Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

131–140 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#131

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court.

Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Constitution. Short of amending the Constitution, which seems highly unlikely, the US will never have a national identity system like European countries.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#132
post #107

Earlier quoted context omitted.

Well, Germany is not the entire EU. I have such card and it comes in handy from time to time, though the implementation could be much better.

I'm pretty sure that in france eIDAS is not there aswell, which would already mean that over 1/3 (probably more, because more states basically don't have it implemented) of the european member states population does not use it (yet)

This is sad and totally not my problem. I like the option to access easily my tax and health information and to get e-signed invoices instead of dealing with paper and stuff. I hope that the rest of the EU will do their part of crossing to the 21th century.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#133
post #106
post #91

Earlier quoted context omitted.

>Can we please have this in the US? Absolutely not. How about not requiring an ID? There are plenty of carriers here that don't do that.

A post paid phone plan in the US is a contract with a rotating line if credit - that is why the ID is required. If you don't want to show id there's plenty of prepaid options (including with TMobile). You can also pay someone else to put you on their plan - the carrier only has the identification information for the plan owner.

Just to add. Mint Mobile offers prepaid plans and doesn’t require a SSN.

Harvard has a list I found on google.

https://www.hio.harvard.edu/telephone-service

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#134

Earlier quoted context omitted.

The only reason companies get away with using it as proof of identity is because the government allows them to hit your credit report with a debt without having to prove you engaged in a transaction, and then make it your problem to prove you never did what someone else is claiming you did. The solution is pretty simple, the government should require others to prove they engaged in a transition with you before being…

> government allows them to hit your credit report with a debt You appear to be operating under a misunderstanding: The government doesn't organize credit reports. Credit reports (in the US, at least) are compiled by independent companies, who operate with very little oversight or recourse (and occasionally leak lots of data themselves).

I know how they operate, but the government can create legislation to change things.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#135

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

Or, we just have a natural/historical aversion to centralized power. Much of the nation initially started out believing that power should be local. Or you can simply make up nonsense about 'mark of the beast'.

It's crazy how a nation of "religious fundamentalists" created the modern world. Crazy how "religious fundamentalists" created the wealthiest nation.

There has always been a backlash against centralized/federalized anything. From taxes to gun registration to you name it. As it should be. But you'll be happy to know that the trend is towards more centralized control and power.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#136
post #111

Any entity using SSN and DOB as identity verification should be solely liable for any loss caused by fraud.

But that's already the case? You just have to go through the hassle of getting it resolved. You're also not liable for credit card fraud, but you still have to go through the hassle of calling the bank and getting it reversed.

Going through a hassle is effectively being liable, in this context. Especially when the credit reporting bureaus absolutely do not give a crap about you and make contacting them a job in itself.

It is akin to “the process is the punishment” when you get tied up in the US legal/criminal justice system, even if you are innocent.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#137
post #81

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

This is just nonsense. Where are you coming up with this theory? Everyone has an ssn already wouldn’t that qualify for the mark?

I literally overheard someone (at a science museum no less) claim the mRNA vaccines were the beginnings of the mark of the beast basically because they messed with your genetics. People do take it seriously.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#138
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

Sophistication is contextual. Among computer criminals, exploiting unpatched or poorly credentialed systems is unimpressive. In the context of the animal kingdom at large, it's astonishing.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#139

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

What are you referring to? I wasn’t aware of any SCOTUS ruling re: national ID, and after a brief search just now I still can’t find any relevant precedent.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#140

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

Geez, such a weird segway. You've completely missed talking about how the EU private key has no concept of getting updated in a secure fashion and is basically unusable.

The Baltic states have a private key that is actually usable to an end user. Open source, document signing format that works.

Plus a process that allows updating these keys in a safe fashion. None of that exists with the EU infrastructure.

Post reply on HN