You are probably unaware of, and maybe even unconcerned with the fact that the House of Representatives is about to vote on a piece of identity theft legislation that is an insult to the citizens of this country. But why should you care? You’ve let it get this far without protest, so, like the saying goes, you reap what you sow.
HR 3997, The Financial Data Protection Act of 2005, will take away most of the rights you currently have, placing absolute control over your name and personal data in the hands of the same culprits who keep losing it. Like the 540,000 New Yorkers’ names, addresses, and Social Security numbers contained on a piece of computer hardware—didn’t say if it was a laptop—that is now missing since Monday of this week. Story on MSNBC.com.
But why should you care. It hasn’t affected you. Yet. The House leadership will most likely pass a bill that allows companies like ChoicePoint, Bank of America, Sharper Image, or just any junk mail or non-junk mail facility that holds your private information, to notify you only if they decide you are at risk. In other words, after the fact. If you are willing to take that, then, maybe the means justify the end.
Washington state Attorney General, Rob McKenna, said it best, when commenting in the NewStandardNews.net article, “’Protection’ Act Would Strip Consumers of Credit Safeguards.” He said: It’s like telling someone you can’t put a deadbolt on your front door until after you’ve been burglarized . The same article documents how the finance and credit industries have donated over $12 million to political campaigns, and spent nearly $30 million on lobbying.
Susanna Montezemolo, Policy Analyst with Consumers Union, and Ed Mierzwinski, Consumer Program Director for the U.S. Public Interest Research Group, both oppose the legislation. Montezemolo says, “Congress should be helping consumers prevent identity theft, not making things worse.” Paraphrased, Mierzwinski adds that what the states have given—like the California law that caught ChoicePoint—Congress wants to take away, “…with this industry-approved bill that won’t prevent data breaches…”
Montezemolo also makes a point I have been blogging about for over a year now. She states: “Consumers are the greatest protectors of their own personal information.” Therefore, why not pass federal legislation giving them control over their names and personal data, and, while we’re at it, pay them when it is sold? Read more of their article at: USNewswire.com.
What everyone should know is that HR 3997 will amend the Fair Credit Reporting Act. The Act’s coverage, of course, does not fully protect consumers, but it is all we have from lawmakers who are either afraid, or too inept to serve notice on government agencies and the business community that the public, also, has rights.
And this will never happen unless consumers stand up for these rights, and demand that Congress do the right thing when it comes to the identity crisis. Tell them you want control over your name and private information. Encourage friends and family to do the same.
Write, E-mail or telephone your Congressional representatives and tell them what you think of this concept of controlling your name and personal data, and, being paid when it is sold. Contacting the House of Representatives. Contacting the Senate.
Wednesday, July 26, 2006
Wednesday, July 19, 2006
Junk Mail Industry Continues to Rob Customers
Perhaps this headline is somewhat severe when you consider the connotation, but certainly well within reasonable boundaries, when you look at the damage. The junk mail list industry reaps around $4 billion each year from the sale of your name and personal data. You are lured into the conspiracy by supposed convenience and the sale of products you desire, with a feeble warning that your name “might” be “occasionally” shared with other junk mailers.
You receive your merchandise, but not one penny from the repeated sale—25 to 50 times annually—of your name and private information that follows each purchase. The irony of this is that 98 of each 100 mailings go in the trash. And they wonder why it is called junk mail.
This all comes from my experience selling mailing lists for 35 years. As a privacy activist now, my goal is to pass federal legislation that will give consumers control over their names and personal data. At the same time, you should share in at least half of that $4 billion windfall each year. The proceeds could be taken either in cash, or put away in an interest-bearing account for retirement.
On July 4, I posted the article, “Independence Is Control Over Your Name and Personal Data,” which lays out my plan, and shows how similar law in the United Kingdom has worked in favor of the consumer without halting related business interests. Just this week I received data from the Brits’ Information Commissioner’s Office that shows just how effective their Data Protection Act has been. A complete article on this later.
Identity theft is rampant. Gasoline prices could reach $3 dollars per gallon any day. What better reasons for this control and compensation?
On the other hand, we’re dealing with a current administration and an incompetent Congress in so many areas that ID theft, and Americans’ privacy in general, is slowly evaporating. Along with this, data brokers and junk mailers, as well as non-junk mail companies that gather and sell our private information, go on their merry way harvesting obscene profits.
Yet, the very culprits responsible for the conspiracy are whining over how to get even more results from your names and private information. In a recent article, “Marketers Feel Data-Challenged,” from Direct, a junk mail industry publication, a survey reveals a general unhappiness by companies of not realizing the highest return from your personal data. They want more and more of it, but don’t know how to use it. Pathetic.
In keeping with the inaccuracy of ChoicePoint and Acxiom data from another survey ( 73% and 67%, respectively), junk mail marketers seem to fare no better, with only 30% reporting their data as reliable. Have you ever known of an industry selling its product—mailing lists—for $4 billion a year with an average error rate of 70%? I think not.
I did a couple of posts earlier in this blog that explore how junk mailers feel about being the proprietor of your names and private information: “Junk Mail 101: Junk Mailers Believe They Own Your Name,” and “Junk Mail 101: Junk Mailers Believe They Own Your Name II.” Each has its points about a business greedy to take advantage of this by-product of your junk mail shopping, and II even quotes some prices of industry mailing lists.
It’s almost a “squatter’s rights” mentality used for real property, but legally that won’t even work. This approach requires “exclusive use,” and your name and personal data is in the hands of several hundred junk mailers and data brokers…simultaneously. And, I have yet to see a valid argument from anyone in the business that it is legal to take control of something as private as this data by any party other than the name-holder.
So, it’s time to take back what is rightfully yours. Write, E-mail or telephone your Congressional representatives and tell them what you think of this concept of controlling your name and personal data, and, being paid when it is sold. Contacting the House of Representatives. Contacting the Senate.
You receive your merchandise, but not one penny from the repeated sale—25 to 50 times annually—of your name and private information that follows each purchase. The irony of this is that 98 of each 100 mailings go in the trash. And they wonder why it is called junk mail.
This all comes from my experience selling mailing lists for 35 years. As a privacy activist now, my goal is to pass federal legislation that will give consumers control over their names and personal data. At the same time, you should share in at least half of that $4 billion windfall each year. The proceeds could be taken either in cash, or put away in an interest-bearing account for retirement.
On July 4, I posted the article, “Independence Is Control Over Your Name and Personal Data,” which lays out my plan, and shows how similar law in the United Kingdom has worked in favor of the consumer without halting related business interests. Just this week I received data from the Brits’ Information Commissioner’s Office that shows just how effective their Data Protection Act has been. A complete article on this later.
Identity theft is rampant. Gasoline prices could reach $3 dollars per gallon any day. What better reasons for this control and compensation?
On the other hand, we’re dealing with a current administration and an incompetent Congress in so many areas that ID theft, and Americans’ privacy in general, is slowly evaporating. Along with this, data brokers and junk mailers, as well as non-junk mail companies that gather and sell our private information, go on their merry way harvesting obscene profits.
Yet, the very culprits responsible for the conspiracy are whining over how to get even more results from your names and private information. In a recent article, “Marketers Feel Data-Challenged,” from Direct, a junk mail industry publication, a survey reveals a general unhappiness by companies of not realizing the highest return from your personal data. They want more and more of it, but don’t know how to use it. Pathetic.
In keeping with the inaccuracy of ChoicePoint and Acxiom data from another survey ( 73% and 67%, respectively), junk mail marketers seem to fare no better, with only 30% reporting their data as reliable. Have you ever known of an industry selling its product—mailing lists—for $4 billion a year with an average error rate of 70%? I think not.
I did a couple of posts earlier in this blog that explore how junk mailers feel about being the proprietor of your names and private information: “Junk Mail 101: Junk Mailers Believe They Own Your Name,” and “Junk Mail 101: Junk Mailers Believe They Own Your Name II.” Each has its points about a business greedy to take advantage of this by-product of your junk mail shopping, and II even quotes some prices of industry mailing lists.
It’s almost a “squatter’s rights” mentality used for real property, but legally that won’t even work. This approach requires “exclusive use,” and your name and personal data is in the hands of several hundred junk mailers and data brokers…simultaneously. And, I have yet to see a valid argument from anyone in the business that it is legal to take control of something as private as this data by any party other than the name-holder.
So, it’s time to take back what is rightfully yours. Write, E-mail or telephone your Congressional representatives and tell them what you think of this concept of controlling your name and personal data, and, being paid when it is sold. Contacting the House of Representatives. Contacting the Senate.
Wednesday, July 12, 2006
Winner of the Big Brother Awards
George Orwell could not have envisioned that his imaginary 1984 character, Big Brother, would manifest itself into the symbol of the loss of privacy for generations to come. Although it is speculated by some that he really meant that 1984 would occur sometime after 2000—1984 could have been the year he completed the novel, 1948, with the last two numbers reversed—once again, could he have visualized a George W. Bush, with his rag-tag bunch of incompetent flunkies attempting to create an imperial presidency?
Probably not, but 1984’s major legacy is a tyrant called Big Brother, and we attach it to anything that reminds us of being under surveillance by government or business. And that is exactly where we are, characterized by the feds’ unrelenting spying techniques on innocent Americans, and junk mail and non-junk mail companies’ obsessive accumulations of our names and personal data.
Privacy International, a non-profit based in London, with its affiliates, presents the “Big Brother Awards” each year to government and private sector organizations that have done the most to threaten personal privacy. The ceremony has been held in sixteen countries since 1998, but we will concern ourselves with just the U.S.
The first of any significance was in 2000, where DoubleClick, then engaged in online media, received the “Greatest Corporate Invader” award for monitoring the surfing of 50 million net users. In the prior year, DoubleClick had acquired Abacus, a company performing analytical services for junk mailers by using sensitive customer data from catalog purchases covering almost half the U.S. households.
DoubleClick wanted to marry this private information with the net surfing habits of its 5 billion record database. This strategy was quickly rethought when privacy advocates, even junk mail industry leaders, reacted with shock.
Also in 2000, the “Lifetime Menace” award was bestowed on TransUnion, one of the big-three credit reporting companies, for selling credit reports to marketers and keeping inaccurate reports for years. TransUnion was also a persistent litigator to sell personal data their way. They went through a ten-year court battle with the Federal Trade Commission over the selling of sensitive credit information. They lost. In the end, the Supreme Court refused the case.
It should come with no surprise that ChoicePoint won as the “Greatest Corporate Invader” in 2001, for massive selling of records, accurate and inaccurate, to cops, direct marketers, and election officials. Then, of course, the bomb dropped in February of 2005, starting a string of data breaches that it seems will never end.
In connection with the “inaccurate” records, Privacy Activism, another non-profit, did a study on errors found in ChoicePoint’s data, which included name, Social Security number, address, and phone number. The mistake rate was 73 percent. Still not surprised.
And the one to watch that could bring Big Brother to all our doorsteps is Acxiom, winner of the “Worst Corporate Invader” in 2005, for a tradition of data brokering. Has to have something to do with that Privacy Activism study, where Acxiom’s sensitive records had an error rate of 67 percent. The reason to keep an eye on them is partly due to the company’s aggressiveness in pursuing government contracts for clandestine programs like CAPPS II, where the feds could secretly share with them everything they know about you.
Oh, by the way, a mailing list company by the name of Response Unlimited shared the Acxiom award, because they tried to sell the list of donors to the Terri Schiavo cause…while she was still alive. I can hardly wait for the 2006 Big Brother Awards.
Probably not, but 1984’s major legacy is a tyrant called Big Brother, and we attach it to anything that reminds us of being under surveillance by government or business. And that is exactly where we are, characterized by the feds’ unrelenting spying techniques on innocent Americans, and junk mail and non-junk mail companies’ obsessive accumulations of our names and personal data.
Privacy International, a non-profit based in London, with its affiliates, presents the “Big Brother Awards” each year to government and private sector organizations that have done the most to threaten personal privacy. The ceremony has been held in sixteen countries since 1998, but we will concern ourselves with just the U.S.
The first of any significance was in 2000, where DoubleClick, then engaged in online media, received the “Greatest Corporate Invader” award for monitoring the surfing of 50 million net users. In the prior year, DoubleClick had acquired Abacus, a company performing analytical services for junk mailers by using sensitive customer data from catalog purchases covering almost half the U.S. households.
DoubleClick wanted to marry this private information with the net surfing habits of its 5 billion record database. This strategy was quickly rethought when privacy advocates, even junk mail industry leaders, reacted with shock.
Also in 2000, the “Lifetime Menace” award was bestowed on TransUnion, one of the big-three credit reporting companies, for selling credit reports to marketers and keeping inaccurate reports for years. TransUnion was also a persistent litigator to sell personal data their way. They went through a ten-year court battle with the Federal Trade Commission over the selling of sensitive credit information. They lost. In the end, the Supreme Court refused the case.
It should come with no surprise that ChoicePoint won as the “Greatest Corporate Invader” in 2001, for massive selling of records, accurate and inaccurate, to cops, direct marketers, and election officials. Then, of course, the bomb dropped in February of 2005, starting a string of data breaches that it seems will never end.
In connection with the “inaccurate” records, Privacy Activism, another non-profit, did a study on errors found in ChoicePoint’s data, which included name, Social Security number, address, and phone number. The mistake rate was 73 percent. Still not surprised.
And the one to watch that could bring Big Brother to all our doorsteps is Acxiom, winner of the “Worst Corporate Invader” in 2005, for a tradition of data brokering. Has to have something to do with that Privacy Activism study, where Acxiom’s sensitive records had an error rate of 67 percent. The reason to keep an eye on them is partly due to the company’s aggressiveness in pursuing government contracts for clandestine programs like CAPPS II, where the feds could secretly share with them everything they know about you.
Oh, by the way, a mailing list company by the name of Response Unlimited shared the Acxiom award, because they tried to sell the list of donors to the Terri Schiavo cause…while she was still alive. I can hardly wait for the 2006 Big Brother Awards.
Tuesday, July 04, 2006
Independence Is Control Over Your Name and Personal Data
What better way to celebrate July 4th than having the right to control your name and personal data, and be paid each time it is used. It won’t happen this year, but it could by 2007. It all depends on your reaction to this concept, and being able to get a grass-roots movement going that would force Congress to pass federal legislation to give consumers this right.
It is not only a right, it is a necessity, if we are to curb the onslaught of the current identity crisis. And if you have read any of the carefully planted articles that claim the crisis is overblown, be aware of the statistics from Javelin Research, provided on the Privacy Rights Clearing House site, “How Many Identity Theft Victims Are There? What Is The Impact On Victims?” PRC is one of the largest and most respected privacy advocates in the U.S.
Javelin says that even with a decrease, the number of identity fraud victims was 9.3 million in 2005. Total fraud was $54.4 billion that same year. At the hands of ID thieves in 2005, each victim suffered $5,885 in financial loss, and it took them 28 hours to correct the problem. But it’s a problem you probably won’t worry about until it happens to you and…then it’s too late.
Freezing your credit will help, but unless you are notified at once and you react immediately, there is still the chance the crooks can hijack your private information. And, there is the hassle involved for you to unfreeze your account for legitimate reasons. Paul Wenske did a good article on this subject in the Kansas City Star, “’Freeze’ on credit meets a lukewarm reception.”
There is only one answer to protecting our names and personal data, and holding Big Brother at bay when it comes to business and government usurping individual privacy. Orwell’s 1984 predicted it, and we are very close to fulfilling his prophesy, but Americans are beginning to see the light and the need to protect their inner sanctum.
This can be accomplished by passing federal legislation that gives consumers (1 CONTROL over their names and private information, and while we’re at it, give them the (2 RIGHT TO BE PAID each time it is sold. Government and business reaction is that this would halt commerce in its tracks, but this hasn’t happened under the United Kingdom’s Data Protection Act of 1998. The Act requires the U.K.’s Information Commissioner’s Office to approve any use of personal data.
1) Taking the U.K.’s Act one step further in giving the individual approval, U.S. law would set up a system where consumers, business and federal agencies are assembled in a database that assigns each a unique ID, which would replace the Social Security number for identification. This ID, along with a Pin number chosen by each person, firm or agency involved, would be the key to using the system. Any business or government entity wishing to access consumer names and private information would sign in with their ID and Pin.
