How fraud-detection services like Sift and SecureAuth use thousands of signals and opaque algorithms to generate user-trustworthiness scores
Why ‘Move Fast and Break Things’ Is Out Tweets: Ellen Timmer / @ellen_timmer : When you're logging in to a Starbucks account, booking an Airbnb or making a reservation on OpenTable, loads of information about you is crunched instantly into a single score, then evaluated along with other personal data to determine if you're a risk http://www.wsj.com/... Scott Galloway / @profgalloway : .@airbnb, @Starbucks @Xerox use trust scores (the new credit scores)—companies like Sift use >16,000 signals for a “Sift score,” (1-100) used to flag devices, credit cards and accounts owned by any entities a company might want to block. @mims @WSJ http://www.wsj.com/... @wsj : How many of us realize our account behaviors are shared with companies we've never heard of, in the name of security, writes @mims http://www.wsj.com/... @wsj : If you're buying airplane tickets for other people, are you a scammer or a wealthy frequent flyer? A new kind of online score attempts to solve that puzzle http://www.wsj.com/... Christopher Mims / @mims : To be clear, bad guys share information about attacking our financial infrastructure, so good guys should too. And I think most of the big companies involved are careful. Which means there's going to be companies on the margins that are shady afhttps://t.co/i6nqPgDIzR Christopher Mims / @mims : I wrote about trust scores, which are like credit scores, only they're secret and not transparent and not specifically regulated, and will probably lead to good times if anyone ever proves they are potentially discriminatoryhttps://t.co/i6nqPgDIzR Elizabeth Joh / @elizabeth_joh : “Sift judges whether or not you can be trusted, yet there's no file with your name that it can produce upon request. That's because it doesn't need your name to analyze your behavior.” A world that's incompatible with ordinary standards of due process. http://www.wsj.com/... See also Mediagazer
Context & Ripple Effects
The WSJ piece lands mid-arc in a run of stories about algorithmic scoring of people outside the credit system. Weeks earlier, Predictim was generating AI character scores for babysitters from years of scraped online activity, and days before this article Equifax and FICO packaged their credit-bureau data into a new product for marketers via Data Decision Cloud. Sift extends the same logic to everyday logins: a 'Sift score' of 1–100 built from over 16,000 signals, consumed by Airbnb, Starbucks, Xerox and OpenTable to flag devices, cards and accounts.
What makes it consequential is the opacity: unlike a FICO score, users can't see or contest a Sift score, and experts cited in the coverage warn it lacks due process and could produce discriminatory outcomes. The pattern echoes earlier warnings about scoring systems like China's Sesame Credit enabling social control, now arriving through commercial fraud tooling rather than state programs.
First-order effects
- Consumers logging into Starbucks, booking an Airbnb or reserving on OpenTable are being scored in real time by vendors they've never heard of, with flags attached to their devices, credit cards and accounts that follow them across services.
- Airbnb, Starbucks and Xerox effectively outsource risk decisions on individual users to Sift and SecureAuth, whose algorithms and signal lists are not disclosed even to the people being judged.
Second-order effects
- Credit-data incumbents see the market: Equifax and FICO's Data Decision Cloud repackages consumer-credit data for financial companies and marketers, pushing scoring vendors to compete on data breadth rather than accuracy alone.
- Scored individuals face pressure to surrender more data to defend themselves — the dynamic already visible where Predictim pressures babysitters to grant broad access to their social media in exchange for a better evaluation.
Third-order effects
- A two-tier accountability gap is forming: privacy laws like GDPR and CCPA force disclosure of collected data, yet reporting shows many firms have insecure practices when handing users their files and still outsource identity verification — so the scores stay opaque while the underlying data gets exposed.
- If trust scores keep spreading as de facto gatekeeping infrastructure without contestability mechanisms, the industry drifts toward the social-scoring outcomes critics have warned about since the FICO/Sesame Credit comparisons — with regulation likely to eventually target explainability and appeal rights rather than the scores' existence.
The trend: Consumer trustworthiness scoring is quietly becoming a parallel credit-score layer across platforms — built by fraud vendors faster than transparency or due-process rules are catching up.