|
|
Log in / Subscribe / Register

Apache Struts Statement on Equifax Security Breach

Apache Struts Statement on Equifax Security Breach

Posted Sep 12, 2017 23:45 UTC (Tue) by ssmith32 (subscriber, #72404)
In reply to: Apache Struts Statement on Equifax Security Breach by tialaramex
Parent article: Apache Struts Statement on Equifax Security Breach

I'm aware of pgp. It does not solve the identity issue without a side channel. Key distribution at any non-trivial scale is hard.

I believe the kernel team does it by having "key parties" where people show up with... wait for it... driver's license and/or passports.

Exactly those things that are the "plain facts" you reject.


to post comments

Apache Struts Statement on Equifax Security Breach

Posted Sep 13, 2017 14:26 UTC (Wed) by nybble41 (subscriber, #55106) [Link] (6 responses)

> I'm aware of pgp. It does not solve the identity issue without a side channel. Key distribution at any non-trivial scale is hard.

In this case you don't need secure key distribution. You aren't actually trying to associate a particular public key with a real-world identity. You just need to show that the person applying for this loan is the same person who has a history of on-time payments on previous loans, utility bills, etc. The key itself is all the identity you need. When you first start out you just generate a fresh key and are treated as someone with no prior credit history; perhaps others with established credit who trust you (or institutions which know your real-life identity and are willing to back you) co-sign your key to give you a head start. Over time you build up a history of payments associated with your key. When you need a loan you sign the application with your private key to prove to the lender that the person submitting the application has an established credit history.

Apache Struts Statement on Equifax Security Breach

Posted Sep 13, 2017 15:03 UTC (Wed) by farnz (subscriber, #17727) [Link] (5 responses)

The problem with the model you outline is that some people have a bad credit history - the "baseline" of no history is higher than the credit record associated with someone who's taken loans and refused to repay. Without this, you have a bootstrapping issue for people who are credit-worthy but who have no history yet (e.g. homosexuals who've run away from a bigoted home situation) - how do I get credit to prove that I'm trustworthy when no-one will vouch for me because the people who could refuse to do so until I acknowledge that I was "wrong" to be gay?

Thus, you also need some mechanism to either prevent people from creating new identities to defraud the banks with, or some mechanism to demonstrate to a high standard that I've never had credit before - otherwise, the baseline inevitably reduces to "not credit worthy".

And, FWIW, the introduction standard is how credit worked in the dim and distant past - one effect was to limit credit to people from "good" families, as you needed an introduction from someone credit-worthy to yourself be eligible to get credit, and you needed to have credit to become credit-worthy.

Apache Struts Statement on Equifax Security Breach

Posted Sep 13, 2017 18:27 UTC (Wed) by raven667 (subscriber, #5198) [Link]

> And, FWIW, the introduction standard is how credit worked in the dim and distant past - one effect was to limit credit to people from "good" families, as you needed an introduction from someone credit-worthy to yourself be eligible to get credit, and you needed to have credit to become credit-worthy.

In that time if your reputation was questioned in any way this was death sentence as you cannot operate a business like a farm/plantation without credit, leading to the rise of duels as a way to settle questions of reputation.

Apache Struts Statement on Equifax Security Breach

Posted Sep 13, 2017 19:08 UTC (Wed) by nybble41 (subscriber, #55106) [Link] (3 responses)

> some people have a bad credit history - the "baseline" of no history is higher than the credit record associated with someone who's taken loans and refused to repay

This is a flaw in the current system. You can't presume the ability to identify all bad actors; it's too easy to change one's identity and start over. Someone with no known history _could_ have failed to repay prior debts under another name. The only sane default is to trust no one, and extend significant credit only when there is someone with an established credit history at stake.

I addressed your concerns about the "introduction standard" already, in the form of "institutions which know your real-life identity and are willing to back you". To qualify for a significant loan with no prior history you'll need to find someone willing to cosign, or at least stake their own credit score on your good behavior. That may be someone you know personally, but it could also be a business offering "loan insurance" for a minor fee following a more traditional background check. Alternately, you can start with small amounts of credit, such as utility payments. The utility company already knows where you live and takes on little risk by extending a month's worth of services on credit, making this a simple (and already commonplace) way to bootstrap your credit history.

