3 ms·
In interest to your circumstance, mitigating identity fraud in the sense of situations where people have stolen another person's identity, or people who create
by chrononaut 3y ago
In interest to your circumstance, mitigating identity fraud in the sense of situations where people have stolen another person's identity, or people who create completely fake identities, where both of them then committing some other act like theft?
I am curious how it would play out for X, if someone created a new identity and simply attempted to subscribe to their service in that sense.
- toomuchtodo 3y agoYou cannot fake a new identity that doesn’t have any backing in canonical identity systems. With sufficient data enrichment, you can rapidly ascertain which systems are inaccurate or deficient. I recommend https://doi.org/10.6028/NIST.SP.800-63-3 https://doi.org/10.6028/NIST.SP.800-63-3 for further reading on digital identity and identity assurance. I admit my experience in this domain has primarily been in financial services. We have different motivations than say, a social network. We plug into…as much signal is as commercially reasonable. Regardless, your identity assurance level will be governed by the effort and resources you’re willing to sink into the effort (data sources, remote identity proofing, device fingerprinting, activity heuristics, etc). If X wants to make sure you are who you say you are, they can, for a few dollars per user. And if you can’t identity proof because you don’t have a government credential, I’d hazard you don’t have much economic value to the platform (just facts, not a sleight). For X, if you can show a gov ID that matches your credit card you’re paying with, that’s pretty high confidence you are who you say you are. Otherwise, you’re breaking the law (financial fraud if it’s not your credit card, edge cases aside if someone else is authorizing you to use their plastic).