Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

91–100 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#91

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

>Can we please have this in the US?

Absolutely not. How about not requiring an ID? There are plenty of carriers here that don't do that.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#92
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

The problem is you can't easily change your SSN. Recently I got a new state id and reported it as lost. They sent me a new license and it has the same DL number and everything. Why can't we rotate things? Is it a slow convergence thing into other systems or something? It's really concerning.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#93
post #42

The article mentions "names, date of birth, Social Security number and driver's license/ID information", but no credit card numbers in that list.

Who knows, but it might be that no credit card numbers were stolen.

If you want to accept credit card payments, the industry requires PCI compliance (https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...), which actually does involve taking substantial steps to protect those card numbers. An outside organization does some amount of validation that you're handling the card numbers in a reasonable way.

There's a difference here, which is that if personal details like names, date of birth, and driver's license are leaked, it affects individuals' interests. But if card numbers are leaked, it affects the interests of huge corporations.

Those corporations have the resources and power to get involved and protect their interests in a way that consumers don't.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#94

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

But Canada, Australia, and uk doesn't have them either, and they can't really be described as fundamentalist like the US is. Maybe it's just an anglo thing?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#95
post #75

>Can we please have this in the US? No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.

There’s no reason why the id system can’t be federated like the EU solution. Also all those hypothetical “mark of the beast” people you mention already have SSNs.

They're not hypothetical:

http://archive.boston.com/news/local/maine/articles/2007/03/...

>"People are very concerned if the federal government gives you a number, it will be the mark of the beast," said Missouri Rep. Jim Guest, the sponsor of a resolution similar to Whitaker's. "There are everyday people who get the connection to 666."

https://www.register-herald.com/news/local_news/is-real-id-a...

>Hudok emphasized he wasn’t saying that those enrolled in the global system are under the thumb of the ultimate Beast, but said the use of Real ID means biblical prophecy is “well under way.”

https://apps.itd.idaho.gov/Apps/MediaManagerMVC/NewsClipping...

>But some evangelical Christians take the "mark" of Revelation more literally, and believe that a number-based identification system in the U.S. will eventually spread throughout the world, only to be used by a global dictator (the antichrist) who will control international trade with the numbers issued under the Real ID program.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#96
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

https://twitter.com/damienmiller/status/1427195852011937797

They probably put more money into that banner than into keeping these systems patched. That there banner was probably a dozen plus hours of legal work. :(

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#97
post #47

There is seemingly less and less reason for identities at all. Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password. And before anyone makes the terrorism argument, it would seem that our country has deprioritized that initiative.

> As long as the bills are paid on time

I'm assuming that's what they use your SSN for, to run a credit check. I'm not saying that's ok, just that that's how it's done.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#98

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

Better yet, why does my cell phone provider need all this information about me anyway? Why is there an ID involved at all?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#100

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

You're significantly overestimating the amount of pull that type of person has in the US anymore, while simultaneously dramatically (I can only assume willfully) misquoting that bible verse.

"That type of person" accounts for some substantial fraction of the vaccine-hesitant population that accounts for freely available covid-19 vaccines for everyone age 12+ in the US but only 51% of the population being fully vaccinated[1].

So, even if you consider it absurd, this particular belief IS widely-enough held to influence behavior and public policy in the US.

[1] https://covid.cdc.gov/covid-data-tracker/#vaccinations_vacc-...

Post reply on HN