Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

61–70 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#61
post #45

Earlier quoted context omitted.

This is just an unhelpful argument. You might take issue with how government functions, and necessary improvements, but these government functions are still required in a developed nation.

Clarification: OC doesn’t seem to be arguing that these govt functions shouldn’t exist; they’re arguing that it’s wrong to trust govt with digital security more than we trust private companies.

Exactly. I don't dispute government services existing, I'm disputing that the government will do a better job than T-Mobile just because they're the government.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#62
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

A SSN should be useless anyway. It shouldn't matter any more than your mailing address being out there.

I agree and they were generally designed with that intention. The reason they aren't used that way is because we have no other means of federal ID.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#63

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

Wow, it exists. I dreamed about having something like this in the US, with the possibility of changing your private key if you visit the DMV. It would make a significant difference in the fight against identity theft, versus our current system of having a number of which only 4 digits are "secret" (and I hear those are sequential too. Worse still, they are the same 4 digits everyone asks you for).

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#64

Earlier quoted context omitted.

This is just an unhelpful argument. You might take issue with how government functions, and necessary improvements, but these government functions are still required in a developed nation.

Well, the government in the US functions just fine without the centralized ID System the OP is wishing for, even though stuff like this occurs. There is literally no reason why Americans would trust the central government to be more secure than T-Mobile at this point.

I disagree here. There are innovative solutions for private decentralized encryption. Other countries have also already implemented similar solutions. Almost anything is better than a 9 digit number. The government also has the resources to hire some of the top academics. Companies have proven time and time again to only care about money. While politics is messed up in a larger sense, there are some divisions that are majorly effective and good at what they do.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#65

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

[deleted]

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#66
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

Someone did put the blame on COVID! Not sure if it is Tmobile or Reuters

From a Reuters article on same news

https://www.reuters.com/technology/hackers-steal-some-person...

> T-Mobile’s data breach is the latest high-profile cyberattacks as digital thieves take advantage of security weakened by work-from-home policies due the COVID-19 pandemic

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#67
post #49

Earlier quoted context omitted.

Serious question, how would that be any different than a SSN?

SSNs sit in a middle ground between being public and private. A large number of companies and organizations use it to both identify people and as proof of identity. Those are two separate functions. When I go to a bank for a loan, I should give them some form of private id as proof I am who I say I am (this doesn't have to be a federally issued number). When companies communicate about me with each other (such as run…

The only reason companies get away with using it as proof of identity is because the government allows them to hit your credit report with a debt without having to prove you engaged in a transaction, and then make it your problem to prove you never did what someone else is claiming you did.

The solution is pretty simple, the government should require others to prove they engaged in a transition with you before being able to put an unpaid debt on your credit report, not the other way around.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#68
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

Serious question, how would that be any different than a SSN?

One option would be to offer a national oauth-style ID verification system.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#70

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

except that eIDAS is basically not in use in germany.
Post reply on HN