10 ms·
I feel like companies like this should have to register a data breach like this in a national register, and then should someone become a victim of identity thef
by cascom 5y ago
I feel like companies like this should have to register a data breach like this in a national register, and then should someone become a victim of identity theft, the companies on that register associated with that person should bear the costs associated with that theft (importantly without the victim having to show that it was a direct result of that breach). E.g. John Smith ss#123-45-6789 (T-mobile, Experian) has a false refund filed in his name, $10k in legal costs associated with clearing his name, t-mobile and experian each owe him $5k…
Until companies are held accountable for the negative externalities they are causing, this won’t end.
- slg 5y agoPlus money for the wasted time and stress this causes. Often people won’t be responsible for huge financial outlays once these issues are resolved, but it can take countless hours and an unmeasurable about of stress to get there.
- dheera 5y agoYes this. Every hour on the phone is an hour less salary for many people.
- maxerickson 5y agoYou shouldn't become a victim when a bank opens a fraudulent account. The law shouldn't be that someone else has to pay the costs, the law should be that you tell them to prove it was you that acted to open an account and they go pound sand if they can't do that.
- jjeaff 5y agoI agree. Surely there are cases where people have sued the bank or whatever provider for opening an account in their name. It seems like I should just be able to send them a certified letter that says no, i didn't open that account, please close and correct your credit reporting unless you have proof otherwise. If you don't comply I'll see you in my nearest small claim court. Seems like it would be an open and shut case.
- acdha 5y agoYes - “identity theft” in common usage has been a phenomenally successful effort by financial companies to shift the cost of their negligence to the consumer.
- infogulch 5y agoYes even the name itself implies the burden should be bourne by the individual. It's a fantastically successful disinformation campaign. We should refuse to call it "identity theft" and call it "identity fraud" instead.
- NortySpock 5y agoI just go all the way to "bank fraud" to make it obvious who should be doing more due diligence.
- IgorPartola 5y agoThis is the correct terminology. If someone opens an account with a bank using false credentials that’s just fraud. And the victim here is the bank, not the individual.
- otterley 5y agoIf undetected by the bank, the individual becomes the victim when their financial reputation is sullied by false reports of failure to repay debts.
- infogulch 5y agoSend like a clear cut case of bank libel to me: > Libel is a method of defamation expressed by print, writing ... that is injurious to a person's reputation, ... or injures a person in his/her business or profession. Might even be able to get punitive damages. https://www.law.cornell.edu/wex/libel https://www.law.cornell.edu/wex/libel Note, the person who "had their identity stolen" (that phrasing is an absurdity, twisted language designed to obscure and defraud the truth) was never a party to the deal. The only parties relevant here are the bank and the person that defrauded the bank. The only victim is the bank. Nobody here is arguing that this problem doesn't exist for real people, we're saying that it's insane that it even exists at all.
- User23 5y agoThat is the law. But your legal rights are worthless if you can't afford a lawyer, and only in very specific circumstances does the law say the losing party has to pay the winner's fees. Unfortunately, the US government doesn't take identity theft seriously from a criminal prosecution perspective. At least not when it's affecting regular Americans.
- travoc 5y agoOn the bright side, identity theft insurance is very inexpensive because costly claims are rare. Most homeowners insurance policies include identity theft coverage.
- edoceo 5y agoI have to buy insurance in case the financial institution responsible for detecting the fraud fails and blame me?
- CrazyCatDog 5y agoAbsolutely—AFLAK for identity insurance. The free attach plans are pretty thin, most retail contracts will include their man hours to waste away with the credit card companies and fair Isaac / credit bureaus — but it’s obviously more $ than “free with purchase”
- supertrope 5y agoA de facto protection racket.
- otterley 5y agoThere are lots of reasons for insurance. One kind of insurance (liability) is to protect you in case you screw up. Other kinds of insurance (e.g., uninsured motorist, fire, etc.) are to protect you in case other people screw up.
- skeeter2020 5y agoTHe cost of identity theft is only partially monetary. A huge component is the ongling (sometimes lifetime) fight to reclaim your person, reputation and wel... identity. My homeowner policy may cover the cost of a fraudulently issued credit card, but no one at my insurance company will spend days, weeks and years trying to straighten out my credit issues and chasing down the many knock-on effects the fraud is going to cause.
- Wowfunhappy 5y ago...at first blush, I like this line of thinking, but I wonder what the side effects would be. If banks make it much harder to open accounts, that might hurt poorer folks the most, and perpetuate inequality.
- andy-x 5y agoThis is very odd argument, in the name "equality" anyone should be able to open account in your name?
