Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

21–30 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#21
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

I can agree. At one of my previous employers, IT management was adamant that no password vaults of any kinds could be used. It was a bigger company with tons of various systems to get into all with different sets of requirements. So what was the result? Average user ended up storing passwords info in excel and text files. Yay.

I think only recently there was some movement to approve a vendor there.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#22
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

https://twitter.com/damienmiller/status/1427195852011937797

OpenSSH from 2014. That'll do it.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#23
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system.

In any case, the private key is stored on a plastic ID, only released with a PIN, and the databases only store the corresponding public key.

A leak of a public key without the private key is harmless.

https://en.m.wikipedia.org/wiki/EIDAS

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#24

Will T-Mobile or anyone in a leadership position there face consequences for this?

Target might be a good comparison.

The total cost to them was ~$300M, and the CEO had to step down. Though $300M when your annual revenues are ~90B isn't really a huge hit. Less than 1/10th of net earnings for a year.

https://www.thesslstore.com/blog/2013-target-data-breach-set...

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#26
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

This is just an unhelpful argument. You might take issue with how government functions, and necessary improvements, but these government functions are still required in a developed nation.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#27
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Serious question, how would that be any different than a SSN?

SSNs aren't a great source of identity mostly because they were never designed to be - they aren't unique, until somewhat recently they were issued in a predictable order, an individual can have their SSN changed, and since they are only 9 digits we're going to run out of them on a practical timeline, etc.

They became a defacto identifier for many institutions just because US citizens and permanent residents generally have one - but aside from convenience, they're pretty problematic compared even to something like a UUID/GUID.

If you were trying to design a true national ID number, you'd probably want to approach the problem more like a database designer would: you'd want something that had possible unique values far exceeding the reasonable number of people you expect to exist before the collapse of society, that was reasonably random and difficult to predict based on other known attributes about the person, that by spec was never shared with another person, etc.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#28

Any entity using SSN and DOB as identity verification should be solely liable for any loss caused by fraud.

Are you talking about T-Mobile, or the companies that fraudsters actually go to with this information? You're not going to do much damage creating a T-Mobile account with my SSN. You will signing up for a credit card or resetting the password on my bank account.

Anyone that gets defrauded because they are using SSN/DOB/address as some type of identify verification/signature/authorization mechanism.

Which would include pretty much all consumer level/retail financial companies I think, but certainly is not limited to them.

When entity A defrauds entity B by pretending to be entity C, entity C should not be affected in any way, other than letting entity B know they were not party to the transaction.

In other words, it should be entity B’s responsibility to prove entity C engaged in a transaction with them before being able to affect entity C’s credit.

And that would solve all of this nonsense very quickly.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#29

Earlier quoted context omitted.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

This is just an unhelpful argument. You might take issue with how government functions, and necessary improvements, but these government functions are still required in a developed nation.

Well, the government in the US functions just fine without the centralized ID System the OP is wishing for, even though stuff like this occurs.

There is literally no reason why Americans would trust the central government to be more secure than T-Mobile at this point.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#30

Earlier quoted context omitted.

This is just an unhelpful argument. You might take issue with how government functions, and necessary improvements, but these government functions are still required in a developed nation.

Well, the government in the US functions just fine without the centralized ID System the OP is wishing for, even though stuff like this occurs. There is literally no reason why Americans would trust the central government to be more secure than T-Mobile at this point.

It clearly doesn’t, and it’s foolish to say it does based on the evidence.
Post reply on HN