Live data from Hacker News

The Equifax Breach Exposes America's Identity Crisis

wired.com

111–120 of 132 posts

Re: The Equifax Breach Exposes America's Identity Crisis

#111

Earlier quoted context omitted.

> National IDs are a nonstarter politically in the US. One side thinks it is undue encroachment on local rights, and the other side thinks requiring ID disenfranchises the poor and undocumented. That's the tl;dr version of course -- reality is more nuanced. As a non-American, this doesn't really make much sense to me. There's already a national ID, the Social Security card. It's just a really really terrible form of…

Social Security card is made of paper, has nothing but the number and your name, and 99% of people in the US have lost, destroyed, or never carried it to begin with. Stupid paper card even says "Do not laminate" but mine is laminated and thus intact after 40 years. SS#'s were never meant to be personal ID numbers or national ID numbers. This was a big thing when they were introduced. Unfortunately, companies use them…

Except if the SS number was not meant to identify people, what was it for? It was meant to track people throughout their lives to set the amount they get paid by the program based on what they made / what SS tax they paid.

It is terrible at that, it is terrible as a general id, and its just another example of doublethink in American politics - we want national welfare programs that are restricted only to valid citizens, but we don't want to actually know who the citizens are or keep track of them, or have any concrete way to identify them.

Re: The Equifax Breach Exposes America's Identity Crisis

#112

Earlier quoted context omitted.

The UK is also heavily resistant to any sort of national ID scheme, and so National Insurance numbers (our equiv of SSN) are also a sortof proxy ID for people in work etc. But the difference is we don't pretend they are secret. In other words: we use it as a primary key, but we don't assume its a shared secret.

So let's say you want to apply for a bank loan or credit card online, or look up information about yourself on a government website - how do you prove you're you? Or is this simply not possible in the UK without visiting a bank branch etc.?

You usually end up sending copies of your passport and proof of address (eg utility bill) by post. Sometimes the copies have to be certified by a lawyer/solicitor, to prove they are true copies of the original document

Re: The Equifax Breach Exposes America's Identity Crisis

#113
post #111

Earlier quoted context omitted.

Social Security card is made of paper, has nothing but the number and your name, and 99% of people in the US have lost, destroyed, or never carried it to begin with. Stupid paper card even says "Do not laminate" but mine is laminated and thus intact after 40 years. SS#'s were never meant to be personal ID numbers or national ID numbers. This was a big thing when they were introduced. Unfortunately, companies use them…

Except if the SS number was not meant to identify people, what was it for ? It was meant to track people throughout their lives to set the amount they get paid by the program based on what they made / what SS tax they paid. It is terrible at that, it is terrible as a general id, and its just another example of doublethink in American politics - we want national welfare programs that are restricted only to valid citiz…

> Except if the SS number was not meant to identify people, what was it for? It was meant to track people throughout their lives to set the amount they get paid by the program based on what they made / what SS tax they paid.

Sure, but there's a huge difference between identifying people's accounts with Social Security / IRS and being a National ID card used for everything everywhere. It's was designed for the first, and intentionally forbidden for use as the latter, despite everyone using it that way anyway.

Social Security cards literally said "NOT FOR IDENTIFICATION" right on them, for 30 years, to try to stop this from happening. It did anyway...

Re: The Equifax Breach Exposes America's Identity Crisis

#114

a federal id smart card would be a great solution, but people won't let it happen because it might be "the mark of the beast". I'm not joking. I have heard that more than once.

this was also a thing when barcodes got widespread

for an entertaining version (published by "The Family" a.k.a. "Children of God"): https://youtu.be/0RfU5r63AXY?t=1009

Re: The Equifax Breach Exposes America's Identity Crisis

#115

Earlier quoted context omitted.

Ability to execute data as code is present in many languages. Almost all of them these days. I think you are saying that banks should only use C or C++ ??

Programs in C and C++ can still execute data as code with buffer overflows. They're not a panacea either.

That's right, but the OP did mention how that issue is addressed in c/c++:

> so you can't use straightforward NoExecute bits (provided by hardware and supported by OS loaders to disallow calling into dynamically allocated memory

Re: The Equifax Breach Exposes America's Identity Crisis

#116

Earlier quoted context omitted.

