3 ms·
The "creepy questions" -- in the USA at least -- are just another revenue stream for the three credit reporting agencies. They (or third party companies paying
by bm98 13y ago
The "creepy questions" -- in the USA at least -- are just another revenue stream for the three credit reporting agencies. They (or third party companies paying them for the data) pull data from your credit report and then ask multiple-choice questions based on the data. It's absurdly insecure given the large number of people who have subscription access to credit reports (landlords, car dealerships, employers, etc.). Even more ridiculous is that the questions are based on data that is often false. A scammer who applies for a credit card in your name provides a false address; that false address is added to your credit report and now can become part of the identity verification scheme. And of course the onus is on you to fix the bad data held by these companies.
- dman 13y agoI recently failed such an authentication. The system had bad data about someone they thought was my relative even though I have no relative by that name. I was asked three different questions about this "relative" and on all three said I dont know anyone by that name. In the end the agent administering the test told me I had failed the self identification. I was eventually able to talk her into putting in a manual override but the whole experience was disconcerting.
- tptacek 13y agoIt's insecure against a motivated, targeted attack. It is on the other hand a bitch to automate, given a file of 10,000 stolen identities, which is probably the primary concern animating most uses of these services.