Unlike a Gilliamesque world in which a bad actor assumes your identity, generally a bad guy gains access to your resources, bypassing the protections set in. While the consumer is guilty of this sometimes, the victim harmed is almost always the institution, not the consumer; and yet the consumer is framed as the victim.
In a signature based authentication system, the banks suggest YOU are the victim of identity theft if someone gets your credit card number when it's their authentication system that was 'hacked.'
Similarly, checking account numbers, etc.
Of course there are exceptions, people use bad passwords, they allow others to get their info, etc.
But, I do think this term "identity theft" is often overused.
You could generalize most of those to "financial fraud", though. Although there are some cases of identities being used for non-financial (or not directly financial) purposes.
> In a signature based authentication system, the banks suggest YOU are the victim of identity theft if someone gets your credit card number when it's their authentication system that was 'hacked.'
And yet you're the one who has to go to the trouble and possible expense of dealing with it. Describing you as the victim seems more relevant.
Now, who and what you're the victim of is a different question. When yet another break-in turns up millions of plaintext passwords, we don't just blame those who obtained them illicitly; we also blame the company that stored them in plaintext.
So, I don't think it's reasonable to describe a bank as a victim in "identity theft". On the contrary, I think it's reasonable to describe them as negligent in protecting your account and personal information.
"""
“Identity theft” is a lie. There is no such thing as “identity theft”, it’s all fraud. The term “identity theft” was created to put the burden back on the consumer, away from financial institutions. The actual problem is that the cost of actually verifying identity is higher than financial institutions want to bear. Most of the cost would be in missed loan opportunities. Financial institutions don’t want to bear the cost of verifying identity so they experience fraud (surprise!) and then tell us that somehow we have to protect our identity. It’s insane.
If it was legally required that you appear in a bank with an ID to get a loan or a credit card, imagine what would happen to “identity theft”. There’s nothing wrong with filing electronically, but how about having people come to the post office, with ID and a thumb drive, show ID and sign a log, then file from there?
"""
There are very real, persistent, and hugely negative repercussions suffered by a consumer in identity theft. Destroyed credit, unknown debt tied to their identity, etc.
Well. Sure. But that's the point. That's why it's called identity theft. Someone has acquired the information about you needed to effectively pretend to be you.
For example, say I convince the police that you committed murder. As a result they arrest you and put you in jail. By your logic, you're not a victim in this scenario because if the police didn't get fooled into arresting you nothing would have happened.
I think almost any reasonable person would agree that you were a victim in the above scenario. Regardless whether a third party bears some level of responsibility or was used as an instrument in that victimization.
This low bar is set by the banks!
I'm not saying that innocent third parties that the banks and financial system harass are not victims, I'm saying that the central role of the bank in the crime makes it more reasonable to describe it as bank fraud.
The murder analogy sort of breaks down, the dead guy (which I see as analogous to the bank) can't do a whole lot to push the consequences of you murdering him onto me. A bank that opens a fraudulent account can (and in fact, this is the major source of the problems for those that are impersonated).
I honestly love this point. It's never occured to me.
This is the most interesting comment in the whole story, in my opinion. I might be taking it entirely out of context, but I wonder if, as our world grows larger and more automated, celebrity becomes a relatively more important form of capital. The growing prosperity and connectedness of the world population creates a new class of consumers to be influenced by celebrity, which is infinitely replicable due to the internet. Meanwhile, typical jobs get robotized whereas social capital is hard to automate away.
Celebrity has always been an object of desire, but it probably feels more attainable these days. There are more niches to fill and easier distribution channels for it. We used to compete for attention in our vicinity, but the internet makes us small and has us pining to be noticed. [/armchair analysis]
Successful/influential people tend to greatly underestimate the lengths that some people will go to just to put thoughts inside their influential brains.
When you let someone else's thoughts get inside your brain, you are giving them power over you. You should only give that power to people you actually trust, not random people who hacked into your account.
I think that's why it's so hard to reach influential people (aside from the fact that they get zillions of emails per day). At least at a subconscious level, they must feel like their brains are constantly under assault by foreign thoughts (often coming from people who are trying to gain something out of it).
The mind is like a sponge, it absorbs everything around it. People believe that they have control over what they believe, but it's not the case. Your environment will decide for you what you believe.
That's why brainwashing works and why there are so many terrorists. Everyone is vulnerable.
Everyone is vulnerable.
You are included in everyone.
Perhaps the Harvard email system will allow you to send a Reset Password link to an arbitrary (?) email address if you correctly identify some "identity verification" questions, and this guy was able to glean the answers to those questions from reading the article author's bio?
Gaining control of email accounts is how other accounts are typically captured when multi-factor auth is not enabled, of course. The question is how exactly the attacker got into Thurston's email account at Harvard. The reset instructions read like answering a verification question is all that is needed to change the password without knowing the original password. That would mean two lessons:
1. Harvard should add at least one additional step to this procedure, such as requiring confirmation through a secondary email address.
2. Nobody should ever use publicly available information as answers for password reset "security" questions.
(Both not exactly surprising insights here, of course...)
What still doesn't add up is the part about the attacker "creating gmail account like yours".
Exactly. However, there's a wiff of sociopath in the responses, ever so slight. He seems to not feel remorse about things I would never do.
Efficiently re-contextualizing each of his actions in an attempt to garner sympathy. It's not a slam dunk but there is a possibility of some psychopathic characteristics here.
For the record, I'd lay odds at 2% ish. If I was on Baratunde Thurston side of the conversation though, I would be operating on that assumption that he is one.
OH NO SOMEONE HACKED MY AOL ACCOUNT BETTER CALL THE FEDS
Can definitely be a slippery slope, though.
I know people blame poverty and stuff but so did Taiwan, Japan, Germany, Korea have all gone through far worse state but you never see the same behavior. People leave their cars with keys or wallet hanging out while passed out drunk in Korea, and miraculously you are belongings and yourself is intact. If you don't believe me just go to Korea or Japan.
In general folks in India have a policy of "respecting elders" and "those above you" (teachers, your boss, etc), but this is mostly faux respect in the form of honorifics and not arguing with statements by these people. I don't like this too much (grew up in the States, people earn respect there), but sometimes I do it too in some contexts because it's a social norm.
I don't think this has anything to do with British oppression. Sir is just an honorific applied willy-nilly by Indians both online and offline.