Home | About | RSS Feed | Contact and Publicity Guidelines | Comment Policy the Law, the Universe, and Everything 

advertise-here4


Slip Opinions


Whatever happened to Henry Simons? (fp)

Wow -- that's some very scary poll results (kw)

The scarlet ankle bracelet. (fp)

Every good article should have one idea. (fp)

Family values in market turnover culture. (fp)

Banks really create value: probably $58 billion in overdraft fees & credit card penalties in 2009. (fp)

A Citizens United dream: Exxon could have deployed 10% of its 2008 profits to outspend every presidential and senatorial candidate that year. (fp)

Eternal Earth-Bound Pets promises to adopt your pet if you are raptured. (fp)

Habermas doesn't tweet, but does interview well. (fp)

Lessig on Google, copyright, orphans, and the future of access to information. (kw)

Our Podcast

Subscribe to Law Talk

law-rev-contents2.jpg


  • Posts by Author

  • Categories

  • Archives


  • Recent Comments

    • Kristina on Spring 2010: Is the Window Open?

    • PrometheeFeu on The Advantages and Disadvantages of Rewards

    • PoNyman on Very scary poll results

    • Civ Pro King on Privacy Rights in Death Photos: Catsuouras Case Decided

    • ParatrooperJJ on Privacy Rights in Death Photos: Catsuouras Case Decided

    • Lotta on The Take Away About Take Home Exams

    • Alan on Constitutional Rorschach Test (or Zen Koan)

    • Colin Crowe on The Take Away About Take Home Exams

    • Glomarization on Links and short thoughts on Amazonfail

    • Vinca on Book Review: Divergent Opinions: Why Community Matters — A Review of Sunstein’s Going to Extremes

    • A.J. Sutter on My Letter to the Economist on Climate Change

    • Keri Brooks on Spring 2010: Is the Window Open?

    • Illinois on Spring 2010: Is the Window Open?

    • Ken Rhodes on Constitutional Rorschach Test (or Zen Koan)

    • Ken Rhodes on My Letter to the Economist on Climate Change

  •  

    Site Meter

Verifying Identity: From One Foolish Way to Another

posted by Daniel Solove

money-2a.jpgFor quite some time, banks and financial institutions have been using people’s Social Security Numbers (SSNs) to verify their identities. Suppose you want to access your bank account to check your balance, change addresses, or close out the account. You call the bank, but how does the bank know it’s really you? For a while, banks were asking you for your SSN. Your SSN was used akin to a password. If you knew this “secret” number, then it must be you. Of course, as I have written about at length, a SSN is one of the dumbest choices for a password. Not only is it a password that can readily be found out, but it is a password that’s very hard to change. Not a wise combination. People’s SSNs are widely available, and the data security breaches in the past two years exacerbated the exposure. A lot of legislative attention has focused on the leakers of the data, and rightly so, but not enough attention has been focused on the businesses that use people’s SSNs as passwords. If SSNs weren’t used in this way, leaking them wouldn’t cause the harm it does.

But now, it seems, banks are starting to rethink the use of SSNs. According to a USA Today story:

A growing number of banks and retailers are moving beyond Social Security numbers to verify your identity. They’re relying on such personal details as your car color, your father-in-law’s name and the city you lived in five years ago.

No, you never gave them this information; rather, they pulled it from public and private databases. These private details are increasingly being used to approve you for credit at a store, give you access to your account online or to verify that you — rather than an impostor — are making a purchase.

It’s the latest effort by financial institutions to fight a growing threat of identity theft from online “phishing” and other scams. Chase, HSBC, Vanguard, American Express and Barclaycard US use this customer-verification technique. Mellon Financial is testing it. In the past two years, the technology has been adopted by six of the top 10 U.S. banks and thrifts, says Verid, a provider of the technology.

The problem with using this method is that the information in public databases is often riddled with errors. Why do banks need to go behind your back to snoop out information about you? Banks and financial institutions already have a relationship with you — after all, you established an account with them. They can use some of the information they gathered at that time to establish your identity and then ask you to supply additional information to help identify you. But going behind people’s backs and trolling public records for data does not strike me as a particularly effective method given the possibility for errors in those records.

The story continues:

Frank Lapiano, a sales rep in New York, got a taste of this technology when he and his fiancée bought a wedding ring at a department store in September.

To verify his identity, his credit card issuer, Chase, asked about the last four digits of his Social Security number, his mother’s maiden name and charges he’d made in the past 48 hours. Then the bank dug deeper: It asked multiple-choice questions about which age range reflected his father’s age and also about the city his mother lived in.

