Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

121–130 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#121

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

When Social Security was introduced, the government encouraged people to get a tattoo of their SSN so they wouldn't forget it [1]. [1]: https://blog.nyhistory.org/tattoo-as-memory-prompt/

It seems like it was tattoo artists (not the government) recommending tattoos, as you would expect. It is still interesting, but a bit less sensationalist.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#122
post #109

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

I'm against it. Not for religious reasons but because of the potential to concentrate power.

How is this worse than a SSN?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#123

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

The ID is not always on a plastic id card, for example BankID (at least the swedish variant) is eIDAS compliant and is instead an app where the identity is issued by your bank. I have the ID card with smartcard capabilities too but I've never seen any place in sweden where they are used, but it's good to know I have it if I need to identify in the rest of europe.

Here's hoping they at least store the key on Secure Enclave [1]/Secure Element so it's inaccessible to the operating system in case of a breach.

[1] https://developer.apple.com/documentation/security/certifica...

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#124
post #49

Earlier quoted context omitted.

SSNs sit in a middle ground between being public and private. A large number of companies and organizations use it to both identify people and as proof of identity. Those are two separate functions. When I go to a bank for a loan, I should give them some form of private id as proof I am who I say I am (this doesn't have to be a federally issued number). When companies communicate about me with each other (such as run…

The only reason companies get away with using it as proof of identity is because the government allows them to hit your credit report with a debt without having to prove you engaged in a transaction, and then make it your problem to prove you never did what someone else is claiming you did. The solution is pretty simple, the government should require others to prove they engaged in a transition with you before being…

> government allows them to hit your credit report with a debt

You appear to be operating under a misunderstanding: The government doesn't organize credit reports. Credit reports (in the US, at least) are compiled by independent companies, who operate with very little oversight or recourse (and occasionally leak lots of data themselves).

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#125
post #101
post #98

Earlier quoted context omitted.

Better yet, why does my cell phone provider need all this information about me anyway? Why is there an ID involved at all?

credit checks (for post-paid plans), I believe.

They could just require a cash deposit and pause service when you run up a bill exceeding that amt, but to the best of my knowledge they don't offer this option or if they do they don't promote it.

It's just pre-paid or credit-based contracts AIUI.

My power company asked for my SSN when setting up the utilities, after plainly refusing to provide it they said a $250 deposit would be required, done!

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#126
post #81

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

This is just nonsense. Where are you coming up with this theory? Everyone has an ssn already wouldn’t that qualify for the mark?

Are SSN's assigned at birth?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#127
post #70

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

except that eIDAS is basically not in use in germany.

These things take time to implement. It's slowly getting rolled out. Germany in particular is.. digitally challenged as a country.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#128
post #81

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

This is just nonsense. Where are you coming up with this theory? Everyone has an ssn already wouldn’t that qualify for the mark?

My mother is one of these people. They exist. Their logic is flimsy at best, but there are enough of them embedded in churches that it's a thing.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#129
post #58

Well, at least it doesn't compromise the cheaper resellers (like Boost or Mint Mobile or Metro). Ironic that the cheap resellers are safer than the supposedly premium network.

Does the article mention this? Sorry I have been looking for this information and did not see it. Regardless I am a Mint Mobile user and I don’t think I gave my SSN to Mint. Hell I don’t even think they have my DOB.

> Does the article mention this? Sorry I have been looking for this information and did not see it.

Yep, here you go: "No Metro by T-Mobile, former Sprint prepaid, or Boost customers had their names or PINs exposed," T-Mobile said. "We have also confirmed that there was some additional information from inactive prepaid accounts accessed through prepaid billing files. No customer financial information, credit card information, debit or other payment information or SSN was in this inactive file."

Post reply on HN