- macintux 5y agoNot the person you’re replying to, but every well-intentioned regulation has a negative impact on someone. It’s always worth asking who, and whether there’s some way to mitigate the impact on people who are already struggling to make ends meet. Being poor is incredibly expensive and exhausting.
- kmonsen 5y agoIt seems a bit weird to try to fight inequality by reducing regulations on banks and make it easier for them to blame consumers for the banks mistakes. That argument would only make sense in the U.S.
- Wowfunhappy 5y agoI consider myself a liberal, I'm broadly in favor of more regulation, and I might even be in favor of this regulation given something to assuage my initial concerns (because as I said, I like the idea). But I believe there are also lots of well-intentioned but bad regulations, and so they need to be considered carefully!
- maxerickson 5y agoIs making it 'hard' to open an account the only way to prevent fraudulent accounts from being opened? I don't think I accept that premise. My argument is that the party that can actually do something about the fraud is the one that should feel the pain of dealing with it.
- vmception 5y agoThat's an interesting point, nobody here would actually know if someone has opened a bank account in their name! Going even further, nobody would actually complain if someone hijacked their identity and improved their credit score with good behavior! This is probably much more common than people being framed or having issues proving their identity.
- ajsnigrutin 5y agoYou can open an account without actually going to a bank in person with your ID card? Where the hell can you do that?
- discordance 5y agoNot sure about the US, but in Australia you can register a new bank account in a few mins online. Up, :86400, Hay… etc
- meowster 5y agoIn the U.S., I've opened all of my checking accounts and credit card accounts online. The only thing I've ever had to do in person was sign for a home mortgage.
- adrr 5y agoOnline banks let you do it.
- JCharante 5y agoCharles Schwab (Bank) is great and entirely online
- pjc50 5y agoUS doesn't have ID cards. Although people are trying to mandate them for voting.
- mikecoles 5y agoThe US has passports. The states do. They're called a driver's license. IDs are also issued to those that don't drive. It's a great idea to have for financial security. It's an even better idea to require them for election security.
- ajsnigrutin 5y agoSo... how do you identify yourself? I mean.. what's stopping me from saying I'm Jeff Bezos and that I'd like to withdraw a million or two?
- adrr 5y agoBank has to prove its you if there are debts. Just knowing your personal info isn’t enough. End of the day bank is eating the loss. The challenger banks lose millions in fraud per year with fake accounts.
- u801e 5y ago> You shouldn't become a victim when a bank opens a fraudulent account Imagine a world where banks have to pay you for identity theft protection so that you're more "diligent" about not going to phishing websites.
- zenexer 5y agoAlternative: Banks are incentivized to better authenticate people, rather than relying on faulty KBA and public IDs like SSNs—information that is often leaked and can be phished. That being said, none of the compromises described in the comment chain thus far required action on the part of the consumer; they all involved compromises of third-party companies. Like T-Mobile.
- pkulak 5y agoYou guys are both right.
- njarboe 5y agoThe Fair Credit Reporting Act of 1970 was/is promoted as a great milestone in helping people to get protection from secret databases that companies were creating on the whole populous. That part was true and it did prevent this problem that was arising of mass secret corporate dossiers on everyone (but secret government dossiers on everyone, of course still fine). On the other-hand, it gave the credit bureaus legal protection in creating these databases and people could only recover actual or statutory damages, attorney's fee, court costs and punitive damages if the violation was willful.[1] Since all those false reports ("identity thefts") are never willful on the part of banks and other lenders, there is almost no penalties that can be brought. The consumer bringing the most reasonable charge of libel against a credit bureau is specifically prohibited by this law, if the credit bureaus follow all of the rules (allowing people to see their reports, removing false info (good luck with that), etc.). If not a case of regulatory capture at the time, then at least this law needs to be updated given how important credit reports have become, how easy fraudsters can get your report tarnished, and how hard it is to get your reports corrected. [1] https://en.wikipedia.org/wiki/Fair_Credit_Reporting_Act https://en.wikipedia.org/wiki/Fair_Credit_Reporting_Act
- ljm 5y agoRunning with this idea, then as a customer, John Smith shouldn't have to even think about 10k worth of legal costs to clear his name. It should be cleared for him. Basically multiple layers of regulation in the form of consumer protection laws that put the onus on businesses to be accountable for what they do. You can't blame the victim for having their identity stolen just because they chose T-Mobile over a competitor, or expect them to fight the case in court (which most people won't do because it's too expensive).
- jalino23 5y agothen this national register gets breached what now
- cascom 5y agoThey add their name right next to t-mobile’s
- skeeter2020 5y agoWouldn't the register be metadata about the breach? Why would it include the actual breached data? This would be essentially "Have I been Pwned" with some legislative teeth and funding - perhaps from the penalities imposed on the offenders!
