- What does Cisco have against Quebec?
- Attrition.org nails another nitwit
- Diary of a deliberately spammed housewife
- Seven cloud-computing security risks
- 20 great Windows open source projects
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
Austrian journalist Erich Möchel asked me why there might be a higher rate of identity theft in the United States than in Austria. He published an article in German about identity theft in which he quoted extensively from my responses (in translation) but, never wanting to waste any writing, I am using an edited version of my original comments (with a few additions) here for readers of English.
* * *
One of the problems any society faces is the use of universal identifiers. In the U.S., in contravention of the original legal restrictions on its use, the Social Security number is increasingly being used throughout society as an identifier. In Europe and many other parts of the world, a government-issued identity number is commonplace.
These uniform identifiers, if inadequately controlled, allow data aggregation: the use of disparate collections of data (e.g., bank records + air travel records + library usage records + credit-card records + etc.) to create an increasingly detailed profile of everything a person does, whether viewed as private or not by the individual. The United States is still behind Europe in its privacy regulations.
Another issue that lies at the root of the rise in identity theft involving credit-card fraud is the system of fraud-recovery in the U.S. banking system.
Yes, a person who has been defrauded does have limits (typically $50 in total) on liability for someone else's fraudulent use of their account - but who bears the cost of the fraud? Is it the banks? No, it's card holders who don't pay their accounts on time.
Interest rates for credit cards are two to three times the rates for secured loans. The enormous difference pays for the fraud. But shifting the costs onto users deflects responsibility away from the card suppliers; instead of investing in better identification and authentication schemes for cards, they have shied away from anything that would reduce credit-card use. Some European banks (e.g., the Bank of Scotland) have pictures on the credit cards they issue; very few (e.g., Citibank) in the U.S. do the same. Smart cards would make forging much more difficult, but they are not in use.
Stopping the practice of sending unsolicited, pre-approved application forms to millions of residents would deprive thieves of the opportunity to steal the forms from mailboxes. The stolen forms are then filled in and sent in with a different address from the original but the same name and identifying data as the original recipient's. The victim gets the bills and the thief gets the goods.
There is no way their store and forward switches (or s2410 - fulcrum trash) can deliver that performance....- Anonymous
Comments (13)
The answer is sort of obviousBy kLevkoff on March 13, 2008, 11:28 pmThe answer is obvious, the merchants should stop accepting those nasty credit cards..... Oh, wait, merchants take credit cards because they all know that a customer...
Reply | Read entire comment
Whose fault is itBy Anonymous on March 13, 2008, 11:19 pmClearly there is a reason why the banks act as irresponsibly as they do. As you said, they make money when people use their credit cards. Any attempt to improve...
Reply | Read entire comment
Re: ID TheftBy Anonymous on March 12, 2008, 1:48 pm"I would rather have them check my ID than have a valid signature available to a theft if my wallet gets stolen" Assuming your ID is in the same stolen wallet,...
Reply | Read entire comment
ID TheftBy Anonymous on March 12, 2008, 10:23 amI agree with your comments. I do not sign the back of my card, I would rather have them check my ID than have a valid signature available to a theft if my wallet...
Reply | Read entire comment
Don't use the SSN for authenticationBy Anonymous on March 12, 2008, 3:33 amYou mention the Social Security Number being used in the US as a ubiquitous identifyer - due to the lack of alternatives and inspite of the fact that the SSN was...
Reply | Read entire comment
View all comments