Live data from Hacker News

No, I did not hack your MS Exchange server

krebsonsecurity.com

21–30 of 74 posts

Re: No, I did not hack your MS Exchange server

#21
post #15

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

I live in Denmark so also Europe. Our social security number (which can be guessed with enough information and a few tries) has been incorrectly used as a password instead of a key just like you describe. You make a call, provide this number and the clerk on the phone believes that you are who you claim to be.

Nowadays things are better because computers are used everywhere We have a national ID system using 2FA which is pretty safe. Unfortunately, identify theft is still a thing.

Recently someone installed keyloggers on public computers. The second factor in the 2FA is a cardboard card with a list of one time password codes. You use a code on each sign in.

The criminals were able to determine when there were only a few codes left on the card. You then get a new cardboard card sent to your home address. They would stalk their victim's mail box and steal the new card as soon as it arrived.

With user name (your social security number) and password from the key logger together with the 2FA codes they were able to perform identity theft.

It's not easy to guard against attacks like this.

Re: No, I did not hack your MS Exchange server

#22
post #15

Earlier quoted context omitted.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

I live in Denmark so also Europe. Our social security number (which can be guessed with enough information and a few tries) has been incorrectly used as a password instead of a key just like you describe. You make a call, provide this number and the clerk on the phone believes that you are who you claim to be. Nowadays things are better because computers are used everywhere We have a national ID system using 2FA whic…

Absolutely, but it's more effort than knowing an SSN and being immediately able to get a loan in the name of that person. That would be ridiculous in Europe.

Re: No, I did not hack your MS Exchange server

#23
post #15

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

> identity theft [...] just doesn’t exist in Italy

Big lol. The country used to be famous for frauds and scams! Of course identity fraud exists, but precisely because everyone expects it, the majority of systems errs on the side of caution and requires validation from multiple sources. The result is that fraud processes become so much harder to pull off that fewer and fewer bad guys attempt it, but on the other hand every validation step becomes a bureaucratic nightmare (“did you include certificate X from office A, Y from office B, and Z from office C, as well as your ID card, health card, tax card, and recent pictures? No? Sorry, no cookie for you.”)

This is also why the country has a pretty secure and advanced way to carry out official acts electronically (PEC) - because otherwise fraud would be even more rampant.

I do agree that the “anglo” hate for ID documents (“such Napoleonic constructs, so barbaric!”) leaves the door open to scammers, but it’s not like they don’t exist in Italy too.

Re: No, I did not hack your MS Exchange server

#24
post #3

> What was the subdomain I X’d out of his message? Just my Social Security number. I’d been doxed via DNS. That would freak me the fuck out wow.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

Basically the same in Denmark, I believe many other European nations have a similar situation.

Re: No, I did not hack your MS Exchange server

#25
post #3

> What was the subdomain I X’d out of his message? Just my Social Security number. I’d been doxed via DNS. That would freak me the fuck out wow.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The story of how this happened is quite interesting. CGP Grey did a video about how it evolved [0]. I'm not American so I can't judge how likely it is to ever change because it seems to be politically radioactive to propose a government mandated ID.

We had a similar issue in Australia, but our workaround is that your drivers license (or ID card from the equivalent of the DMV) typically acts as your ID.

[0] https://www.youtube.com/watch?v=Erp8IAUouus

Re: No, I did not hack your MS Exchange server

#27
post #17

Earlier quoted context omitted.

US Social Security cards used to say "NOT FOR IDENTIFICATION" but I guess it's just too hard to pass up a good primary key.

When I was first enrolled at University of Illinois of Chicago in 1985, your SSN was your student ID. You could log in to the mainframe using your SSN in the username field (although thankfully, the actual user ID was a sequentially assigned five-digit number and not the SSN. I was U10754). I think around 1986 or 1987, universities were instructed to stop using SSNs as student ID numbers.

Lol. My SUNY school addressed this by suppressing the first three numbers.

Considering that about 30% of the student body seemed to be from Islip, it was pretty trivial to guess the first three.

Re: No, I did not hack your MS Exchange server

#28
post #25

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The story of how this happened is quite interesting. CGP Grey did a video about how it evolved [0]. I'm not American so I can't judge how likely it is to ever change because it seems to be politically radioactive to propose a government mandated ID. We had a similar issue in Australia, but our workaround is that your drivers license (or ID card from the equivalent of the DMV) typically acts as your ID. [0] https://ww…

My first driver's license number was my SSN

Re: No, I did not hack your MS Exchange server

#29
post #23
post #15

Earlier quoted context omitted.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

> identity theft [...] just doesn’t exist in Italy Big lol. The country used to be famous for frauds and scams! Of course identity fraud exists, but precisely because everyone expects it, the majority of systems errs on the side of caution and requires validation from multiple sources. The result is that fraud processes become so much harder to pull off that fewer and fewer bad guys attempt it, but on the other hand…

I see, the good old racist card. But no, you're wrong. I have opened bank accounts in three EU countries and the procedure was the same everywhere. No ID, no bank account.

I still have to see a headline like "identity theft ruined my life" in any other language than English. Every single time "furto di identità" makes the news in Italy, it's just about someone impersonating a famous person on social media to scam the followers, which is a completely different thing than in the US.

So yeah of course scams and credit card skimmers exist in Italy (though the US's disdain for chip and PIN would be another interesting topic). Dishonest telemarketers convince gullible people to switch into more expensive utilities contracts. But identity theft in the US is not in any way comparable to "scamming".

And yeah, PEC ("registered email") is pretty cool. :)

Re: No, I did not hack your MS Exchange server

#30
post #23
post #15

Earlier quoted context omitted.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

> identity theft [...] just doesn’t exist in Italy Big lol. The country used to be famous for frauds and scams! Of course identity fraud exists, but precisely because everyone expects it, the majority of systems errs on the side of caution and requires validation from multiple sources. The result is that fraud processes become so much harder to pull off that fewer and fewer bad guys attempt it, but on the other hand…

When I visit Italy I’m often impressed by the physical lock & key systems in use even in pretty humble domiciles. Those keys look incredibly complex compared to anything I normally see in the US short of, say, a Mult-T-Lock.
Post reply on HN