> National IDs are a nonstarter politically in the US. One side thinks it is undue encroachment on local rights, and the other side thinks requiring ID disenfranchises the poor and undocumented. That's the tl;dr version of course -- reality is more nuanced. As a non-American, this doesn't really make much sense to me. There's already a national ID, the Social Security card. It's just a really really terrible form of…

Social Security card is made of paper, has nothing but the number and your name, and 99% of people in the US have lost, destroyed, or never carried it to begin with. Stupid paper card even says "Do not laminate" but mine is laminated and thus intact after 40 years. SS#'s were never meant to be personal ID numbers or national ID numbers. This was a big thing when they were introduced. Unfortunately, companies use them…

I was wondering why it says "do not laminate". I found this FAQ:

> Do not laminate your card. Lamination prevents detection of many security features. However, you may cover the card with plastic or other removable material if it does not damage the card

https://faq.ssa.gov/link/portal/34011/34019/Article/3786/Can...

Re: The Equifax Breach Exposes America's Identity Crisis

#117

I don't know. I found the argument convincing that even naming the breach "identity theft" is beginning to push responsibility away from Equifax and make it seem a personal problem of those affected, or a general societal phenomenon. When in reality it's just Equifax's poor security practices. As you probably know, the exploit basically is using Java's ability to dynamically execute code from JVM bytecodes (supplied…

There are two massive problems and neither of them have anything to do with executing attacker's code.

First, for Equifax, their databases should be sufficiently isolated from front-end web servers. SQL gives you the ability to, in essence, ask the database any question the data can possibly answer. Instead, Equifax needs to do the work to enumerate all the questions they want the data to answer and put intermediate API services in place that answer only those questions. Public-facing web servers should only be allowed contact the intermediate API servers, and not the database. With data that has the value (to an attacker) that Equifax's database does, this is the minimum that needs to be done to offer reasonable security.

Second, there's an identity problem. That identities can be stolen using largely facts about people (name, address and such and, yes, SSN) is a fundamental problem in how we identify people. They're using non-secrets in a way that assumes they are secret. A Keybase identity is much closer to the model that the industry needs to adopt.

Chalking up the cause of this to flaws in some ancient Java web framework that's barely used anymore is just sweeping the true problems under the rug. The industry needs a fundamental overhaul to how they identify people and mandatory security compliance (hey...they foisted PCI-DSS on etailers and card processors, so they can't complain when something similar is foisted back on them) to keep our information safe.

Re: The Equifax Breach Exposes America's Identity Crisis

#118

The real crisis here is that Equifax isn't being held responsible for providing meaningful fraud protection beyond one year. When I lived in the UK, the banks were constantly trying to sell me "fraud protection" and "identity protection" - trying to argue with the salesdrones about why you think it is insane that they are trying to sell me protection against their own shoddy information security practices was useless…

Would you trust them after this? https://twitter.com/webster/status/906638411930497029

I don't trust them at all. Never have, never will, and I am not sure I follow the context of your comment....

Re: The Equifax Breach Exposes America's Identity Crisis

#119
It makes me wonder why identity has to be a centralized government thing. For most purposes, my google account is my primary identity. If I forget a password, resets go there, so it's my foundational identity online. Per-purpose identity seems like an okay thing. I could have a financial identity, and gaming identity, a communication identity, etc. Just like the government doesn't need to know what I own on steam, it doesn't need to know my credit score. And just like steam doesn't need to know my drivers license/social, maybe my bank shouldn't either?

Writing this, I'm realizing how closely identity and privacy are related. For any transaction with memory (like games I buy on steam) there needs to be some identity. Connecting that identity to my other identities is a privacy question. We're probably at a tipping point where we could go either way next. It scares the crap out of me to think about it that way.

Re: The Equifax Breach Exposes America's Identity Crisis

#120

Earlier quoted context omitted.

I moved from the US to the UK last year. I have seen two paper cheques in that time. It is much more common over here to pay electronically, though both Direct Debit (receiver pull) and Standing Orders (payer push) require one person giving their bank details to someone.

FWIW paper checks are not nearly as popular in the US as they once were. Especially hand written. They are ironically useful as a "secure" form of receiving payment because ACH is such a big gaping security hole. Receiving paper isolates you from handing out an account number.

[deleted]
Post reply on HN