But first, the individual would opt-in, or opt-out of all junk mail use of their name. Opting-out would deny any commercial or government use of data, except for emergencies.
Whether one or a million records are required, an automatic signal would be sent to each name-holder by urgent e-mail or telephone message, repeated regularly until the recipient responds. The notification would alert the consumer as to what the nature of the data request is, and, if legitimate, could be authorized immediately. If not valid, the individual so indicates, and the transaction is stopped at that point, causing no harm, and with minimum effort by all concerned.
Arrangement would be made for medical or financial emergencies, as well as the needs of national security. All activity would be subject to oversight by a committee including private citizens, along with federal and industry representation.
(2 In the case of compensation in the sale of consumer names and personal data, this same system would calculate revenue by individual, and maintain an accounting of what is due. Based on the junk mail industry’s annual take of $4 billion for the selling of names and private information, I feel the name-holder should receive one-half. Ideally, it could be placed in an account bearing simple interest of 3 percent, and the person could eventually draw around $607 a month to supplement their retirement, or take the proceeds in cash.
Write, E-mail or telephone your Congressional representatives and tell them what you think of this concept. Contacting the House of Representatives. Contacting the Senate.
It is not only a right, it is a necessity, if we are to curb the onslaught of the current identity crisis. And if you have read any of the carefully planted articles that claim the crisis is overblown, be aware of the statistics from Javelin Research, provided on the Privacy Rights Clearing House site, “How Many Identity Theft Victims Are There? What Is The Impact On Victims?” PRC is one of the largest and most respected privacy advocates in the U.S.
Javelin says that even with a decrease, the number of identity fraud victims was 9.3 million in 2005. Total fraud was $54.4 billion that same year. At the hands of ID thieves in 2005, each victim suffered $5,885 in financial loss, and it took them 28 hours to correct the problem. But it’s a problem you probably won’t worry about until it happens to you and…then it’s too late.
Freezing your credit will help, but unless you are notified at once and you react immediately, there is still the chance the crooks can hijack your private information. And, there is the hassle involved for you to unfreeze your account for legitimate reasons. Paul Wenske did a good article on this subject in the Kansas City Star, “’Freeze’ on credit meets a lukewarm reception.”
There is only one answer to protecting our names and personal data, and holding Big Brother at bay when it comes to business and government usurping individual privacy. Orwell’s 1984 predicted it, and we are very close to fulfilling his prophesy, but Americans are beginning to see the light and the need to protect their inner sanctum.
This can be accomplished by passing federal legislation that gives consumers (1 CONTROL over their names and private information, and while we’re at it, give them the (2 RIGHT TO BE PAID each time it is sold. Government and business reaction is that this would halt commerce in its tracks, but this hasn’t happened under the United Kingdom’s Data Protection Act of 1998. The Act requires the U.K.’s Information Commissioner’s Office to approve any use of personal data.
1) Taking the U.K.’s Act one step further in giving the individual approval, U.S. law would set up a system where consumers, business and federal agencies are assembled in a database that assigns each a unique ID, which would replace the Social Security number for identification. This ID, along with a Pin number chosen by each person, firm or agency involved, would be the key to using the system. Any business or government entity wishing to access consumer names and private information would sign in with their ID and Pin.
But first, the individual would opt-in, or opt-out of all junk mail use of their name. Opting-out would deny any commercial or government use of data, except for emergencies.
Whether one or a million records are required, an automatic signal would be sent to each name-holder by urgent e-mail or telephone message, repeated regularly until the recipient responds. The notification would alert the consumer as to what the nature of the data request is, and, if legitimate, could be authorized immediately. If not valid, the individual so indicates, and the transaction is stopped at that point, causing no harm, and with minimum effort by all concerned.
Arrangement would be made for medical or financial emergencies, as well as the needs of national security. All activity would be subject to oversight by a committee including private citizens, along with federal and industry representation.
(2 In the case of compensation in the sale of consumer names and personal data, this same system would calculate revenue by individual, and maintain an accounting of what is due. Based on the junk mail industry’s annual take of $4 billion for the selling of names and private information, I feel the name-holder should receive one-half. Ideally, it could be placed in an account bearing simple interest of 3 percent, and the person could eventually draw around $607 a month to supplement their retirement, or take the proceeds in cash.
Write, E-mail or telephone your Congressional representatives and tell them what you think of this concept. Contacting the House of Representatives. Contacting the Senate.
Wednesday, June 28, 2006
Identity Theft 101
Identity thieves are becoming much more sophisticated in their strategy. You could even say this is becoming a cottage industry since they have so many incompetent businesses and government agencies to work with. The kind that allow their employees to take laptops home with them crammed with personal data on just about every household in the U.S. Any person who would do this has to be working with a double-digit IQ in common sense.
In just the last couple of months, the following organizations have lost a laptop(s) containing combined sensitive information on almost 26.8 million individuals:
• Veterans Administration – 26.5 million
• Hotels.com – 250,000
• IRS – 291
• ING Financial Services – 13,000
• Equifax Credit Bureau – 2,500
• Federal Trade Commission – 110
In many cases the data included name, address, Social Security number, birth date, and credit card information. The perfect formula for ID fraud.
And then a computer server was stolen on March 31, from the Midwest office of insurance giant, AIG, containing 930,000 names, addresses, Social Security numbers and thousands of medical records. The data had been sent to AIG by 690 insurance brokers who were shopping their clients for medical coverage. A “server” seems like a strange thing to steal, unless you know what you’re getting. Read the story: “Stolen computer server sparks ID theft fears” on MSNBC.
That’s just the laptops and one server. There have been several others where hackers have broken into systems, but two are worth mentioning because of the unique methods used.
Somehow, 28,000 sailors and their families ended up on a civilian Web site. Included were names, birth dates, and Social Security numbers. Once again, just what the crooks need. In an MSNBC story, “Sailors’ personal data found on the Internet,” the Navy admits it has no idea how the information was stolen.
Then, one that could top the dunce responsible for the VA breach, a Humana insurance employee called up data on 17,000 Medicare beneficiaries through a hotel computer, and then failed to delete the file. In a Washington Post story by Kevin Freking, “Medicare Beneficiary Data Left in Hotel,” it was an auditor from the Department of Health Services, using the exact same hotel computer in Baltimore that caught the mistake.
If I recall correctly, in every incident, the statement was made: “There is no evidence that the information fell into the wrong hands and was misused.” This will probably end up being the quote of the century. Perhaps, one of the most famous disclaimers ever written, and it probably didn’t require a staff of legal experts.
And here’s why it’s so ludicrous. It’s what I call Identity Theft 101.
No, there is no evidence the thieves have used the private information yet, because they are smarter than the businesses and government agencies they lifted it from. When the inexperienced culprits who took it in the first place realize they can’t use the data, and because of the media attention—which, by the way, is justified—this petty thief will sell it to the next level of the more sophisticated identity swindler. This bunch will sit on it for a year and one day, when the credit monitoring has expired, and go for the gold. Yours, that is.
Eventually, the inexperienced, petty thief will graduate to Identity Theft 102, or higher, realizing that you can easily cut out the middle-person since data gatherers are focused squarely on profits, not consumer security. In this scenario, the students will excel in their field without ever graduating.
In just the last couple of months, the following organizations have lost a laptop(s) containing combined sensitive information on almost 26.8 million individuals:
• Veterans Administration – 26.5 million
• Hotels.com – 250,000
• IRS – 291
• ING Financial Services – 13,000
• Equifax Credit Bureau – 2,500
• Federal Trade Commission – 110
In many cases the data included name, address, Social Security number, birth date, and credit card information. The perfect formula for ID fraud.
And then a computer server was stolen on March 31, from the Midwest office of insurance giant, AIG, containing 930,000 names, addresses, Social Security numbers and thousands of medical records. The data had been sent to AIG by 690 insurance brokers who were shopping their clients for medical coverage. A “server” seems like a strange thing to steal, unless you know what you’re getting. Read the story: “Stolen computer server sparks ID theft fears” on MSNBC.
That’s just the laptops and one server. There have been several others where hackers have broken into systems, but two are worth mentioning because of the unique methods used.
Somehow, 28,000 sailors and their families ended up on a civilian Web site. Included were names, birth dates, and Social Security numbers. Once again, just what the crooks need. In an MSNBC story, “Sailors’ personal data found on the Internet,” the Navy admits it has no idea how the information was stolen.
Then, one that could top the dunce responsible for the VA breach, a Humana insurance employee called up data on 17,000 Medicare beneficiaries through a hotel computer, and then failed to delete the file. In a Washington Post story by Kevin Freking, “Medicare Beneficiary Data Left in Hotel,” it was an auditor from the Department of Health Services, using the exact same hotel computer in Baltimore that caught the mistake.
If I recall correctly, in every incident, the statement was made: “There is no evidence that the information fell into the wrong hands and was misused.” This will probably end up being the quote of the century. Perhaps, one of the most famous disclaimers ever written, and it probably didn’t require a staff of legal experts.
And here’s why it’s so ludicrous. It’s what I call Identity Theft 101.
No, there is no evidence the thieves have used the private information yet, because they are smarter than the businesses and government agencies they lifted it from. When the inexperienced culprits who took it in the first place realize they can’t use the data, and because of the media attention—which, by the way, is justified—this petty thief will sell it to the next level of the more sophisticated identity swindler. This bunch will sit on it for a year and one day, when the credit monitoring has expired, and go for the gold. Yours, that is.
Eventually, the inexperienced, petty thief will graduate to Identity Theft 102, or higher, realizing that you can easily cut out the middle-person since data gatherers are focused squarely on profits, not consumer security. In this scenario, the students will excel in their field without ever graduating.
Wednesday, June 21, 2006
FEMA and ChoicePoint Deserve Each Other, but We Don't Deserve Either
According to the Government Accountability Office (GAO), poor information technology and lack of management controls is responsible for as much as $1.4 billion fraudulently paid out in hurricane relief funds by FEMA. Lack of management is FEMA’s specialty, but not securing the technology to access consumers’ personal data takes their incompetence to yet another level since every other governmental agency does it regularly. FBI, Homeland Security, Pentagon, NSA, Justice Department…the White House.
Michael Arnone writes in Federal Computer Week, that the GAO uncovered this figure through the same technology that FEMA should have used to catch the crooks: data mining and database matching techniques. His article, “FEMA pledges better disaster relief fund payouts,” quotes the GAO as saying that around 16 percent of the disaster assistance was questionable. Some of the millions of dollars even went to federal and state prison inmates.
So far nothing unexpected. However, then Arnone drops the bombshell. FEMA has hired data broker ChoicePoint to verify identities, using Social Security numbers for those applying for assistance. That’s the same ChoicePoint that led the charge in February of 2005, with 145,000 personal records stolen by ID thieves, an incident that was revealed only because of a new California law on identity theft.
Not satisfied with the original version, ChoicePoint goes for two sequels, one totaling 9,900 names and private information stolen September of 2005, another 17,000, November of the same year. That’s almost 172 thousand consumers who have had to run for cover, and sweat out the threat that their identities could be taken from them at any time. Maybe tomorrow, maybe next month, or even a year or two from now.
By the way, the Federal Trade commission reports that there have already been at least 800 cases of ID theft resulting from the ChoicePoint breaches.
According to an Information Week article by Thomas Claburn, titled “The Federal Information Tax,” the government has become one of ChoicePoint’s best customers. Based on the Privacy Act of 1974, there are major questions regarding what the feds can ask for from these data brokers, and also what private information they are allowed to maintain on American consumers.
This fact notwithstanding, the question is, after three data breaches by ChoicePoint, are they qualified to provide personal data on consumers for businesses or government? Privacy Activism, a non-profit organization reporting on privacy issues, isn’t sure. In an article, “Privacy Activism study finds new problems for ChoicePoint, Acxiom,”they found a majority of participants found errors in the most basic of biographical information: name, Social Security number, address, and telephone number.
But the shock of the day was that the background check reports (your private information) provided by ChoicePoint were inaccurate 73 percent of the time. By the way, the same Acxiom figure was 67 percent.
Are you ready to see the light and demand federal legislation to give you control over your name and personal data, and, pay you when it is sold? Let me hear from you.
Michael Arnone writes in Federal Computer Week, that the GAO uncovered this figure through the same technology that FEMA should have used to catch the crooks: data mining and database matching techniques. His article, “FEMA pledges better disaster relief fund payouts,” quotes the GAO as saying that around 16 percent of the disaster assistance was questionable. Some of the millions of dollars even went to federal and state prison inmates.
So far nothing unexpected. However, then Arnone drops the bombshell. FEMA has hired data broker ChoicePoint to verify identities, using Social Security numbers for those applying for assistance. That’s the same ChoicePoint that led the charge in February of 2005, with 145,000 personal records stolen by ID thieves, an incident that was revealed only because of a new California law on identity theft.
Not satisfied with the original version, ChoicePoint goes for two sequels, one totaling 9,900 names and private information stolen September of 2005, another 17,000, November of the same year. That’s almost 172 thousand consumers who have had to run for cover, and sweat out the threat that their identities could be taken from them at any time. Maybe tomorrow, maybe next month, or even a year or two from now.
By the way, the Federal Trade commission reports that there have already been at least 800 cases of ID theft resulting from the ChoicePoint breaches.
According to an Information Week article by Thomas Claburn, titled “The Federal Information Tax,” the government has become one of ChoicePoint’s best customers. Based on the Privacy Act of 1974, there are major questions regarding what the feds can ask for from these data brokers, and also what private information they are allowed to maintain on American consumers.
This fact notwithstanding, the question is, after three data breaches by ChoicePoint, are they qualified to provide personal data on consumers for businesses or government? Privacy Activism, a non-profit organization reporting on privacy issues, isn’t sure. In an article, “Privacy Activism study finds new problems for ChoicePoint, Acxiom,”they found a majority of participants found errors in the most basic of biographical information: name, Social Security number, address, and telephone number.
But the shock of the day was that the background check reports (your private information) provided by ChoicePoint were inaccurate 73 percent of the time. By the way, the same Acxiom figure was 67 percent.
Are you ready to see the light and demand federal legislation to give you control over your name and personal data, and, pay you when it is sold? Let me hear from you.
Tuesday, June 13, 2006
British Consumers Aren't Stupid Either
No, consumers in the United Kingdom aren’t stupid; as we also agreed in my last post, neither are Americans. The big difference is that the Brits are doing something about it, and this country isn’t. By “country” I mean the Bush administration, congressional leaders on both sides of the aisle, and you, the consumer.
You can forget the Bush/Cheney duet when it comes to going to bat for the average individual. If neither business nor the moneyed elite profit in the transaction, there’s absolutely no interest on their part.
And then, while Washington flounders in a mass of mostly meaningless legislation on identity theft, the U.K. has had the Data Protection Act (DPA) since 1998, which seeks to strike a balance between the rights of individuals and the sometimes competing interests of business. Anyone processing personal information must notify the Information Commissioner’s Office (ICO) that they are doing so, unless their processing is exempt.
In my last post, “Is the American Consumer Stupid?,” I quoted from an article in junk mail industry publication, Direct, and an interview with Martin Abrams, executive director of the Center for Information Policy Leadership at Hunton & Williams in Washington. One of his points is that U.S. privacy laws are based on preventing harm, as compared to European law which is based on giving consumers control. Actually, Abrams was saying that American business has it easy, compared to the United Kingdom.
The Brits have taken control over consumers’ names and personal data with the requirement that business must inform the ICO of their use. Yes, there are exemptions, but this is the kind of balance we must strive for if we are to put a stop to the current identity crisis in the U.S. I would advocate that we take it one step further, and give the control to individual consumers, and pay them when their names and private information is sold.
But this won’t happen unless you speak up and tell your congressional representatives that you’re tired of this crap and won’t take it anymore. Contact your elected officials in the House of Representatives and in the Senate.Tell them you read about this in The Dunning Letter, and you want to know why we are eight years behind the United Kingdom.
On the other hand, the UK is having its own problems with compliance; naturally, in the business community. As late as November of 2005, that country’s Accountancy Age journal reported in the article, “Data protection disaster looms for thousands,” that less than half the profession’s companies had registered with the ICO, a requirement costing only £35, $64.48 U.S. Apparently the accountants aren’t the only non-compliers in Great Britain, but the ICO is threatening further action.
