Freeze Social Security Number Equifax – Have you ever been annoyed by an ad playing before the trailer starts at the movie theater? It’s an experience I call “Beholden Design.”

Filled with dark patterns and pain, Beholden Design is the evil, goatee-bearded twin of Universal Design. This forces people to interact with the interface to get what they need, but choosing other options usually has dire consequences. This is the opposite of most experiences where the user has a choice whether or not to use the service.

When we look at the world through this lens, we see a lot of things, with varying degrees of severity: tax forms (both physical and digital), healthcare-related websites and systems, DMVs, ATMs, and more. It will be.

Top 10 Ways To Protect Yourself In The Wake Of The Equifax Data Breach

Beholden design practitioners create suboptimal experiences for users, either unintentionally through ignorance or negligence, or intentionally in an effort to force profitable choices onto users. In my opinion, both are inexcusable.

In this post, we talk about Beholden Design’s most important experience: his Equifax data breach.

Equifax is one of the three major credit reporting companies in the United States. Credit bureaus use direct and indirect data collection techniques to track U.S. citizens and assess credit scores. These scores are used to measure how responsible a person is likely to be in repaying a loan. Loans are the only practical way for most people to make large purchases that allow them to function in society.

Even ignoring for now that these data collection techniques are far from perfect, all Americans essentially automatically choose to participate in these privately operated services. This is a particularly frightening fact following his Equifax data breach in September 2017, where the personal data of 143 million people was compromised without their knowledge.

Freeze Your Credit Report At Equifax For Free

For tech-savvy individuals, having access to the personal identifying information of approximately two-thirds of the U.S. population means that mass credit fraud has essentially become a turnkey process. All the information needed to impersonate someone else and take out loans in their name has been removed from her supposedly secure Equifax server. The scale and impact of this type of event is historically unprecedented.

One option an individual can take, either as a victim or proactively, is to request a so-called credit freeze. A credit freeze limits who can see your credit report and effectively prevents new lines of credit from being issued. The company against which the freeze was requested will then issue you a code, which you can use at a later date to regain access to your credit report.

Complicating matters, the information needed to request a credit freeze be lifted is also the information stolen in the breach. This whole system is a great opportunity to apply big-picture service design thinking, but we’ll focus on the experience of someone requesting a credit freeze.

Beholden design is selfish. The system is built to serve the needs of the service, not the needs of the person who needs it.

Infographic: Expanding Access To Credit With Alternative Data

To request a credit freeze, an individual must petition each service that monitors them. In addition to the big three (Equifax, TransUnion, and Experian), there are also several smaller companies (Innovis and ChexSystems). There may be others, but I honestly don’t know, and frankly that’s part of the problem.

These companies have access to your contact information, but currently individuals must contact each company individually to request a credit freeze using their own freeze request service.

Holding all credit bureaus accountable for honoring a single request submitted by a user will ultimately improve the experience for everyone involved. A single, centralized command reduces potential errors overall.

The forms provided by these companies are the holy grail of bad design. All aspects of them are hostile to users, but necessary to protect themselves from harm.

Equifax Data Breach Could Have A Silver Lining

Screenshot of the 5 credit freeze request page (link to view the full credit freeze request form for 5 credit monitoring services).

Beholden Design prioritizes input data meeting the needs of internal systems rather than end users. At that point, each credit freeze request form requests the same information in slightly different ways, with different language and number of steps throughout the process.

From the perspective of someone who has gone through the effort of going through each service to request a freeze, the process appears to be non-standardized. This can lead to feelings of anger, frustration, anxiety, and doubt in high-risk situations.

This is very likely the first page you encounter when you visit this type of site. Even if the dialogue is standard when it comes to credit monitoring websites, it may not reflect the way the majority of forms on the rest of the Internet work.

Guide To Freeze The Work Number By Equifax

Your visitors may not have experienced this specialized navigation before. The type of information required during this process is not unusual. Rely on external consistency to help the process move forward with as little friction as possible.

All of these forms have too much content in the right places. For inward-facing priorities, satisfying the legal team is paramount, even if the resulting copy is incomprehensible to a layman.

A well-designed form not only meets legal requirements, but is also usable. His two tricks for doing so are delivering the right thing at the right time, and anticipating questions and providing just-in-time clarification.

If a form requires special or sensitive information, avoid suspicion at the time and explain its use as close as possible to the relevant input field. If you have a huge preamble to create a form, use gradual disclosure to break it up and place relevant content and input fields that it affects.

Equifax Exposes Credit Services’ Woeful It, Processes, Security

Validation is the process of verifying that the information entered in a form is correct and properly formatted. This is a widespread and deep practice in the design and security world and can go a long way in preventing events like this data breach from happening.

Proper form validation walks the line between usability and preventing incorrect or malicious input from entering. In Beholden Design, form validation is combative and unintuitive. The company focuses on inputting text into the system with minimal interaction behind the scenes.

An example of this is requiring that phone numbers not use brackets for area codes, even if you are used to writing that information out in other contexts. While it would be easy to programmatically manipulate and standardize this information after a user submits a form, Beholden Design is happy with the cheaper option of letting users do all the work.

Beholden’s design is also lazy. Typically, this kind of formatting needs are exposed only after the form is submitted, usually with a bunch of messages at the top of the form. This behavior violates the Gestalt principles of proximity and continuity.

After Equifax Hack, Credit Freezes Now Free Starting Sept. 21

Errors are not placed next to the form field to which they apply. Form fields with errors are not highlighted. The appropriate format for the required information was not specified. Input indicators (*) that require color are not supported. Validation occurs only if the entire form is submitted (link to full Experian validation screenshot).

Interestingly, this validation approach tends to have the unintended consequence of promoting incorrect input. Frustrated users will try to fix form errors for convenience rather than accuracy, even if the information they’re entering is very important. Have you ever banged on the side of your computer to get it to work when it wasn’t responding? That’s exactly right.

Another interesting aspect of Beholden Design form validation is that it tends to make broad assumptions about the type of content it reviews. If you can’t handle the nuances in the type of information you’re looking for, you’re much more likely to lock people out, especially if you’re operating on a national scale.

Instead, accompany her input with just-in-time messaging that notifies the user after the user navigates to another form’s field. Even better, place hints and examples near the form fields. User tests, applied wisely, can reveal what kinds of information people struggle with.

Equifax’s Instructions Are Confusing. Here’s What To Do Now.

Needless to say, you will need to work harder to ensure that you are able to handle all of the false cases outlined in the two links before this paragraph.

The horrifying details of Equifax’s lax security practices have been gleefully dissected elsewhere by industry experts, so I won’t go into them here.

However, it is important to remember that presenting the entire credit freeze request form is also a consideration. Simply put, a page is treated as legitimate if it doesn’t appear to be legitimate. Sorry, Equifax, but that flattering stock photo of a confident woman doesn’t really matter.

Ignoring unsexy but important things like this

Equifax Faqs: Answers To Potential Hack Victims’ Most Common Questions

