was picked up by The Register, which still was then still Mike Magee's baby, so honourable 1., 2.. I can't find a link from my phone, but even if you never believe me the actual events happened, I bet you had a thought that you would not be surprised if it happened more often. 1.(added to qualify that adjective "honourable" which I apply to individuals not companies, and individuals who risk sacrifice without burdening others. My career is in advertising and I am truly impressed when publishers are able to maintain standards that are able to raise their costs of sales. (a large publisher may not lose a account, but the sale often consumes expensive energy, even only to explain why policies exist. I work far from such high sensitivity issues, as does the company I started around the time of this recollection.) 2. last I spoke to Mike, he was telling me how he simply was never issued his shares in "ElReg" and he was long enough into The Inquirer to think that Limitations applied. But Limitations 80 runs from the time of discovery of tort, not the event of tort. Before the chance arose to catch up, and establish facts, Mike had passed away. RIP a great man and two great journalistic servants to the IT community. I did not establish the facts that were alleged, therefore my statement is hearsay, but protected by the statutory defence of genuine belief, and I had always faith in my source. Edit: italics removed from footnote, earn out replaced phypo earnings, and great man replaced good man. Mike was exceptional and altruistic to a fault.