6 ms·
The problem is, as you articulated, they are required by law to provide credit reporting information about you to you. They have no incentive to do this because
by vegetablepotpie 3y ago
The problem is, as you articulated, they are required by law to provide credit reporting information about you to you. They have no incentive to do this because they make their money by collecting and selling data about us.
They have every reason to use this reporting requirement to collect more information about you.
They have every reason to conflate credit freeze with credit hold, and confuse consumers in order to extract regular payments from them.
They have zero reason to keep sensitive data about you secure. In fact, they have every reason to promote fear and uncertainty in the public that their sensitive personal information is in the hands of criminals as a growth opportunity for their industry to sell credit monitoring services.
They have successfully convinced the public that identity theft is a separate and distinct crime done exclusively by one person to another rather than simply fraud that they are aiding and abetting.
Consumers and credit reporting bureaus have a fundamentally adversarial relationship that no legislation can harmonize. They exist because they do serve a purpose for finance, which is to give an indication of how much money they can make lending money to someone. Regardless, this reporting does not have to be done by for-profit corporations. This can just as easily be done by non-profits or government agencies. Although these are not perfect, they are free of the perverse incentives driven by for profit corporate structures.
- cheriot 3y ago100% agree on the incentives Similar to why cookie accept/deny interfaces are atrocious. They're intended to be! I think a solution will require more creativity than "have the government do it", but the current system is clearly broken.
- para_parolu 3y agoI don’t think government should do it at all. That would be same broken thing. I just don’t want a selected (not by me) set of companies collect information about me without my consent. I would rather have an opt-in system where I can select a vendor to make a report on me to provide to lender. Only when I want it.
- WarOnPrivacy 3y ago> I don’t think government should do it at all. I'd want a non-profit to handle it. I'd want full public disclosure of internal processes, data sources and data buyers. I'd want strong, unhindered oversight provided by a fully independent public board along with separate oversight provided by the FTC - with oversight entities able to exhort meaningful influence over methods, sources and customers.
- NoblePublius 3y agoEvery financial institution has its own credit file on you. They don’t need the third party services at all. Credit profiles can be created easily from any number of public data sources. These companies exist because we wrote laws requiring them to exist, and for no other reason.
- cheriot 3y agoIf you don't like the terms with your current bank, how would you apply for a loan with a different one [that doesn't know you]? People need the ability to shop around.
- NoblePublius 3y agoPlaid
- cheriot 3y agoNobody will volunteer their unpaid debts so terms for those a good credit history will suffer.
- NoblePublius 3y agoGive me your checking account login and tax return and I will know who you owe money to
- cheriot 3y agoa) I take out a credit card at a new bank, spend the balance, and never make a payment. b) I bounced a check, don't remedy, and owe money to a furniture store. c) I move a random amount of money each month to a separate account and make loan payments from there. d) How far back does someone need to account for their spending in order to get a loan? People complain about mortgage applications, but this is a whole new level. Access to credit gets more expensive without a 3rd party aggregator.
- 3y ago
- no_wizard 3y agoHere's an idea: lets burn down FICO and the credit reporting bureaus. After all things seemed to work fine before credit scores. Perhaps we put too much "stock" in them in the first place. There has to be better ways to manage this. One way I could forsee is a government agency that acted as a reporting depot. Then you could forbid the sale of information, and create legislative firewalls for it to keep it out of the hands of other agencies[1]. Though I will continue to argue that credit scores are deeply flawed[0]. [0]: FWIW, I have excellent credit too, so I hardly run into any real issues with it, but I have see the other side of this table. They are often used in such a way I would classify it as prejudiced discrimination with extra steps. For bigger / riskier loans. You could instead opt for point in time financial audits, for example. [1]: Two things of note. One, last I looked into this, the government very much pulls credit reports on pull without any oversight as it sits today. Two, there is a history of legislative firewalls that do work, they need clear and strong oversight provisions, and today we have almost zero oversight of the credit bureaus. I'd roll the dice on creating something akin to the GAO or Federal Reserve type agencies (that is to say, very independent from lawmakers and presidents but still have competent oversight), but for something that functions for the intentions behind what these scores are suppose to be for.
- ziddoap 3y ago>lets burn down FICO and the credit reporting bureaus. This seems to be the harder problem. I read potentially better solutions all the time, but I never read about how to get to that point first.
