Live data from Hacker News

No, I did not hack your MS Exchange server

krebsonsecurity.com

31–40 of 74 posts

Re: No, I did not hack your MS Exchange server

#31

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

US Social Security cards used to say "NOT FOR IDENTIFICATION" but I guess it's just too hard to pass up a good primary key.

Hum... When normal people say "identification" the almost always mean what we understand by "authentication"¹. They main intended use of a social security number is as a key, that's the intended use 99.(some more 9s)% of the times a government gives a number to somebody.

1 - And when they say "authentication", they almost always mean what we understand by "non-repudiation".

Re: No, I did not hack your MS Exchange server

#32
post #19
post #15

Earlier quoted context omitted.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

5 out of the 9 numbers for an American social security number is also derived from location and date of birth.

This was finally done away with in 2011. I only found out because I was surprised that our second child's SSN (issued in 2012) had a different prefix than that of our first child (2009).

Re: No, I did not hack your MS Exchange server

#33
post #3

> What was the subdomain I X’d out of his message? Just my Social Security number. I’d been doxed via DNS. That would freak me the fuck out wow.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

And possession of the original paper SSN card is sometimes required as a form of identity. Not the hardest thing to print.

Re: No, I did not hack your MS Exchange server

#35
post #3

> What was the subdomain I X’d out of his message? Just my Social Security number. I’d been doxed via DNS. That would freak me the fuck out wow.

Pretty sure every American's SSN has been public since 2017 anyways. Thanks Equifax!

I thought for quite awhile that the whole list should be made public on a pre-announced date to "scorch the earth". On that date, liability for any fraud committed using the data would be placed on the party improperly using SSNs for authentication tokens.

The Equifax breach did the publishing part, but nothing changed with liability. A golden opportunity missed to fix this particular bullshit.

Re: No, I did not hack your MS Exchange server

#36
post #22

Earlier quoted context omitted.

I live in Denmark so also Europe. Our social security number (which can be guessed with enough information and a few tries) has been incorrectly used as a password instead of a key just like you describe. You make a call, provide this number and the clerk on the phone believes that you are who you claim to be. Nowadays things are better because computers are used everywhere We have a national ID system using 2FA whic…

Absolutely, but it's more effort than knowing an SSN and being immediately able to get a loan in the name of that person. That would be ridiculous in Europe.

That’s pretty ridiculous in the US as well. An SSN is never enough. Usually they will need some copy of a state ID and proof of access to a mailing address on your credit history.

Re: No, I did not hack your MS Exchange server

#37
post #29
post #23

Earlier quoted context omitted.

> identity theft [...] just doesn’t exist in Italy Big lol. The country used to be famous for frauds and scams! Of course identity fraud exists, but precisely because everyone expects it, the majority of systems errs on the side of caution and requires validation from multiple sources. The result is that fraud processes become so much harder to pull off that fewer and fewer bad guys attempt it, but on the other hand…

I see, the good old racist card. But no, you're wrong. I have opened bank accounts in three EU countries and the procedure was the same everywhere. No ID, no bank account. I still have to see a headline like "identity theft ruined my life" in any other language than English. Every single time "furto di identità" makes the news in Italy, it's just about someone impersonating a famous person on social media to scam the…

Identity theft if very common in Italy for pension fraud, people don’t report deaths of their elderly parents and assume their identities to cash in pensions.

Re: No, I did not hack your MS Exchange server

#38
post #15

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

'No Way To Prevent This,' Says Only Nation Where This Regularly Happens.

Re: No, I did not hack your MS Exchange server

#39
post #17

Earlier quoted context omitted.

US Social Security cards used to say "NOT FOR IDENTIFICATION" but I guess it's just too hard to pass up a good primary key.

When I was first enrolled at University of Illinois of Chicago in 1985, your SSN was your student ID. You could log in to the mainframe using your SSN in the username field (although thankfully, the actual user ID was a sequentially assigned five-digit number and not the SSN. I was U10754). I think around 1986 or 1987, universities were instructed to stop using SSNs as student ID numbers.

The State (Commonwealth!) of Massachusetts used your SSN for your Driver License number, as recently as the mid-1990s.

Every time you had to show ID anywhere, you were giving your SSN away.

Post reply on HN