I spent the weekend researching data removal methods and decided to start with my credit report. I’m not even going to get into all of the alarming privacy invasions that popped up during this process. But when I got to the experian report, I was met with T&C box that says I have to hand over my phone carrier info and it wouldn’t let me proceed without doing so. The bureaus are legally required to give you one free report a year. It’s bad enough that these companies are even given rights to my data and now they’re using it to request further information.

I’m just so angry, frustrated, and violated.

-8 points
*

Try GDPR them. Fuck their form.

permalink
report
reply
1 point

German democracy volk republic?!

permalink
report
parent
reply
12 points

Why would a US credit agency care about the GDPR?

permalink
report
parent
reply
4 points

I wonder if it affects them if they are collecting purchasing data from US citizens residing in the EU. If nothing else, the US military and diplomats are there. From what I’ve found, it protects anyone in the EU, citizen or not.

permalink
report
parent
reply
4 points

Us corporate doesn’t follow domestic law, cute of you to assume they would follow a foreign country’s laws.

permalink
report
parent
reply
5 points

No applicable here, like at all

permalink
report
parent
reply
13 points

I’m not really sure what you expect to be able to do with your credit report, but you should request it through https://www.annualcreditreport.com/. That’s the legit source.

permalink
report
reply
14 points

This happened on annualcreditreport.com.

permalink
report
parent
reply
-14 points

Don’t use credit.

permalink
report
reply
4 points

Good luck with that in the US. Credit is like a shitty pay to win scheme that you’re required to play. Some jobs check your credit report and unless you have cash to buy a house you’d be fucked without credit.

permalink
report
parent
reply
5 points

That may be viable for some combinations of finances and lifestyle, but credit scores are used in interactions that don’t involve borrowing money. I’m inclined to believer they shouldn’t be, but I don’t make the rules.

permalink
report
parent
reply
11 points

Good luck with that.

permalink
report
parent
reply
41 points

guessing they’re using the carrier’s data for verification. name, address, phone number, socials and at least partials of credit cards, bank accounts. whatever relevant that they have.

this is all data the credit bureau has on you already

permalink
report
reply
1 point
Deleted by creator
permalink
report
parent
reply
6 points

I’ve run into issues with SMS-based 2FA (yikes) on some websites because my phone number was a landline number I purchased then later transferred to my wireless carrier.

I bring this up because I’ve noticed some websites have the typical “we’ll confirm your information with your wireless carrier” verbiage, but those generally mention they do so to determine whether the number is a landline or wireless.

I’m super unsure of what’s going on in this case, but when I first saw this screenshot this is what came to mind.

permalink
report
parent
reply
9 points

Experian is stuck on an old phone number for 2FA and I can’t remove it because I don’t have a phone number. I really hate how they tie everything to a phone number.

permalink
report
parent
reply
5 points

I really hate how they tie everything to a phone number.

The online social security

permalink
report
parent
reply
3 points

Me too, and it’s worse because it’s not secure.

I keep saying this a lot but I don’t know why recently (the last ~5 years) everyone is jumping on SMS-based 2FA. I remember this was really big around 2010 and as a developer all the tools for SMS-based 2FA are deprecated or unmaintained. It seems like all these websites that jumped on board 10 years late have very poor security practices.

permalink
report
parent
reply
11 points

Can confirm, it is information they already have. Below is likely the API the telco exposes to the bureau. Each data point queried returns true, false, or a confidence score.

It is intended as an anti-fraud tool. Not saying I agree with it. Something like PGP is sufficient for building out a web-of-trust without needing to share my personal information.

https://redocly.github.io/redoc/?url=https://raw.githubusercontent.com/camaraproject/KnowYourCustomer/r1.4/code/API_definitions/kyc-match.yaml&nocors#tag/Match/operation/KYC_Match

permalink
report
parent
reply
1 point

Please stop with the defiling of the word ‘Fraud’. Fraud does not mean someone who claims ownership of their own identity. A $20 billion dollar association missing a handful of verified data points on someone’s life doesn’t constitute fraud. We’re talking about a corporation whose whole market is based on repurposing the data they collect about us. So if you’re going to make an inference as to their intention, assume it’s the one they have had since 1970. To gather more information about the public for profit and control.

permalink
report
parent
reply
1 point

It’s not, or they wouldn’t need to request my explicit permission to obtain it. You don’t need to guess what it’s for because we know that credit “bureaus” exist to profile “consumers” and sell their information, whether aggregate or personal. They’re asking to gain access to my carrier account and my device information. This is about data inventory. The credit bureaus know who has it and want permission to buy it from them.

permalink
report
parent
reply
-4 points

time to look up some alternatives.

permalink
report
reply
5 points

There are no alternatives to the credit bureaus for your credit report.

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 6.5K

    Monthly active users

  • 3.1K

    Posts

  • 84K

    Comments