Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

181–190 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#181

I was a tmobile customer in the past. For all I know, my information could be in this leak. What should I do to protect myself? I called T mobile but received no update.

Freeze your credit reports, it's a PITA if someone opens accounts under your name, which will be super easy if they've got your name, SSN, and DOB.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#182
post #45

Earlier quoted context omitted.

Clarification: OC doesn’t seem to be arguing that these govt functions shouldn’t exist; they’re arguing that it’s wrong to trust govt with digital security more than we trust private companies.

Exactly. I don't dispute government services existing, I'm disputing that the government will do a better job than T-Mobile just because they're the government.

Companies like T-Mobile don't do a better job because their is no incentive to do better. Either the government needs to force company's hands through legislation with real teeth or take over the job themselves. The status quo is a failure.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#183

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

Wow, it exists. I dreamed about having something like this in the US, with the possibility of changing your private key if you visit the DMV. It would make a significant difference in the fight against identity theft, versus our current system of having a number of which only 4 digits are "secret" (and I hear those are sequential too. Worse still, they are the same 4 digits everyone asks you for).

How would the DMV authenticate you?

Would you like each state to do it, or a federal system?

Many state DMVs sell their whole database to private companies like auto insurers and marketers. What makes you think they should continue to be stewards of this sensitive personal information when they have mishandled it so badly in the past?

Why do we need strong ID so often anyway? Most things people demand ID for don't actually need ID.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#184

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

Real ID is a backdoor national ID, just administrated piecemeal by the states.

The feds have all of the secure flight data and all of the Real ID license/state ID card data, linked to SSN.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#185
post #142

Earlier quoted context omitted.

Things like the Real ID Act seem to be as close as we can get without constitutional changes. Something like the above could potentially be implemented like that, but still would not be as widespread as an SSN.

The Real ID Act has not been tested in court yet because it has not gone into effect, having been delayed a decade now. As soon as it goes into effect, lawsuits will immediately drop on several grounds. Furthermore, many States have declined to implement the part of the Act that requires them to share their identity databases with the Federal government, only complying with the "identity standards" part. Prior Suprem…

> The Real ID Act has not been tested in court yet because it has not gone into effect

It went into effect in 2014. You are probably confusing Phase 4 requirements (the requirement for Real ID for commercial air travel being the main one) with the act as a whole. Real ID are issued, and are required for a variety of purposes.

> Prior Supreme Court cases have ruled that the Federal government cannot coerce the States, e.g. via taxation or regulatory authority, to do something for the Federal government that the Federal government is prohibited from doing itself.

Which would be relevant if cases had also established that the federal government cannot issue photo ID cards that the Federal government required for functions subject to federal regulation under the Constitution.

But no such ruling has been made, and the federal government issues a variety of IDs (passports, permanent resident ID, military ID), and mandates their use (allowing, in some cases—like commercial air travel—the use of an acceptable alternative) for a variety of purposes.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#186
post #12

These breaches keep happening, and I’m super pissed how little I can do. What concrete proposals exist for phasing out SSN as proof of identity in the US? And how can I (as a person in tech) get involved?

> What concrete proposals exist for phasing out SSN as proof of identity in the US?

> And how can I (as a person in tech) get involved?

Wide distribution of name, ssn, dob lists seems to be a good way to reduce the effectiveness of SSN as proof of identity. If you'd like to get involved, you can probably take part in breaches or distribution. /s

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#187

Earlier quoted context omitted.

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

There are cases spanning a century across several creative legislative attempts by the US Congress to create a de facto mandatory national identity system. This information is not difficult to find. All of them tried to workaround the fact that States can create mandatory identity systems but the Federal government cannot. (It is one of the reasons SSN cards go out of their way to assert they are not to be used as an…

Name a case.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#188
post #101
post #98

Earlier quoted context omitted.

Better yet, why does my cell phone provider need all this information about me anyway? Why is there an ID involved at all?

credit checks (for post-paid plans), I believe.

But why do they store it?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#189
post #47

There is seemingly less and less reason for identities at all. Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password. And before anyone makes the terrorism argument, it would seem that our country has deprioritized that initiative.

> As long as the bills are paid on time I'm assuming that's what they use your SSN for, to run a credit check. I'm not saying that's ok, just that that's how it's done.

The bigger question, though, should be why are they storing the actual SSN? They can run a credit check and store only the result of the credit check and not all the personal data they had to collect to run the check. Presumably, they do need some way to report delinquent accounts to the credit bureaus after the fact, but there's no reason why credit monitors can't use a tokenized system (i.e. submit the SSN to the credit bureau and receive back a UUID which has the singular purpose of reporting back to the credit monitors.)

We really need to start attaching eye-watering financial penalties to companies that leak data so that we make the only sane decision be not storing that data in the first place. Collect it and shuttle it to where it needs to go...but under no circumstances commit it to at rest storage.

Post reply on HN