Live data from Hacker News

Confessions of an ID Theft Kingpin

krebsonsecurity.com

21–29 of 29 posts

Re: Confessions of an ID Theft Kingpin

#21
post #3

The usual, credit agencies ARE JUST AS BAD AS WE THOUGHT. They exchange all of our information with each other, and their security is so absolutely horrible that a 20 something hacker in Vietnam who just learned English could stay in their systems for years and build a business off of reading queries directly from these databases. It’s actually insane.

(Please don't use uppercase for emphasis. If you want to emphasize a word or phrase, put asterisks around it and it will get italicized. https://news.ycombinator.com/newsguidelines.html)

Re: Confessions of an ID Theft Kingpin

#22
post #4
post #3

The usual, credit agencies ARE JUST AS BAD AS WE THOUGHT. They exchange all of our information with each other, and their security is so absolutely horrible that a 20 something hacker in Vietnam who just learned English could stay in their systems for years and build a business off of reading queries directly from these databases. It’s actually insane.

The existence of these databases, especially given how insecure they are is, of course, a real national security threat, but the lack of reaction from the government is telling.

That is because the surveillance bureaus form part of the government. We have a microkernel government.

Re: Confessions of an ID Theft Kingpin

#24

Earlier quoted context omitted.

Are there places that it would require more to steal an identity? What countries and what type of information do they ask for?

I’m gonna rant here, but a big problem is that SSNs were never designed to be used as an identifier. It was simply used to allow someone to receive Social Security, hence the name. They literally used to have the text “Not to be used for verification.” As for its problems, there’s quite a few, but the two big ones IMO are (1) no check digits and (2) (up until relatively recently) they’re sequential. I don’t know when…

The problem is that they get relied on for authentication.

(Name+SSN is likely to be unique, the issue is that knowing a name+SSN doesn't prove you are the person with that name and SSN...)

Re: Confessions of an ID Theft Kingpin

#25

Earlier quoted context omitted.

Facebook sell your favourite movies, friends, political views and anything else they know about you to advertisers. it's a very similar business model.

They actually don't, unless you define selling as they allow advertisers to select what demographics/attributes their ads target. But the actual data stays on the Facebook servers. If you're referring to the apps having access to user data, that was not selling at all, but instead a permission originally granted by users by probably forgotten about. Basically, unless you contort the definition of selling to a very di…

Yes, that's how I define selling in the context of that sentence, as the only other way to read 'they sell your favourite movies' is the wilful misinterpretation that they actually sell movies, which would be a non-issue.

I think it's pretty clear they sell your preferences to advertisers and let apps misuse your data (there have been plenty of scandals where people didn't understand what apps would get).

This is emphatically not the business model of most businesses large or small.

Re: Confessions of an ID Theft Kingpin

#26
post #14

Earlier quoted context omitted.

Well the modern countries use documents such as ID card or passport, you can't just walk to a bank and start opening accounts from that little data. It's actually insane Americans have that archaic system.

> Well the modern countries use documents such as ID card or passport, you can't just walk to a bank and start opening accounts from that little data. It's actually insane Americans have that archaic system. It's archaic to allow opening bank accounts completely online with no physical presence/authentication required?

I don't know about you, but I wouldn't like for anyone to be able to open a bank account in my name.

Opening bank accounts (and accessing them later) without authentication is insane not archaic :)

Most banks here require physical presence and the government issued (photo) ID to open accounts, and online banking has 2FA via either physical token or at least SMS.

There is an unique number assigned to you on that ID, but it's stored basically everywhere and only used to look you up faster, never for authentication.

If you call the bank and try to do something over the phone they either tell you it's impossible or for less impactful things they randomly ask you pieces of info about older transactions, info that isn't on your ID card etc. Or just give you a plain phone PIN when you open the account.

Re: Confessions of an ID Theft Kingpin

#27
post #14

Earlier quoted context omitted.

Well the modern countries use documents such as ID card or passport, you can't just walk to a bank and start opening accounts from that little data. It's actually insane Americans have that archaic system.

> Well the modern countries use documents such as ID card or passport, you can't just walk to a bank and start opening accounts from that little data. It's actually insane Americans have that archaic system. It's archaic to allow opening bank accounts completely online with no physical presence/authentication required?

Yes because of security issues? Also some countries have chips in their ID cards that allow secure, online authentication with a card reader. Banks still want to check you in their office because of money laundry laws.

Re: Confessions of an ID Theft Kingpin

#28
post #10

I regularly wonder why we don’t have some form of physical verification token which signs things with our identity, the whole system is broken in that regard.

That would be quite nice, but I’m not sure I’d trust the government to not store and then lose all the secret keys near instantly. If they can overcome that, sign me up.

The beauty of public key cryptography is they don’t need to hold your private key, ever :)

Re: Confessions of an ID Theft Kingpin

#29

Earlier quoted context omitted.

They actually don't, unless you define selling as they allow advertisers to select what demographics/attributes their ads target. But the actual data stays on the Facebook servers. If you're referring to the apps having access to user data, that was not selling at all, but instead a permission originally granted by users by probably forgotten about. Basically, unless you contort the definition of selling to a very di…

Yes, that's how I define selling in the context of that sentence, as the only other way to read 'they sell your favourite movies' is the wilful misinterpretation that they actually sell movies, which would be a non-issue. I think it's pretty clear they sell your preferences to advertisers and let apps misuse your data (there have been plenty of scandals where people didn't understand what apps would get). This is emp…

I think I see the confusion between us. You don't see the difference between selling data to a company, and selling ad space where the advertiser can choose for what demographics it shows up for.

Let me try to make it more clear. Do you see the difference between "hey Chase Bank, do you want to buy this file containing data about grey-area's interests, age, political stance, credit score, purchasing habits, etc." versus "hey Chase Bank, do you want to put an ad on my website that is only shown to people with credit scores above 600 and are interested in savings accounts"?

If they both seem the same to you, then I don't think your perspective is one that a reasonable person would take. If you do see the difference, then Facebook is doing the latter, but the word "selling data" conjures the former, which you do recognize as a different matter.

I'm going to ignore the nonsensical definition you gave of selling data = selling movies, being the only other definition of selling you could imagine, in hopes that it was just an oversight.

Post reply on HN