Which all goes to say that eight years after the enactment of the UK DPA, there are still problems that will probably take yet more time. But the U.S. Congress is currently muddling through several bills on the ID theft issue—most of which will not get the job done—which are really delay tactics to soothe us into believing they are working on our behalf. They aren’t.
If we don’t get serious about this today, tomorrow could pose an ID crisis for your family. Folks, there have been eighty-three data breaches since the beginning of 2006, and there were 8.9 million victims of identity fraud in 2005.
Take a look at the Chronology of Data Breaches, and the Javelin/BBB ID Theft Survey, both from Privacy Rights Clearinghouse, and if you can come away from that with indifference, and you are in the majority, we are on a fast track to George Orwell’s Big Brother.
You can forget the Bush/Cheney duet when it comes to going to bat for the average individual. If neither business nor the moneyed elite profit in the transaction, there’s absolutely no interest on their part.
And then, while Washington flounders in a mass of mostly meaningless legislation on identity theft, the U.K. has had the Data Protection Act (DPA) since 1998, which seeks to strike a balance between the rights of individuals and the sometimes competing interests of business. Anyone processing personal information must notify the Information Commissioner’s Office (ICO) that they are doing so, unless their processing is exempt.
In my last post, “Is the American Consumer Stupid?,” I quoted from an article in junk mail industry publication, Direct, and an interview with Martin Abrams, executive director of the Center for Information Policy Leadership at Hunton & Williams in Washington. One of his points is that U.S. privacy laws are based on preventing harm, as compared to European law which is based on giving consumers control. Actually, Abrams was saying that American business has it easy, compared to the United Kingdom.
The Brits have taken control over consumers’ names and personal data with the requirement that business must inform the ICO of their use. Yes, there are exemptions, but this is the kind of balance we must strive for if we are to put a stop to the current identity crisis in the U.S. I would advocate that we take it one step further, and give the control to individual consumers, and pay them when their names and private information is sold.
But this won’t happen unless you speak up and tell your congressional representatives that you’re tired of this crap and won’t take it anymore. Contact your elected officials in the House of Representatives and in the Senate.Tell them you read about this in The Dunning Letter, and you want to know why we are eight years behind the United Kingdom.
On the other hand, the UK is having its own problems with compliance; naturally, in the business community. As late as November of 2005, that country’s Accountancy Age journal reported in the article, “Data protection disaster looms for thousands,” that less than half the profession’s companies had registered with the ICO, a requirement costing only £35, $64.48 U.S. Apparently the accountants aren’t the only non-compliers in Great Britain, but the ICO is threatening further action.
Which all goes to say that eight years after the enactment of the UK DPA, there are still problems that will probably take yet more time. But the U.S. Congress is currently muddling through several bills on the ID theft issue—most of which will not get the job done—which are really delay tactics to soothe us into believing they are working on our behalf. They aren’t.
If we don’t get serious about this today, tomorrow could pose an ID crisis for your family. Folks, there have been eighty-three data breaches since the beginning of 2006, and there were 8.9 million victims of identity fraud in 2005.
Take a look at the Chronology of Data Breaches, and the Javelin/BBB ID Theft Survey, both from Privacy Rights Clearinghouse, and if you can come away from that with indifference, and you are in the majority, we are on a fast track to George Orwell’s Big Brother.
Wednesday, June 07, 2006
Is the American Consumer Stupid?
I don’t think so, although government and business are steadfast in their efforts to convince us that we are not competent to manage our personal affairs. Like controlling our names and private information so that they don’t fall into the hands of ID thieves. Like government and business are better equipped to do this.
The latest major incident is the 26.5 million records lost by the Veterans Administration; some moron took it home with him where it was later stolen. The first occurrence was a theft from data broker, ChoicePoint, in February 2005, who revealed the loss only after being forced to by California law. There have been twelve more breaches since the VA abduction May 22, and you can see the whole sordid story at the Privacy Rights Clearinghouse site, “A Chronology of Data Breaches Since ChoicePoint.”
Total personal records lost or stolen as of this date: 84,797,096. It will probably increase even before I can post this article.
So back to my original question: Is the American consumer stupid? Since I’ll bet you agree with me that most of us aren’t, why are we being treated as if we are too dumb to regulate the use of our names and personal data? And why haven’t we, as an intelligent group, risen up and demanded to take command over this most valued possession? Actually, the second question answers the first.
Just as George Orwell’s citizens of Oceania were completely apathetic about the Party and Big Brother controlling their lives, today’s population is at an indifference level regarding their privacy that is alarming. With just over 9 million victims of identity fraud confirmed, and a huge media circus built around the data breach hullabaloo in 2005, an Experian/Gallup survey at the end of that year recorded an ID theft concern rate of a dismal 35 percent.
I don’t have to point to, nor even provide any specific quotes, as to how the government has contempt for our intellect. From Bush on down, we are being told that: 1)either things are not as bad as they seem; 2)that someone is looking into and analyzing the situation; or 3)that Congress is drafting legislation to solve the problem. Unfortunately, we’re batting zero on one, and two and three are very questionable.
From the standpoint of business, particularly junk mail and non-junk mail companies maintaining dossiers on every U.S. household, and including data brokers, I can speak with some authority. There is a high level of concern over potential privacy laws, but this bunch still chooses to stick their heads in the sand. Outwardly, they are exclaiming concern that consumers will get control over their names and private information, but inwardly, still convinced they own your data.
Kinda like 1984’s Doublethink.
A recent case in point is an article, “Bad Law Rising,” in a junk mail publication, Direct, by Ray Schultz, Editorial Director. Schultz is a good journalist and from past articles, has a high respect for consumer privacy. He talks with Martin Abrams, executive director, Center for Information Policy Leadership at Hunton & Williams in Washington. Also well respected in the industry.
The interview focuses on financial data, which is certainly one of the most important areas we want to protect. Abrams first statement is, “Privacy law in the United States is unstable.” For the most part, his remark refers to the effect on business, not the consumer, and he rightfully states that much of the fault lies in the advance of technology. What is downright frightening is that he feels any real change has to come from the top (not sure if this is government or business) and is three to seven years away.
By then, the identity crisis will have arisen to humongous proportions, a situation that could very well stop commerce in its tracks. At that point, it won’t matter who we are for the chaos will probably shut down both government and business.
More on this issue next time. How individual control over names and personal data works in the United Kingdom.
The latest major incident is the 26.5 million records lost by the Veterans Administration; some moron took it home with him where it was later stolen. The first occurrence was a theft from data broker, ChoicePoint, in February 2005, who revealed the loss only after being forced to by California law. There have been twelve more breaches since the VA abduction May 22, and you can see the whole sordid story at the Privacy Rights Clearinghouse site, “A Chronology of Data Breaches Since ChoicePoint.”
Total personal records lost or stolen as of this date: 84,797,096. It will probably increase even before I can post this article.
So back to my original question: Is the American consumer stupid? Since I’ll bet you agree with me that most of us aren’t, why are we being treated as if we are too dumb to regulate the use of our names and personal data? And why haven’t we, as an intelligent group, risen up and demanded to take command over this most valued possession? Actually, the second question answers the first.
Just as George Orwell’s citizens of Oceania were completely apathetic about the Party and Big Brother controlling their lives, today’s population is at an indifference level regarding their privacy that is alarming. With just over 9 million victims of identity fraud confirmed, and a huge media circus built around the data breach hullabaloo in 2005, an Experian/Gallup survey at the end of that year recorded an ID theft concern rate of a dismal 35 percent.
I don’t have to point to, nor even provide any specific quotes, as to how the government has contempt for our intellect. From Bush on down, we are being told that: 1)either things are not as bad as they seem; 2)that someone is looking into and analyzing the situation; or 3)that Congress is drafting legislation to solve the problem. Unfortunately, we’re batting zero on one, and two and three are very questionable.
From the standpoint of business, particularly junk mail and non-junk mail companies maintaining dossiers on every U.S. household, and including data brokers, I can speak with some authority. There is a high level of concern over potential privacy laws, but this bunch still chooses to stick their heads in the sand. Outwardly, they are exclaiming concern that consumers will get control over their names and private information, but inwardly, still convinced they own your data.
Kinda like 1984’s Doublethink.
A recent case in point is an article, “Bad Law Rising,” in a junk mail publication, Direct, by Ray Schultz, Editorial Director. Schultz is a good journalist and from past articles, has a high respect for consumer privacy. He talks with Martin Abrams, executive director, Center for Information Policy Leadership at Hunton & Williams in Washington. Also well respected in the industry.
The interview focuses on financial data, which is certainly one of the most important areas we want to protect. Abrams first statement is, “Privacy law in the United States is unstable.” For the most part, his remark refers to the effect on business, not the consumer, and he rightfully states that much of the fault lies in the advance of technology. What is downright frightening is that he feels any real change has to come from the top (not sure if this is government or business) and is three to seven years away.
By then, the identity crisis will have arisen to humongous proportions, a situation that could very well stop commerce in its tracks. At that point, it won’t matter who we are for the chaos will probably shut down both government and business.
More on this issue next time. How individual control over names and personal data works in the United Kingdom.
Thursday, June 01, 2006
It's Monday Morning. Do You Know Where Your Name Is?
When the junk mail industry—and that includes data brokers like ChoicePoint, Acxiom and LexisNexis—opens every Monday morning, there is already a flurry of data mining going on. Actually, the predictive modeling episodes have been in progress over the weekend, sort of a 24/7 event in this business. And your name and personal data? Always an integral part of the process.
During my tenure as a broker of mailing lists, I became interested, and eventually learned the technique of predictive modeling, primarily as a targeting means, to cut down on my clients’ “junk mail.” Most data mining/modeling companies work at the individual household level with their personalized data, something I refused to do. Working only with zip codes, it was possible for me to get acceptable results, while not encroaching on the privacy of individuals.
So what really happens when computer meets your private information in the process of data mining? First of all, there is a human being conducting the modeling procedure, who, by the way, is privy to all your personal data. Usually, there are assistants with the same access. The data arrives at the data mining company in a digital format. It is delivered by one of the services like UPS, who lost 3.9 million records of the Citigroup in mid-2005, including customers’ names, addresses, Social Security numbers, account number, etc.
Let’s say the data arrives securely, but then it must be logged in by a clerk in the tape library. In my 35 years experience in junk mail, this was where an alarming number of computer tapes housing your private information were lost. Just vanished. But in our hypothetical case it is accounted for and moves on to the people who analyze the data. Could be one or several, and each has entrée to all your private information.
Next, it reaches the human being doing the modeling, with advice from the analysts on how to crunch the data. Here’s where the fun part starts. Let’s say Sharper Image has a home humidifier/air purifier that sells for over $500, and they want to target households that both can afford the item, and have some underlying health issue need. This is where your personal data comes into play.
First, the modeler might determine if you own a home, moving next to your home value for verification, then to your income to substantiate your ability to buy the product. Other factors are marital status, children in household, whether you are a junk mail shopper, and your education level, the latter two confirming that you might carefully read the humidifier advertisement.
Our human being will want to know if there are any pets in the home, whether anyone is a smoker, who has what allergies or related ailments, and what medications are being taken, which further confirms these allergies. Other factors like your fitness level, what you buy from junk mail catalogs, and what you buy at the super market could be used.
All this data is fed into high technology software that will look at each item, determine its relevancy, evaluate its impact on the purchase of the humidifier, and spit out millions of qualified names and addresses. Sound simple? It is if you are experienced in data mining and have sophisticated programs at your disposal like neural networks (artificial intelligence).
So what’s the downside to this for the average consumer? Sharper Image determines who wants their humidifier, and you get a mailing you might just be glad to receive for a change. The answer is that nothing is wrong if you had control over your name and private information from the beginning. I am talking about my concept to pass federal legislation to give you this control, and pay you when it is sold.
This would have allowed you to say yes to the whole procedure, knowing your name and personal data was out there in junk mail limbo, able to target the breach immediately if it occurred. Believe me, the security level of your data would be significantly higher than it is now, if the junk mailers knew you had this control.
Folks, the alarming rate of stolen private information is only going to get worse. Your enlightenment is the sole purpose of this blog, and it is posts like this that point the need for individual control
There’s more to say about this in future posts. Encryption of data is one of the top levels of protection. Another possibility is anonymous separation of name and personal data. Something being used in the United Kingdom, and being explored in the U.S.
During my tenure as a broker of mailing lists, I became interested, and eventually learned the technique of predictive modeling, primarily as a targeting means, to cut down on my clients’ “junk mail.” Most data mining/modeling companies work at the individual household level with their personalized data, something I refused to do. Working only with zip codes, it was possible for me to get acceptable results, while not encroaching on the privacy of individuals.
So what really happens when computer meets your private information in the process of data mining? First of all, there is a human being conducting the modeling procedure, who, by the way, is privy to all your personal data. Usually, there are assistants with the same access. The data arrives at the data mining company in a digital format. It is delivered by one of the services like UPS, who lost 3.9 million records of the Citigroup in mid-2005, including customers’ names, addresses, Social Security numbers, account number, etc.
Let’s say the data arrives securely, but then it must be logged in by a clerk in the tape library. In my 35 years experience in junk mail, this was where an alarming number of computer tapes housing your private information were lost. Just vanished. But in our hypothetical case it is accounted for and moves on to the people who analyze the data. Could be one or several, and each has entrée to all your private information.
Next, it reaches the human being doing the modeling, with advice from the analysts on how to crunch the data. Here’s where the fun part starts. Let’s say Sharper Image has a home humidifier/air purifier that sells for over $500, and they want to target households that both can afford the item, and have some underlying health issue need. This is where your personal data comes into play.
First, the modeler might determine if you own a home, moving next to your home value for verification, then to your income to substantiate your ability to buy the product. Other factors are marital status, children in household, whether you are a junk mail shopper, and your education level, the latter two confirming that you might carefully read the humidifier advertisement.
Our human being will want to know if there are any pets in the home, whether anyone is a smoker, who has what allergies or related ailments, and what medications are being taken, which further confirms these allergies. Other factors like your fitness level, what you buy from junk mail catalogs, and what you buy at the super market could be used.
All this data is fed into high technology software that will look at each item, determine its relevancy, evaluate its impact on the purchase of the humidifier, and spit out millions of qualified names and addresses. Sound simple? It is if you are experienced in data mining and have sophisticated programs at your disposal like neural networks (artificial intelligence).
So what’s the downside to this for the average consumer? Sharper Image determines who wants their humidifier, and you get a mailing you might just be glad to receive for a change. The answer is that nothing is wrong if you had control over your name and private information from the beginning. I am talking about my concept to pass federal legislation to give you this control, and pay you when it is sold.
This would have allowed you to say yes to the whole procedure, knowing your name and personal data was out there in junk mail limbo, able to target the breach immediately if it occurred. Believe me, the security level of your data would be significantly higher than it is now, if the junk mailers knew you had this control.
Folks, the alarming rate of stolen private information is only going to get worse. Your enlightenment is the sole purpose of this blog, and it is posts like this that point the need for individual control
There’s more to say about this in future posts. Encryption of data is one of the top levels of protection. Another possibility is anonymous separation of name and personal data. Something being used in the United Kingdom, and being explored in the U.S.
Thursday, May 25, 2006
Yes, Virginia, Data Mining Can Catch Terrorists
A recent article from Information Week, “Can Data Mining Catch Terrorists?,” asks a question I first thought was rhetorical…until I read further. The author, J. Nicholas Hoover, covers all the recent activity of the National Security Agency (NSA) spying issue, touching on USA Today’s article, “NSA has massive database of Americans’ phone calls,” by Leslie Cauley. They’re both worth reading.
Hoover is right about the technology for assembling humongous databases, not the least of which is Microsoft’s Access. Data, of course, is a necessary part of the equation, and the jury is still out on whether that has been given up. If the NSA does not have the algorithms that allow them to conduct the predictive modeling/data mining that identifies patterns of terrorism, it is simply a matter of incompetence. It is expensive—when has that ever bothered this administration?—but readily available.
But there is one part of the article that I take issue with, and it is where Hoover indicates the NSA could learn from retailers (junk mailers) who mine customer data “without invading customer privacy.” When CitiBank buys your name and financial data from TransUnion (one of the big three credit bureaus that uses data mining techniques for selection), to send you a credit card offer that could be intercepted by an ID thief, that is invading your privacy.
