Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

31–40 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#31

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

up till late 1990s SSN and DOB were public information, as they were printed on never-secured student IDs in American schools, for instance, and who knows where those unprotected lists went.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#33
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Serious question, how would that be any different than a SSN?

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system.

In any case, the private key is stored on a plastic ID, only released with a PIN, and the databases only store the corresponding public key.

A leak of a public key without the private key is harmless.

https://en.m.wikipedia.org/wiki/EIDAS

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#34
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Serious question, how would that be any different than a SSN?

An SSN is a username, not a password. We need an identity system with real passwords that can be changed in the case of a breach.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#35

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

Most European countries have some sort of strong online authentication with two factor, so it is doable.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#36
The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system.

In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only store the corresponding public key.

A leak of a public key without the private key is (relative to SSN) harmless.

https://en.m.wikipedia.org/wiki/EIDAS

Can we please have this in the US?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#37
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

Fantastic. Instead of one location that can be properly outfitted with the best practices let's have 1000 shitty ones.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#38

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

As always comes up, its not really identity theft, as that information doesnt help you do anything but defraud banks who are not taking time to properly verify who they are lending to. We just call it that so it's not the bank's fault. "Your identity was stolen, we couldn't do anything! "

Check a photo ID. Check a public cert. Take a fingerprint.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#39

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

Can you imagine a private company giving you an account number that you can use to do things without needing to know a password?

Would that situation persist for decades?

Post reply on HN