Live data from Hacker News

No, I did not hack your MS Exchange server

krebsonsecurity.com

51–60 of 74 posts

Re: No, I did not hack your MS Exchange server

#52
post #29
post #23

Earlier quoted context omitted.

> identity theft [...] just doesn’t exist in Italy Big lol. The country used to be famous for frauds and scams! Of course identity fraud exists, but precisely because everyone expects it, the majority of systems errs on the side of caution and requires validation from multiple sources. The result is that fraud processes become so much harder to pull off that fewer and fewer bad guys attempt it, but on the other hand…

I see, the good old racist card. But no, you're wrong. I have opened bank accounts in three EU countries and the procedure was the same everywhere. No ID, no bank account. I still have to see a headline like "identity theft ruined my life" in any other language than English. Every single time "furto di identità" makes the news in Italy, it's just about someone impersonating a famous person on social media to scam the…

> the good old racist card

Mate, I’m Italian ;) I might be self-hating at best.

Re: No, I did not hack your MS Exchange server

#53
post #29
post #23

Earlier quoted context omitted.

> identity theft [...] just doesn’t exist in Italy Big lol. The country used to be famous for frauds and scams! Of course identity fraud exists, but precisely because everyone expects it, the majority of systems errs on the side of caution and requires validation from multiple sources. The result is that fraud processes become so much harder to pull off that fewer and fewer bad guys attempt it, but on the other hand…

I see, the good old racist card. But no, you're wrong. I have opened bank accounts in three EU countries and the procedure was the same everywhere. No ID, no bank account. I still have to see a headline like "identity theft ruined my life" in any other language than English. Every single time "furto di identità" makes the news in Italy, it's just about someone impersonating a famous person on social media to scam the…

I don't speak Italian so I can't really say anything about that, but searching "identity fraud" in Dutch turns up plenty of results: https://www.google.nl/search?q=identiteitsfraude&hl=nl

Here's a "identity theft ruined my life" story: https://www.ad.nl/tech/hanna-krijgt-door-identiteitsfraude-i...

The problem might be worse in the US and UK, but it's not like it doesn't exist at all in the EU.

Re: No, I did not hack your MS Exchange server

#54
post #23

Earlier quoted context omitted.

> identity theft [...] just doesn’t exist in Italy Big lol. The country used to be famous for frauds and scams! Of course identity fraud exists, but precisely because everyone expects it, the majority of systems errs on the side of caution and requires validation from multiple sources. The result is that fraud processes become so much harder to pull off that fewer and fewer bad guys attempt it, but on the other hand…

When I visit Italy I’m often impressed by the physical lock & key systems in use even in pretty humble domiciles. Those keys look incredibly complex compared to anything I normally see in the US short of, say, a Mult-T-Lock.

It’s necessary. I grew up on the outskirts of a pretty wealthy, pretty law-abiding Italian city, and still: the flats on the first floor were burgled twice in a few years, my family’s own flat was squatted before it was even finished, and bikes or motorbikes were routinely stolen. My dad just told me this week that the closet where his amateur football club keeps training material was burgled: the idiots literally cut through the wall to remove the hardened door, just to get to a few footballs and plastic cones. This was the fifth attempt in two years, and they finally succeeded - thanks to the lockdown there was nobody around, my dad found out just because they littered some of the training bags nearby. Security remains a big problem.

Re: No, I did not hack your MS Exchange server

#55
post #49

Earlier quoted context omitted.

Identity theft if very common in Italy for pension fraud, people don’t report deaths of their elderly parents and assume their identities to cash in pensions.

It's not really the same—a caregiver keeping on doing bureaucracy tasks after a person's death, vs. an unknown person using a living person's identity to get loans or credit cards.

It’s not just direct carers and it’s still an identity theft, what identity theft can be used for ranges between different countries based on financial incentives in some countries getting a loan or credit is far more easier than others in others state pensions and benefits are higher.

In the US stealing the identity of a 30 year old with decent credit can allow you to rack up a decent bill in their name. In Italy the state pension is universal and is about €14,000 a year and whilst in the US technically you can get far more in social security payments the people who are susceptible to identity theft in that group tend to not be the ones who maxed out their contributions over the past 30-40 years.

Re: No, I did not hack your MS Exchange server

#56
post #29
post #23

Earlier quoted context omitted.

> identity theft [...] just doesn’t exist in Italy Big lol. The country used to be famous for frauds and scams! Of course identity fraud exists, but precisely because everyone expects it, the majority of systems errs on the side of caution and requires validation from multiple sources. The result is that fraud processes become so much harder to pull off that fewer and fewer bad guys attempt it, but on the other hand…

I see, the good old racist card. But no, you're wrong. I have opened bank accounts in three EU countries and the procedure was the same everywhere. No ID, no bank account. I still have to see a headline like "identity theft ruined my life" in any other language than English. Every single time "furto di identità" makes the news in Italy, it's just about someone impersonating a famous person on social media to scam the…

I have to wonder if part of the difference is down to how we deal with creditors in the US and the financial welfare of the population. We have a huge population living paycheck to paycheck with almost no cushion for crisis and we have a system where creditors can take the money from your bank account or directly from you wages.

If the money acquired by a creditor was what was needed to pay your rent you could be looking at eviction in short order. The law in my state until 2020 required only a 3 day delay to begin eviction for non payment. It used to be possible to be due on May 1st. Receive an eviction notice on May 4th and be homeless by mid month. I think it now takes a whole month for your life to disintegrate.

Being homeless doesn't bode extremely well for you continued employment as a handful of missed days can terminate your employment.

Being jobless doesn't bode well for your health insurance which there is no way you can afford to maintain past employment.

Being without insurance, job, money doesn't bode well for being able to afford medical care hopefully you aren't receiving continuing care for a major medical situation because you might be dead.

I have to hope western Europe isn't remotely like that.

Re: No, I did not hack your MS Exchange server

#57
post #39
post #17

Earlier quoted context omitted.

When I was first enrolled at University of Illinois of Chicago in 1985, your SSN was your student ID. You could log in to the mainframe using your SSN in the username field (although thankfully, the actual user ID was a sequentially assigned five-digit number and not the SSN. I was U10754). I think around 1986 or 1987, universities were instructed to stop using SSNs as student ID numbers.

The State (Commonwealth!) of Massachusetts used your SSN for your Driver License number, as recently as the mid-1990s. Every time you had to show ID anywhere, you were giving your SSN away.

When looking up the details of the incarceration of a POS we had locked up in the state of Washington we discovered his electronically available prior warrants show his entire SSN NOW.

Re: No, I did not hack your MS Exchange server

#58
post #53
post #29

Earlier quoted context omitted.

I see, the good old racist card. But no, you're wrong. I have opened bank accounts in three EU countries and the procedure was the same everywhere. No ID, no bank account. I still have to see a headline like "identity theft ruined my life" in any other language than English. Every single time "furto di identità" makes the news in Italy, it's just about someone impersonating a famous person on social media to scam the…

I don't speak Italian so I can't really say anything about that, but searching "identity fraud" in Dutch turns up plenty of results: https://www.google.nl/search?q=identiteitsfraude&hl=nl Here's a "identity theft ruined my life" story: https://www.ad.nl/tech/hanna-krijgt-door-identiteitsfraude-i... The problem might be worse in the US and UK, but it's not like it doesn't exist at all in the EU.

[deleted]

Re: No, I did not hack your MS Exchange server

#59
post #49

Earlier quoted context omitted.

It's not really the same—a caregiver keeping on doing bureaucracy tasks after a person's death, vs. an unknown person using a living person's identity to get loans or credit cards.

It’s not just direct carers and it’s still an identity theft, what identity theft can be used for ranges between different countries based on financial incentives in some countries getting a loan or credit is far more easier than others in others state pensions and benefits are higher. In the US stealing the identity of a 30 year old with decent credit can allow you to rack up a decent bill in their name. In Italy th…

No, it's identity fraud which is a superset of identity theft.

Re: No, I did not hack your MS Exchange server

#60
post #15

Earlier quoted context omitted.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

When your identity gets stolen enough times, the IRS assigns you an identity protection PIN and mails you a new one every year. Too bad it's only useful for your taxes.

Just the fact that there is a process for that, and you have people whose "identity gets stolen enough times", is worth an Onion headline...
Post reply on HN