Live data from Hacker News

No, I did not hack your MS Exchange server

krebsonsecurity.com

41–50 of 74 posts

Re: No, I did not hack your MS Exchange server

#41

Earlier quoted context omitted.

Pretty sure every American's SSN has been public since 2017 anyways. Thanks Equifax!

I thought for quite awhile that the whole list should be made public on a pre-announced date to "scorch the earth". On that date, liability for any fraud committed using the data would be placed on the party improperly using SSNs for authentication tokens. The Equifax breach did the publishing part, but nothing changed with liability. A golden opportunity missed to fix this particular bullshit.

100% agree with this. Our SSNs are fully “compromised” many times over at this point. Scare quotes because—as far as I know—they weren’t originally regarded as a secret to begin with.

But the fiction of a secret SSN still persists. You're told to protect it; sensitive financial documents ask for it as part of proving you’re you; forgotten password pages use the last 4 digits as some sort of 2nd factor.

The best thing that could happen is if the names and corresponding numbers were published far and wide. So obviously public that nobody could keep this fiction up.

Banks and other high-stakes firms need to figure out how they want to identify their clients. It’s not an easy problem to solve, I get that. But that doesn’t mean we should be happy with them taking the easy way out.

Re: No, I did not hack your MS Exchange server

#42
post #15

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

When your identity gets stolen enough times, the IRS assigns you an identity protection PIN and mails you a new one every year. Too bad it's only useful for your taxes.

Re: No, I did not hack your MS Exchange server

#43
post #15

Earlier quoted context omitted.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

I live in Denmark so also Europe. Our social security number (which can be guessed with enough information and a few tries) has been incorrectly used as a password instead of a key just like you describe. You make a call, provide this number and the clerk on the phone believes that you are who you claim to be. Nowadays things are better because computers are used everywhere We have a national ID system using 2FA whic…

While all that is accurate, it should be noted that they have already mitigated some of the problems mentioned above (no more displaying number of keys left), but also that the entire system is being replaced this year with one that does not rely on a physical cardboard key card, but can use something like a Yubikey instead.

You can also change your username to something other than your CPR-number. Indeed, the problem lies more with other services that has used it as a password rather than 'username'. But those are rarer to come by these days.

Re: No, I did not hack your MS Exchange server

#44

thoughts specific to SSN: Seems like the SSA will will run out of 9-digit usable numbers in about 1 generation (~70 years). Then what ? Is this software's next Y2K ? https://www.quora.com/Why-havent-we-run-out-of-Social-Securi...

A generation is generally defined as 20 years. So you mean 3.5 generations i guess?

Re: No, I did not hack your MS Exchange server

#45

thoughts specific to SSN: Seems like the SSA will will run out of 9-digit usable numbers in about 1 generation (~70 years). Then what ? Is this software's next Y2K ? https://www.quora.com/Why-havent-we-run-out-of-Social-Securi...

Recycle old ones? Add a few digits? They can give 10 years notice, then a bunch of corps will kick off huge projects for consultants.

Re: No, I did not hack your MS Exchange server

#46

thoughts specific to SSN: Seems like the SSA will will run out of 9-digit usable numbers in about 1 generation (~70 years). Then what ? Is this software's next Y2K ? https://www.quora.com/Why-havent-we-run-out-of-Social-Securi...

There would need to be a billion people in the US for us to run out of SSNs. I find it highly unlikely that our population will triple in 70 years. The Census Bureau finds it unlikely, too, considering they expect us to add only 76m by 2060. They could also decide to re-use the SSNs of those who have been dead for decades.

Re: No, I did not hack your MS Exchange server

#49
post #29

Earlier quoted context omitted.

I see, the good old racist card. But no, you're wrong. I have opened bank accounts in three EU countries and the procedure was the same everywhere. No ID, no bank account. I still have to see a headline like "identity theft ruined my life" in any other language than English. Every single time "furto di identità" makes the news in Italy, it's just about someone impersonating a famous person on social media to scam the…

Identity theft if very common in Italy for pension fraud, people don’t report deaths of their elderly parents and assume their identities to cash in pensions.

It's not really the same—a caregiver keeping on doing bureaucracy tasks after a person's death, vs. an unknown person using a living person's identity to get loans or credit cards.

Re: No, I did not hack your MS Exchange server

#50
post #22

Earlier quoted context omitted.

Absolutely, but it's more effort than knowing an SSN and being immediately able to get a loan in the name of that person. That would be ridiculous in Europe.

That’s pretty ridiculous in the US as well. An SSN is never enough. Usually they will need some copy of a state ID and proof of access to a mailing address on your credit history.

I didn't say that, the US government does:

> Identity thieves can use your number and your good credit to apply for more credit in your name. Then, they use the credit cards and don’t pay the bills, it damages your credit. You may not find out that someone is using your number until you’re turned down for credit, or you begin to get calls from unknown creditors demanding payment for items you never bought.

https://www.ssa.gov/pubs/EN-05-10064.pdf

Post reply on HN