Apache Struts Statement on Equifax Security Breach

Posted Sep 14, 2017 16:34 UTC (Thu) by farnz (subscriber, #17727) [Link] (2 responses)

But the same flaw exists in your system, and is made worse by the requirement to cope with people having lots of legitimate IDs. At least in the current system, it's a criminal offence (not just civil) to create a second ID for the purpose of fraud; in your system, multiple IDs are expected, as I can legally create a new ID at the drop of a hat.

And no, you didn't address my concerns - you completely ignored them. I asked how someone with no prior history (so no institutions that are willing to back you, albeit they know your real-life identity) would get on the credit ladder; your description of "loan insurance" is basically how the current system works. Utilities are no use to someone who's on the bottom of the ladder - they generally don't have utility bills, as those are taken care of as part of their rent on a room in someone else's property; they do pay towards utilities, but they pay a roommate, not a utility firm.

At least in the current system, these people show up as a previously unknown borrower - no added risk from failed credit, but no evidence of good risk either; in your system, such a person ends up in the same pool as people who've refused to pay their debts, making it even harder for someone in a bad situation to get minimal credit to establish their credit-worthiness. Unless, of course, I add in the current system, but described as "loan insurance" and "guarantors" instead...

Ultimately, you're not fixing the issues with the current system, you're just adding a new system on top that adds more issues but doesn't fix the core issues in the current system.

Apache Struts Statement on Equifax Security Breach

Posted Sep 14, 2017 17:38 UTC (Thu) by nybble41 (subscriber, #55106) [Link] (1 responses)

> someone with no prior history ... so no institutions that are willing to back you

Non sequitur. A lack of history does not imply that no institution would be willing to back you. It implies that you are higher-risk, but that risk is easily manageable.

> Utilities are no use to someone who's on the bottom of the ladder - they generally don't have utility bills, as those are taken care of as part of their rent on a room in someone else's property...

For this purpose rent would count as a utility. Anything you have to make regular payments on would serve to establish history.

> At least in the current system, these people show up as a previously unknown borrower - no added risk from failed credit, but no evidence of good risk either...

Which is an error. An unknown borrower should be considered maximum risk, on par with someone who has refused to pay. You know nothing about them, including whether they care about their credit score. As far as you know they have nothing at stake.

Anyway, there are any number of ways to handle the bootstrapping issue and this is getting quite far off-topic. The original point was simply that public key cryptography can be used to establish identity far more securely than the current system of asking you for slightly obscure—but not truly private—information about yourself, such as previous addresses and your Social Security number. If you want a system linked to real-world identity that's not so difficult to do; just have some authority figure endorse the key after running a thorough background check to verify that you are who you say you are. Doing that in one place, once per person, would certainly be an improvement over every lender verifying your identity separately using their own insecure, ad-hoc procedures based on knowledge just about anyone could collect with a bit of effort.

Apache Struts Statement on Equifax Security Breach

Posted Sep 14, 2017 18:03 UTC (Thu) by farnz (subscriber, #17727) [Link]

Note that a lack of history in your system is not distinguishable from bad history - it could be that I have no history, or it could be that I've run away from debts and created a new key. There's no way to distinguish the two situations.

And if rent counts, then what stops me lying and reporting that my kids pay me $10,000 per month in rent reliably? In general, if arbitrary private actors can report, what stops me falsely claiming "good" behaviour for friends - bearing in mind that I can establish new identities as quickly as you can blacklist them? If you whitelist, how do I as head tenant on a flatshare get on the whitelist?

And no, an unknown borrower is not maximum risk - there are legal penalties for trying to disguise your identity to get money, which mean that unknown is lower risk than known bad, since known bad puts you at risk of having to sue, while unknown but with history of not paying lets you get the police forces involved. This is, however, only possible because you are only permitted to have a single identity - as soon as you're allowed to create multiple identities, the system breaks down.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds