WEBVTT

00:00:00.000 --> 00:00:02.899
We are diving deep into one of the most powerful,

00:00:03.040 --> 00:00:05.980
yet often misunderstood, tools available to protect

00:00:05.980 --> 00:00:08.800
your financial identity. The credit freeze. It's

00:00:08.800 --> 00:00:10.699
a tool that so many people have heard of, but

00:00:10.699 --> 00:00:13.539
maybe don't fully grasp. Exactly. And today our

00:00:13.539 --> 00:00:15.980
mission is to deliver a complete breakdown of

00:00:15.980 --> 00:00:18.699
this security mechanism. We'll trace its evolution,

00:00:18.920 --> 00:00:21.460
you know, from this fragmented patchwork of state

00:00:21.460 --> 00:00:24.460
laws all the way to a unified, mandatory federal

00:00:24.460 --> 00:00:26.579
standard. And we're going to drill down into

00:00:26.579 --> 00:00:30.190
why experts consistently laud it as... Really,

00:00:30.250 --> 00:00:33.490
the single most effective defense against a specific

00:00:33.490 --> 00:00:36.770
and incredibly damaging type of financial crime.

00:00:37.090 --> 00:00:39.409
It's a vital exploration. I mean, when you just

00:00:39.409 --> 00:00:41.929
consider the sheer scale of global data breaches

00:00:41.929 --> 00:00:44.530
these days, it feels like everyone's information

00:00:44.530 --> 00:00:46.570
is already out there. Well, that's just it. The

00:00:46.570 --> 00:00:49.270
credit freeze, or to use its formal name, a security

00:00:49.270 --> 00:00:51.609
freeze, it represents a fundamental shift in

00:00:51.609 --> 00:00:54.409
control. For way too long, consumer reporting

00:00:54.409 --> 00:00:57.009
agencies managed our data largely on their own

00:00:57.009 --> 00:00:59.859
terms. The freeze is the tool that puts you,

00:00:59.920 --> 00:01:02.259
the individual, back in the driver's seat. Right.

00:01:02.340 --> 00:01:04.659
It lets you voluntarily lock down your own personal

00:01:04.659 --> 00:01:06.900
financial identity data. It's your hand on the

00:01:06.900 --> 00:01:09.019
switch. So when we use that phrase credit freeze,

00:01:09.200 --> 00:01:11.400
what we're really defining is the mechanism where

00:01:11.400 --> 00:01:14.439
you, the consumer, get the power to directly

00:01:14.439 --> 00:01:17.799
restrict how a consumer reporting agency, a CRA,

00:01:18.060 --> 00:01:21.540
can sell or distribute your private sensitive

00:01:21.540 --> 00:01:24.519
data. And it's not just a pause button. I think

00:01:24.519 --> 00:01:26.819
that's a common misconception. No, it's not a

00:01:26.819 --> 00:01:29.640
pause. It's an active voluntary lockdown. It's

00:01:29.640 --> 00:01:31.939
like you're choosing to build a wall around your

00:01:31.939 --> 00:01:34.219
financial history. And to really understand the

00:01:34.219 --> 00:01:36.819
scope of this protection, you have to recognize

00:01:36.819 --> 00:01:39.680
the major players that are holding this information

00:01:39.680 --> 00:01:42.640
in the first place. When we refer to CRAs, we're

00:01:42.640 --> 00:01:45.659
talking about the institutions that compile and

00:01:45.659 --> 00:01:50.250
curate that data profile that basically. dictates

00:01:50.250 --> 00:01:51.930
your access to credit. We're talking about the

00:01:51.930 --> 00:01:54.489
big ones everyone knows. Yes. So that means Equifax,

00:01:54.569 --> 00:01:58.069
Experian, TransUnion, and also the often overlooked

00:01:58.069 --> 00:02:01.409
fourth agency, Inovus. A really complete security

00:02:01.409 --> 00:02:03.650
strategy has to engage with all four of them.

00:02:03.750 --> 00:02:06.909
All four. And the beauty of the mechanism really

00:02:06.909 --> 00:02:10.669
lies in its simplicity. The whole concept is

00:02:10.669 --> 00:02:13.189
that the freeze literally locks the data at the

00:02:13.189 --> 00:02:16.099
CRA. It just stays locked. Totally inaccessible

00:02:16.099 --> 00:02:19.039
until you, the individual who owns that identity,

00:02:19.219 --> 00:02:22.120
provide explicit, clear permission for its release.

00:02:22.360 --> 00:02:24.659
Without your green light, without your authorization,

00:02:25.000 --> 00:02:27.599
there was just no access. Full stop. And that

00:02:27.599 --> 00:02:30.219
simple act is the foundation for everything we're

00:02:30.219 --> 00:02:32.379
going to discuss today. That lock mechanism really

00:02:32.379 --> 00:02:35.259
is the game changer. It completely shifts the

00:02:35.259 --> 00:02:38.770
consumer stance from being reactive. scrambling

00:02:38.770 --> 00:02:40.830
to repair the damage after your data is stolen

00:02:40.830 --> 00:02:43.750
to being proactively protected. It's an advance

00:02:43.750 --> 00:02:46.449
guard rather than a cleanup crew. Exactly. Now

00:02:46.449 --> 00:02:48.349
that we understand the goal, let's dissect the

00:02:48.349 --> 00:02:50.509
mechanism itself. We need to look critically

00:02:50.509 --> 00:02:52.969
at what this lockdown does and maybe even more

00:02:52.969 --> 00:02:55.210
importantly, what critical financial activities

00:02:55.210 --> 00:02:57.189
it doesn't stop because those distinctions are

00:02:57.189 --> 00:02:59.990
absolutely key to using it effectively. That's

00:02:59.990 --> 00:03:01.870
the critical pivot point in this discussion,

00:03:01.969 --> 00:03:04.490
I think. We have to start by understanding the

00:03:04.490 --> 00:03:07.509
specific target of the freeze. It is not, as

00:03:07.509 --> 00:03:10.110
many people believe, some kind of universal shield

00:03:10.110 --> 00:03:12.750
against all types of identity theft. No, it's

00:03:12.750 --> 00:03:15.110
not a silver bullet. Not at all. It's a highly

00:03:15.110 --> 00:03:18.169
focused, highly effective weapon against one

00:03:18.169 --> 00:03:21.009
particular vulnerability. Right. So its primary

00:03:21.009 --> 00:03:23.430
function is preventing financial identity theft.

00:03:23.979 --> 00:03:25.939
But let's use the specific language because it

00:03:25.939 --> 00:03:28.120
matters. The Federal Trade Commission calls it

00:03:28.120 --> 00:03:31.439
new account origination identity theft. And this

00:03:31.439 --> 00:03:35.199
is the kind of fraud that causes just massive

00:03:35.199 --> 00:03:37.939
immediate financial trauma. Think about the scenario

00:03:37.939 --> 00:03:40.400
for a second. A criminal gets just enough of

00:03:40.400 --> 00:03:42.979
your personal identifiers, your name, your date

00:03:42.979 --> 00:03:45.699
of birth, social security number from some data

00:03:45.699 --> 00:03:48.219
breach. The basics. The basics. Then they go

00:03:48.219 --> 00:03:50.699
to an online bank or an auto dealership or they

00:03:50.699 --> 00:03:52.900
apply for a major credit card. They're applying

00:03:52.900 --> 00:03:55.280
for a brand new line of credit entirely in your

00:03:55.280 --> 00:03:57.039
name. And of course, they get the funds or the

00:03:57.039 --> 00:03:59.240
card. They vanish instantly. And the initial

00:03:59.240 --> 00:04:01.159
massive debt and all the subsequent collections

00:04:01.159 --> 00:04:04.620
calls, they fall squarely on you, the victim.

00:04:04.819 --> 00:04:08.000
And this is precisely where the credit freeze

00:04:08.000 --> 00:04:11.110
becomes that ultimate. impenetrable block so

00:04:11.110 --> 00:04:13.150
to explain why it works we have to remember the

00:04:13.150 --> 00:04:16.189
fundamental process of lending when a lender

00:04:16.189 --> 00:04:18.629
gets an application for any new credit doesn't

00:04:18.629 --> 00:04:20.129
matter if it's a mortgage or just a department

00:04:20.129 --> 00:04:24.000
store card they must access a credit report That

00:04:24.000 --> 00:04:26.680
report is the central source of truth they use

00:04:26.680 --> 00:04:28.879
to determine the applicant's risk. It's the whole

00:04:28.879 --> 00:04:31.600
underwriting process. That's it. Underwriting

00:04:31.600 --> 00:04:34.360
is built on risk assessment. So if a lender cannot

00:04:34.360 --> 00:04:36.920
pull a credit report from one of the major CRAs,

00:04:36.920 --> 00:04:39.279
they simply cannot complete their due diligence.

00:04:39.339 --> 00:04:41.500
They can't calculate risk. And legally, they

00:04:41.500 --> 00:04:43.300
cannot move forward with the credit application.

00:04:43.660 --> 00:04:46.379
The application just stops dead in its tracks.

00:04:46.540 --> 00:04:48.139
It does. I mean, to give you a more concrete

00:04:48.139 --> 00:04:51.029
picture. Yeah. Imagine a lender's sophisticated

00:04:51.029 --> 00:04:54.430
automated underwriting system making an API call

00:04:54.430 --> 00:04:58.110
to, say, Equifax requesting your report. If your

00:04:58.110 --> 00:05:00.649
file is frozen, the system doesn't receive data

00:05:00.649 --> 00:05:03.209
back. It receives a frozen flag. A stop sign.

00:05:03.290 --> 00:05:05.930
A hard stop sign. That entire multi -million

00:05:05.930 --> 00:05:08.730
dollar banking process is stalled by that one

00:05:08.730 --> 00:05:11.759
little flag. That simplified image, the system

00:05:11.759 --> 00:05:14.660
just receiving a stop sign, makes the whole mechanism

00:05:14.660 --> 00:05:17.579
incredibly clear. The inability to access the

00:05:17.579 --> 00:05:20.420
report is absolutely critical. So since a credit

00:05:20.420 --> 00:05:23.620
freeze immediately halts any access for new credit

00:05:23.620 --> 00:05:26.920
purposes, it creates this immovable, federally

00:05:26.920 --> 00:05:29.420
enforced block. Right. And the source material

00:05:29.420 --> 00:05:31.500
highlights the magnitude of the problem this

00:05:31.500 --> 00:05:35.379
solves. According to the FTC, Approximately 15

00:05:35.379 --> 00:05:38.779
% of all identity theft cases in the United States

00:05:38.779 --> 00:05:42.279
fall into this specific category of new account

00:05:42.279 --> 00:05:45.560
origination identity theft. 15 %? That's a huge

00:05:45.560 --> 00:05:48.379
chunk. And that 15 % represents the crimes that

00:05:48.379 --> 00:05:50.899
involve significant dollar amounts and, frankly,

00:05:51.019 --> 00:05:53.319
years of financial and emotional repair for the

00:05:53.319 --> 00:05:56.300
victim. Freezing your report proactively removes

00:05:56.300 --> 00:05:59.060
the possibility of that specific highly damaging

00:05:59.060 --> 00:06:01.339
crime ever happening. It's an undeniable advantage.

00:06:01.850 --> 00:06:04.110
OK, so the freeze is brilliantly effective against

00:06:04.110 --> 00:06:06.029
that specific vulnerability, which is the creation

00:06:06.029 --> 00:06:08.829
of new debt. But now we absolutely have to address

00:06:08.829 --> 00:06:10.970
the critical caveats. What are the limitations?

00:06:11.069 --> 00:06:13.310
What financial processes does a freeze not interrupt?

00:06:13.569 --> 00:06:15.089
This is where we have to clear up the biggest

00:06:15.089 --> 00:06:18.350
misconception. People often assume that freezing

00:06:18.350 --> 00:06:21.670
their credit profile means their financial life

00:06:21.670 --> 00:06:24.949
is essentially paused, you know, placed in stasis.

00:06:25.110 --> 00:06:27.629
Right. That everything is just on ice. That is

00:06:27.629 --> 00:06:30.290
completely incorrect. The most important distinction

00:06:30.290 --> 00:06:33.939
is this. Freezing your credit will not prevent

00:06:33.939 --> 00:06:36.660
your credit score from changing. Wait, that feels

00:06:36.660 --> 00:06:39.160
counterintuitive. If I've locked down access

00:06:39.160 --> 00:06:41.899
to my entire file, how can my credit score, that

00:06:41.899 --> 00:06:45.160
numerical representation of my file, still fluctuate?

00:06:45.300 --> 00:06:47.899
It all comes down to the definition of access

00:06:47.899 --> 00:06:50.660
that the freeze actually controls. The freeze

00:06:50.660 --> 00:06:53.339
only prevents new entities from gaining new access

00:06:53.339 --> 00:06:56.139
for the purpose of extending new credit. Okay,

00:06:56.199 --> 00:06:58.199
so it's about new relationships, not existing

00:06:58.199 --> 00:07:00.680
ones. Exactly. It does not affect your existing

00:07:00.680 --> 00:07:04.220
established relationships. Meaning that the companies

00:07:04.220 --> 00:07:06.300
you already do business with, your current mortgage

00:07:06.300 --> 00:07:07.819
lender, the credit card company you've had for

00:07:07.819 --> 00:07:10.319
10 years, your student loan servicer, your utility

00:07:10.319 --> 00:07:12.740
provider, they already have access to your profile.

00:07:12.920 --> 00:07:14.839
They're already inside the wall. They're considered

00:07:14.839 --> 00:07:17.420
existing creditors. So they can still report

00:07:17.420 --> 00:07:19.500
your behavior. They can report positive behavior,

00:07:19.699 --> 00:07:22.259
like if you pay down a significant debt, or they

00:07:22.259 --> 00:07:24.360
can report negative behavior, like a late or

00:07:24.360 --> 00:07:26.980
a missed payment. I see. So the mechanism protects

00:07:26.980 --> 00:07:29.519
against the stranger using my identity to open

00:07:29.519 --> 00:07:31.660
a new account, but it doesn't shield me from

00:07:31.660 --> 00:07:33.639
the consequences of my own financial decisions

00:07:33.639 --> 00:07:36.079
or, you know, errors regarding the accounts I

00:07:36.079 --> 00:07:38.779
already hold. Precisely. So if I miss a payment

00:07:38.779 --> 00:07:42.160
on my current credit card, my score drops, freeze

00:07:42.160 --> 00:07:45.269
or no freeze. Precisely. The credit score can

00:07:45.269 --> 00:07:48.050
still fluctuate wildly, going up or down based

00:07:48.050 --> 00:07:50.709
on your performance. The freeze protects the

00:07:50.709 --> 00:07:53.170
integrity of your identity, who can access the

00:07:53.170 --> 00:07:56.370
report to issue new credit. But it does not stabilize

00:07:56.370 --> 00:07:58.389
or protect the integrity of your performance

00:07:58.389 --> 00:08:01.310
within your existing financial ecosystem. That's

00:08:01.310 --> 00:08:03.310
a vital distinction for you to grasp. It certainly

00:08:03.310 --> 00:08:06.069
is. Now let's turn to the operational side of

00:08:06.069 --> 00:08:09.019
things. If this defense mechanism is so powerful,

00:08:09.240 --> 00:08:12.480
how much of a hassle is it to actually use? Because

00:08:12.480 --> 00:08:14.639
convenience is a huge factor in whether people

00:08:14.639 --> 00:08:17.100
will actually adopt a security measure. If I

00:08:17.100 --> 00:08:19.939
want to buy a house or get a new car loan, how

00:08:19.939 --> 00:08:22.779
inconvenient is the unfreezing process? That's

00:08:22.779 --> 00:08:25.040
a completely fair line of questioning, because

00:08:25.040 --> 00:08:27.439
if the process were arduous, nobody would use

00:08:27.439 --> 00:08:29.399
it. And we saw that in the early days of the

00:08:29.399 --> 00:08:31.740
state laws, it could be a real pain. However,

00:08:32.179 --> 00:08:34.379
the system has thankfully evolved to prioritize

00:08:34.379 --> 00:08:36.779
consumer convenience, especially since the federal

00:08:36.779 --> 00:08:40.440
mandate. So, yes, you must manually unfreeze

00:08:40.440 --> 00:08:42.340
your reports before applying for credit yourself.

00:08:42.720 --> 00:08:44.899
But the key takeaway from the source material

00:08:44.899 --> 00:08:48.409
is the sheer speed of this process now. And what

00:08:48.409 --> 00:08:50.210
are we looking at in terms of time? Are we talking

00:08:50.210 --> 00:08:54.669
hours, days? Minutes. With proper pre -planning,

00:08:54.690 --> 00:08:56.389
and that just means you have your login information

00:08:56.389 --> 00:08:59.610
in your PIN stored and accessible, most individuals

00:08:59.610 --> 00:09:02.309
can unfreeze their credit profiles with all three

00:09:02.309 --> 00:09:05.409
major bureaus, Equifax, Experian, and TransUnion,

00:09:05.409 --> 00:09:08.190
within a window of maybe 15 to 20 minutes. 15

00:09:08.190 --> 00:09:10.529
to 20 minutes. That's incredibly efficient. A

00:09:10.529 --> 00:09:12.809
matter of minutes to unlock potentially massive

00:09:12.809 --> 00:09:17.029
financial transactions? Yes. The electronic unfreezing

00:09:17.029 --> 00:09:19.889
process, so doing it online, generally takes

00:09:19.889 --> 00:09:22.250
effect immediately or within a matter of minutes

00:09:22.250 --> 00:09:24.629
at most. The inconvenience has been measured

00:09:24.629 --> 00:09:28.210
in minutes, not days. This low barrier to entry

00:09:28.210 --> 00:09:31.149
is absolutely essential. Why is that so important?

00:09:32.120 --> 00:09:34.480
The utility of the freeze is directly proportional

00:09:34.480 --> 00:09:36.820
to how quickly and easily you can toggle it on

00:09:36.820 --> 00:09:39.740
and off. If it took three days to unfreeze, people

00:09:39.740 --> 00:09:41.779
just wouldn't use it. They couldn't be that spontaneous

00:09:41.779 --> 00:09:43.960
with financial decisions. That accessibility

00:09:43.960 --> 00:09:46.960
is crucial. But while we're on the mechanics

00:09:46.960 --> 00:09:49.360
of fraud prevention, there is a whole category

00:09:49.360 --> 00:09:51.259
of identity theft that often gets overlooked,

00:09:51.419 --> 00:09:54.179
and that's utilities fraud. The security measures

00:09:54.179 --> 00:09:56.759
we've discussed so far focus primarily on financial

00:09:56.759 --> 00:09:59.480
credit. We need to talk about the forgotten freeze

00:09:59.480 --> 00:10:01.600
here. This is a layer of protection that often

00:10:01.600 --> 00:10:03.980
goes unmentioned, but it is just as necessary.

00:10:04.159 --> 00:10:06.700
To address this, we need to bring in the National

00:10:06.700 --> 00:10:10.940
Consumer Telecom and Utilities Exchange, or NCTU.

00:10:11.399 --> 00:10:15.000
NCTU. Okay, so if the big three CRAs handle mortgages,

00:10:15.000 --> 00:10:18.080
credit cards, and auto loans, what exactly does

00:10:18.080 --> 00:10:20.620
the NCTUE track, and why is it so important to

00:10:20.620 --> 00:10:23.299
freeze that file separately? The NCTUE tracks

00:10:23.299 --> 00:10:26.320
data related specifically to the opening, maintenance,

00:10:26.559 --> 00:10:29.200
and payment history of utility and telecom accounts.

00:10:29.840 --> 00:10:32.500
So think about your monthly bills, your cell

00:10:32.500 --> 00:10:35.200
phone contracts, your internet services, residential

00:10:35.200 --> 00:10:38.259
electricity, water. gas. All the essentials.

00:10:38.500 --> 00:10:41.000
A huge amount of data moves through this system.

00:10:41.100 --> 00:10:43.600
And the risk here isn't just, what, a lost cell

00:10:43.600 --> 00:10:46.360
phone bill, right? It's a bad actor using a stolen

00:10:46.360 --> 00:10:49.659
identity to establish service, often at a vacant

00:10:49.659 --> 00:10:52.379
or rented property, running up thousands of dollars

00:10:52.379 --> 00:10:55.000
in bills and then just disappearing. Exactly.

00:10:55.080 --> 00:10:57.600
And the damage is twofold. First, the victim

00:10:57.600 --> 00:10:59.620
is left with potentially massive unwarranted

00:10:59.620 --> 00:11:02.179
bills that are a nightmare to dispute. But second,

00:11:02.299 --> 00:11:04.659
and maybe more critically, that negative history

00:11:04.659 --> 00:11:07.820
on your NCTUE file. can prevent you from establishing

00:11:07.820 --> 00:11:10.559
essential services in the future. How so? Well,

00:11:10.600 --> 00:11:12.659
imagine trying to rent an apartment or buy a

00:11:12.659 --> 00:11:15.379
house, and you get denied utilities because your

00:11:15.379 --> 00:11:18.740
NCTUE file shows a history of thousands in unpaid

00:11:18.740 --> 00:11:21.559
debt linked to fraud. It impedes your fundamental

00:11:21.559 --> 00:11:24.549
ability to live your life. So the core takeaway

00:11:24.549 --> 00:11:27.610
here is that a freeze with Equifax isn't going

00:11:27.610 --> 00:11:29.990
to stop a criminal from opening a Comcast account

00:11:29.990 --> 00:11:32.690
in your name. You need that separate layer of

00:11:32.690 --> 00:11:35.269
defense. Absolutely. The source material confirms

00:11:35.269 --> 00:11:37.909
that a separate credit freeze can and should

00:11:37.909 --> 00:11:41.389
be placed on the file with the NCTUE. It's specifically

00:11:41.389 --> 00:11:44.769
to limit fraud through a bad actor creating a

00:11:44.769 --> 00:11:47.149
utilities account in someone else's name. It's

00:11:47.149 --> 00:11:49.149
an essential, often overlooked layer of protection

00:11:49.149 --> 00:11:51.769
against a very common consequence of identity

00:11:51.769 --> 00:11:54.129
theft. So we have an effective system that is

00:11:54.129 --> 00:11:55.830
fast to toggle and it covers both traditional

00:11:55.830 --> 00:11:58.350
financial credit and essential utilities. It

00:11:58.350 --> 00:12:00.330
sounds like a remarkably robust defense, yet

00:12:00.330 --> 00:12:03.370
there is a gaping critical flaw identified in

00:12:03.370 --> 00:12:04.629
the source material that we have to discuss.

00:12:04.950 --> 00:12:08.690
The P .I .M. problem. The irony is just stunning.

00:12:09.710 --> 00:12:12.009
protecting the best defense mechanism is often

00:12:12.009 --> 00:12:13.990
the weakest point. You've hit on the central

00:12:13.990 --> 00:12:16.470
paradox of digital security. Lifting a credit

00:12:16.470 --> 00:12:18.889
freeze requires a personal identification number,

00:12:18.970 --> 00:12:22.230
a PI. It is the designated master key to the

00:12:22.230 --> 00:12:24.590
vault. So if a criminal somehow manages to get

00:12:24.590 --> 00:12:27.950
that PI, the protective freeze becomes instantaneously

00:12:27.950 --> 00:12:31.299
useless. And the security vulnerability that

00:12:31.299 --> 00:12:34.320
was identified back in September 2017 was incredibly

00:12:34.320 --> 00:12:36.899
alarming. It wasn't just about a one off breach.

00:12:37.139 --> 00:12:40.279
It exposed a systemic weakness in how these keys

00:12:40.279 --> 00:12:43.370
were generated and managed. Right. The peon in

00:12:43.370 --> 00:12:45.909
many cases was reported as being easily guessable.

00:12:45.990 --> 00:12:47.889
And what was worse was the management of that

00:12:47.889 --> 00:12:50.529
key. It wasn't just that it was potentially went

00:12:50.529 --> 00:12:52.809
or maybe derived from easily obtainable public

00:12:52.809 --> 00:12:56.110
data. It's that once a peon was assigned, it

00:12:56.110 --> 00:12:58.590
was often reported as being difficult or in some

00:12:58.590 --> 00:13:02.250
cases impossible for the consumer to reset. That

00:13:02.250 --> 00:13:04.250
is the definition of being locked into a latent

00:13:04.250 --> 00:13:07.049
vulnerability. It really is. If the system assigns

00:13:07.049 --> 00:13:09.230
you a weak static identifier, maybe something

00:13:09.230 --> 00:13:11.129
based on your birth date or even linked to part

00:13:11.129 --> 00:13:13.049
of your social security number, and then prevents

00:13:13.049 --> 00:13:14.889
you from changing it, your strongest defense

00:13:14.889 --> 00:13:17.769
is protected by a brittle lock. It forces you

00:13:17.769 --> 00:13:20.269
to rely entirely on the Bureau's opaque internal

00:13:20.269 --> 00:13:22.710
security practices regarding peon generation,

00:13:23.009 --> 00:13:26.009
which historically have proven inadequate at

00:13:26.009 --> 00:13:28.710
times. So the Bureau's had a massive tradeoff

00:13:28.710 --> 00:13:31.980
here. They needed a simple, rapid system for

00:13:31.980 --> 00:13:34.480
unfreezing the profile to satisfy consumer convenience.

00:13:34.779 --> 00:13:37.679
But that rapid system required a simple key,

00:13:37.879 --> 00:13:41.419
the PIN -IN. And if that key is flawed, the entire

00:13:41.419 --> 00:13:44.539
security measure just collapses instantly, potentially,

00:13:44.679 --> 00:13:47.120
without you ever knowing until the fraud has

00:13:47.120 --> 00:13:49.100
already occurred. It requires some critical thinking

00:13:49.100 --> 00:13:51.460
from you, the consumer. Your security is being

00:13:51.460 --> 00:13:53.720
outsourced to the very agencies that housed the

00:13:53.720 --> 00:13:56.529
vulnerable data in the first place. underscores

00:13:56.529 --> 00:13:58.750
the constant challenge of balancing security

00:13:58.750 --> 00:14:03.169
and access. And this necessity for robust consumer

00:14:03.169 --> 00:14:06.110
protection, coupled with massive data breaches

00:14:06.110 --> 00:14:08.149
and the inherent flaws in the pin and system

00:14:08.149 --> 00:14:10.750
is ultimately what prompted large scale legislative

00:14:10.750 --> 00:14:13.590
action. And that legislative story. It played

00:14:13.590 --> 00:14:15.470
out very differently and far more quickly in

00:14:15.470 --> 00:14:17.669
the U .S. compared to Canada. It's a fascinating

00:14:17.669 --> 00:14:20.009
legislative case study. The U .S. journey starts

00:14:20.009 --> 00:14:21.850
at the state level and eventually leads to a

00:14:21.850 --> 00:14:23.889
unified federal mandate. And that legislative

00:14:23.889 --> 00:14:26.149
journey begins with a single pioneering state

00:14:26.149 --> 00:14:28.450
that decided consumer rights should take precedence

00:14:28.450 --> 00:14:31.490
over industry inertia, California. That's right.

00:14:31.690 --> 00:14:35.110
California was the very first state to pass a

00:14:35.110 --> 00:14:39.309
credit freeze law. This was SB 1386, sponsored

00:14:39.309 --> 00:14:42.450
by Senator Deborah Bowen. It was passed in 2002

00:14:42.450 --> 00:14:45.190
and became effective in 2003. That was revolutionary

00:14:45.190 --> 00:14:48.110
at the time. It really was. California, which

00:14:48.110 --> 00:14:50.230
was already a hotbed for technological innovation

00:14:50.230 --> 00:14:54.429
and, ironically, data breaches, recognized that

00:14:54.429 --> 00:14:57.009
consumers needed an opt out mechanism for the

00:14:57.009 --> 00:14:59.409
data being collected about them. And that leadership

00:14:59.409 --> 00:15:01.830
from California really provided the context for

00:15:01.830 --> 00:15:04.350
the rapid spread. Once California made that move,

00:15:04.490 --> 00:15:06.870
it became very difficult for other state legislatures

00:15:06.870 --> 00:15:09.009
to argue against providing the same level of

00:15:09.009 --> 00:15:11.049
protection to their own constituents. Especially

00:15:11.049 --> 00:15:13.230
as the number of publicly reported data breaches

00:15:13.230 --> 00:15:15.990
just soared throughout the 2000s. Momentum was

00:15:15.990 --> 00:15:18.909
undeniable. So by late 2007, just four to five

00:15:18.909 --> 00:15:21.529
years after that initial California law, we saw

00:15:21.529 --> 00:15:23.809
a reaction from the industry itself. Yes, all

00:15:23.809 --> 00:15:25.909
three major credit bureaus announced they would

00:15:25.909 --> 00:15:27.889
voluntarily let consumers freeze their credit.

00:15:27.919 --> 00:15:29.960
credit reports, regardless of their state of

00:15:29.960 --> 00:15:32.580
residency. Now, that sounds like corporate goodwill,

00:15:32.820 --> 00:15:35.200
but it was really a proactive move to try and

00:15:35.200 --> 00:15:38.779
standardize a chaotic state by state legal battle,

00:15:38.940 --> 00:15:41.820
wasn't it? Exactly. TransUnion was a leader in

00:15:41.820 --> 00:15:43.700
offering this industry sponsored alternative.

00:15:44.080 --> 00:15:46.419
They were attempting to get ahead of the legislative

00:15:46.419 --> 00:15:49.879
curve, but it created a very complicated landscape.

00:15:50.120 --> 00:15:53.299
How so? Well, if a state had already passed a

00:15:53.299 --> 00:15:57.440
law, which many had by 2007. That state law still

00:15:57.440 --> 00:16:00.679
applied if its terms like the cost or specific

00:16:00.679 --> 00:16:03.220
compliance details, were more favorable to the

00:16:03.220 --> 00:16:05.159
consumer than the voluntary offering from the

00:16:05.159 --> 00:16:07.919
Bureau. So the state laws acted as a floor for

00:16:07.919 --> 00:16:10.120
consumer protection. The industry could offer

00:16:10.120 --> 00:16:12.179
something better, but they couldn't undercut

00:16:12.179 --> 00:16:14.279
the state mandate. Correct. And this resulted

00:16:14.279 --> 00:16:16.759
in widespread adoption across the entire country,

00:16:16.860 --> 00:16:19.399
but in a very, very fragmented manner. It was

00:16:19.399 --> 00:16:21.379
inevitable, really. Every state saw the need.

00:16:21.539 --> 00:16:23.899
The source material confirms that all 50 states

00:16:23.899 --> 00:16:25.899
and the District of Columbia eventually passed

00:16:25.899 --> 00:16:28.669
a credit freeze law. Yes, and it's noted that

00:16:28.669 --> 00:16:31.009
Michigan was one of the late adopters, passing

00:16:31.009 --> 00:16:34.789
its law relatively recently in 2018. But by that

00:16:34.789 --> 00:16:38.139
point, we had a universal right. But we had 51

00:16:38.139 --> 00:16:40.259
different versions of that right. With varying

00:16:40.259 --> 00:16:43.460
fees, varying procedures. And crucially, varying

00:16:43.460 --> 00:16:46.139
time frames for compliance and unfreezing. It

00:16:46.139 --> 00:16:48.240
was a regulatory nightmare. A nightmare for both

00:16:48.240 --> 00:16:50.940
the bureaus and for the consumer who might move

00:16:50.940 --> 00:16:53.840
between states frequently. And this is where

00:16:53.840 --> 00:16:55.820
the federal government stepped in and changed

00:16:55.820 --> 00:16:58.639
the entire dynamic, moving it from that confusing

00:16:58.639 --> 00:17:01.960
patchwork to a unified standard. The legislation

00:17:01.960 --> 00:17:04.859
was the economic growth. Regulatory Relief and

00:17:04.859 --> 00:17:08.240
Consumer Protection Act passed in 2018. And while

00:17:08.240 --> 00:17:11.000
its title suggests a broad financial scope, it

00:17:11.000 --> 00:17:13.119
contained a critical provision concerning credit

00:17:13.119 --> 00:17:15.339
freezes that preempted all those complex state

00:17:15.339 --> 00:17:17.640
laws. So the federal standard replaced the state

00:17:17.640 --> 00:17:19.559
standard, unifying the rules across the entire

00:17:19.559 --> 00:17:21.799
country. And what was the single most important

00:17:21.799 --> 00:17:24.220
impact of this federal law on the average person?

00:17:24.400 --> 00:17:27.789
The single most important impact. bar none, was

00:17:27.789 --> 00:17:30.329
the elimination of the financial barrier. The

00:17:30.329 --> 00:17:33.049
federal law required all credit freezes and any

00:17:33.049 --> 00:17:35.869
subsequent unfreezes to be completely free of

00:17:35.869 --> 00:17:38.529
charge. Free of charge? Free. This became effective

00:17:38.529 --> 00:17:42.089
on September 21, 2018. We need to spend a moment

00:17:42.089 --> 00:17:44.190
dwelling on the importance of that fee elimination.

00:17:44.970 --> 00:17:48.289
Before 2018, the average cost to freeze a report

00:17:48.289 --> 00:17:52.089
might range from $5 to maybe $20 per bureau.

00:17:53.019 --> 00:17:56.160
Why did that $5 to $20 fee represent such a massive

00:17:56.160 --> 00:17:58.579
barrier to access? Well, think about the practical

00:17:58.579 --> 00:18:01.500
application. First, you had to freeze your reports

00:18:01.500 --> 00:18:05.599
with all four agencies, Equifax, Experian, TransUnion,

00:18:05.599 --> 00:18:08.880
and Inovus. If you were paying, say, $10 per

00:18:08.880 --> 00:18:11.700
freeze, that's $40 just to lock down your identity.

00:18:11.920 --> 00:18:14.089
$40 right out of the gate. Right. And second,

00:18:14.210 --> 00:18:15.990
if you were applying for a mortgage or a car

00:18:15.990 --> 00:18:18.549
loan, you might have to temporarily unfreeze

00:18:18.549 --> 00:18:20.470
and then immediately refreeze again with multiple

00:18:20.470 --> 00:18:22.750
bureaus. So you're paying the fee to list it

00:18:22.750 --> 00:18:24.410
and then you're paying the fee to put it back

00:18:24.410 --> 00:18:26.390
on. So every single time you wanted to exercise

00:18:26.390 --> 00:18:28.690
your credit rights, you were incurring a cost.

00:18:29.150 --> 00:18:32.720
Exactly. But the cost was most punitive for the

00:18:32.720 --> 00:18:35.220
most vulnerable populations or for individuals

00:18:35.220 --> 00:18:37.799
managing the aftermath of repeated data breaches.

00:18:38.119 --> 00:18:40.160
If you were a victim of a breach, you were being

00:18:40.160 --> 00:18:42.559
financially penalized just for taking the most

00:18:42.559 --> 00:18:45.039
basic step to protect yourself after the breach.

00:18:45.319 --> 00:18:48.420
And if you were low income, that $40 or $50 to

00:18:48.420 --> 00:18:51.299
initiate and then toggle the freeze could be

00:18:51.299 --> 00:18:54.799
a significant deterrent. A huge deterrent. The

00:18:54.799 --> 00:18:56.700
federal law essentially moved credit freezing

00:18:56.700 --> 00:19:00.400
from a premium security choice. to a universal

00:19:00.400 --> 00:19:02.740
right. It eliminated that financial friction

00:19:02.740 --> 00:19:05.559
completely. That's a huge victory for consumer

00:19:05.559 --> 00:19:08.779
accessibility. But the federal law didn't stop

00:19:08.779 --> 00:19:11.599
at just making it free. It also mandated efficiency

00:19:11.599 --> 00:19:15.180
and speed, addressing those inconsistent timeframes

00:19:15.180 --> 00:19:17.599
that plague the state -by -state system. Absolutely.

00:19:17.799 --> 00:19:20.220
The legislation imposed specific compliance requirements

00:19:20.220 --> 00:19:23.180
on the bureaus to ensure rapid service. This

00:19:23.180 --> 00:19:25.240
was crucial, especially for the unfreezing process

00:19:25.240 --> 00:19:27.920
needed for urgent transactions, like buying a

00:19:27.920 --> 00:19:29.599
car on a weekend. And what are those specific

00:19:29.599 --> 00:19:32.140
deadlines that were imposed on the bureaus? If

00:19:32.140 --> 00:19:35.480
you make a request to initiate a freeze or to

00:19:35.480 --> 00:19:38.299
temporarily lift one via an electronic method,

00:19:38.420 --> 00:19:41.019
so their online portal or over the phone, the

00:19:41.019 --> 00:19:43.619
bureaus must complete that request and institute

00:19:43.619 --> 00:19:46.440
the change within one business day. One business

00:19:46.440 --> 00:19:49.660
day. That is rapid compliance. It is. And even

00:19:49.660 --> 00:19:52.259
for the slowest method. sending a physical letter

00:19:52.259 --> 00:19:54.339
through the mail. Which people still do. They

00:19:54.339 --> 00:19:56.779
do. Even then, they have a strict three -business

00:19:56.779 --> 00:19:59.740
-day window to comply with the request. This

00:19:59.740 --> 00:20:02.440
entire transition from a potentially costly,

00:20:02.700 --> 00:20:06.799
varied and slow system to a free, fast, federally

00:20:06.799 --> 00:20:09.660
mandated standard is indeed the major success

00:20:09.660 --> 00:20:12.440
story for consumer financial protection in the

00:20:12.440 --> 00:20:15.420
modern U .S. legislative landscape. It's an undeniable

00:20:15.420 --> 00:20:17.519
example of regulation working to the benefit

00:20:17.519 --> 00:20:19.519
of the average person, forcing industry adaptation.

00:20:19.980 --> 00:20:21.900
But if we connect this to the bigger picture,

00:20:22.079 --> 00:20:24.640
the U .S. experience highlights a pattern. that

00:20:24.640 --> 00:20:27.000
CRAs really needed legislative pressure to offer

00:20:27.000 --> 00:20:29.319
the best, most protective features. They absolutely

00:20:29.319 --> 00:20:31.539
do. And we see this dynamic confirmed when we

00:20:31.539 --> 00:20:34.019
examine the Canadian contrast. The comparison

00:20:34.019 --> 00:20:36.880
to Canada is, as you said, incredibly illuminating

00:20:36.880 --> 00:20:39.180
because it shows what happens when that legislative

00:20:39.180 --> 00:20:42.630
push is delayed or just absent. We see a clear,

00:20:42.690 --> 00:20:45.990
contrasting approach, a reluctance on the part

00:20:45.990 --> 00:20:48.289
of the industry that delayed crucial consumer

00:20:48.289 --> 00:20:50.789
protection for years. The source material is

00:20:50.789 --> 00:20:53.150
quite explicit in its finding. It says consumer

00:20:53.150 --> 00:20:55.609
reporting agencies typically only develop and

00:20:55.609 --> 00:20:58.390
offer a robust credit freeze feature when they

00:20:58.390 --> 00:21:00.750
are directly prompted or mandated by legislation.

00:21:00.990 --> 00:21:03.650
Right. Without that regulatory incentive, they

00:21:03.650 --> 00:21:05.710
seem resistant to providing it as a standard

00:21:05.710 --> 00:21:08.039
consumer right. And the consequence of that was

00:21:08.039 --> 00:21:10.779
evident in many Canadian jurisdictions. For a

00:21:10.779 --> 00:21:13.700
significant period of time, TransUnion and Equifax

00:21:13.700 --> 00:21:16.339
simply did not offer any form of credit freeze.

00:21:16.539 --> 00:21:18.940
None at all. And if a consumer was concerned

00:21:18.940 --> 00:21:21.079
about identity theft, the industry's default

00:21:21.079 --> 00:21:23.440
response was to direct them toward their paid

00:21:23.440 --> 00:21:25.920
identity monitoring services. And the source

00:21:25.920 --> 00:21:28.180
material describes those paid services as having

00:21:28.180 --> 00:21:30.619
been viewed as ineffective. We need to go into

00:21:30.619 --> 00:21:33.259
detail here. Why is a paid identity monitoring

00:21:33.259 --> 00:21:35.519
service considered so ineffective compared to

00:21:35.519 --> 00:21:38.700
a free, legislatively mandated credit freeze?

00:21:38.980 --> 00:21:41.440
The difference boils down entirely to timing

00:21:41.440 --> 00:21:45.019
and action. A paid identity monitoring service

00:21:45.019 --> 00:21:48.099
is fundamentally reactive. It monitors public

00:21:48.099 --> 00:21:50.720
records and credit inquiries, and if it detects

00:21:50.720 --> 00:21:53.380
something suspicious, say a hard inquiry for

00:21:53.380 --> 00:21:55.619
a new credit card application, it sends you an

00:21:55.619 --> 00:21:57.799
alert. Okay, so it's basically just a notification

00:21:57.799 --> 00:22:00.819
service. Exactly. It notifies you after the event

00:22:00.819 --> 00:22:03.160
has already occurred. The criminal has already

00:22:03.160 --> 00:22:06.000
successfully used your stolen identity to request

00:22:06.000 --> 00:22:08.940
credit. In the worst -case scenarios, the monitoring

00:22:08.940 --> 00:22:11.539
service notifies you that a new account was opened.

00:22:11.849 --> 00:22:13.849
meaning the fraud already succeeded. And the

00:22:13.849 --> 00:22:16.670
burden then falls entirely on the victim. Entirely.

00:22:16.670 --> 00:22:18.690
You have to initiate the fraud report, contact

00:22:18.690 --> 00:22:21.930
the credit issuer, and begin that arduous, emotionally

00:22:21.930 --> 00:22:24.470
exhausting process of cleaning up the mess and

00:22:24.470 --> 00:22:26.329
removing the fraudulent debt from your name.

00:22:26.490 --> 00:22:29.289
Whereas the freeze is proactive. The freeze is

00:22:29.289 --> 00:22:31.609
a firewall. It doesn't send you an alert. It

00:22:31.609 --> 00:22:33.410
prevents the transaction from completing in the

00:22:33.410 --> 00:22:36.380
first place. The lender's system hits that frozen

00:22:36.380 --> 00:22:39.220
flag, the loan cannot be processed, and the fraud

00:22:39.220 --> 00:22:41.900
is stopped before any financial damage or burden

00:22:41.900 --> 00:22:43.759
of proof is placed upon you. That difference

00:22:43.759 --> 00:22:46.079
is massive. It's the difference between notification

00:22:46.079 --> 00:22:49.279
and prevention. And the industry, when not compelled

00:22:49.279 --> 00:22:52.299
by law, tended to favor the profitable, less

00:22:52.299 --> 00:22:55.359
effective reactive monitoring service over the

00:22:55.359 --> 00:22:58.240
proactive identity securing freeze. So without

00:22:58.240 --> 00:23:00.539
that proactive protection, the pressure had to

00:23:00.539 --> 00:23:02.960
build in Canada, jurisdiction by jurisdiction,

00:23:03.200 --> 00:23:05.140
just as it had built state by state in the U

00:23:05.140 --> 00:23:07.900
.S. decades earlier. Which jurisdiction led the

00:23:07.900 --> 00:23:10.500
way across the border? That was Quebec. Quebec

00:23:10.500 --> 00:23:13.680
was the first jurisdiction in Canada to legislatively

00:23:13.680 --> 00:23:16.339
provide for credit freezes. That came with the

00:23:16.339 --> 00:23:19.480
passage of Bill 53, the Credit Assessment Agents

00:23:19.480 --> 00:23:21.839
Act. Then what was the timeline there? That legislative

00:23:21.839 --> 00:23:24.579
victory seems quite recent. It is remarkably

00:23:24.579 --> 00:23:26.700
recent, especially when you compare it to the

00:23:26.700 --> 00:23:30.339
2003 origin in California. Quebec residents gained

00:23:30.339 --> 00:23:32.619
the ability to place a freeze starting only in

00:23:32.619 --> 00:23:36.400
February 2023. 2023. Yes. This just illustrates

00:23:36.400 --> 00:23:38.740
the regulatory lag when industry opposition is

00:23:38.740 --> 00:23:41.920
strong or legislative priority is low. That's

00:23:41.920 --> 00:23:43.980
a 20 -year difference in consumer protection

00:23:43.980 --> 00:23:46.500
timelines between California and Quebec. And

00:23:46.500 --> 00:23:48.380
are other parts of Canada following suit now?

00:23:48.599 --> 00:23:51.720
Yes. The movement is spreading, although slowly.

00:23:52.160 --> 00:23:56.140
As of February 2021, Ontario is also considering

00:23:56.140 --> 00:23:58.180
significant changes to its Consumer Reporting

00:23:58.180 --> 00:24:00.660
Act that would also provide for credit freezes.

