Live data from Hacker News

The Equifax Breach Exposes America's Identity Crisis

wired.com

21–30 of 132 posts

Re: The Equifax Breach Exposes America's Identity Crisis

#21
post #3

In Sweden your SSN is public information. I posted the same comment on another Equifax thread and got some pretty interesting replies relevant to this discussion: https://news.ycombinator.com/item?id=15208223

I believe that all EU has a similar approach, it is just the US that misuse the SSN.

The way it is done in Italy (it is called "Codice Fiscale") it is composed through a public algorithm from name, surname, place and date of birth with a final "control" character (derived by the preceding characters) so - with the exception of the very few cases of total homonimy - it can be recreated "on the spot".

Nowadays it is however printed on an electronic card, with both a magnetic stripe and a chip and it is the actual card (together with an ID document[1]) that "authenticates" your identity (in person) while on some government sites you can use the card (with a smart card reader) to authenticate.

[1] actually the main thing is the ID document, passport, ID card or - in some cases - driving license, with that you can declare your Codice Fiscale even if you don't have the actual card with you.

Re: The Equifax Breach Exposes America's Identity Crisis

#23
post #14
post #9

Earlier quoted context omitted.

Anything collected will eventually leak. The issue is that companies shouldn't be collecting ANYTHING , and what they do collect should get purged ASAP. The problem is that every company got addicted to collecting information and nobody made them pay the price for doing so.

There are legitimate use cases where collecting and storing (in some manner at least) is necessary. You cannot just stop companies from collecting information, and furthermore stop them from storing any of it. Thats just naive.

The private university I went to used to issue student emails that were first three letters of last name followed by last four digits of social security number. It always seemed odd to me. Years later, they've switched and we don't have that problem any more.

Companies can generate a unique identifier without using SSN. Of course, the main problem is that they can't do authentication based on that identifier. So why can they do authentication based on SSN?

Re: The Equifax Breach Exposes America's Identity Crisis

#24

For everybody who isn't acquainted with how Social Security Cards work in the US and how they came to be I highly recommend watching "Social Security Cards Explained" by CGP Grey https://www.youtube.com/watch?v=Erp8IAUouus He also explains why US citizens don't have an Identity Card as opposed to many European countries.

That’s quite crazy. Though here in NZ we don’t have a National ID number either, we have several different numbers for different purposes. Most places will work with a driver licence or passport number, but given there’s no need to register a change of name it gets a little tricky.

If you don’t have any of those you can get a statutory declaration of identity from a local court. You just have to swear you’re the person in front of a justice of the peace and provide a passport photo.

Re: The Equifax Breach Exposes America's Identity Crisis

#25
post #15

The real crisis here is that Equifax isn't being held responsible for providing meaningful fraud protection beyond one year. When I lived in the UK, the banks were constantly trying to sell me "fraud protection" and "identity protection" - trying to argue with the salesdrones about why you think it is insane that they are trying to sell me protection against their own shoddy information security practices was useless…

Instead of heavily regulating I say we should make this service obsolete by passing similar to European laws where people can request what information given company holds about them, request removal and not allowing data collection without permission. Neither of those companies provides anything valuable to ordinary citizens and the data collection they do comes with great price to us as it shown with recent Equifax…

well, Equifax is big in the UK, mostly to keep track of your credit rating, to allow individuals to borrow money.

I think you will find on closer inspection that EU data protection laws prove to be surprisingly flexible when it comes to things relating to money. But hey, at least we are protected from evil cookies tracking us! Talk about a fucking sleight of hand....

Re: The Equifax Breach Exposes America's Identity Crisis

#26
post #17

I never realised till now that American's SSNs were supposed to be kept secret. That's absolutely ridiculous. The idea of trying to keep the UK equivalent (National Insurance Number) secret is laughable. How can anything function when an important id number is also supposed to be known by very few people?

The same holds for bank account numbers which seems just as ridiculous to us Europeans.

I’ve recently seen inside the horror that is the US interbank clearing system. It seems crazy to me. In New Zealand we regularly share bank account numbers for payments, most obviously via TradeMe, our ebay equivalent.

If you had my bank account number you could authorise a payment with an approved direct debit provider, who have to keep the approval on file in case of a dispute.

Re: The Equifax Breach Exposes America's Identity Crisis

#27
post #21
post #3

In Sweden your SSN is public information. I posted the same comment on another Equifax thread and got some pretty interesting replies relevant to this discussion: https://news.ycombinator.com/item?id=15208223

I believe that all EU has a similar approach, it is just the US that misuse the SSN. The way it is done in Italy (it is called "Codice Fiscale") it is composed through a public algorithm from name, surname, place and date of birth with a final "control" character (derived by the preceding characters) so - with the exception of the very few cases of total homonimy - it can be recreated "on the spot". Nowadays it is ho…

Thanks for the great content and information.

Just a minor nitpick: your identity can't be authenticated. You, as an individual, can be identified, but the only thing that can be authenticated is the piece of plastic (ensuring it is not counterfeit).

I wrote down an analogy for the different lingo some months ago: https://news.ycombinator.com/item?id=13635820

Re: The Equifax Breach Exposes America's Identity Crisis

#28
post #5

I think we're mixing two different purposes here. Authentication through knowledge of a SSN is an absurd practice, and is a non problem in countries which have a national ID card scheme. Introducing ID cards would be my obvious response to this leak. Not re-issuing SSN until the next major leak. Having a universal unique identifier for every individual across systems is a different matter and I am not convinced this…

For the purposes of fraud, it's fairly easy to link accounts across datasets even without a unique key like SSN. You can just guess based on name and address or something and if you're only right 90% of the time that's still a pretty big win.

You would be surprised how difficult that problem is.

Re: The Equifax Breach Exposes America's Identity Crisis

#29
The article goes a bit off the rails at the end, with all the focus on using a changeable identifier ("And if this new identifier were easy enough to change (unlike SSNs), breaches, leaks, and other unintended exposures would be less consequential.")

There's no reason not to keep SSN as an identifier. Just the same as I wouldn't change my name if I suffered identity theft. Instead there needs to be authentication (eg via a method such as a token, 2FA or whatever) - and it's that which needs to be resettable.

Simply making use of SSN alone illegal in certain industries would be a reasonable approach: it would stop current problems whilst not insensing the "mark of the beast" brigade.

Re: The Equifax Breach Exposes America's Identity Crisis

#30
post #5

I think we're mixing two different purposes here. Authentication through knowledge of a SSN is an absurd practice, and is a non problem in countries which have a national ID card scheme. Introducing ID cards would be my obvious response to this leak. Not re-issuing SSN until the next major leak. Having a universal unique identifier for every individual across systems is a different matter and I am not convinced this…

Have a unique public identifier for everyone.

An identifier is not a verifier. Just because I know my neighbors id number doesn't mean I can e.g open a bank account in his name.

The act of validating that you are the person with the given ID requires some form of id validation (drivers license, passport, digital id).

I can't even understand how you even keep a reliable customer database that works through name and address changes without having a single immutable identifier for everyone. I can understand how people started using SSN if that is the only number there is.

Here I just record bob the customer as 123467890 and he can change name, address etc all he wants without telling me. I can still send him his bill because I can lookup both a name and address for any id at any point in time by just asking the tax- (and id-) authority for the details for that national id number.

If my customer db is leaked it's considered "bad" but it's not disastrous. All those addresses/names/ids were mostly public anyway (there could be protected identities etc so one shouldn't assume all is public)

Post reply on HN