Harm:

Identity Theft

Definition: Stealing credentials or other personal information, typically for financial impersonation.
Motivation:
Financial
Legal Status:
Almost always illegal
Platform ToS:
Violates Policy
Victim Visibility:
Aware
Classification:
Contextually Sensitive
TSPA Abuse Type:
Deceptive & Fraudulent Behavior: Impersonation

As repositories of personal information, platforms are often core tools used to facilitate identity theft, since malicious users can use publicly accessible information to divine a huge volume of information about someone's preferences, habits, relationships, and assets.  These can often be used in concert to make impersonating a real person much easier in customer-support contexts, to guess passwords, or to abuse account recovery tools, typically toward financially motivated aims. Platforms have a role to play in limiting this form of abuse - particularly in how they handle sensitive data by default, and the audience that they expose potentially sensitive data.

In other cases where the platform identity can itself be of financial value, a user's on platform identity can be targeted for theft. Platforms can secure users' on-platform identities by encouraging (or requiring) them to take steps that make taking over a user's account more challenging, including a variety of mechanisms that make their authentication process more secure, or prevent them from utilizing poor security practices. 

What features facilitate Identity Theft?

Identity
Individuals' ability to represent themselves in a digital space.

How can platform design prevent Identity Theft?

Identity Verification
Require users to register for an application with a state issued identity document.
Two-Factor Authentication
Authenticating users through two types of credentials (something you have, something you know, something you are).
Require unleaked passwords
During signup, don't allow users to use a password that has been included in a leaked dataset.
Use an OAuth Provider
Centralize identity management + risk with a company that thinks about it full time.
Is something missing, or could it be better?
Loading...