My other major concern is the attention given to the “accuracy of data” in the piece. Hoover indicates its integrity “is different” for each data broker. What isn’t mentioned is the fact that much of your private information is also incorrect. In the article, “Privacy Activism study finds new problems for ChoicePoint, Acxion,” two major data brokers, there are alarming facts that should make every American consumer rise up and insist on control over their names and personal data.
The error rates for private information by Acxiom and ChoicePoint were 67 percent and 73 percent, respectively. 100 percent of the eleven participants in the survey had mistakes in their background check reports. This included the most basic information of name and address, but also involved Social Security numbers and phone numbers. The latter, of course, the basis of NSA’s database.
ChoicePoint has 19 billion records, including information on most U.S. residents. Acxiom’s warehouse is similar and includes over two hundred demographic and lifestyle items the last time I checked. Each has sufficient data to insure that the NSA could easily determine your household’s daily habits.
In the Hoover piece, the Government Accountability Office found in a 2004 survey that federal agencies were already involved in or planning 199 data mining projects, including 122 involving personal data. That’s your private stuff, folks. And, many of these will use ChoicePoint and/or Acxiom data, because of the contract these companies already have with the government.
So yes, Virginia, data mining can catch terrorists. But only if it is done correctly and with accurate data. It must not in the process, however, randomly access the personal records of innocent U.S. citizens, who give up this data for purposes that have absolutely no relationship to terrorism.
In my next post, I’m going to reveal the technology and antics of the predictive modeler/data miner, so that readers can understand the process their names and private information go through to forecast their next move. It’s an event that occurs hundreds of times daily, creating an identity crisis for your household each time.
Hoover is right about the technology for assembling humongous databases, not the least of which is Microsoft’s Access. Data, of course, is a necessary part of the equation, and the jury is still out on whether that has been given up. If the NSA does not have the algorithms that allow them to conduct the predictive modeling/data mining that identifies patterns of terrorism, it is simply a matter of incompetence. It is expensive—when has that ever bothered this administration?—but readily available.
But there is one part of the article that I take issue with, and it is where Hoover indicates the NSA could learn from retailers (junk mailers) who mine customer data “without invading customer privacy.” When CitiBank buys your name and financial data from TransUnion (one of the big three credit bureaus that uses data mining techniques for selection), to send you a credit card offer that could be intercepted by an ID thief, that is invading your privacy.
My other major concern is the attention given to the “accuracy of data” in the piece. Hoover indicates its integrity “is different” for each data broker. What isn’t mentioned is the fact that much of your private information is also incorrect. In the article, “Privacy Activism study finds new problems for ChoicePoint, Acxion,” two major data brokers, there are alarming facts that should make every American consumer rise up and insist on control over their names and personal data.
The error rates for private information by Acxiom and ChoicePoint were 67 percent and 73 percent, respectively. 100 percent of the eleven participants in the survey had mistakes in their background check reports. This included the most basic information of name and address, but also involved Social Security numbers and phone numbers. The latter, of course, the basis of NSA’s database.
ChoicePoint has 19 billion records, including information on most U.S. residents. Acxiom’s warehouse is similar and includes over two hundred demographic and lifestyle items the last time I checked. Each has sufficient data to insure that the NSA could easily determine your household’s daily habits.
In the Hoover piece, the Government Accountability Office found in a 2004 survey that federal agencies were already involved in or planning 199 data mining projects, including 122 involving personal data. That’s your private stuff, folks. And, many of these will use ChoicePoint and/or Acxiom data, because of the contract these companies already have with the government.
So yes, Virginia, data mining can catch terrorists. But only if it is done correctly and with accurate data. It must not in the process, however, randomly access the personal records of innocent U.S. citizens, who give up this data for purposes that have absolutely no relationship to terrorism.
In my next post, I’m going to reveal the technology and antics of the predictive modeler/data miner, so that readers can understand the process their names and private information go through to forecast their next move. It’s an event that occurs hundreds of times daily, creating an identity crisis for your household each time.
Tuesday, May 23, 2006
Veterans Discharged After Vietnam...Beware Stolen Data
It’s hot news today, and worth a quick post to get out the word. It also underscores my fight to give U.S. consumers the right to control their names and personal data. If we had that right, there would be no need for the millions of veterans to worry about their identity being stolen, after the recent data theft.
What happened was that the private information of 26.5 million veterans was lifted from the Veterans Administration in another bizarre example of loose security. Those affected are discharges after 1975, or those who submitted claims to the agency before 1975.
According to Consumers Union, information such as names, Social Security numbers, dates of birth—all that is necessary to steal your life—were stolen from the home of a long-term employee. The data was downloaded to his or her home computer, which was stolen in the burglary. No indication from the VA why this moron was “allowed” to capture such sensitive, private information, supposedly protected by security.
In an article, “U.S. Veterans Data Stolen, VA Shows Little Concern Over Data Theft,” by Dave Porter, the VA has yet to explain why they waited until now—the data was taken early May—to make the announcement. This is, in fact, required by law in several states—remember California’s law and ChoicePoint?—and just another example of government incompetence.
And, while on that subject, Porter tells us that George W. Bush just got around to establishing a task force on identity theft on May 10, giving his henchman AG, Alberto Gonzales, the go-ahead to exercise zero tolerance in the prosecution of data loss cases. Yeah, right. At the same time one of the biggest culprits, ChoicePoint, continues to enjoy lucrative government contracts.
So, what to do? There’s a VA telephone number to call but I heard the incompetence persists even there. It is (800) 333-4636. If you get a letter from the VA, and you live in a state that allows a security freeze on your credit files, you have to consider this in relation to the risk. I suggest a free credit report from each of the three credit reporting agencies, spread out over a period of time that, hopefully, will either allow recovery of the data, or the circumstances are too hot for the ID thieves to act.
Beth Givens, Director, Privacy Rights Clearinghouse (PRC), warns veterans and their families to monitor their financial picture “indefinitely.” What does that tell you about their future? If you go to the PRC web site, there is a Chronology of Data Breaches showing close to 82 million American consumers who have had their personal data compromised since February 2005.
Folks, it’s time to voice your support for my goal of passing federal legislation giving you control over your name and private information. And, pay you, when it is sold. Let your local print and broadcast media know what you think. Contact your representative in the House, and your Senator.
Dave Porter said it best. “The one way you'd get lawmakers to pass legislation that would control how data is managed would be to go to Visa or Mastercard and buy the personal information on them and start posting it online.” He goes on to say what I have been saying for months, that there is no meaningful identity theft legislation in the works. He also agrees that it is lobbying money that has put us in this position.
What happened was that the private information of 26.5 million veterans was lifted from the Veterans Administration in another bizarre example of loose security. Those affected are discharges after 1975, or those who submitted claims to the agency before 1975.
According to Consumers Union, information such as names, Social Security numbers, dates of birth—all that is necessary to steal your life—were stolen from the home of a long-term employee. The data was downloaded to his or her home computer, which was stolen in the burglary. No indication from the VA why this moron was “allowed” to capture such sensitive, private information, supposedly protected by security.
In an article, “U.S. Veterans Data Stolen, VA Shows Little Concern Over Data Theft,” by Dave Porter, the VA has yet to explain why they waited until now—the data was taken early May—to make the announcement. This is, in fact, required by law in several states—remember California’s law and ChoicePoint?—and just another example of government incompetence.
And, while on that subject, Porter tells us that George W. Bush just got around to establishing a task force on identity theft on May 10, giving his henchman AG, Alberto Gonzales, the go-ahead to exercise zero tolerance in the prosecution of data loss cases. Yeah, right. At the same time one of the biggest culprits, ChoicePoint, continues to enjoy lucrative government contracts.
So, what to do? There’s a VA telephone number to call but I heard the incompetence persists even there. It is (800) 333-4636. If you get a letter from the VA, and you live in a state that allows a security freeze on your credit files, you have to consider this in relation to the risk. I suggest a free credit report from each of the three credit reporting agencies, spread out over a period of time that, hopefully, will either allow recovery of the data, or the circumstances are too hot for the ID thieves to act.
Beth Givens, Director, Privacy Rights Clearinghouse (PRC), warns veterans and their families to monitor their financial picture “indefinitely.” What does that tell you about their future? If you go to the PRC web site, there is a Chronology of Data Breaches showing close to 82 million American consumers who have had their personal data compromised since February 2005.
Folks, it’s time to voice your support for my goal of passing federal legislation giving you control over your name and private information. And, pay you, when it is sold. Let your local print and broadcast media know what you think. Contact your representative in the House, and your Senator.
Dave Porter said it best. “The one way you'd get lawmakers to pass legislation that would control how data is managed would be to go to Visa or Mastercard and buy the personal information on them and start posting it online.” He goes on to say what I have been saying for months, that there is no meaningful identity theft legislation in the works. He also agrees that it is lobbying money that has put us in this position.
Wednesday, May 17, 2006
Junk Mail Ethics IV
So far we have covered marketing surveys, envelope “teaser” copy, and shipping and handling costs, in relation to the Direct Marketing Assn.’s (DMA) guidelines: “DMA Releases Latest Ethics Report; Refers Listing Service To FCC.” My intent was to pick the four most prominent issues and highlight their importance from my experience as a former junk mail list broker. Number four is by far the most significant.
“Where do they get my name?” is a question on the minds of most junk mail shoppers, and the number one priority for anyone who has suffered identity theft. My concept of passing federal legislation to give consumers control over their names and personal data would not dampen in the least the efforts of the junk mail industry in finding new sources to uncover your name and private information. Why? Because this is inherent in the never-ending process of bulding intimate dossiers on every American household.
It would, however, stop them from using this data without you having full control and knowledge of the fact.
The DMA guideline states: “Direct marketers should disclose the source from which they obtained information about consumers upon a consumer’s request. Marketers should tell consumers the source of their name on a specific list, or, if not possible, the kinds of sources used.” I would add one more point. The junk mailer should also be prepared to tell the consumer how much they paid for their name and personal data.
Any regular reader of The Dunning Letter knows of my grass-roots movement to pass the above legislation that also advocates that the consumer be paid whenever their name and private information is sold. In all of my 35 years of selling mailing lists, I cannot remember the DMA seriously addressing the issue of letting individuals control their names and personal data. The reason is the bottom line for their members; selling lists is a $4 billion annual business.
But after 100 significant data breaches in 2005, affecting nearly 56 million consumers, resulting in 9.3 million victims, and a per-victim cost of $5,885, you should want to know where they got your name.
A few years ago, after placing list orders for one of my clients, and after their advertisement was sent, they contacted me about a disgruntled recipient who wanted to know where the junk mailer had gotten their name. Since every name is key-coded by list, it was easy to identity the source. I contacted the junk mailer as a courtesy to let them know they might get a call re. this matter. They stonewalled me with a complete refusal to allow me to reveal their name.
Probably not true of all junk mailers, but this gives you an idea of the secrecy level over names and private information. It certainly does not conform to DMA guidelines, above.
So what to do? Like with the shipping and handling charges in my last post, call or e-mail the junk mailer from whom you receive the advertisement. Look on the order page for a telephone number or web site, or just Google the company. Click on either “Contact Us” or “Customer Service.”
You have a right to know who is selling your name and personal data, and you really should put out the above effort to keep the junk mailers on the ball. Hopefully, this will all change soon when the consumer is finally in complete control.
“Where do they get my name?” is a question on the minds of most junk mail shoppers, and the number one priority for anyone who has suffered identity theft. My concept of passing federal legislation to give consumers control over their names and personal data would not dampen in the least the efforts of the junk mail industry in finding new sources to uncover your name and private information. Why? Because this is inherent in the never-ending process of bulding intimate dossiers on every American household.
It would, however, stop them from using this data without you having full control and knowledge of the fact.
The DMA guideline states: “Direct marketers should disclose the source from which they obtained information about consumers upon a consumer’s request. Marketers should tell consumers the source of their name on a specific list, or, if not possible, the kinds of sources used.” I would add one more point. The junk mailer should also be prepared to tell the consumer how much they paid for their name and personal data.
Any regular reader of The Dunning Letter knows of my grass-roots movement to pass the above legislation that also advocates that the consumer be paid whenever their name and private information is sold. In all of my 35 years of selling mailing lists, I cannot remember the DMA seriously addressing the issue of letting individuals control their names and personal data. The reason is the bottom line for their members; selling lists is a $4 billion annual business.
But after 100 significant data breaches in 2005, affecting nearly 56 million consumers, resulting in 9.3 million victims, and a per-victim cost of $5,885, you should want to know where they got your name.
A few years ago, after placing list orders for one of my clients, and after their advertisement was sent, they contacted me about a disgruntled recipient who wanted to know where the junk mailer had gotten their name. Since every name is key-coded by list, it was easy to identity the source. I contacted the junk mailer as a courtesy to let them know they might get a call re. this matter. They stonewalled me with a complete refusal to allow me to reveal their name.
Probably not true of all junk mailers, but this gives you an idea of the secrecy level over names and private information. It certainly does not conform to DMA guidelines, above.
So what to do? Like with the shipping and handling charges in my last post, call or e-mail the junk mailer from whom you receive the advertisement. Look on the order page for a telephone number or web site, or just Google the company. Click on either “Contact Us” or “Customer Service.”
You have a right to know who is selling your name and personal data, and you really should put out the above effort to keep the junk mailers on the ball. Hopefully, this will all change soon when the consumer is finally in complete control.
Monday, May 08, 2006
Junk Mail Ethics III
We’ve covered junk mail marketing surveys that sell your personal data, and envelope “teaser” copy that is meant to lure you inside for the kill. In both instances, the Direct Marketing Assn. (DMA), touts its ethics standards for these and other issues, as covered in their article, “DMA Releases latest Ethics Report; Refers Listing Service to FCC.”
Next, let’s turn to another DMA point of concern. Junk mailers charge you a shipping and handling charge for sending the products you ordered. After 35 years of selling mailing lists to these companies, I am still confused about just how they arrive at the S&H. It is supposed to be the total of postage, UPS, Fed EX, etc., and the labor necessary to prepare your package for shipping.
Here are the DMA ethical guidelines: “Shipping and handling costs should not be excessive. They should bear a reasonable relationship to actual costs incurred, according to DMA’s guidelines. Marketers should be able to substantiate their shipping and handling charges.” I went to the DMA site, “Guidance For Establishing And Substantiating Shipping And Handling Charges,” and found three pages of text that basically say junk mailers should charge a fair amount.
But it is this part that I don’t understand from the above statement: “They (S&H charge) should bear a reasonable relationship to actual costs incurred…” Does that mean junk mailers can mark up shipping and handling, as if it is an extension of the merchandise they are selling? I am here to tell you that it is done. In doing list work for one company a few years ago, the person in charge told me it was customary to tack on a few bucks to S&H.
However, it is the manner in which the shipping and handling is calculated that mystifies me most. The figure you pay is based on the dollar amount of the order. If you purchase items weighing five pounds that add up to $25.00, you pay the same amount as the customer who has the same dollar amount, but the order weighs ten pounds. When I go to UPS or USPS to ship something—companies many junk mailers use—the package is weighed and I am charged accordingly, supposedly including handling.
I decided to do an analysis of major catalogs to determine a range of shipping and handling costs, based on this industry-wide system. My fictional order would total $50.00 to make sure each catalog was measured equally. Out of twelve catalogs, the S&H cost extended from FREE to 24 cents per dollar ordered, with the average around 18 cents. That means you must add an average of 18 cents to each dollar purchase you make by junk mail, which is a bargain if you don’t have the time to go to the mall. Particularly, with current gas prices.
To name a few names, Lillian Vernon ships free for over $40.00 purchases. TravelSmith is the next cheapest at 14 cents per pound. Harry and David came in highest at a whopping 24 cents. Improvements was 22 cents; Plow & Hearth and Signals 20 cents; Sharper Image and Walter Drake 18 cents; Crate and Barrel 17 cents; and Maryland Square, Coldwater Creek and PetsMart at 16 cents. Go figure.
Here’s my advice. Call or send an e-mail to your favorite junk mail catalog and ask them just what they base their shipping and handling charges on, and how they are calculated. Look on the order page for a telephone number or web site, or just Google the company of your choice. Click on either “Contact Us” or “Customer Service.” You might be interested in what you find out and I would like to hear about your results.