00:24:01.099 --> 00:24:04.220
So while the dominoes are starting to fall, they

00:24:04.220 --> 00:24:06.799
are clearly falling due to legislative necessity,

00:24:07.180 --> 00:24:10.299
the Credit Assessment Agents Act, not due to

00:24:10.299 --> 00:24:12.930
proactive industry goodwill. The narrative is

00:24:12.930 --> 00:24:15.289
consistent then across two different legislative

00:24:15.289 --> 00:24:17.829
environments. The implementation of the credit

00:24:17.829 --> 00:24:19.970
freeze feature, the consumer's most effective

00:24:19.970 --> 00:24:22.630
defense against new account fraud, is almost

00:24:22.630 --> 00:24:25.369
entirely driven by regulatory requirements. And

00:24:25.369 --> 00:24:27.710
those requirements often lag years behind the

00:24:27.710 --> 00:24:30.569
technological vulnerability. It absolutely reinforces

00:24:30.569 --> 00:24:32.750
that finding. The history of the credit freeze

00:24:32.750 --> 00:24:35.029
is fundamentally a story of consumer activists

00:24:35.029 --> 00:24:37.490
and legislators fighting to shift the burden

00:24:37.490 --> 00:24:40.089
of protection away from the victim and onto the

00:24:40.089 --> 00:24:42.259
systems that profit from the data. This has been

00:24:42.259 --> 00:24:44.660
an incredibly detailed and frankly sobering deep

00:24:44.660 --> 00:24:48.000
dive into a powerful consumer tool. Let's synthesize

00:24:48.000 --> 00:24:50.000
the most critical takeaways so every listener

00:24:50.000 --> 00:24:51.859
walks away knowing exactly what this tool is

00:24:51.859 --> 00:24:54.079
and why they should be using it. The first most

00:24:54.079 --> 00:24:57.180
important point is clarity on purpose. The credit

00:24:57.180 --> 00:25:00.079
freeze is a powerful, legislatively mandated

00:25:00.079 --> 00:25:03.359
tool designed to stop new account origination

00:25:03.359 --> 00:25:06.680
identity theft. It is your best defense against

00:25:06.680 --> 00:25:09.220
a criminal opening a brand new financial product

00:25:09.220 --> 00:25:11.549
in your name. And secondly, the federal mandate

00:25:11.549 --> 00:25:13.670
in the U .S. changed everything. Since September

00:25:13.670 --> 00:25:17.009
2018, this vital protection is required to be

00:25:17.009 --> 00:25:20.529
free of charge across all major CRAs, Equifax,

00:25:20.670 --> 00:25:24.089
Experian, TransUnion, and Inovus. And not only

00:25:24.089 --> 00:25:27.420
is it free. But the law requires that rapid compliance.

00:25:27.680 --> 00:25:30.140
One business day for phone or online request.

00:25:30.420 --> 00:25:33.119
It is accessible and is mandatory. And we must

00:25:33.119 --> 00:25:35.319
not forget the necessary complexity of protection.

00:25:35.579 --> 00:25:38.079
Remember the NCTUE, the Utilities Reporting Agency.

00:25:38.359 --> 00:25:40.460
You need to pursue a separate freeze there to

00:25:40.460 --> 00:25:42.240
protect yourself from identity theft leading

00:25:42.240 --> 00:25:44.819
to utility or telecom service fraud. Which can

00:25:44.819 --> 00:25:46.660
be just as damaging to your ability to secure

00:25:46.660 --> 00:25:48.940
housing or essential services. And finally, the

00:25:48.940 --> 00:25:50.700
history lesson provided by the U .S.-Canadian

00:25:50.700 --> 00:25:53.140
contrast is just vital. When we look at the U

00:25:53.140 --> 00:25:55.740
.S. transition to a pre -unified federal law.

00:25:55.900 --> 00:25:57.579
And then we contrast that with jurisdictions

00:25:57.579 --> 00:26:00.019
like Quebec, which only legislatively mandated

00:26:00.019 --> 00:26:02.960
this right in 2023. It just proves that CRAs

00:26:02.960 --> 00:26:05.680
often require legislative prompting to offer

00:26:05.680 --> 00:26:09.000
the best, most proactive security features. It's

00:26:09.000 --> 00:26:11.180
a protection that was fought for state by state

00:26:11.180 --> 00:26:14.359
and then federally mandated, showcasing a genuine

00:26:14.359 --> 00:26:17.559
legislative success in consumer protection. But

00:26:17.559 --> 00:26:19.920
as we noted earlier, the credit freeze is not

00:26:19.920 --> 00:26:22.720
a flawless shield. It's one vital component of

00:26:22.720 --> 00:26:25.660
a larger security strategy. We identified two

00:26:25.660 --> 00:26:29.119
areas of lingering vulnerability. First, the

00:26:29.119 --> 00:26:31.640
fact that freezing access doesn't stop your credit

00:26:31.640 --> 00:26:33.619
score from changing due to your existing behaviors.

00:26:34.039 --> 00:26:36.380
Right. And second, that crucial weakness of the

00:26:36.380 --> 00:26:39.240
peep on system used to unlock the entire profile.

00:26:39.460 --> 00:26:41.279
So we want to leave you with a final provocative

00:26:41.279 --> 00:26:43.640
thought that ties the mechanics to the legislation

00:26:43.640 --> 00:26:46.400
we discussed. Given that regulation historically

00:26:46.400 --> 00:26:49.140
had to fight the CRAs just to provide the freeze,

00:26:49.359 --> 00:26:52.319
and that fight took decades, what does that tell

00:26:52.319 --> 00:26:55.700
us about the inevitable regulatory lag in addressing

00:26:55.700 --> 00:26:57.960
the next vulnerability? That's the question.

00:26:58.039 --> 00:27:01.000
If the PN system, or maybe the rise of account

00:27:01.000 --> 00:27:03.920
takeover fraud where existing accounts are hijacked,

00:27:04.079 --> 00:27:06.539
if that represents the current security frontier,

00:27:06.859 --> 00:27:09.279
how long will it take for legislative solutions

00:27:09.279 --> 00:27:12.140
to catch up and mandate proactive free protection

00:27:12.140 --> 00:27:15.279
against those threats too? The focus shifts from

00:27:15.279 --> 00:27:17.960
securing your file to securing the key to the

00:27:17.960 --> 00:27:20.240
file. And we have to ask whether we can afford

00:27:20.240 --> 00:27:22.819
to wait another 20 years for the next layer of

00:27:22.819 --> 00:27:25.319
mandated protection. Something profound for you

00:27:25.319 --> 00:27:27.740
to consider as you review your own security strategy.

00:27:28.099 --> 00:27:30.420
We've reached the bottom of the deep dive. Stay

00:27:30.420 --> 00:27:33.160
proactive, stay informed, and stay curious. We'll

00:27:33.160 --> 00:27:33.700
see you next time.
