Live data from Hacker News

No, I did not hack your MS Exchange server

krebsonsecurity.com

11–20 of 74 posts

Re: No, I did not hack your MS Exchange server

#11
post #3

> What was the subdomain I X’d out of his message? Just my Social Security number. I’d been doxed via DNS. That would freak me the fuck out wow.

It always amazes me that in the US there is such a weak identification system, relying on a single number.

Then it is apparently to the owner of said number to worry if it leaked.

Re: No, I did not hack your MS Exchange server

#13
post #3

> What was the subdomain I X’d out of his message? Just my Social Security number. I’d been doxed via DNS. That would freak me the fuck out wow.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

> It always amazes me that in the US there is such a weak identification system, relying on a single number.

Offer Govs/LEO/Biz an alternative that will allow them stronger & less visible influence over the public and it will be adopted yesterday.

Re: No, I did not hack your MS Exchange server

#14
post #3

> What was the subdomain I X’d out of his message? Just my Social Security number. I’d been doxed via DNS. That would freak me the fuck out wow.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

US Social Security cards used to say "NOT FOR IDENTIFICATION" but I guess it's just too hard to pass up a good primary key.

Re: No, I did not hack your MS Exchange server

#15
post #3

> What was the subdomain I X’d out of his message? Just my Social Security number. I’d been doxed via DNS. That would freak me the fuck out wow.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license.

My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding to the closest hospitals. But that doesn't worry me, because I don't fear identity theft, it just doesn't exist in Italy.

Instead, as a result of America's allergy to ID, they are essentially the only country where identity theft is a thing.

Re: No, I did not hack your MS Exchange server

#16
post #9
post #8

Earlier quoted context omitted.

Iirc some ppl used it to extract his credit report from experian - we need better govt identification than just a few numbers

I'm surprised that governments aren't using some kind of 2FA tokens for peoples' identities, while credit cards are.

I don't know about most of Europe, but in Norway, we use a 2FA system called BankID. You authenticate with either with your phone using a custom SIM app, or an app, or a OTP device. This system is used for everything from banking, to checking taxes, medical records, or signing documents.

Re: No, I did not hack your MS Exchange server

#17

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

US Social Security cards used to say "NOT FOR IDENTIFICATION" but I guess it's just too hard to pass up a good primary key.

When I was first enrolled at University of Illinois of Chicago in 1985, your SSN was your student ID. You could log in to the mainframe using your SSN in the username field (although thankfully, the actual user ID was a sequentially assigned five-digit number and not the SSN. I was U10754). I think around 1986 or 1987, universities were instructed to stop using SSNs as student ID numbers.

Re: No, I did not hack your MS Exchange server

#18
post #17

Earlier quoted context omitted.

US Social Security cards used to say "NOT FOR IDENTIFICATION" but I guess it's just too hard to pass up a good primary key.

When I was first enrolled at University of Illinois of Chicago in 1985, your SSN was your student ID. You could log in to the mainframe using your SSN in the username field (although thankfully, the actual user ID was a sequentially assigned five-digit number and not the SSN. I was U10754). I think around 1986 or 1987, universities were instructed to stop using SSNs as student ID numbers.

> I think around 1986 or 1987, universities were instructed to stop using SSNs as student ID numbers.

And around 2005 they actually mostly stopped.

Re: No, I did not hack your MS Exchange server

#19
post #15

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

5 out of the 9 numbers for an American social security number is also derived from location and date of birth.

Re: No, I did not hack your MS Exchange server

#20
post #17

Earlier quoted context omitted.

US Social Security cards used to say "NOT FOR IDENTIFICATION" but I guess it's just too hard to pass up a good primary key.

When I was first enrolled at University of Illinois of Chicago in 1985, your SSN was your student ID. You could log in to the mainframe using your SSN in the username field (although thankfully, the actual user ID was a sequentially assigned five-digit number and not the SSN. I was U10754). I think around 1986 or 1987, universities were instructed to stop using SSNs as student ID numbers.

In the early 90s I had a professor who passed around a sheet of paper for us the first day of class to write down our names and our SSN.

I had to point out to him after class that was a rather boneheaded idea (I'm sure I was a bit more polite than that).

Post reply on HN