Recent generations' adoption of the Internet as a social tool has sharply reduced the amount of privacy they have. To people who remember "the way it used to be" this seems like an obvious problem. To them, privacy = good, publicizing personal information = bad. Identity theft, many people believe, is only one easily identifiable problem with decreased privacy. The solution many (most?) people offer is to use "best practices" and not reveal anything online. Shred your documents! Don't post your phone number! Etc.
However, this is a mistake. Identity theft is not possible just because personal information is available online; it is possible because historically that information was so expensive to get that society and industry allowed a ludicrously insecure identity management infrastructure to come into existence. We now suffer under that same stupid system even though the world has changed drastically regarding availability of personal information.
First, let's not be naive: personal privacy has not been eroded just because technology has run amok and modern Internet users have no idea how to protect themselves. Personal privacy has been eroded because modern Internet users don't care as much about it as past generations might have. Today I saw a photo on Facebook of two fellow law students, both females, necking on a dance floor. This is common enough that they probably don't care. Other law students—people who have good reason to worry about future reputations—routinely post or have posted more embarrassing photos or profanities or whatever. It is becoming accepted that indiscretions become public-ish these days and people seem to care less about them. Presumably these personal tidbits are becoming less dangerous as a result. (i.e. It's hard to fire someone because she was photographed kissing another woman when 37% of your female staff has been photographed similarly.)
Now, given that personal privacy is just less important to modern Internet users and is likely to become less so still, why is the "solution" to ID theft to "lock up your valuables"? This ignores the other half of the problem: ID theft is possible because we care less about privacy and because credit reporting agencies, lenders and other institutions that wield power over us are willing to accept ridiculously flimsy "evidence" as "proof" of identity. If we as a society want to worry less about privacy, it is time for us to demand that the ways we manage our identities improve. The solution to identity theft is not to tell modern Internet users to stop behaving the way they want to. It is to tell industry and government to smarten up and implement the obvious and relatively simple policies needed to prevent it.
For example, in Canada credit reporting agencies are required by law to provide consumers with "free" access to their credit report once per calendar year. The quotes are around "free" because credit reporting agencies follow this law to the letter—providing one free report by Canada Post, after submission of a written application form with photocopies of 2 pieces of ID. Please allow 5 to 10 business days. Or, if you want it right now, just enter your information and credit card number, pay $15 and get it right away. Yes, both credit reporting agencies in Canada have already set up the technology to instantly provide credit reports to consumers but will only do so if you pay. If you just demand your legal right to a free copy (once per year), they will force you to go through the hassle of photocopying, using Canada Post and waiting 5 to 10 days. It would actually be cheaper for them (from a straight cost perspective) to just use their existing fee-based system to send you your one free report per year. But if they inconvenience you by making you go through Canada Post, they obviously assume you will break down and just pay the $15.
Imagine a different system, where credit reporting agencies were required by law to give consumers their own credit reports for free whenever they asked. Better yet, imagine if they implemented systems where consumers had to authorize each request for a credit report. How then would anyone apply for a credit card in my name? It's a simple solution that should completely negate the "danger" of Internet phishers discovering my SIN or address. But to imagine such a system is to imagine a lost source of revenue for Equifax and Trans-Union so don't expect it any time soon—unless you're willing to wake up and demand it.
Monday, July 30, 2007
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment