PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Here’s why our system for authenticating consumers is busted

Posted on September 27, 2013July 1, 2025 by Dissent

Andrea Peterson reports:

When you apply for a loan or try to recover your lost e-mail password, you’ll often be asked to give information about a long-ago address, employer, or bank account. You might also be asked for your Social Security number or driver’s license. The idea is that only the real you would know such obscure details about your past.

This system provides a convenient way to authenticate consumers, but it also has an important vulnerability: anyone who has access to a comprehensive database that contains this kind of information can impersonate you.

Read more on Washington Post.

I had linked to Brian Krebs’ scoop over on DataBreaches.net, and of course, his findings are relevant to the same issues I raised in my complaint to the FTC about Experian, who also uses “knowledge based authentication.” The status of my complaint to the FTC is unknown to me as they never tell you what they’re doing, if anything, until they actually do something and issue a press release.

The  FTC and congressional committees looking into data aggregators and data brokers need to read Brian’s report carefully and assume that this is not just LexisNexis, Dun & Bradstreet, and Kroll – those are the only ones he knows about from what he acquired, but I would bet that there are more that we don’t know about.

No related posts.

Category: BreachesBusinessFeatured News

Post navigation

← Feinstein outlines NSA changes
FBI Drones Flew Since 2006, Audit Says →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
  • EPIC Publishes New Whitepaper Detailing Privacy Risks of Government Data Mining Programs

RSS Recent Posts at DataBreaches.net

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
©2025 PogoWasRight.org. All rights reserved.