The next and final ethics issue is the answer to everyone’s question: where did they get my name?
Next, let’s turn to another DMA point of concern. Junk mailers charge you a shipping and handling charge for sending the products you ordered. After 35 years of selling mailing lists to these companies, I am still confused about just how they arrive at the S&H. It is supposed to be the total of postage, UPS, Fed EX, etc., and the labor necessary to prepare your package for shipping.
Here are the DMA ethical guidelines: “Shipping and handling costs should not be excessive. They should bear a reasonable relationship to actual costs incurred, according to DMA’s guidelines. Marketers should be able to substantiate their shipping and handling charges.” I went to the DMA site, “Guidance For Establishing And Substantiating Shipping And Handling Charges,” and found three pages of text that basically say junk mailers should charge a fair amount.
But it is this part that I don’t understand from the above statement: “They (S&H charge) should bear a reasonable relationship to actual costs incurred…” Does that mean junk mailers can mark up shipping and handling, as if it is an extension of the merchandise they are selling? I am here to tell you that it is done. In doing list work for one company a few years ago, the person in charge told me it was customary to tack on a few bucks to S&H.
However, it is the manner in which the shipping and handling is calculated that mystifies me most. The figure you pay is based on the dollar amount of the order. If you purchase items weighing five pounds that add up to $25.00, you pay the same amount as the customer who has the same dollar amount, but the order weighs ten pounds. When I go to UPS or USPS to ship something—companies many junk mailers use—the package is weighed and I am charged accordingly, supposedly including handling.
I decided to do an analysis of major catalogs to determine a range of shipping and handling costs, based on this industry-wide system. My fictional order would total $50.00 to make sure each catalog was measured equally. Out of twelve catalogs, the S&H cost extended from FREE to 24 cents per dollar ordered, with the average around 18 cents. That means you must add an average of 18 cents to each dollar purchase you make by junk mail, which is a bargain if you don’t have the time to go to the mall. Particularly, with current gas prices.
To name a few names, Lillian Vernon ships free for over $40.00 purchases. TravelSmith is the next cheapest at 14 cents per pound. Harry and David came in highest at a whopping 24 cents. Improvements was 22 cents; Plow & Hearth and Signals 20 cents; Sharper Image and Walter Drake 18 cents; Crate and Barrel 17 cents; and Maryland Square, Coldwater Creek and PetsMart at 16 cents. Go figure.
Here’s my advice. Call or send an e-mail to your favorite junk mail catalog and ask them just what they base their shipping and handling charges on, and how they are calculated. Look on the order page for a telephone number or web site, or just Google the company of your choice. Click on either “Contact Us” or “Customer Service.” You might be interested in what you find out and I would like to hear about your results.
The next and final ethics issue is the answer to everyone’s question: where did they get my name?
Wednesday, May 03, 2006
Junk Mail Ethics II
In my last post, I covered junk mail marketing surveys, which was listed in the Direct Marketing Assn.’s (DMA) article, “DMA Releases latest Ethics Report; Refers Listing Service to FCC,” as a priority in their ethics agenda. My blog pointed out just how much of your personal data is requested in these questionnaires, and how rich the junk mailers get from selling it.
Another DMA issue from the article was “teaser” copy; those alluring statements on the front of junk mail envelopes designed to get you inside. The DMA states that they, “…should not cross the line into deceiving a consumer about the nature of the promotion.”
One only needs to remember the sweepstakes mailing received by an individual not too long ago that indicated they were a winner. The person paid their own way to Florida, if I recall correctly, to redeem the prize, only to find out they had won nothing.
My wife just received a mailing from the AAA; we both are members. The envelope has two pieces of “teaser” copy. First, the “Club President” has authorized an upgrade in our membership, “free of charge.” Second, on an oval black and gold seal: “Courtesy Upgrade, FREE, To AAA Plus.” We are instructed to confirm by return mail.
Not until you get inside the envelope and carefully read all the literature, do you find out that it’s only free for one year. Then it costs you $58.00, and that’s in addition to the $73.00 we already pay. Although the letter mentions a $58 renewal after one year, you must go to the “Return Receipt” to find out your grand total is going to be $131 ($58+$73). There are additions to the coverage but the only thing we have used AAA for in the last year is maps, so I’m not sure of the value.
Junk mail auto insurance company, 21st Century, sent us a mailing recently soliciting our business. The envelope says: “Think you have the best auto insurance just because you’re with one of the biggest companies? You’re in for a surprise.” That got me inside, because I was curious just how they knew I was with one of the “biggest companies.” They didn’t.
That was just another ploy to tell me four things my “big company” insurance agent won’t tell me: 1) I can save $300 switching to 21st; 2) No other company offers the important policy features 21st does; 3)No other company is as accessible and easy to work with; 4) They are rated A+ by Fitch Ratings. As to one through three…questionable. And for number four, my “big company” is rated AA+ by Fitch.
Finally, probably the fastest known data acquisition known to man: when you buy or refinance your home. Your name, and a bunch of private information, is made available to a host of predators, not the least of which is the very company with whom you bought or refinanced. You told them at closing you didn’t want all the extra insurance, but apparently they didn’t believe you. Add to that a number of companies you’ve never heard of, and you begin to understand the true meaning of “junk mail.”
Envelope messages like: “Important Information concerning Your Mortgage!,” “Personal and Confidential,” “Protect Your Home.” Here’s my answer. I would like to protect my home from the inane junk mail I receive, or, give me a piece of the action and pay me every time my name and personal data is sold.
Next issue of concern: do junk mailers make a profit from your shipping and handling charges?
Another DMA issue from the article was “teaser” copy; those alluring statements on the front of junk mail envelopes designed to get you inside. The DMA states that they, “…should not cross the line into deceiving a consumer about the nature of the promotion.”
One only needs to remember the sweepstakes mailing received by an individual not too long ago that indicated they were a winner. The person paid their own way to Florida, if I recall correctly, to redeem the prize, only to find out they had won nothing.
My wife just received a mailing from the AAA; we both are members. The envelope has two pieces of “teaser” copy. First, the “Club President” has authorized an upgrade in our membership, “free of charge.” Second, on an oval black and gold seal: “Courtesy Upgrade, FREE, To AAA Plus.” We are instructed to confirm by return mail.
Not until you get inside the envelope and carefully read all the literature, do you find out that it’s only free for one year. Then it costs you $58.00, and that’s in addition to the $73.00 we already pay. Although the letter mentions a $58 renewal after one year, you must go to the “Return Receipt” to find out your grand total is going to be $131 ($58+$73). There are additions to the coverage but the only thing we have used AAA for in the last year is maps, so I’m not sure of the value.
Junk mail auto insurance company, 21st Century, sent us a mailing recently soliciting our business. The envelope says: “Think you have the best auto insurance just because you’re with one of the biggest companies? You’re in for a surprise.” That got me inside, because I was curious just how they knew I was with one of the “biggest companies.” They didn’t.
That was just another ploy to tell me four things my “big company” insurance agent won’t tell me: 1) I can save $300 switching to 21st; 2) No other company offers the important policy features 21st does; 3)No other company is as accessible and easy to work with; 4) They are rated A+ by Fitch Ratings. As to one through three…questionable. And for number four, my “big company” is rated AA+ by Fitch.
Finally, probably the fastest known data acquisition known to man: when you buy or refinance your home. Your name, and a bunch of private information, is made available to a host of predators, not the least of which is the very company with whom you bought or refinanced. You told them at closing you didn’t want all the extra insurance, but apparently they didn’t believe you. Add to that a number of companies you’ve never heard of, and you begin to understand the true meaning of “junk mail.”
Envelope messages like: “Important Information concerning Your Mortgage!,” “Personal and Confidential,” “Protect Your Home.” Here’s my answer. I would like to protect my home from the inane junk mail I receive, or, give me a piece of the action and pay me every time my name and personal data is sold.
Next issue of concern: do junk mailers make a profit from your shipping and handling charges?
Wednesday, April 26, 2006
Junk Mail Ethics
Back in December of 2005, the Direct Marketing Assn. (DMA) published an article on its website that identifies current action against three companies for lack of cooperation in solving matters of ethics. Neither of the companies is a member of DMA, so therefore, they really don’t have to cooperate. They didn’t, and there’s really not much more the organization can do but refer the companies on to the appropriate law enforcement authority.
What the DMA did do in the article, “DMA Releases Latest Ethics Report; Refers Listing Service to FCC,” is compile a list of six issues of primary concern, based on 20 current cases. Based on my 35 years as a broker of mailing lists, I am impressed with the issues, but not moved in the least with what I know of junk mail compliance. Four are worth mentioning, however.
Number one: Customer information should not be readily available for access by other individuals; here they are primarily concerned with services that make this data available online. “Customers would not reasonably expect that information about what they purchased, or how they responded to a marketing survey, would result in their inclusion in an online look-up service.”
One of the most lucrative areas of selling your name and personal data comes from marketing surveys you complete to get free products. OK. We’re all frugal to a point, but if you knew how quick and widely distributed your private information was after filling out these detailed questionnaires, you’d think twice next time.
The giants of this gold mine are Equifax and Experian, both credit reporting firms. Their subsidiaries, Lifestyle Selector and Behaviorbank, maintain databases of your personal data and daily habits, numbering 56 million and 40 million households, respectively. Things like what you read, what you drink, what ailments you have and the medications you take, how you invest, if you smoke and what brand, whether you gamble…and much, much more.
And these aren’t the only companies who assemble and sell this data. Be assured that just about anytime you put your private information on paper, online, or give it up by telephone, it will be collected and sold to the highest bidder. There are billions of dollars to be made, and you won’t realize one penny in the deal. To add insult to injury, you might even suffer identity theft down the line.
Please tell me, what is worse? Making the survey data available to Web surfers online (as is the point of the article’s issue), or selling it to thousands of junk mailers that, as we have already experienced, can lose the data to potential ID thieves? The DMA’s focus is typical of an industry that covets the sale of your name and personal data, and is willing to protect this supposed right at any risk.
It’s already enough that Equifax and Experian turn over this data for the marketing strategies of those companies who provide you the free products. It’s equally troubling that they fail to make it clear to you that your private information will be sold over, and over, and over…ad infinitum.
If you, the consumer, had control over this personal data, there wouldn’t be a problem, and you would be enjoying the fruits of the sale of this data.
Next issue of concern, the “teaser” copy on junk mail envelopes that bribe you to open them.
What the DMA did do in the article, “DMA Releases Latest Ethics Report; Refers Listing Service to FCC,” is compile a list of six issues of primary concern, based on 20 current cases. Based on my 35 years as a broker of mailing lists, I am impressed with the issues, but not moved in the least with what I know of junk mail compliance. Four are worth mentioning, however.
Number one: Customer information should not be readily available for access by other individuals; here they are primarily concerned with services that make this data available online. “Customers would not reasonably expect that information about what they purchased, or how they responded to a marketing survey, would result in their inclusion in an online look-up service.”
One of the most lucrative areas of selling your name and personal data comes from marketing surveys you complete to get free products. OK. We’re all frugal to a point, but if you knew how quick and widely distributed your private information was after filling out these detailed questionnaires, you’d think twice next time.
The giants of this gold mine are Equifax and Experian, both credit reporting firms. Their subsidiaries, Lifestyle Selector and Behaviorbank, maintain databases of your personal data and daily habits, numbering 56 million and 40 million households, respectively. Things like what you read, what you drink, what ailments you have and the medications you take, how you invest, if you smoke and what brand, whether you gamble…and much, much more.
And these aren’t the only companies who assemble and sell this data. Be assured that just about anytime you put your private information on paper, online, or give it up by telephone, it will be collected and sold to the highest bidder. There are billions of dollars to be made, and you won’t realize one penny in the deal. To add insult to injury, you might even suffer identity theft down the line.
Please tell me, what is worse? Making the survey data available to Web surfers online (as is the point of the article’s issue), or selling it to thousands of junk mailers that, as we have already experienced, can lose the data to potential ID thieves? The DMA’s focus is typical of an industry that covets the sale of your name and personal data, and is willing to protect this supposed right at any risk.
It’s already enough that Equifax and Experian turn over this data for the marketing strategies of those companies who provide you the free products. It’s equally troubling that they fail to make it clear to you that your private information will be sold over, and over, and over…ad infinitum.
If you, the consumer, had control over this personal data, there wouldn’t be a problem, and you would be enjoying the fruits of the sale of this data.
Next issue of concern, the “teaser” copy on junk mail envelopes that bribe you to open them.
Wednesday, April 19, 2006
Junk Mail Industry Rag Puts Down Consumers
Direct Magazine, a junk mail industry publication, obviously must back the business it receives its advertising revenue from, but when they belittle the very customers who support Direct’s advertisers, that sucks. It all comes from a recent article on DirectMag.com, “No, Consumers Shouldn’t Always Be in Control.”
Right out of the gate they’re wrong. Consumers should have complete control over their names and personal data.
The article comments on Phil Raymond’s concept that e-mail recipients should be paid when they receive e-mail they do not want. YES! Very similar to my theory that consumers should be paid each time their name and private information is sold. Raymond is CEO of Vanquish Labs, and plans to introduce software that will support his concept.
Direct calls the idea interesting, but then states it gets “wackier” and “wackier” when scrutinized. Continuing, they contend there would be a “chilling effect” by letting “unpredictable” and “hair-trigger consumers” make decisions like this.
The put-down progresses to Direct’s conclusion that, “…consumers simply don’t deserve money for accepting e-mail.” Their reasoning is you pay little to nothing for e-mail boxes. What they don’t mention is that junk mailers charge premium prices for the sale of your name with an e-mail address.
According to junk mail list manager/broker Worldata in their latest “List Price Index,” names with e-mail addresses sell for 50 percent more than the average junk mail shopper. Naturally, this segment of merchandising your names and private information is growing at a high rate of 38 percent annually.
Phil Raymond is backed by Boston University economics professor, Marshall Van Alstyne, who did research for the project. See “Boston U. professor to develop anti-spam program.” Reaction is mixed at BU. Most students didn’t think they would charge the spammers, and an engineering junior stated flatly there was no reason to charge for something some people could find “entertaining.” That’s a switch.
This is not just about e-mail lists, or anti-spam, or whether Raymond and the BU professor have a good idea. It is about an arrogant junk mail industry that continues to take the position that it owns your name and personal data, and you, the name-holder, have no rights whatsoever.
This, after over 100 significant data security breaches in 2005, affecting nearly 56 million consumers, while junk mailers and data brokers continue to reap over $4 billion each year from private information they are supposed to protect and don’t want to pay you for. It’s pathetic, and the issue worsens with each new loss of data, compounded by self-serving articles like the one above in Direct Magazine.
There is only one way to solve the identity crisis, and at the same time put some of the junk mail fortunes in your pocket. Pass federal legislation that will give consumers control over their names and personal data, and pay them when it is sold. Click on the following to contact your congressional representatives: House of Representatives; Senators. Folks, I cannot do this alone.
As usual, tell them I sent you.
Right out of the gate they’re wrong. Consumers should have complete control over their names and personal data.
The article comments on Phil Raymond’s concept that e-mail recipients should be paid when they receive e-mail they do not want. YES! Very similar to my theory that consumers should be paid each time their name and private information is sold. Raymond is CEO of Vanquish Labs, and plans to introduce software that will support his concept.
Direct calls the idea interesting, but then states it gets “wackier” and “wackier” when scrutinized. Continuing, they contend there would be a “chilling effect” by letting “unpredictable” and “hair-trigger consumers” make decisions like this.
The put-down progresses to Direct’s conclusion that, “…consumers simply don’t deserve money for accepting e-mail.” Their reasoning is you pay little to nothing for e-mail boxes. What they don’t mention is that junk mailers charge premium prices for the sale of your name with an e-mail address.
According to junk mail list manager/broker Worldata in their latest “List Price Index,” names with e-mail addresses sell for 50 percent more than the average junk mail shopper. Naturally, this segment of merchandising your names and private information is growing at a high rate of 38 percent annually.