- no_wizard 3y agoIts lack of motivation really. I think people have become ingrained / numb to them that they don't really think about it until they have a problem, or some sector of society gets repeatedly screwed by the bureaus etc. There's been no systematic callout of the bureaus in wider society, that I can tell.
- Vvector 3y agoWe are not the customers, we are the product. The customers are the banks and other entities that want to check our credit. Probably the only answer is legislation
- g051051 3y ago> They have successfully convinced the public that identity theft is a separate and distinct crime done exclusively by one person to another rather than simply fraud that they are aiding and abetting. This demonstrates a fundamental misunderstanding of how credit reporting works. When "identity theft" occurs, it's important to realize that the credit reporting firms are not involved. That is solely due to failures, at the institutions that actually grant credit, to verify the identity of the person they are interacting with. The flow goes: a fraudster uses harvested data to impersonate someone to a credit grantor, such as a credit card company. The credit grantor, accepting this identity at face value, asks the credit reporting agency (CRA) about the credit rating of the impersonated entity. The CRA says "Joe Victim has a relatively low risk of fraud". So the identity theft has already occurred before the CRA is even consulted. Later on, when the fraudster fails to pay as agreed, the credit grantor incorrectly reports to the CRA that the fraud was caused by Joe Victim. Again, the CRA is just relying on the data provided to them by their clients.
- lolinder 3y agoI understood the comment about aiding and abetting to be a reference to the fact that Equifax leaked about half of all Social Security Numbers back in 2017. For 145 million Americans the "harvested data" you refer to was data that the credit bureaus hoovered up and then failed to protect.
- g051051 3y ago> Equifax leaked about half of all Social Security Numbers back in 2017. They weren't leaked, they were stolen. Does a bank "leak money" when it's robbed?
- lolinder 3y agoIf the bank failed to apply industry-standard security techniques then yeah, I'd say the bank leaked money. The criminals are obviously the most culpable, but when you're storing more than 100 million SSNs it's not unreasonable to expect your IT department to: * Update their dependencies within two months of a critical security vulnerability being patched (Mar 7 to May 12). * In the event of a breach, detect it within a reasonable timeframe (76 days is not reasonable when you're the Fort Knox of financial information). * Have a reasonably well-segmented network such that a compromise in a single user-facing web app doesn't lead to your entire network being compromised.
- godelski 3y agoI don't think OP is reporting because they need to be educated on the motivations of these institutions.[0] I think instead OP is reporting to bring to light an abuse to the system. I'm happy OP is doing this and making noise because we can only address issues we're aware of and that get enough traction. But I find comments like these often become popular and highly upvoted because of their formulation but end up serving very little utility and ultimately dismissive. I think they're upvoted because they are in factual and accurate, and we like the confirmation because it shows how intelligent we are. But I think they end up being dismissive because it is missing the point. It is dismissive because there are no actual points being addressed or solutions being offered. There is an implicit solution of the government generating said report, but I think this would need to be (more) explicit. It also seems that anytime these comments raise to the top that the conversations become very unorganized and off topic, because frankly there is little to go off of. If writing a purely educational response I think it is quite hard to do (and even this comment might have the same repercussions but I'm trying to add more and my intent here is to align the thread. No one need reply to my comment). Personally I think a good solution would be for the law regarding these free reports should be updated to specify that they should not be a data collecting process. That they are only allowed to ask for information that they already have and that this is solely used to verify the authenticity of the user. Using this process to generate novel data is an abuse of the system. I also personally feel that the public should be able to have more recourse for mistakes that are made by these companies (within reason). I still feel like there has not been enough recourse for the Equifax breach and that not enough has been done to protect citizens. I don't think this is an unpopular opinion, but ensuring our politicians are aligned with public beliefs is a whole other conversation. [0] Personally I feel it is pretty obvious and apparent that credit agencies operate to collect and process data about people. It is then also apparent, to me, that of course the incentives align to them getting even more data about you as possible. It seems to me that anyone that is doing yearly report generating is highly likely to be aware of the business model. But not everyone is me so maybe that's not the intent. And what's obvious to one person isn't always obvious to others.
- ugh123 3y ago>They have successfully convinced the public that identity theft is a separate and distinct crime done exclusively by one person to another rather than simply fraud that they are aiding and abetting. I interpret that as: Companies like Equifax allow (or disregard good security practices to enable) data breaches to land your data into identity theft rings. They (Equifax) then try to sell you "protection services" while they continue to dangle your data to tantalized thieves. What a fucking racket.