Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

51–60 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#51

Earlier quoted context omitted.

Most European countries have some sort of strong online authentication with two factor, so it is doable.

For example?

Not sure it's strong, but The Netherlands has DigiD with 2FA?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#54
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

Or, just a thought, design an identifier where compromising one system doesn't immediately compromise all the individual data contained within it. SSN breaches only really hurt because its exposure means instant compromise of identity, whereas a system with some sort of partial key, signature, etc, where the user retains a portion means they have to compromise the database and the user, and if a "central" system (i.e. government, private key issuer, etc) is compromised you can re-issue the user identifier portions.

If anything it might encourage companies to smarten up if there was a law on the books that required companies that get compromised to pay for the re-issuing of the user tokens to every impacted individual.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#55

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

Most European countries have some sort of strong online authentication with two factor, so it is doable.

Of course it's doable.

But SSNs aren't even ONE factor.

It's time the US government entered the 21st century.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#56

Earlier quoted context omitted.

Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, only released with a PIN, and the databases only store the corresponding public key. A leak of a public key without the private key is harmless. https://en.m.wikipedia.org/wiki/EIDAS

Yep. Public private key is absolutely great for this.

SSH been using it all these years and still going strong.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#57
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Serious question, how would that be any different than a SSN?

If the US was capable of rational policy decisions, you could do any of a number of things to present a trusted representation of your identity without a “secret” 9 digit number.

We already have such a system, it’s called a passport, and it has complementary “cousins” like passport cards and nexus cards. That framework could easily be built upon, but there is a mountain of paranoia and stupid to climb first.

Instead we have the current system where fraud is endemic and where millions of people are marginalized by poor access to ID.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#58

Well, at least it doesn't compromise the cheaper resellers (like Boost or Mint Mobile or Metro). Ironic that the cheap resellers are safer than the supposedly premium network.

Does the article mention this? Sorry I have been looking for this information and did not see it. Regardless I am a Mint Mobile user and I don’t think I gave my SSN to Mint. Hell I don’t even think they have my DOB.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#59
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

https://twitter.com/damienmiller/status/1427195852011937797

> That allowed the person to eventually pivot to the LAN.

Once on the LAN, the same person claims the data was "sitting in plaintext on an insecure backup server": https://twitter.com/und0xxed/status/1427639599636041742

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#60

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

As always comes up, its not really identity theft, as that information doesnt help you do anything but defraud banks who are not taking time to properly verify who they are lending to. We just call it that so it's not the bank's fault. "Your identity was stolen, we couldn't do anything! " Check a photo ID. Check a public cert. Take a fingerprint.

I have heard that in some poorer countries, authorities are requiring fingerprints, passport size photos, and even video statements for certain transactions and real estate.
Post reply on HN