Earlier quoted context omitted.
Most European countries have some sort of strong online authentication with two factor, so it is doable.
For example?
T-Mobile: Breach Exposed SSN/DOB of 40M+ People
51–60 of 282 posts
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#52Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#53No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#54There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.
Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.
If anything it might encourage companies to smarten up if there was a law on the books that required companies that get compromised to pay for the re-issuing of the user tokens to every impacted individual.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#55With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.
Most European countries have some sort of strong online authentication with two factor, so it is doable.
But SSNs aren't even ONE factor.
It's time the US government entered the 21st century.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#56Earlier quoted context omitted.
Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.
The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, only released with a PIN, and the databases only store the corresponding public key. A leak of a public key without the private key is harmless. https://en.m.wikipedia.org/wiki/EIDAS
SSH been using it all these years and still going strong.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#57There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.
Serious question, how would that be any different than a SSN?
We already have such a system, it’s called a passport, and it has complementary “cousins” like passport cards and nexus cards. That framework could easily be built upon, but there is a mountain of paranoia and stupid to climb first.
Instead we have the current system where fraud is endemic and where millions of people are marginalized by poor access to ID.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#58Well, at least it doesn't compromise the cheaper resellers (like Boost or Mint Mobile or Metro). Ironic that the cheap resellers are safer than the supposedly premium network.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#59As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.
https://twitter.com/damienmiller/status/1427195852011937797
Once on the LAN, the same person claims the data was "sitting in plaintext on an insecure backup server": https://twitter.com/und0xxed/status/1427639599636041742
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#60With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.
As always comes up, its not really identity theft, as that information doesnt help you do anything but defraud banks who are not taking time to properly verify who they are lending to. We just call it that so it's not the bank's fault. "Your identity was stolen, we couldn't do anything! " Check a photo ID. Check a public cert. Take a fingerprint.