- jabroni_salad 5y agoThe HHS keeps a list for healthcare orgs, actually: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf A lot of incidents get reported to the state attorney general offices that the customers reside in, as well, but that is less convenient to keep an eye on since there are 50 of them. These don't really make the news because there are just too many of them to keep up with. One of my clients recently had to send breach notifications to all their customers and it did not even make the local papers. This is a town of 20k people where nothing ever happens and apparently that wasn't enough to waste ink on. The takeaway here is that there is infinite work available for security incident responders, if you are looking for a change of pace.
- mithusingh32 5y agoThat's the whole problem. There is literally no one holding anyone accountable. These corporations already expect to have a data breach. They call it "cost of doing business". And USA let's every company do this.
- tau255 5y agoI think everyone here seen this but I like to remind myself from time to time: https://youtu.be/CS9ptA3Ya9E https://youtu.be/CS9ptA3Ya9E
- throwaway98797 5y agoIdentity fraud is the bank scapegoating their compliance onto you.
- teawrecks 5y agoThat database would need to store everyone's info in order to know who's who, right? What happens when that database is breached?
- onlyrealcuzzo 5y agoSo companies are guilty until proven innocent? You could get your identity stolen from many different places. Just because your location data was leaked, doesn't mean T-Mobile should be on the hook carte blanche for any identify theft you face in the future. Can you really not see this leading to massive fraud?
- meowster 5y agoIt seems like a great incentive to not have leaks, share information, or hold onto information they don't actually need. Cell phone companies ask for social security numbers (SSNs) to do a credit check when opening post-paid accounts. Most people don't know any better, so the give out their SSNs. The companies can just delete the SSN after they use it once, but they don't. That should be on them. If I was a company, I would not want to take on any more responsibility than necessary. These companies decided to take on the responsibility, so it is on them.
- 542354234235 5y agoThere already is massive fraud. It is just committed by huge corporations that use their size and money to shield themselves from accountability. Which is the better scenario? The current one where companies, that are already proven to have negligently allowed someone’s data to be leaked, drag out and exhaust legitimate claimants against them, allowing them to profit off their negligent activities and leave countless regular people as victims with little to no compensation. Or one where legitimate claimants are able to quickly get compensation, but also claimants that were victims of a company’s negligence, but their identity theft did not come directly from that negligence. The “fraud” you imagine would require both that a company is negligent with someone’s data, exposing them to the risk of identity theft, and that the same person is the victim of identity theft in a totally unrelated way or unrelated reason. That isn’t guilty until proven innocent, because it is proven that the company was negligent and did allow data to be leaked. If it makes you feel better, we could just fine them $10,000 for each person’s data that was leaked right off the bat, and then hold that for all future claims where those people end up having their identity stolen.
- u801e 5y ago> should someone become a victim of identity theft The only reason identity theft is a thing is because federal law[1] doesn't allow consumers to sue creditors or credit bureaus for inaccurate information about the consumer unless they were doing it out of malice. If the law was changed to allow consumers to sue them for damages, you can bet that they will be far more diligent in verifying the identity of the person they're entering into a contract with. [1] https://www.law.cornell.edu/uscode/text/15/1681h https://www.law.cornell.edu/uscode/text/15/1681h (e)
- judge2020 5y agoSure, but the problem stems from a malicious actor fraudulently saying they're someone else and having the same info to back that up as the person themselves would, kind of like credential stuffing attacks on websites. Short of doing some sort of facial recognition (like id.me's selfies[0] perhaps), if someone knows your SSN and where you lived as a child, how do credit bureaus verify identity? 0: https://help.id.me/hc/en-us/articles/360061369314-How-do-I-take-and-submit-a-selfie- https://help.id.me/hc/en-us/articles/360061369314-How-do-I-t...
- toomuchtodo 5y agoThis is the point of national IDs, trust anchors, identity proofing, etc. Credit reporting agencies and financial service providers should be required to use a government provided identity provider (Login.gov is getting there; it’s currently only offering identity services to federal agencies and select state and local governments) or in person proofing with government IDs to verify identity. If they don’t, they are entirely liable for the transaction(s) and related losses, instead of rolling the dice with security question voodoo and foisting the liability on consumers. Solve digital identity and you solve identity fraud.
- zo1 5y agoIt's hard and there is a lot of weird pushback against national ID cards. E.g. In the UK they had it and then abolished it after public backlash. To me it's utterly backwards to not have one and then point the finger at banks as if they can have a magical investigation and "due diligence" department that can solve fraud and figure out who is who.
- Haemm0r 5y agoAh, can't wait for data leaks from that database ;-)
- deleted 5y ago[deleted]