Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

41–50 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#41

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

Most European countries have some sort of strong online authentication with two factor, so it is doable.

For example?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#43

Earlier quoted context omitted.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

Fantastic. Instead of one location that can be properly outfitted with the best practices let's have 1000 shitty ones.

As an American... don't trust for a second that they will follow "best practices."

After all, how did the NSA's top-secret Vault7 weapons get stolen considering that they were following "best practices"? And then proceed to bring havoc to the world with WannaCry...

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#45

Earlier quoted context omitted.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

This is just an unhelpful argument. You might take issue with how government functions, and necessary improvements, but these government functions are still required in a developed nation.

Clarification: OC doesn’t seem to be arguing that these govt functions shouldn’t exist; they’re arguing that it’s wrong to trust govt with digital security more than we trust private companies.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#46

Earlier quoted context omitted.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, only released with a PIN, and the databases only store the corresponding public key. A leak of a public key without the private key is harmless. https://en.m.wikipedia.org/wiki/EIDAS

That makes more sense than the OP's suggestion.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#47
There is seemingly less and less reason for identities at all.

Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password.

And before anyone makes the terrorism argument, it would seem that our country has deprioritized that initiative.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#49
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Serious question, how would that be any different than a SSN?

SSNs sit in a middle ground between being public and private. A large number of companies and organizations use it to both identify people and as proof of identity. Those are two separate functions.

When I go to a bank for a loan, I should give them some form of private id as proof I am who I say I am (this doesn't have to be a federally issued number).

When companies communicate about me with each other (such as running a credit check on me which is likely why T-Mobile even had SSNs) they should use my public id.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#50

Earlier quoted context omitted.

Well, the government in the US functions just fine without the centralized ID System the OP is wishing for, even though stuff like this occurs. There is literally no reason why Americans would trust the central government to be more secure than T-Mobile at this point.

It clearly doesn’t, and it’s foolish to say it does based on the evidence.

WannaCry was developed with stolen NSA technology in 2017. Despite that the National Security Agency should be more secure than anyone and these tools weren't available to the public. You really trust a public service, not run by the Security Agency, to be more secure than that?
Post reply on HN