The problem here is that the last four digits of the SSN are not a good password. Neither is one’s mother’s maiden name, since it readily appears in public records such as birth certificates. Charges made in the past 48 hours might not be ideal to use either, since a thief who stole a person’s credit card might be the one who made such charges. And the details about his father’s age and whereabouts of his mother come from public records, which may not be reliable and which can readily be found out by a fraudster too. All a fraudster needs to do is buy a public records report about a victim from a database company, and the fraudster will have all the information he needs to circumvent this security tool. Moreover, asking numerous questions can slow down the identification process and make it less efficient. What we want isn’t perfect security; it is smart security using passwords that do not contain information anybody can readily find out and that can be changed easily if they fall into the hands of a frauster.

So it’s a good thing that banks are moving past the SSN, but I’m not sure they’re moving to something much wiser.


 November 9, 2006 at 12:15 pm   Posted in: Privacy (ID Theft)   Print This Post Print This Post

Responses (6)

  1. William McGeveran - November 9, 2006 at 4:31 pm

    Great post. You are right, of course.

    I would add another independent problem: if the public records are inaccurate (as is so often the case), you may find yourself giving the “wrong” answer about your own personal details. This happened to me once recently. I had the surreal experience of needing to insist to a skeptical customer service rep on the other end of the phone line that I am indeed me and that I knew my own past home addresses better than she did. Turns out there was a typo, of course.

    Worse still from the point of view of banks and other institutions who adopt this strategy, quality control is essentially impossible. The error must have been made by some faceless data entry clerk at some other entity with whom I interacted in the past, and the bad info gradually migrated its way into my Choicepoint profile or some similar aggregated dossier.

    (cross posted at Info/Law)

  2. Bruce Boyden - November 9, 2006 at 7:10 pm

    What’s the worst that can happen here? You occasionally suffer the inconvenience of going into the bank with your drivers’ license? A phone call that takes 20 minutes instead of 5? Aside from the security issue, the downside to the consumer appears to be occasional inconvenience.

    As for the upside, for one thing, banks et al. are dealing with a “legacy” problem — a mass of customers who opened their account years ago before the banks woke up to the scale of the identity theft problem. It’s WAY cheaper and faster to cull that information from databases rather than calling up each existing customer and playing 20 questions. For another, most consumers probably do not want to answer a series of personal questions each time they open a new account.

  3. William McGeveran - November 9, 2006 at 9:53 pm

    Well, first of all, one personal question with a clear and correct answer might do the trick. That’s better than repeat “20 questions” games, often when you are busy just trying to use your credit card or withdraw some cash.

    I don’t suggest this is sky-is-falling stuff. But it does undermine my confidence in security if protective measures hinge on inaccurate information. And it is not hard to imagine a situation where customers actually are denied access to service — possibly the use of their own credit cards — because the bank (or, as in my case, utility company) mistakenly disbelieves their answers about where their mothers live or whatever.

    Finally, given the enormous attention and investment that customer-facing operations make in monitoring, timing, and improving their telephone and online interactions with customers (for, as we are always told on the phone, “quality assurance purposes”), they mighyt consider a pattern of such problems a pretty big deal business-wise. Customers who get grilled about their personal data when they are just trying to buy stuff are not happy customers.

  4. Antiquated Tory - November 10, 2006 at 6:32 am

    How very odd. Here in the Czech Republic, where banking has a long way to go in terms of service, I can’t get any information over the phone. I can over the Internet but that’s password and certificate protected. I also cannot use my credit (really debit) card remotely to buy things. I have to have a separate ‘Internet’ card for this; it has a limit of 2 purchases/day which cannot total more than $400. Anything more, I have to physically swipe it.

    I ran into problems with this recently while trying to rehabilitate my US Student Loan. It seems that the US Department of Education does not accept bank transfers, which are the normal (and fast and secure) way of moving funds over borders, and expected me to provide them with lots of credit card details instead. But this wouldn’t do them any good, because Czech credit card security won’t allow such transactions…

  5. dan - March 22, 2007 at 1:29 pm

    It is easy to pick apart a system of verification, but what solution can be provided? The Chase example could discredited further if the account was fraudlently opened to begin with. How do you stop someone from opening an account with someone else’s info? I think using public/private databases is the best method out there. The questions are random, so the fraudster doesnt have time to prepare what could be asked.

    I would be interested to see your solution to the problems.

  6. Jon - October 2, 2007 at 8:40 am

    I just recently ran into this rash of question asking. My bank asked me an age question about my step-brother’s 3rd ex-wife. I didn’t have a clue. Just a minute ago, I was trying to order a birth certificate online and could tell the questions were targeted at my father and not me. Have you ever owned a home at one of the following addresses…nope, but my father did. You answer “None of the above” and are kicked to the curb and made to do things manually. It’s irritating and annoying because they have BAD data. In the computer world, the term GIGO jumps to mind: Garbage In, Garbage Out. These ID verification folks are putting a lot of Garbage In.

Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word


  • « Previous post
  • Next post »

Authors

Daniel J. Solove
Kaimipono Wenger
Dave Hoffman
Nate Oman
Frank Pasquale
Deven Desai
Danielle Citron
Lawrence Cunningham
Sarah Waldeck
Jaya Ramji-Nogales
Solangel Maldonado
Gerard Magliocca

Guests

Adam Benforado
Mark Edwards
Michelle Harner
Kristin Johnson
Jeffrey Kahn
Alex Kreit
Viva Moffat
Adam Steinman










Previous Guests

Michael Abramowicz
Michelle Adams
Robert Ahdieh
Michelle Anderson
Laura Appleman
Ann Bartow
Francesca Bignami
Jeremy Blumenthal
Kathleen Boozang
Bruce Boyden
Donald Braman
Al Brophy
Neil H. Buchanan
Bill Burke-White
Scott Burris
Paul Butler
Naomi Cahn
Anupam Chander
Miriam Cherry
Jack Chin
Jennifer Collins
Thomas Crocker
Allison Danner
Brannon Denning
Deven Desai
Mike Dimino
Mark Edwards
David Fagundes
Christine Haight Farley
Kim Ferzan
Dan Filler
Michael Froomkin
Amanda Frost
Timothy Glynn
Rachel Godsil
Eric Goldman
David Gray
Craig Green
Tristin Green
Jeffrey Harrison
Erica Hashimoto
Carissa Hessick
Laura Heymann
Robert Hillman
Christine Hurt
Darian Ibrahim
John Ip
Kevin Johnson
Dan Kahan
Brian Kalt
Sam Kamin
Michael Kang
Chimène Keitner
Orin Kerr
Nancy Kim
Heidi Kitrosser
Adam Kolber
Russell Korobkin
Anita S. Krishnakumar
Susan Kuo
Greg Lastowka
Sarah Lawsky
Erik Lillquist
Jeff Lipshaw
Jonathan Lipson
Jacqueline Lipton
Joseph Liu
Michael Madison
Solangel Maldonado
Jason Mazzone
Linda McClain
William McGeveran
Salil Mehra
Carrie Menkel-Meadow
Max Minzner
Scott Moss
Eric Muller
Jaya Ramji-Nogales
Helen Norton
Elizabeth Nowicki
Paul Ohm
Michael O'Shea
David Opderback
Kristen Osenga
Rafael Pardo
Marcy Peek
Eduardo Peñalver
Robert Percival
David Post
Shruti Rana
Geoffrey Rapp
Neil Richards
Lori Ringhand
Alice Ristroph
Susan Scafidi
Paul Secunda
Jonathan Siegel
Jessica Silbey
Peter Smith
Charles Sullivan
Rick Swedloff
Steph Tai
Andrew Taslitz
Robert Tsai
Jenia Turner
Steve Vladeck
Spencer Weber Waller
Howard Wasserman
Melissa Waters
Frank Wu
Alfred Yen
Corey Yung
David Zaring
Timothy Zick
Michael Zimmer
Jonathan Zittrain

Ownership

Concurring Opinions is a
general-interest legal blog
operated by Concurring
Opinions LLC, a Pennsylvania
Limited Liability Corporation.

Blogroll

Above the Law
ACS Blog
Althouse
Balkinization
Becker-Posner Blog
BlackProf
BoingBoing
Chicago Law Faculty Blog
Conglomerate
CrimLaw
Crime & Federalism
CrimProf Blog
Crooked Timber
Discourse.net
Dorf on Law
Election Law
Emergent Chaos
The Faculty Lounge
Feminist Law Profs
43(B)log
Freakonomics Blog
Freedom to Tinker
Google Blogoscoped
How Appealing
Ideoblog
Info/Law
Instapundit.com
Juris Novus
Jurisdynamics
Law and Humanities Blog
Law and Letters
Law Librarian Blog
Legal Profession Blog
Legal Theory Blog
Legal Times Blog
Leiter Reports
Brian Leiter's Law School Reports
Lessig Blog
Madisonian Theory
Media Law Blog
Mirror of Justice
The Moderate Voice
National Security Advisors
Opinio Juris
Point of Law
PrawfsBlawg
ProfessorBainbridge.com
Property Prof Blog
Red Tape Chronicles
The Right Coast
Schneier on Security
SCOTUSBlog
Security Dilemmas
Sentencing Law and Policy
Simple Justice
Sivacracy.net
The Situationist
Susan Crawford
TalkLeft
Talking Points Memo
TaxProf Blog
Tech & Marketing Law
Truth on the Market
Volokh Conspiracy
WorkPlace Prof Blog
WSJ Law Blog
Wonkette
The Yin Blog


© Concurring Opinions

Powered by WordPress