8 ms·
No, it needs to be strict liability. If an entity is as responsible as possible and still accidentally causes millions of dollars of damage, they've still cause
by vec 9y ago
No, it needs to be strict liability. If an entity is as responsible as possible and still accidentally causes millions of dollars of damage, they've still caused millions of dollars of damage. Some things cannot be done safely, and if entities want to do them anyway they should be prepared to bear the consequences.
It may be the case that once all the privacy related externalities are pushed back onto credit reporting agencies then their business model is no longer viable. I, for one, am fine with that outcome. If that's the case then credit reporting agencies were never a net good for society in the first place, and all the regulations are doing is exposing that truth.
- scrumper 9y agoNo, not in that case (your hypothetical responsible bureau): it's the criminals who have caused millions of dollars of damage. The insurance proposal creates the right blend of incentives to promote responsible behavior and punish - significantly - incompetence (i.e. denied coverage). To extend your thinking, consider air travel. Airlines act responsibly, even to the point of having government provide much of their security, yet occasionally terrorists manage to blow up aircraft. In that scenario, you'd have the airline be fully ('strictly') liable because of an external event they did everything to avoid. The harm is greater too - death is worse than ID theft. Truth is, nothing can be done safely. Not travel, not business. There is always a tradeoff between risk and benefit. Credit itself is an enabler for the economy. Credit bureaux facilitate comprehensible risk management, which allows for market forces to operate around interest rate setting reasonably effectively. Absent bureaux that same function needs to be performed, but it'll be done in a decentralized, ad hoc fashion by individual lenders which will impinge on their business models and ultimately drive up rates. So you don't like the bureaux; well, nobody does really. But what is an alternative which allows lenders to compare applicants on a like-for-like basis with some degree of confidence?
- rapind 9y agoWhen I fly, I'm aware that there are risks, and I choose to opt in when I buy a ticket. The risks are super obvious, and I'm the "customer". Not to mention airport security is pretty heavy handed and visible. Data gathering is usually not opt-in and it's also intentionally non-obvious who your information is shared with in most cases. I'm also rarely the customer, which means there's very little chance that my interests are being represented. Security or lack thereof is pretty hidden as well. I suspect we would find a way to fill the economic holes if every credit bureaux was phased out over the next 5 years. IMO, the entire vertical needs to be more transparent.
- scrumper 9y agoYou're entirely right on the first two points. But you do implicitly opt in by being a consumer of credit. I recognize that's a bit mealy-mouthed, since it's rather hard to exist in modern America without being on Equifax's radar, but nevertheless there is at least some illusory optionality. I completely agree with your final point about a need for greater transparency. But this is the situation we are in. I think the much more interesting discussion is about how those economic holes are filled, and it's why I posed that question in my note above. Of all the corners of the internet where you might expect such a solution to be proposed, HN is surely the best. What does post-bureau creditworthiness attestation look like? Presumably it's decentralized, to minimize aggregate harm to people in the event of a hack. Presumably it's de facto (and de jure) verifiable and correctable by each individual. It must also have some sort of graduated 'need to know' disclosure mechanism, with crude aggregate scores available to low-ranked creditors (cellphone companies, for example), and much more detailed information available to senior stuff like mortgage lenders. And why wouldn't it also have a facility, which didn't disclose creditworthiness data, for authenticating users to various services? But then why not go one step further. Why have this stuff in one place per consumer at all? Why not have lenders jus reach out over an API to every other lender to ask in effect "How good a debtor has scrumper, with SSN 01-234-5678, been for you? How long have you done business with her?" and get various answers back, all of which can be factored into some model which conforms minimally to a regulator-provided specification? The size or risk of the loan dictates the depth of that pan-industry query. Companies don't hold any more than they already hold, and there's no nexus for that data at all. And all the lender is allowed to keep is the model result, some sort of FICO equivalent, for a particular applicant.
- rapind 9y agoAt the risk of being trendy, I'd wager the credit bureaux 2.0 (3.0?) involves blockchain.
- vec 9y ago> consider air travel With air travel the people bearing the risk are the direct customers. If I'm uncomfortable with the safety record of airlines I can simply not fly. How do I opt out of the risks imposed by a credit rating agency? The closer analogy, I think, would be if cargo planes were routinely crashing in populated areas. The air freight company and its clients may well be completely comfortable with their loss rate, but the unaffiliated third parties living underneath would have a pretty justifiable reason to complain. > Truth is, nothing can be done safely. Not travel, not business. There is always a tradeoff between risk and benefit. This is absolutely true, but as currently constructed credit agencies get to reap the benefits while pushing the risk off onto the general public. If we regulate to internalize that risk and the agencies still think it's a good risk/reward tradeoff then that's fine. If they no longer think it's a good tradeoff that's fine too. > So you don't like the bureaux; well, nobody does really. But what is an alternative which allows lenders to compare applicants on a like-for-like basis with some degree of confidence? There's several suggestions elsewhere in the thread, but I'm going to go out on a limb and suggest: nothing. On a macroeconomic level, easy availability of credit increases average growth but also increases total risk, and therefore volatility. It's not apparent to me that that's a good trade. On a microeconomic level, the benefits I receive from being able to get credit easily have to be weighed against both the suboptimal personal accounting I have to engage in to keep my credit score up and against the long tail risk that a third party can open a line of credit in my name. It's not apparent to me that that's a good trade either. Maybe lenders should be much more conservative with who they loan to. Maybe they should price in a much higher default rate. Maybe individuals should seek a single line of credit from their bank of choice instead of expecting expenses to be financed individually. I don't know, I'm just some guy with 2 semesters of college-level economics. What I do know is that the status quo isn't sacred and the arguments explicitly in support of it seem to boil down to "growth is good and change is scary", which seems like really weak rationale for giving someone most of us don't even have a business relationship with essentially unilateral control of millions of people's financial fates.
