4 ms·
In the US, a combination of personal information is taken by most as proof that you are who you claim to be. If you know enough of someone else's information,
by unit91 9y ago
In the US, a combination of personal information is taken by most as proof that you are who you claim to be. If you know enough of someone else's information, you can steal money rather easily. We need a better identity solution, but it's what we have right now.
- literallycancer 9y agoThere is probably no way to make that work, without improving the security. Same thing with credit cards, is it so hard to ask for a PIN when trying to pay with them? Or use 2FA like in any internet banking? For what it's worth, here in Europe you could pretend to be someone else as well, if you have enough information, but what's the point when you can't touch their money?
- quuquuquu 9y agoWhat do you mean by, "you can't touch their money"? You can spoof their identity, to instantly acquire material goods / lines of credit. And, if you are extremely persistent, you can spoof identity documents and hack bank accounts.
- literallycancer 9y ago>What do you mean by, "you can't touch their money"? If you had the number of my credit card, my account number, my social security number (or the local equivalent), my address or my name, or whatever else, short of my 2FA device and my internet banking credentials, you won't be able to steal anything. (And at that point, you might as well walk up to my house, break a window and steal whatever the hell you need while I'm somewhere else, why bother with hacking.) If the 2FA device is just a phone, there's a few things you can do, otherwise not really. Are you going to deploy a fake cell tower to steal the code? Probably just conning the cell company support person would be good enough. Not sure whether they'd mail a new SIM to a different address (and they'd probably let me know). Maybe they'd give it to you if you presented an ID. You could have a fake one made, I guess. It would be a bit weird if you didn't speak the local language though. Quite a lot of effort compared to copy pasting a credit card number. Not something you'd do on a large scale. >And, if you are extremely persistent, you can spoof identity documents and hack bank accounts. Yes, but against a determined attacker that singles you out, you are fucked regardless of what you do, especially if it's your bank or similar service provider that screws up even if you don't.
- foota 9y agoYou seem to have jumped over the question of identity theft for applying for lines of credit. I believe this is what most people are concerned about.
- EGreg 9y agoIt should be simple: When applying for new accounts, or logging in from new devices, you should be receiving an email and/or sms on the endpoints of your choice. And then able to stop those things from happening.
- yxhuvud 9y agoThere have indeed been issues of identity theft here in Sweden where the thieves ordered a new login to the 2fa app and then managed to get hold of it from postal offices with bad verification processes. So now the practice is to fetch the credentials from the nearest bank office or something like that.
- quuquuquu 9y ago>Yes, but against a determined attacker that singles you out, you are fucked regardless of what you do, especially if it's your bank or similar service provider that screws up even if you don't. Isn't that what we're trying to prevent- becoming the victim of a determined attacker? I don't really care about protecting myself from /only/ script kiddies. If I put my money in a bank and they "accidentally" allow someone other than myself to withdraw it, /the bank/ has been defrauded, not me. Thanks to corporate control of the US gov't, it is now me who has actually been defrauded, thanks to some fun mental gymnastics. So, I have to spend time and money and frustration trying to convince the bank to uh... what's it called... oh yes, give me my money back, please. The system is broken for sure, but I really truly hope we can vote some people into office who will turn the tables on how these laws currently work. Otherwise we will all eventually be hacked, stolen from, or worse.
- Kluny 9y ago> Or use 2FA like in any internet banking? That's the funny part - there's no 2fa available for most internet banking in Canada or the US. In Denmark we get the NemID card mailed to us, but in Canada it's just your card number+password+sometimes they ask a security question like "what high school did you go to?"