Phil Raymond is backed by Boston University economics professor, Marshall Van Alstyne, who did research for the project. See “Boston U. professor to develop anti-spam program.” Reaction is mixed at BU. Most students didn’t think they would charge the spammers, and an engineering junior stated flatly there was no reason to charge for something some people could find “entertaining.” That’s a switch.
This is not just about e-mail lists, or anti-spam, or whether Raymond and the BU professor have a good idea. It is about an arrogant junk mail industry that continues to take the position that it owns your name and personal data, and you, the name-holder, have no rights whatsoever.
This, after over 100 significant data security breaches in 2005, affecting nearly 56 million consumers, while junk mailers and data brokers continue to reap over $4 billion each year from private information they are supposed to protect and don’t want to pay you for. It’s pathetic, and the issue worsens with each new loss of data, compounded by self-serving articles like the one above in Direct Magazine.
There is only one way to solve the identity crisis, and at the same time put some of the junk mail fortunes in your pocket. Pass federal legislation that will give consumers control over their names and personal data, and pay them when it is sold. Click on the following to contact your congressional representatives: House of Representatives; Senators. Folks, I cannot do this alone.
As usual, tell them I sent you.
Saturday, April 15, 2006
Hispanics and a New Independent Party
All of a sudden both sides of the aisle are interested in the Hispanic vote. That’s because they have finally begun to make themselves heard. In the 2000 presidential election, they registered 7.5 million voters out of a possible 13.1 million citizens. This increased to 9.3 million in 2004, out of 16 million, respectively. I bet the recent demonstrations upped this substantially.
We can all remember when the Democrats championed causes for minorities, but barely a peep has been heard from those party members either running for Congress in 2006, or the Presidency in 2008. Republicans do garner some support, but the individual usually comes from a wealthy background or has made it big in business. There is a tendency to forget the little guy, to whom we owe much of this country’s progress.
I won’t get into the legal aspects of the immigration movement since it is just that, a legal issue. However, I will say that federal legislation is desperately needed to determine the status of the 11 to 12 million Hispanics who are here illegally. And, it isn’t likely that Democrats or Republicans have the guts to do what is right. The opinion is based on both parties’ track record in recent privacy legislation, another concern dear to the average consumer.
Perhaps this potential voting block of over 16 million (citizens only) should consider an independent political party as the answer to their problems. It’s not too far-fetched to combine a civil rights movement with a privacy theme, especially since many of the privacy issues apply to minorities. And there are another 25 to 30 million sharing this status that would join the momentum.
Nearly 58 percent of Hispanics registered to vote in 2004, and 81.5 percent of that voted. However, of the 42 percent not registering, just under 38 percent gave the reason that they weren’t interested in the election or not involved in politics. This doesn’t differ much from the total population where 46.6 percent gave the same excuse. But you can take it to the bank that the recent demonstrations have changed at least the Hispanic thinking.
The next move is to integrate all this enthusiasm into one solid cause that stands for individual rights with no boundaries of race, or otherwise. Starting with the demand for personal privacy, every issue that impacts this mandate becomes part of the independent party platform. Immigration and human rights in general would top the list.
Timing is perfect. Every seat in the House of Representatives is up for grabs in November, along with 33 Senate seats. If you don’t have an independent you can vote for in your area, find a candidate who subscribes to the principles of individual rights and encourage them to run.
The latest LA Times/Bloomberg poll shows only 39 percent of Americans approve of Bush as President; 57 percent disapprove. And, these figures are confirmed in AP/Ipsos, and Washington Post/ABC surveys. Congress fares even worse with a 28 percent approval rating; 61 percent disapproval. You can read about this continued Republican slump in an MSNBC.com article, “Bush job-approval ratings remain low,” by Jeff Pruzan.
Many voters believe that it is impossible to elect an independent President or majority in Congress. Most of this rhetoric comes from the top echelons of the Democratic and Republican parties, as well as their elected officials. Well, Ross Perot’s almost 19 percent of the vote in 1992 established him as the most successful third-party candidate since Teddy Roosevelt’s 27.4 percent in 1912.
The TV show, Commander in Chief, on ABC, portrays Geena Davis, an Independent, as the President, ushered into office from the death of the former President. The question is…will she be re-elected? But I think we can all agree that in the best of Hollywood fashion, this has been predetermined. The show’s creator and Producer, Rod Lurie, had to have done extensive research into the possibility of the election of an Independent Party President, in order to maintain believability in characters and the storyline.
Does he know something we don’t? Stay tuned!
We can all remember when the Democrats championed causes for minorities, but barely a peep has been heard from those party members either running for Congress in 2006, or the Presidency in 2008. Republicans do garner some support, but the individual usually comes from a wealthy background or has made it big in business. There is a tendency to forget the little guy, to whom we owe much of this country’s progress.
I won’t get into the legal aspects of the immigration movement since it is just that, a legal issue. However, I will say that federal legislation is desperately needed to determine the status of the 11 to 12 million Hispanics who are here illegally. And, it isn’t likely that Democrats or Republicans have the guts to do what is right. The opinion is based on both parties’ track record in recent privacy legislation, another concern dear to the average consumer.
Perhaps this potential voting block of over 16 million (citizens only) should consider an independent political party as the answer to their problems. It’s not too far-fetched to combine a civil rights movement with a privacy theme, especially since many of the privacy issues apply to minorities. And there are another 25 to 30 million sharing this status that would join the momentum.
Nearly 58 percent of Hispanics registered to vote in 2004, and 81.5 percent of that voted. However, of the 42 percent not registering, just under 38 percent gave the reason that they weren’t interested in the election or not involved in politics. This doesn’t differ much from the total population where 46.6 percent gave the same excuse. But you can take it to the bank that the recent demonstrations have changed at least the Hispanic thinking.
The next move is to integrate all this enthusiasm into one solid cause that stands for individual rights with no boundaries of race, or otherwise. Starting with the demand for personal privacy, every issue that impacts this mandate becomes part of the independent party platform. Immigration and human rights in general would top the list.
Timing is perfect. Every seat in the House of Representatives is up for grabs in November, along with 33 Senate seats. If you don’t have an independent you can vote for in your area, find a candidate who subscribes to the principles of individual rights and encourage them to run.
The latest LA Times/Bloomberg poll shows only 39 percent of Americans approve of Bush as President; 57 percent disapprove. And, these figures are confirmed in AP/Ipsos, and Washington Post/ABC surveys. Congress fares even worse with a 28 percent approval rating; 61 percent disapproval. You can read about this continued Republican slump in an MSNBC.com article, “Bush job-approval ratings remain low,” by Jeff Pruzan.
Many voters believe that it is impossible to elect an independent President or majority in Congress. Most of this rhetoric comes from the top echelons of the Democratic and Republican parties, as well as their elected officials. Well, Ross Perot’s almost 19 percent of the vote in 1992 established him as the most successful third-party candidate since Teddy Roosevelt’s 27.4 percent in 1912.
The TV show, Commander in Chief, on ABC, portrays Geena Davis, an Independent, as the President, ushered into office from the death of the former President. The question is…will she be re-elected? But I think we can all agree that in the best of Hollywood fashion, this has been predetermined. The show’s creator and Producer, Rod Lurie, had to have done extensive research into the possibility of the election of an Independent Party President, in order to maintain believability in characters and the storyline.
Does he know something we don’t? Stay tuned!
Tuesday, April 11, 2006
New Regulations Needed to Protect Credit Card Users
My wife made a purchase recently at a farmers market using her credit card to complete the transaction. This is one of those planned events held in shopping centers and strip malls across the country which frequently produces unique items you can’t find anywhere else, made by the very people from whom you are buying. It’s an experience thousands flock to regularly, but it could be a disaster in the making if some changes aren’t made.
In December of 2003, the Fair and Accurate Credit Transaction Act-FACTA was passed, which specifies that no more than the last five digits of your credit card number can be printed when you make a purchase. However, the law governs electronically printed receipts, and doesn’t apply to transactions where the number is either written or executed by an imprint. In other words, thousands of times daily, credit card numbers, maybe yours, are recorded on paper that may or may not be secure.
The merchant used the old-fashioned imprint machine to record my wife’s credit card information, which clearly states the full sixteen digit credit card number. From experience, I know he or she must deposit this receipt to a business account for credit, so, hopefully, it won’t be lost. What worries me is just who, and how many, other people see this number in the trip to the bank.
The “mom and pop” merchants in this country are the very backbone of our great system of commerce. They should be given considerations, but not at the expense of losing my identity to thieves that lurk at every corner…and farmers markets. Folks, they are everywhere, as evidenced by the outbreak of security breaches in 2005. Give them a grace period to comply, like Visa and MasterCard did all the other merchants, and make them stick by it.
You would think that one of the first things lawmakers would do after the recent rash of breaches would be to plug the loopholes of existing law to better protect the consumer. Just imagine that the person who took my wife’s credit card number goes to a bar for a drink on the way to the bank, and someone steals all the daily receipts. Then, multiply that possibility by thousands of transactions like this every day.
ChoicePoint, LexisNexis and other data brokers do pose a huge threat to the security of our identities. They can lose millions of personal records in one quick event—illustrated by CardSystems exposing 40 million credit cards in June of 2005—and need to be controlled to prevent this from happening. But alas, it is not likely, with either current law or the recent blitz of identity protection legislation.
Real security will be accomplished only by individual consumer control over their name and personal data.
The Pittsburgh Post-Gazette printed an article by Robin Sidel from the Wall Street Journal “Identity theft—unplugged,” that quotes some recent figures from Javelin Strategy & Research. Some 29 percent of victims in the survey said their private information was stolen when they lost their wallet, checkbook or credit card. The balance of 71 percent is attributed to someone from the outside initiating the theft.
Most privacy experts agree that a large number of ID thieves get their information from traditional, low-tech sources. Even a family member, friend…or small neighborhood merchant.
It is time to update FACTA and include all merchants, no matter who they are, and seal this big hole in the ID theft dike. In the meantime, if you must make one of these purchases, let the businessperson know that you realize your personal data could be in jeopardy.
In December of 2003, the Fair and Accurate Credit Transaction Act-FACTA was passed, which specifies that no more than the last five digits of your credit card number can be printed when you make a purchase. However, the law governs electronically printed receipts, and doesn’t apply to transactions where the number is either written or executed by an imprint. In other words, thousands of times daily, credit card numbers, maybe yours, are recorded on paper that may or may not be secure.
The merchant used the old-fashioned imprint machine to record my wife’s credit card information, which clearly states the full sixteen digit credit card number. From experience, I know he or she must deposit this receipt to a business account for credit, so, hopefully, it won’t be lost. What worries me is just who, and how many, other people see this number in the trip to the bank.
The “mom and pop” merchants in this country are the very backbone of our great system of commerce. They should be given considerations, but not at the expense of losing my identity to thieves that lurk at every corner…and farmers markets. Folks, they are everywhere, as evidenced by the outbreak of security breaches in 2005. Give them a grace period to comply, like Visa and MasterCard did all the other merchants, and make them stick by it.
You would think that one of the first things lawmakers would do after the recent rash of breaches would be to plug the loopholes of existing law to better protect the consumer. Just imagine that the person who took my wife’s credit card number goes to a bar for a drink on the way to the bank, and someone steals all the daily receipts. Then, multiply that possibility by thousands of transactions like this every day.
ChoicePoint, LexisNexis and other data brokers do pose a huge threat to the security of our identities. They can lose millions of personal records in one quick event—illustrated by CardSystems exposing 40 million credit cards in June of 2005—and need to be controlled to prevent this from happening. But alas, it is not likely, with either current law or the recent blitz of identity protection legislation.
Real security will be accomplished only by individual consumer control over their name and personal data.
The Pittsburgh Post-Gazette printed an article by Robin Sidel from the Wall Street Journal “Identity theft—unplugged,” that quotes some recent figures from Javelin Strategy & Research. Some 29 percent of victims in the survey said their private information was stolen when they lost their wallet, checkbook or credit card. The balance of 71 percent is attributed to someone from the outside initiating the theft.
Most privacy experts agree that a large number of ID thieves get their information from traditional, low-tech sources. Even a family member, friend…or small neighborhood merchant.
It is time to update FACTA and include all merchants, no matter who they are, and seal this big hole in the ID theft dike. In the meantime, if you must make one of these purchases, let the businessperson know that you realize your personal data could be in jeopardy.
Thursday, April 06, 2006
What's Your Name and Private (or Public) Information Worth?
As a junk mail shopper, your name could be worth around $65 to you personally on an annual basis. More or less, depending on how many times you buy. The total take each year on consumers’ names and personal data is $4 billion from junk mailers, a part of their business they would rather you know very little about. With each purchase, you have the option to check that you do not wish your name “shared” with other junk mail companies. They will never tell you that your name and private information is sold, over and over and over.
So you don’t think the $65 is enough to worry about? Then let’s put just half of that $4 billion every year in a simple interest-bearing account until you are age 65. Bingo! Retirees could supplement their retirement income with an average of $607 monthly; again, more or less, based on buying habits. Sound better? It could happen if Congress got off their duff and passed federal legislation giving you control over this data.
And that’s only the junk mailers. Your private and public information is being sold by thousands of data brokers other than ChoicePoint and LexisNexis. The SWIPE Toolkit knows this, and has come up with a great site that shows you just how much you are worth. Go to their calculator and you’ll be blown away by what you see. Click “Data Calculator” first, then, “Launch” on the left and you’re on your way.
Trying it myself, I selected address, date of birth, unpublished phone number, Social Security number, credit records, driver’s license info, and voter registration. Total: $40.25. And, that’s only one report out of thousands that are sold daily. I found the SWIPE Toolkit in a CNNMoney.com article by Jeanne Sahadi, “You want a piece of me? Pay me.” She is saying what I have been saying for the last several years, that the name-holder should have control over their name and personal data, and be compensated when it is sold.
Sahadi asked Chris Hoofnagle, “who owns this private information.” Hoofnagle, Director of the West Coast Office and Senior Counsel for Electronic Privacy Information Center, replied: “Whoever possesses it.” The EPIC has been fighting vigorously for years to protect your privacy, so you can understand the frustration in this statement.
And yet another new entry into the private information marketplace, reported by Washington Post columnist, Don Oldenburg, in his article, “Everything You Ever Knew About Yourself—for $79.95.” The company is MyPublicInfo Inc., founded in 2004 to provide personal data retrieval services for consumers. I went to mypublicinfo.com and clicked on “Sample” to see what they offer. Folks, it comes out to a list numbering fifteen pages of public and personal data items about your present-day status, as well as your past.
But, you have to give up your name, address, Social Security number, and birth date to get the report. This is the same stuff an ID thief needs to walk away with your identity. They also claim no one else can get your report—the $79.95 charged should be your best protection—and the safeguards look pretty secure. However, their database is out-sourced—there’s that word again—to a firm in California.
Oldenburg quotes Beth Givens, Founder and Director of Privacy Rights Clearinghouse as saying that access ought to be “free of charge, just like they can get their credit reports for free.” I agree, and the way to solve the whole problem is to pass federal legislation that will give consumers control over their names and private information and, at the same time, pay them when it is sold.
There, I said it again.
So you don’t think the $65 is enough to worry about? Then let’s put just half of that $4 billion every year in a simple interest-bearing account until you are age 65. Bingo! Retirees could supplement their retirement income with an average of $607 monthly; again, more or less, based on buying habits. Sound better? It could happen if Congress got off their duff and passed federal legislation giving you control over this data.
And that’s only the junk mailers. Your private and public information is being sold by thousands of data brokers other than ChoicePoint and LexisNexis. The SWIPE Toolkit knows this, and has come up with a great site that shows you just how much you are worth. Go to their calculator and you’ll be blown away by what you see. Click “Data Calculator” first, then, “Launch” on the left and you’re on your way.
Trying it myself, I selected address, date of birth, unpublished phone number, Social Security number, credit records, driver’s license info, and voter registration. Total: $40.25. And, that’s only one report out of thousands that are sold daily. I found the SWIPE Toolkit in a CNNMoney.com article by Jeanne Sahadi, “You want a piece of me? Pay me.” She is saying what I have been saying for the last several years, that the name-holder should have control over their name and personal data, and be compensated when it is sold.
Sahadi asked Chris Hoofnagle, “who owns this private information.” Hoofnagle, Director of the West Coast Office and Senior Counsel for Electronic Privacy Information Center, replied: “Whoever possesses it.” The EPIC has been fighting vigorously for years to protect your privacy, so you can understand the frustration in this statement.
