This post is Part 3 of a series of 3. Part 1 gives an overview of the problems in the mortgage market, casting them in terms I think technology can go a long way toward helping to solve. Part 2 explains how and why the change I suggest — switching form a market in mortgage-backed securities to one in actual mortgages — would actually work. Part 3 addresses the security and privacy concerns associated with such a transition.
I’ve proposed creating a giant market in individual mortgages, to replace the market in mortgage-backed securities (MBS), because I believe the problems of MBS are inherently unfixable. From most standpoints, that transition is a large yet straightforward challenge. Even so, if security and privacy concerns can’t be addressed, the whole idea will remain a deserved non-starter.
Frankly, I don’t see any unusual security issues, except for those that are connected to privacy. There aren’t a lot of obvious weaknesses that would allow a bad actor to change data. Rather, as is usually the case, the biggest security issues revolve around wrongful viewing of the data .
Given that — what are the great privacy risks of an individual mortgage aftermarket anyway? Possibilities include:
- Information about your actual mortgage circumstances could become more widely known.
- New avenues might open up for other kinds of fraud. Bad actors might figure out enough details to convincingly spoof your mortgage holder, thus capturing money or log-in details from you.
- New incentives might open up to violate your privacy in other ways, because if more information is unearthed about you, your mortgage might be more accurately valued.
The best way to deal with all three of those starts, in my opinion, with legal reform. Here’s why.
the entire privacy risk created by this scheme is misuse of information that today is already captured in credit ratings and reports.
What information would be held in a database of individual mortgages anyway? For starters, there’s owner identity, address, sales price, loan terms, and payment history. Physical information now existing in municipal records might be welcome too, and lender information. The only part of that that isn’t already a matter of public record is payment history (and maybe the identity of the lender, but what’s the privacy problem in that?). Even that is widely distributed via credit reports. Any other kind of information that is allowed to be brought into the analysis process — i.e., further information about an individual home-owner’s financial situation — is likely to be in the credit reports too. Thus,
I’ve argued at passionate length that credit reporting information is already a huge privacy risk, which can only be dealt with long-term by a fundamental change in our legal treatment of privacy. In essence, since dangerous information is inescapably being collected, laws have to control the use of information too. It’s way too late to just rely on locking the door of the collection barn. But as I’ve also argued, these issues are closely akin to ones that are analyzed in connection with the Fourth and Fifth Amendments. Consequences of gathering sensitive information — and limitations on its use — have been well-studied by judges and constitutional lawyers. The problem can be solved, once the politicians realize the necessity of doing so. And by the way, both the President and Vice-President of the United States are former constitutional law instructors.
So how can we ensure that such privacy laws are obeyed? Again, technology helps. Access to sensitive electronic information should be limited to those who — via licenses if need be — agree to use it only in automated, auditable ways. Maybe the laws let you still own your neighbor’s mortgage directly, as a personal favor to him — but if so, you don’t have access to the whole credit information reporting environment. This limitation would solve most of the privacy problems pretty effectively, with the big exception that it doesn’t do much against hacking and hacking-based fraud.
As for hacking and related fraud — opinions vary as to how severe those really are as problems. But whatever you think is the appropriate level of concern, the move to an individual mortgage aftermarket seems unlikely to make the problem significantly or qualitatively worse. So fear of hacking is not a strong argument against a scheme that could bring a multi-trillion benefit to the global economy.
Bottom line: The privacy and security issues created by an individual mortgage aftermarket are similar in size and scope to those that already have to be dealt with today.