- scrumper 9y agoI thought this was an excellent comment with some very strong arguments, good food for thought. So yes, the problem is one here the credit bureaux get to externalize their risk. I was arguing with your rejection of the 'insurance model' for bringing some of those externalities back in house. Your proposal of strict liability is really just a banning of the industry in disguise: without the possibility of insuring away those risks it's not viable to stay in business - an agency is going to get breached even if they are as careful as possible. I don't think the lobby (and it'd be bureaux and lenders lobbying on the same side) would permit that outcome, no matter how strong the political will. It's too far reaching. My response is, insurance doesn't preclude elimination. Those bureaux aren't going anywhere tomorrow. Incremental reform along the lines proposed by whatever grandparent we are both under provides a path to improvement, better risk management for individuals, and it could perhaps ultimately lead to your desired end state of a completely restructured consumer credit market.
- fnordfnordfnord 9y ago> it's the criminals who have caused millions of dollars of damage. Yes, that's true. But as the poster above already said some things are simply not safe to do. If I wanted to warehouse explosives, I wouldn't be allowed to do it near a populated area, I'd have to put my warehouse far away from populates areas. But absent that prohibition, let's say I found a cheap space in town, and so I loaded it up with tons of explosive material. Then a homeless fellow breaks in one night and manages to start a fire, burns the place. He survives, but the explosives were set off and half the town blew up. You'd think it's okay if I shrugged my shoulders and pointed at the homeless fellow? Credit reporting bureaus have free reign to screw up here because there's no oversight like the BATFE and no reasonable way for them to be sued into oblivion when they screw up so badly as Equifax has clearly done here. >Credit bureaux facilitate comprehensible risk management, How anyone can trust Equifax to do anything anymore is beyond me. There is still no corrective force here to cause these companies to become competent with data security. This is a farce.
- scrumper 9y agoWe're all arguing under a parent post which wants to reform the industry to bring some externalities back onto the agencies' books. If it's legal to operate an explosives warehouse in town at the time you do it, then unfortunately yes I have to answer that, provided you'd complied with applicable laws in securing your warehouse full of bombs, then you could shrug your shoulders. But you'd then be shrugging in the face of a barrage of lawsuits (as is happening now with Equifax). Soon after your homeless guy blew up the block the laws would be changed. And that's the situation we're in now: rubble everywhere, with a chance to make legislative changes to prevent a recurrence.
- mikk14 9y ago> So you don't like the bureaux; well, nobody does really. But what is an alternative which allows lenders to compare applicants on a like-for-like basis with some degree of confidence? Ironically, even if I liked the bureaux (I don't) I couldn't do it any more. Their negligence self-defeated their mission. With the leaked information, no credit report from Equifax is believable any more. If somebody slams it in my face I can shrug and say "Nope, that's not me: leaked information". Everybody in the Equifax data can do that. Everybody in the other companies' data which intersect with Equifax's can do it. All of a sudden, these companies are providing zero value.
- scrumper 9y agoExcept that'd be willfully lying in pursuit of financial gain, so no you can't really do that. The burden is on you to correct the record and defend against ID theft. Sucks. I'm not defending it. This is how it is.
- scrumper 9y agoIf only. That's lying for financial gain though (or a job or whatever). Burden is on the consumer - you - to get Equifax to correct it. Credibility may destroy their business if competitors are better, but in the meantime you can't refute by default on a presumption of inaccuracy.( Not trying to sound lawyerish here, I'm talking generally.)
- mikk14 9y agoBut I am not the consumer of Equifax. I have not paid them, nor asked them to do anything, nor indirectly getting a service from them [0]. The consumer is the bank or whoever paid for the information. So, on your logic being "the burden is on the consumer", why should the burden be on me? Second, why would the presumption of inaccuracy trump the presumption of accuracy? Who said Equifax is right? Especially since they have a track record of incompetence. As any debate on facts goes, the burden of the proof is on whomever is making a claim. Equifax is claiming something, i.e. that my credit score is X. I'm saying it is not. I concede you that what you say is probably how the law and the system works right now. And I concede that mine was more like a desire than a real prediction. I know things won't change. But that doesn't change the fact that, after the hack, Equifax and similar are just selling hot air. [0] If you want my credit score, you ask me for my statements, nor Equifax. If anything, Equifax is damaging me with their inaccurate information.