And yet another new entry into the private information marketplace, reported by Washington Post columnist, Don Oldenburg, in his article, “Everything You Ever Knew About Yourself—for $79.95.” The company is MyPublicInfo Inc., founded in 2004 to provide personal data retrieval services for consumers. I went to mypublicinfo.com and clicked on “Sample” to see what they offer. Folks, it comes out to a list numbering fifteen pages of public and personal data items about your present-day status, as well as your past.
But, you have to give up your name, address, Social Security number, and birth date to get the report. This is the same stuff an ID thief needs to walk away with your identity. They also claim no one else can get your report—the $79.95 charged should be your best protection—and the safeguards look pretty secure. However, their database is out-sourced—there’s that word again—to a firm in California.
Oldenburg quotes Beth Givens, Founder and Director of Privacy Rights Clearinghouse as saying that access ought to be “free of charge, just like they can get their credit reports for free.” I agree, and the way to solve the whole problem is to pass federal legislation that will give consumers control over their names and private information and, at the same time, pay them when it is sold.
There, I said it again.
Friday, March 31, 2006
National Consumer Protection Week Has Come and Gone. Notice Any Difference?
National Consumer Protection Week was held February 5-11, and there was much hoopla over protecting you from identity theft, as well as nineteen other scams listed by the Federal Trade Commission (FTC) on its site: “’Consumer Protection: It’s the Name of the Game’ For National Consumer Protection Week 2006.” The week is sponsored by several government agencies, as well as the FTC and major consumer protection organizations.
Try the FTC’s “Grand Slam Challenge” to test your ability to recognize scams, bargains that aren’t, and simple fact or fiction questions that will keep you on your toes. I did, and it’s both interesting and entertaining.
All this fanfare over protecting your rights was going on at the same time your esteemed congressional leaders were pushing legislation in the House of Representatives that severely limits your ability to learn of personal data breaches. The House Committee on Financial Services voted 48-17 to approve a bill that lets the “breacher” (data brokers, banks, junk mail companies, etc) decide if this is necessary. That’s like leaving your cat in charge of the parakeet while you’re gone. See Declan McCullagh’s story on C/Net News.com, “Newsmaker: The politics of data security.”
This dumb bill would completely zap the provisions of the California law that caught ChoicePoint and some sixty other companies, organizations and schools in 2005 that violated the rights of 9 million consumers. Ed Mierzwinski, Consumer Program Director for Public Interest Research Group, says, with this bill, there would be no notices of data breaches because the alert level is so high.
And then I ran into a site—posted just before the consumer protection week started—from junk mail’s industry organization, the Direct Marketing Association (DMA). It tells us that we don’t have to worry about identity theft any longer. The article, “ID Fraud Growth Is Contained, Finds Better Business Bureau And Javelin Study,” is not worth linking to but here are some of the facts:
• ID fraud has declined marginally from 10.1 million people to 8.9 million
(only?)
• Average fraud amount has increased from $5,249 to $6,383 (worse, right?)
• 68% of victims suffer no loss (which means 32% do)
• Time spent fixing the fraud increased from 33 hours to 40 (more bad news)
My interpretation of these facts is that ID fraud is still full-blown, but the fraudsters are becoming more sophisticated, getting more of your money with less effort. It is ludicrous to me that an organization like the DMA would state that identity theft has been contained. Maybe it isn’t so bizarre, since a measurable percent of ID theft comes from junk mail.
You may be sick of hearing it, but there is only one answer to protecting your name and personal information. Pass federal legislation that will give you control. And while we’re at it, make the junk mailers PAY YOU every time they sell your name and private data. Please, take the time to contact your members of Congress. Here are sites that make it easy: U.S. House of Representatives and U.S. Senate. Tell them I sent you!
Try the FTC’s “Grand Slam Challenge” to test your ability to recognize scams, bargains that aren’t, and simple fact or fiction questions that will keep you on your toes. I did, and it’s both interesting and entertaining.
All this fanfare over protecting your rights was going on at the same time your esteemed congressional leaders were pushing legislation in the House of Representatives that severely limits your ability to learn of personal data breaches. The House Committee on Financial Services voted 48-17 to approve a bill that lets the “breacher” (data brokers, banks, junk mail companies, etc) decide if this is necessary. That’s like leaving your cat in charge of the parakeet while you’re gone. See Declan McCullagh’s story on C/Net News.com, “Newsmaker: The politics of data security.”
This dumb bill would completely zap the provisions of the California law that caught ChoicePoint and some sixty other companies, organizations and schools in 2005 that violated the rights of 9 million consumers. Ed Mierzwinski, Consumer Program Director for Public Interest Research Group, says, with this bill, there would be no notices of data breaches because the alert level is so high.
And then I ran into a site—posted just before the consumer protection week started—from junk mail’s industry organization, the Direct Marketing Association (DMA). It tells us that we don’t have to worry about identity theft any longer. The article, “ID Fraud Growth Is Contained, Finds Better Business Bureau And Javelin Study,” is not worth linking to but here are some of the facts:
• ID fraud has declined marginally from 10.1 million people to 8.9 million
(only?)
• Average fraud amount has increased from $5,249 to $6,383 (worse, right?)
• 68% of victims suffer no loss (which means 32% do)
• Time spent fixing the fraud increased from 33 hours to 40 (more bad news)
My interpretation of these facts is that ID fraud is still full-blown, but the fraudsters are becoming more sophisticated, getting more of your money with less effort. It is ludicrous to me that an organization like the DMA would state that identity theft has been contained. Maybe it isn’t so bizarre, since a measurable percent of ID theft comes from junk mail.
You may be sick of hearing it, but there is only one answer to protecting your name and personal information. Pass federal legislation that will give you control. And while we’re at it, make the junk mailers PAY YOU every time they sell your name and private data. Please, take the time to contact your members of Congress. Here are sites that make it easy: U.S. House of Representatives and U.S. Senate. Tell them I sent you!
Tuesday, March 28, 2006
Challenge to Junk Mail List Industry: Put Up or Shut Up
Back in 2004, I was writing op-eds on the subject of protecting individuals’ names and personal data, and submitting them to newspapers around the country with good success. As the result of one titled, “Mining the gold in our names,” appearing in the Rocky Mountain News, Tad Clarke, then Editor in Chief of junk mail industry publication, DM News, took exception with the term “junk mail.” He also called my hand on sharing this revenue with the name-holder, professing that junk mail shoppers already share in the wealth by getting lower prices. This is pure bull----!
If you add up any junk mail purchase, including shipping and handling—also a profit center with some junk mailers—you won’t save a lousy cent. You’ll actually pay more, but it is done in the name of convenience…which is OK. But don’t insult mine, or the public’s intelligence, by trying to pass off this industry fallacy that has been floated for years…that you can save money. I responded to Clarke’s editorial with my side of the story and have been richly ignored since.
When The Dunning Letter was launched in April of 2005, I had hoped to hear from any junk mail professional that agrees or disagrees with my concept that federal legislation should be passed giving consumers control over their names and private information, and pay them when it is sold. I haven’t heard from anyone. In the 35 years while selling names and personal data, it has been my position that the individual should have rights of control, and a good number of former associates know that.
Not only do I know that there are those in the business who agree with my ideas, but from experience, there are many who felt the data breach episodes of 2005 were inevitable, due to a lack of industry standards for security. But all of us were too busy making money to do anything about it. That is, until three years ago when I began my research to start The Dunning Letter, and its eventual introduction as a Blog.
So why should I care? Because it is in everyone’s interest to clean up the junk mail list industry, and I believe there are list professionals out there with stories that could help do just that. Otherwise, these list brokers and list managers are destined to lose the $4 billion annually harvested from the sale of consumers’ names and private information. The public is very angry over the identity crisis, and it is only a matter of time before tough, possibly irreversible, measures are taken.
So let’s hear it junk mailers, especially the list brokers and list managers, and tell me what you think. You can roast me at the stake or hang me in effigy, but at least give me your position on this issue of protecting consumers’ names and personal data. Tell me where I’m wrong and what you would do in this matter. You can get it off your chest and we’ll all be the better for it. Just e-mail me at jack.dundiv@cox.net and tell me what you think.
The clock is running, and there is very little time left. Your industry can survive the “junk” in junk mail, because it is a nickname associated with that 98% that ends up in the city dump. What it cannot endure is the complete loss of public confidence that will occur with continuing identity breaches.
If you add up any junk mail purchase, including shipping and handling—also a profit center with some junk mailers—you won’t save a lousy cent. You’ll actually pay more, but it is done in the name of convenience…which is OK. But don’t insult mine, or the public’s intelligence, by trying to pass off this industry fallacy that has been floated for years…that you can save money. I responded to Clarke’s editorial with my side of the story and have been richly ignored since.
When The Dunning Letter was launched in April of 2005, I had hoped to hear from any junk mail professional that agrees or disagrees with my concept that federal legislation should be passed giving consumers control over their names and private information, and pay them when it is sold. I haven’t heard from anyone. In the 35 years while selling names and personal data, it has been my position that the individual should have rights of control, and a good number of former associates know that.
Not only do I know that there are those in the business who agree with my ideas, but from experience, there are many who felt the data breach episodes of 2005 were inevitable, due to a lack of industry standards for security. But all of us were too busy making money to do anything about it. That is, until three years ago when I began my research to start The Dunning Letter, and its eventual introduction as a Blog.
So why should I care? Because it is in everyone’s interest to clean up the junk mail list industry, and I believe there are list professionals out there with stories that could help do just that. Otherwise, these list brokers and list managers are destined to lose the $4 billion annually harvested from the sale of consumers’ names and private information. The public is very angry over the identity crisis, and it is only a matter of time before tough, possibly irreversible, measures are taken.
So let’s hear it junk mailers, especially the list brokers and list managers, and tell me what you think. You can roast me at the stake or hang me in effigy, but at least give me your position on this issue of protecting consumers’ names and personal data. Tell me where I’m wrong and what you would do in this matter. You can get it off your chest and we’ll all be the better for it. Just e-mail me at jack.dundiv@cox.net and tell me what you think.
The clock is running, and there is very little time left. Your industry can survive the “junk” in junk mail, because it is a nickname associated with that 98% that ends up in the city dump. What it cannot endure is the complete loss of public confidence that will occur with continuing identity breaches.
Friday, March 24, 2006
More on the IRS Selling Your Financial Data
Did you know that in large tax preparer franchises, that anyone in the organization has unrestricted access to your tax records? They do. Are you aware that many tax professionals outsource your tax preparation to contractors overseas? They do. It’s also a fact that smaller companies do not have the electronic capabilities to complete your returns and must use outside computer facilities.
In other words, your income tax data is all over the place just like your name and other private information. Read about it in William Perez’ article in About.com: “IRS Issues Proposed Regulations to Safeguard Taxpayer’s Privacy.” Perez mentions even more participants in the laying open of your financial life, which are banks, loan companies, and investment firms, that partner with the tax pros.
So now they want to open the door to marketing your financial data in the same way they sell lists like Sharper Image, LL Bean, Coldwater Creek, Brookstone and thousands of other mailing lists on the market. And you know who’s standing in line to confiscate your name and all the goodies that go with it? Five hundred list managers and several data brokers that will compete for the right to hawk 295 million tax returns to whoever has the money to buy them.
This will provide a generous increase to the $4 billion already made from your names and private information each year. And…not one penny goes into your pocket. If that doesn’t gall you, it should. Restraint is called for now more than ever, and it can be accomplished by the passing of federal legislation that will give the individual control over their name and personal data, and paying them when it is sold.
Rep. Ed Markey of Massachusetts, a Democrat, along with some other congressional leaders, apparently opened this can of worms by voicing his concern over the outsourcing of tax preparation services to IRS Commissioner, Mark Everson. Markey now seems satisfied with Everson’s regulations allowing the sale of your financial data, which is another strike against the Democratic Party.
Please tell me. How did we end up with the dimwitted notion that it is realistic to place some of the consumer’s most private information in harm’s way, after over 100 data breaches in 2005, affecting 56 million people, at a cost of $47.5 billion? And the beat goes on in 2006 with at least 10 breaches already. I’ll tell you how. The current trend by the GOP to shove as much action toward the business community that it can, protect the banking industry and the consumer be damned. Read another good piece in OpEdNews.com by Douglas Drenkow: “Backed by Big Money, Congress May Gut Identity Theft Laws.”
Two of the largest tax preparers have been involved in legal action over how they handle personal data. H&R Block is being sued by New York State Attorney General Eliot Spitzer for fraudulently marketing retirement savings plans to its customers that caused heavy financial losses. See the Reuters article on MSNBC.com, “New York charges H&R Block with fraud.” The company admits another breach in Kansas City, in an Associated Press piece, “H&R Block acknowledges privacy breach,” again, on MSNBC.com. Get this: they put the recipients Social Security number on the mail out label for software that was being sent.
As an example of general ethics, another biggie in the tax preparation business, Jackson Hewitt, had a manager of one of its locations in Michigan sentenced to 18 months in prison, followed by three years of supervised release, and ordered to pay $231,053 in restitution. Also in Michigan, a second JH manager sent up for 30 months plus three years supervision, and had to pay $229,805. Each was convicted of conspiracy to defraud the IRS by inflating the refunds of clients. You can read about this on the IRS site: “Tax Return Preparer Fraud.”
The consumer does have to give their consent for tax preparers to sell their financial data. A move that I, as a list expert in the junk mail industry for over 35 years, would consider insane. Haven’t we already lost too much control over our personal data? The public hearing on this issue is being held April 4. All I can say is I wish I could be there.
In other words, your income tax data is all over the place just like your name and other private information. Read about it in William Perez’ article in About.com: “IRS Issues Proposed Regulations to Safeguard Taxpayer’s Privacy.” Perez mentions even more participants in the laying open of your financial life, which are banks, loan companies, and investment firms, that partner with the tax pros.
So now they want to open the door to marketing your financial data in the same way they sell lists like Sharper Image, LL Bean, Coldwater Creek, Brookstone and thousands of other mailing lists on the market. And you know who’s standing in line to confiscate your name and all the goodies that go with it? Five hundred list managers and several data brokers that will compete for the right to hawk 295 million tax returns to whoever has the money to buy them.
This will provide a generous increase to the $4 billion already made from your names and private information each year. And…not one penny goes into your pocket. If that doesn’t gall you, it should. Restraint is called for now more than ever, and it can be accomplished by the passing of federal legislation that will give the individual control over their name and personal data, and paying them when it is sold.
Rep. Ed Markey of Massachusetts, a Democrat, along with some other congressional leaders, apparently opened this can of worms by voicing his concern over the outsourcing of tax preparation services to IRS Commissioner, Mark Everson. Markey now seems satisfied with Everson’s regulations allowing the sale of your financial data, which is another strike against the Democratic Party.
Please tell me. How did we end up with the dimwitted notion that it is realistic to place some of the consumer’s most private information in harm’s way, after over 100 data breaches in 2005, affecting 56 million people, at a cost of $47.5 billion? And the beat goes on in 2006 with at least 10 breaches already. I’ll tell you how. The current trend by the GOP to shove as much action toward the business community that it can, protect the banking industry and the consumer be damned. Read another good piece in OpEdNews.com by Douglas Drenkow: “Backed by Big Money, Congress May Gut Identity Theft Laws.”
Two of the largest tax preparers have been involved in legal action over how they handle personal data. H&R Block is being sued by New York State Attorney General Eliot Spitzer for fraudulently marketing retirement savings plans to its customers that caused heavy financial losses. See the Reuters article on MSNBC.com, “New York charges H&R Block with fraud.” The company admits another breach in Kansas City, in an Associated Press piece, “H&R Block acknowledges privacy breach,” again, on MSNBC.com. Get this: they put the recipients Social Security number on the mail out label for software that was being sent.
As an example of general ethics, another biggie in the tax preparation business, Jackson Hewitt, had a manager of one of its locations in Michigan sentenced to 18 months in prison, followed by three years of supervised release, and ordered to pay $231,053 in restitution. Also in Michigan, a second JH manager sent up for 30 months plus three years supervision, and had to pay $229,805. Each was convicted of conspiracy to defraud the IRS by inflating the refunds of clients. You can read about this on the IRS site: “Tax Return Preparer Fraud.”
The consumer does have to give their consent for tax preparers to sell their financial data. A move that I, as a list expert in the junk mail industry for over 35 years, would consider insane. Haven’t we already lost too much control over our personal data? The public hearing on this issue is being held April 4. All I can say is I wish I could be there.
Tuesday, March 21, 2006
Now, Even the IRS Wants to Sell Your Financial Data
Even I can’t believe this, and the past year has been full of surprises. The Internal Revenue Service has decided it should get in the business of selling your name and private information. Not directly, you understand, but to authorize every tax preparer in the country to do so. The IRS is proposing to allow tax preparers to sell the very data you provide them to do your taxes. The stuff we all thought was sacred until now.
Mind you, there have been situations in the past when certain tax information was released, but primarily for legal reasons, not for mass marketing. This is blatant government irresponsibility in the handling of perhaps one of your most personal assets. Sure, the preparer has to get your consent, but this reeks of the days when junk mailers were forced to bury that now infamous phrase in their sales pitches: we may share your name with other (junk) mailers… They don’t even have the guts to say “sell.”
In a ConsumerAffairs.com article by Martin Bosworth, he remarks that H&R Block could sell your tax return information to data brokers such as ChoicePoint, who in turn could sell it to anyone with the ability to buy. Or, as we have observed, lose it to an ID thief (my comment). Bosworth continues with a statement by Ed Mierzwinski from Public Interest Research Group: (this is) “…the same IRS that let Richard Nixon and many other Presidents run roughshod over the privacy of ordinary American citizens…”
Kathleen Pender, in the San Francisco Chronicle, makes an interesting observation: “The IRS, with a straight face, says the existing prohibitions against sharing (there’s that killer word again) confidential data with outside parties ‘restrict the ability of taxpayers to control and direct the use of their own tax return information as they see fit.’” The consent form, which is supposed to be separate from all other material, also has a “disclaimer.” It specifies that the tax preparer has no control over your name and personal data once it is in the hands of the third party—ChoicePoint, etc. Isn’t that comforting?
Jeanne Sahadi, in a piece on CNNMoney.com, says: “You want a piece of me? Pay me.” This is the position everyone should take in the selling of their name and private information. However, if you took legal ownership of your name, you’d probably bargain it away for freebies like cable or other services, according to Chris Hoofnagle of the Electronic Privacy Information Center. He also feels that, at the present time, whoever possesses your personal data, owns it.
And that’s why we must pass federal legislation that will give consumers control over their names and private information, and, while we’re at it, pay them whenever it is sold. Sahadi agrees and cautions taxpayers further: even though the IRS regulations are not final, tax preparers could ask your consent, anticipating this potential windfall. Be aware!
More in my next Post on this issue, including the “biggies” of tax preparation like H&R Block and Jackson Hewitt, the IRS Commissioner, Mark W. Everson’s part in this new regulation, and the junk mail list people now standing in line to sell your financial data found in this new treasure trove.
Mind you, there have been situations in the past when certain tax information was released, but primarily for legal reasons, not for mass marketing. This is blatant government irresponsibility in the handling of perhaps one of your most personal assets. Sure, the preparer has to get your consent, but this reeks of the days when junk mailers were forced to bury that now infamous phrase in their sales pitches: we may share your name with other (junk) mailers… They don’t even have the guts to say “sell.”
In a ConsumerAffairs.com article by Martin Bosworth, he remarks that H&R Block could sell your tax return information to data brokers such as ChoicePoint, who in turn could sell it to anyone with the ability to buy. Or, as we have observed, lose it to an ID thief (my comment). Bosworth continues with a statement by Ed Mierzwinski from Public Interest Research Group: (this is) “…the same IRS that let Richard Nixon and many other Presidents run roughshod over the privacy of ordinary American citizens…”
Kathleen Pender, in the San Francisco Chronicle, makes an interesting observation: “The IRS, with a straight face, says the existing prohibitions against sharing (there’s that killer word again) confidential data with outside parties ‘restrict the ability of taxpayers to control and direct the use of their own tax return information as they see fit.’” The consent form, which is supposed to be separate from all other material, also has a “disclaimer.” It specifies that the tax preparer has no control over your name and personal data once it is in the hands of the third party—ChoicePoint, etc. Isn’t that comforting?
Jeanne Sahadi, in a piece on CNNMoney.com, says: “You want a piece of me? Pay me.” This is the position everyone should take in the selling of their name and private information. However, if you took legal ownership of your name, you’d probably bargain it away for freebies like cable or other services, according to Chris Hoofnagle of the Electronic Privacy Information Center. He also feels that, at the present time, whoever possesses your personal data, owns it.
And that’s why we must pass federal legislation that will give consumers control over their names and private information, and, while we’re at it, pay them whenever it is sold. Sahadi agrees and cautions taxpayers further: even though the IRS regulations are not final, tax preparers could ask your consent, anticipating this potential windfall. Be aware!
More in my next Post on this issue, including the “biggies” of tax preparation like H&R Block and Jackson Hewitt, the IRS Commissioner, Mark W. Everson’s part in this new regulation, and the junk mail list people now standing in line to sell your financial data found in this new treasure trove.
Thursday, March 16, 2006
Statistics Are Boring...Unless They're Yours
When statistical surveys are taken, they use a cross-section of the U.S. to determine the probable answers to certain questions. Based on the replies from this random sampling, public opinion is measured, and conclusions drawn on issues such as privacy. The results are designed to represent the average “you,” the consumer…so, this post is directed to that happy medium.
The reason I bring all this up are two surveys I ran into recently; one re. government’s priority for your privacy, the other the same, but for business. The results are so startling—actually horrifying—that I decided to dig further to resolve just how “you” react to this shabby treatment. But first, how business and government go about protecting your name and personal data.
In a recent Chief Information Officer (CIO) study, federal agencies don’t care about your privacy unless they are forced to by bad publicity. In an article from GovExec.com, “Survey: Agency programs to protect privacy inadequate,” by Daniel Pulliam, he remarks, “…privacy programs are slipping through the cracks and fewer agencies treat them as a priority…” The respondents were top federal CIO’s, one of which stated the law governing IT security, the “2002 Federal Information Security Management Act,” isn’t worth the paper it’s written on.
Business didn’t fare any better. Some excerpts from a series of pieces done by Chief Security Officer Online: only 80 % have privacy or data protection strategy; 38 % believe their resources couldn’t adequately manage the privacy of your personal data; only 31 % are prepared to notify you in case of a breach. /MORE/ Privacy Rights Clearinghouse (PRC) reports that 61 U.S. companies experienced breaches of your private information in just the first half of 2005. /MORE/ A report by the Annenberg Public Policy Center found that 65 % of you feel secure online and 75 % believe that a website’s privacy policy translates to the fact they will not share your personal data. Both, of course, are incorrect assumptions. /MORE/
If you are hooked on numbers, go to Privacy Rights Clearinghouse (PRC), and Electronic Privacy Information Center (EPIC) for a collection of surveys and statistics on privacy-related matters that are unsurpassed, as far as I am concerned. And now, some of the many faces of “you.”
Over 9 million of you were victims of identity fraud in 2005, which was down from 2003, according to Javelin Research. However, what it cost you and the time to fix it, did go up. That means the crooks are getting more sophisticated.
The balance of statistics is listed in chronological order with the newest first. According to the Washington Post in January of 2006, 64 % of you thought federal agencies were intruding on your privacy rights in investigating terrorism, with 44% concerned that Bush would exceed his limits in order to investigate terrorism.
A whopping 32% placed your personal privacy above investigating possible terrorist threats… recruits for my new independent party based on privacy! In another Annenberg survey, an alarming number of you have false beliefs over the safety of your private information in the marketplace.
A Harris Poll found that 35% of you have “very high privacy concerns,” and 79% feel it is extremely important that the personal data collected on you is controlled. According to the American Society of Newspaper Editors, a majority of you are concerned that business and government would violate your privacy. The same study showed that another 52% of you have “very little” or “no confidence at all” that business uses your private information properly.
Eighty-nine percent of you are concerned about privacy, and 54% want Congress to pass legislation to protect your personal data. The statistics go on, but this is decidedly the place to end this post.
Join with me to get that federal legislation passed that will give you control over your private information, and will also pay you when it is sold. Write or e-mail your congressional representatives, send letters to your newspaper’s editorial page, call local TV and talk radio, and tell them all you aren’t going to take it anymore. And, of course…be sure to tell them I sent you!
The reason I bring all this up are two surveys I ran into recently; one re. government’s priority for your privacy, the other the same, but for business. The results are so startling—actually horrifying—that I decided to dig further to resolve just how “you” react to this shabby treatment. But first, how business and government go about protecting your name and personal data.
In a recent Chief Information Officer (CIO) study, federal agencies don’t care about your privacy unless they are forced to by bad publicity. In an article from GovExec.com, “Survey: Agency programs to protect privacy inadequate,” by Daniel Pulliam, he remarks, “…privacy programs are slipping through the cracks and fewer agencies treat them as a priority…” The respondents were top federal CIO’s, one of which stated the law governing IT security, the “2002 Federal Information Security Management Act,” isn’t worth the paper it’s written on.
Business didn’t fare any better. Some excerpts from a series of pieces done by Chief Security Officer Online: only 80 % have privacy or data protection strategy; 38 % believe their resources couldn’t adequately manage the privacy of your personal data; only 31 % are prepared to notify you in case of a breach. /MORE/ Privacy Rights Clearinghouse (PRC) reports that 61 U.S. companies experienced breaches of your private information in just the first half of 2005. /MORE/ A report by the Annenberg Public Policy Center found that 65 % of you feel secure online and 75 % believe that a website’s privacy policy translates to the fact they will not share your personal data. Both, of course, are incorrect assumptions. /MORE/
If you are hooked on numbers, go to Privacy Rights Clearinghouse (PRC), and Electronic Privacy Information Center (EPIC) for a collection of surveys and statistics on privacy-related matters that are unsurpassed, as far as I am concerned. And now, some of the many faces of “you.”
Over 9 million of you were victims of identity fraud in 2005, which was down from 2003, according to Javelin Research. However, what it cost you and the time to fix it, did go up. That means the crooks are getting more sophisticated.
The balance of statistics is listed in chronological order with the newest first. According to the Washington Post in January of 2006, 64 % of you thought federal agencies were intruding on your privacy rights in investigating terrorism, with 44% concerned that Bush would exceed his limits in order to investigate terrorism.
A whopping 32% placed your personal privacy above investigating possible terrorist threats… recruits for my new independent party based on privacy! In another Annenberg survey, an alarming number of you have false beliefs over the safety of your private information in the marketplace.
A Harris Poll found that 35% of you have “very high privacy concerns,” and 79% feel it is extremely important that the personal data collected on you is controlled. According to the American Society of Newspaper Editors, a majority of you are concerned that business and government would violate your privacy. The same study showed that another 52% of you have “very little” or “no confidence at all” that business uses your private information properly.
Eighty-nine percent of you are concerned about privacy, and 54% want Congress to pass legislation to protect your personal data. The statistics go on, but this is decidedly the place to end this post.
Join with me to get that federal legislation passed that will give you control over your private information, and will also pay you when it is sold. Write or e-mail your congressional representatives, send letters to your newspaper’s editorial page, call local TV and talk radio, and tell them all you aren’t going to take it anymore. And, of course…be sure to tell them I sent you!
Tuesday, March 14, 2006
Protection Against the Protection
When you Google “ID theft prevention,” you get 6.9 million sites, some of which are selling you protection, others offer it free. You know they are going to come out of the woodwork when there is a buck to be made. I am not saying you shouldn’t buy this service, because some of us are too lazy, or just do not have the time, to watch over our identity. It does require some effort, and if you want to take charge of this most valuable asset, go to Privacy Rights Clearinghouse for some of the best information available on the subject. It’s free.
If you’re thinking of purchasing protection, there is a good article on Marketwatch.com, “No sure-fire cure/Many products fight ID theft, but none fully prevent it,” by Andrea Coombes. The key here is, none of these services, nor any of the free advice, good as it might be, is 100% guaranteed. Neither is the plethora of identity theft bills currently proposed in Congress. It is all designed to help guard against the possibility of ID theft, or to clean up the situation once it has occurred. Not good enough, in my book.
This is my mandate for solving the identity crisis once and for all. Pass federal legislation to give the individual control over their name and personal data, and, while we’re at it, pay them when it is sold. If you visit this Blog with any regularity, you’ve heard this many times, and if you continue to come back, you’ll keep hearing it. That is…until we get the federal legislation passed.
You might want to check the article, “The ID theft protection racket,” on CNNMoney.com, by Pat Regnier. Sub-headline: “It could get you killed.” It chronicles a stolen identity where the perp ends up in the hospital with the victim’s name, and this data ends up at the Medical Information Bureau (MIB), the vast storehouse of your past health issues. The scenario goes on to show how, if you then went to the hospital, and the perp’s MIB info shows you have heart trouble, they could kill you. Very possible, since I once ended up in the MIB as deceased, and was denied life insurance.
Regnier mentions some elite of the financial community, “…hawking services designed to protect you from the threat.” They include American Express, Chase, Citi, Discover and MBNA, and this household has received offers from all of them. Then Regnier gets right to the point: “Privacy advocates complain that ID protection is often sold by the very companies that have contributed to the problem.”
And, of course, there’s ID theft insurance, covered in another CNN Money.com piece by Regnier, titled, “ID insurance? Who needs this stuff?” Although it doesn’t reimburse you for the stolen money, you can get up to $2,000 for attorney fees and lost wages. Other options are to check if your homeowner’s insurance covers this, and, of course, you should get your free annual credit report.
Some of these paid services are just not worth it. However, if you are one of the lazy ones, or simply too busy to deal with this and have the money to let someone else do it, just be careful with whom you sign up. Read the fine print and make sure it is the plan that fits your needs. And, don’t buy something you do not need. Remember the old reliable axiom, if it looks too good to be true, it probably is. It applies here…more than ever.
If you’re thinking of purchasing protection, there is a good article on Marketwatch.com, “No sure-fire cure/Many products fight ID theft, but none fully prevent it,” by Andrea Coombes. The key here is, none of these services, nor any of the free advice, good as it might be, is 100% guaranteed. Neither is the plethora of identity theft bills currently proposed in Congress. It is all designed to help guard against the possibility of ID theft, or to clean up the situation once it has occurred. Not good enough, in my book.
This is my mandate for solving the identity crisis once and for all. Pass federal legislation to give the individual control over their name and personal data, and, while we’re at it, pay them when it is sold. If you visit this Blog with any regularity, you’ve heard this many times, and if you continue to come back, you’ll keep hearing it. That is…until we get the federal legislation passed.
You might want to check the article, “The ID theft protection racket,” on CNNMoney.com, by Pat Regnier. Sub-headline: “It could get you killed.” It chronicles a stolen identity where the perp ends up in the hospital with the victim’s name, and this data ends up at the Medical Information Bureau (MIB), the vast storehouse of your past health issues. The scenario goes on to show how, if you then went to the hospital, and the perp’s MIB info shows you have heart trouble, they could kill you. Very possible, since I once ended up in the MIB as deceased, and was denied life insurance.
Regnier mentions some elite of the financial community, “…hawking services designed to protect you from the threat.” They include American Express, Chase, Citi, Discover and MBNA, and this household has received offers from all of them. Then Regnier gets right to the point: “Privacy advocates complain that ID protection is often sold by the very companies that have contributed to the problem.”
And, of course, there’s ID theft insurance, covered in another CNN Money.com piece by Regnier, titled, “ID insurance? Who needs this stuff?” Although it doesn’t reimburse you for the stolen money, you can get up to $2,000 for attorney fees and lost wages. Other options are to check if your homeowner’s insurance covers this, and, of course, you should get your free annual credit report.
Some of these paid services are just not worth it. However, if you are one of the lazy ones, or simply too busy to deal with this and have the money to let someone else do it, just be careful with whom you sign up. Read the fine print and make sure it is the plan that fits your needs. And, don’t buy something you do not need. Remember the old reliable axiom, if it looks too good to be true, it probably is. It applies here…more than ever.
Subscribe to:
Posts (Atom)
