What is identity theft?

Opinion
Sep 8, 20033 mins

* Identity theft: blown out of all proportion?

We interrupt the usual education and entertainment of this newsletter to present a rant.

Security seems to loom large in most general discussions of identity these days. Certainly “identity theft” appears to be a buzz phrase that’s showing up on television news, in newspapers and magazines – even Oprah Winfrey claims to have been a victim. Much of this is what we can call “old fashioned” ID theft: service workers who steal credit card numbers; postal workers opening mail; “dumpster divers” rooting through trash and other physical theft of goods and services. Also lumped in is what used to be considered simple fraud as when someone pretends to be someone else such as a film star, sports figure or political noteworthy.

Fortunately, the problem is not as big an issue as the news reports would have you believe. These seem to be part of what I call the “shark phenomenon” – if one person is attacked by a shark, then every shark sighting becomes a big story for a while, even though there’s no real increase in the number of incidents.

Most of the buzz surrounding identity theft comes from the release of a number of different studies, most recently one published by the U.S. Federal Trade Commission (see links below).

These are in fact, surveys that are heavily weighted toward people who self-select and self-identify themselves as victims of identity theft. The FTC report, for example, apparently indicates that over 27 million people have been victims of identity theft over the past five years. But a close reading of the methodology shows that people are included in that count if a phone bill included a charge for a call that they didn’t remember making – whether or not it was really classifiable as theft. Still, even if only one tenth of the reports are correct, that’s still two and a half million folks who are victims of ID theft in a five-year period.

So what should concern us in the area of digital and virtual identity management?

Unfortunately, every report on identity theft – even those talking about thieves who root through trash to find account information – seems to include pictures of computers accompanied by lots of FUD about online privacy, crackers, even worms, viruses and spam. Most reporters don’t understand computers at all, never mind the more arcane functionality of identity management. There also seems to be a never-ending stream of earnest, titled talking heads from industry and academia who’ll go before the camera or the microphone and pontificate about how easy it is to steal identity electronically. Remember, though, that it’s also “easy” to rob banks, to mug people at ATMs, to sell snake oil cures for every imaginable disease or condition and so on. Easy to do it, but hard to do it and not get caught.

Don’t let these stories, which malign the work going on in the identity management field, run without being challenged. Write letters to the editor, call talk shows, even make yourself available to the general press as a counterweight to the Chicken Littles (https://www.geocities.com/mjloundy/) all running around telling us that the sky is falling.

Rant over, for now.