Slashdot Mirror


Combating Identity Theft

An anonymous reader writes "Net-Security is running an interesting article about some of the problems facing organizations when it comes to identity theft. From the article: 'Identity theft is the major security concern facing organizations today. Indeed, for the banking industry, it is the number one security priority for 2006. Identity security has developed beyond the simplest form of authentication where one party issues and verifies identities within a closed group of users. While easy to do, this approach is extremely hard and costly to scale upwards and offers no interoperability with other authentication networks.'"

8 of 204 comments (clear)

  1. Um... by ShaniaTwain · · Score: 4, Informative

    Can't they just use 'whois'?

  2. They're not helping themselves by Kombat · · Score: 5, Informative

    A big part of the problem is that the banking industry isn't always taking advantage of their own safety checks. For example, take a look at these stories to see how merchants pretty much ignore the signatures on the back of credit cards.

    --
    Like woodworking? Build your own picture frames.
    1. Re:They're not helping themselves by Bogtha · · Score: 4, Informative

      Here in the UK, we use the Chip and PIN system, which has been in effect for a while and practically mandatory since Valentine's Day.

      --
      Bogtha Bogtha Bogtha
  3. Combating ID Theft is easy... by digitaldc · · Score: 3, Informative

    ...just buy a deserted island, build a house and NEVER leave.

    --
    He who knows best knows how little he knows. - Thomas Jefferson
  4. ID theft sucks and it's only getting worse by bogie · · Score: 4, Informative

    I was just an ID theft victim. Some douche in Philly opened up a cell phone account with all my info. Now I have to constantly watch my credit for the next year. It's bad enough knowing that your name,address, SS#, etc, all are floating around in 50,000 different legitimate locations, but it really sucks when someone with malicious intent gets ahold of that information. There really isn't anything anyone can do for you either once your information is stolen. You can only file a police report and then notify the credit agenices. Real damage gets done and peoples lives have been completely turned upside because of ID theft. Sadly many people end up battling ID theft for years and years. It's only going to get worse.

    --
    If you wanna get rich, you know that payback is a bitch
  5. Lenders are liable for ID theft, not victims by max+born · · Score: 5, Informative

    I was a victim of ID theft 5 years ago. A credt card company (Next Card IIRC) gave someone a credit card who had only my name and SS#, wrong date of birth and wrong address. Anyway this guy went to Vegas and ran up quite a bill. It was only when the card remained unpaid that the company bothered to track down the real me.

    They wanted me to sign an affidavit. I told them I wan't signing anything, it wasn't my problem. I quoted the following from CHAP. 41, SUBCHAP VI, sections b and e of U.S. Code TITLE 15 which states:

    (b) Burden of proof
    In any action which involves a consumer's liability for an unauthorized electronic fund transfer, the burden of proof is upon the financial institution to show that the electronic fund transfer was authorized or, if the electronic fund transfer was unauthorized, then the burden of proof is upon the financial institution to establish that the conditions of liability set forth in subsection (a) of this section have been met, and, if the transfer was initiated after the effective date of section 1693c of this title, that the disclosures required to be made to the consumer under section 1693c(a)(1) and (2) of this title were in fact made in accordance with such section.

    (e) Scope of liability
    Except as provided in this section, a consumer incurs no liability from an unauthorized electronic fund transfer.


    Anyway, they took care of everything after that. Including my credit rating.

  6. Re:Useless information by Anonymous Coward · · Score: 4, Informative

    The functionality is already available as far as the credit reporting agencies not providing your information for marketing purposes.

    You can protect yourself from identity theft by taking your name off of the credit bureaus mailing lists. The credit bureaus are one of the biggest offender when it comes to selling your name and information to the credit card companies who in turn send you all those pre-approved applications. One call to the Opt Out Request Line (for Equifax, Trans Union, Experian and Consumer Credit Associates) is all it takes to permanently remove your name from all marketing lists that the credit agencies supply to direct marketers. You can also opt for a two-year period, renewing your request at any time in the future.

    1-888-567-8688

    To get rid of most other junk mail, write a letter giving your complete name, name variations and mailing address to:

    Mail Preference Service
    Direct Marketing Association
    P.O. Box 9008
    Farmingdale, NY 11735

    1-800-407-1088 Opt-Out from all mailing and telemarketing lists

    Other sources:
    http://www.dmaconsumers.org/cgi/offtelephonedave
    http://www.dmaconsumers.org/cgi/offmailinglistdave
    http://www.dmaconsumers.org/optoutform_emps.shtml

  7. Merchant rules require sig and ID. by fahrbot-bot · · Score: 3, Informative
    I too was once irked at having to present my ID for a credit card purchase, but then I actually did some research (stops to hear Slashdot audience gasp) and found the following:

    According the merchant rules, for MasterCard anyway, the merchant is suppose to check the signature and request ID as part of their compliance (section 2.1.1.2).

    If a card is not signed, the merchant is suppose to obtain authorization from the card issuer, request ID and have the customer sign the card then and there (section 2.1.1.3).

    MasterCard Merchant Rules

    --
    It must have been something you assimilated. . . .