Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

171–180 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#171
post #98

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

Better yet, why does my cell phone provider need all this information about me anyway? Why is there an ID involved at all?

[deleted]

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#172
post #142

Earlier quoted context omitted.

Things like the Real ID Act seem to be as close as we can get without constitutional changes. Something like the above could potentially be implemented like that, but still would not be as widespread as an SSN.

The Real ID Act has not been tested in court yet because it has not gone into effect, having been delayed a decade now. As soon as it goes into effect, lawsuits will immediately drop on several grounds. Furthermore, many States have declined to implement the part of the Act that requires them to share their identity databases with the Federal government, only complying with the "identity standards" part. Prior Suprem…

Once again, citation please.

You seem very sure of these Supreme Court decisions that appear to have slipped past the rest of us. Not saying you are wrong, with the firehose of info these days it's easy to miss things, even really important things.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#173
post #106
post #91

Earlier quoted context omitted.

>Can we please have this in the US? Absolutely not. How about not requiring an ID? There are plenty of carriers here that don't do that.

A post paid phone plan in the US is a contract with a rotating line if credit - that is why the ID is required. If you don't want to show id there's plenty of prepaid options (including with TMobile). You can also pay someone else to put you on their plan - the carrier only has the identification information for the plan owner.

With today's postpaid plans that have almost no way to get an overage, what's the point of setting it up to require credit?

The postpaid plans are usually more expensive than prepaid, and they require a SSN and I'm not going to make the difference back by investing the payment for a month.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#174
post #81

Earlier quoted context omitted.

This is just nonsense. Where are you coming up with this theory? Everyone has an ssn already wouldn’t that qualify for the mark?

I thought it was a joke at first but maybe not. Of course many of these people I'm sure are in favor of requiring ID at the ballot box...

And other people think you should have to present proof of vaccination to go outside but no ID vote. Neither group is thinking past the propaganda their side presents.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#175
post #47

There is seemingly less and less reason for identities at all. Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password. And before anyone makes the terrorism argument, it would seem that our country has deprioritized that initiative.

When they offer phones on payment they're essentially providing a loan. This does carry some risk as it is, even more if they're not running a credit check.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#176

Earlier quoted context omitted.

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

Voting is not a constitutional right. Voting Rights Act is statutory like most of our laws.

> Voting is not a constitutional right.

Yes it is.

> Voting Rights Act is statutory like most of our laws.

Constitutional rights are often enforced by legislation; Amendments articulating rights often explicitly authorize this. See, with regard to voting rights, the 15th, 19th, and 26th Amendments. (EDIT: also, the 14th Amendment [see Sec. 2 and 5], and, as noted in a sibling comment, the 24th Amendment. Also the 17th Amendment, though that doesn’t have a Congressional enforcement clause. Voting rights are the single most common subject of Constitutional amendments.)

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#177

Earlier quoted context omitted.

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

Thanks for bringing that up. Denmark, an EU member state, does not have ID cards, so it's not exactly mandatory over there. Seems weird that a SSN is not considered a national identity system? What if the federal government sunset SSNs after a bunch of big states implemented an equivalent of EIDAS on their own volition?

It's basically because SSNs were not supposed to be used for that purpose, they were only supposed to be for the SSA to track people, like an account number.

In fact, the paper cards used to say "NOT FOR IDENTIFICATION" on them. I forget when that was removed.

The military started using them for ID in the 60s, then the IRS started using them in the 70s, and it's just kind of morphed into an ID number because "everyone has one".

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#178

Earlier quoted context omitted.

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

There are cases spanning a century across several creative legislative attempts by the US Congress to create a de facto mandatory national identity system. This information is not difficult to find. All of them tried to workaround the fact that States can create mandatory identity systems but the Federal government cannot. (It is one of the reasons SSN cards go out of their way to assert they are not to be used as an ID.)

Past attempts included things like withholding tax disbursements to non-compliant States, but the US Supreme Court deemed that coercive and therefore illegal. The Real ID Act is the latest attempt but it has been delayed for many years by State non-compliance and general unwillingness to share their identity databases with the Federal government.

The ID required to vote is a State ID, which is perfectly Constitutional. No one is requiring a Federal ID to vote. In fact, many States will not recognize any Federal ID, including passports.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#179
post #47

There is seemingly less and less reason for identities at all. Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password. And before anyone makes the terrorism argument, it would seem that our country has deprioritized that initiative.

> Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password.

It's super helpful if T-Mobile knows who I am so they can give me a new sim when my phone is lost or stolen. Of course, it's not great when they give someone else a new sim when they claim to be me and that my phone is lost or stolen.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#180

It is annoying. Between all the breaches, it is virtually guaranteed my information is floating out there. The worst part is, I have zero to no recourse here. What are they gonna offer me? Discounted credit monitoring? What is the tipping point? Did we manage to pass it altogether ( asking since even I took this news as... eh, why bother )? Honestly, what needs to happen to make it 'not so'.

Whats the point of anti money laundering laws when you can open a bank/brokerage/crypto account online with $20 in Monero’s worth of fake IDs and social security numbers.

Could probably boost the GDP by 2% by just acknowledging that compliance is a waste of time and ending that regime.

Post reply on HN