Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

191–200 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#191
post #98

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

Better yet, why does my cell phone provider need all this information about me anyway? Why is there an ID involved at all?

Traceability. I don’t know how it is in the US, but in Europe these days it’s relatively hard to get a SIM without having to show a form of identification. South-East Asia too, in 2013 they would just hand out SIMs like candy, but in 2016 the phone shop / stall that sold you the SIM (illegally) just signed the SIM under the sellers ID and I imagine its even more stringent now.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#192
post #47

There is seemingly less and less reason for identities at all. Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password. And before anyone makes the terrorism argument, it would seem that our country has deprioritized that initiative.

> Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password

Therein lies the problem. Phones these days are sold on loans and this is a postpaid service meaning each billing cycle you owe for the prior billing cycle. People defaulting on phone bills is more common than you think.

I recall some time about ~25 years ago where Sprint was offering a no credit check/no deposit special. They ended it due to having to write off a large portion of their non-paying users. It also ended up being a net loss of total users for them, an unheard of situation in a time of rapid growth and a market nowhere near saturation.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#193
post #24

Will T-Mobile or anyone in a leadership position there face consequences for this?

Target might be a good comparison. The total cost to them was ~$300M, and the CEO had to step down. Though $300M when your annual revenues are ~90B isn't really a huge hit. Less than 1/10th of net earnings for a year. https://www.thesslstore.com/blog/2013-target-data-breach-set...

The CEO probably could’ve survived the data breach if not for the Target Canada fiasco.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#194

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

> everyone asks why don't we just thing that looks like a national identity system

Aren't passports national/federal identity systems?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#195
T-Mobile subscriber here. I just received my first notification from T-mobile via a text message status that they have determined that unauthorized access to their data has occurred. They have no evidence that exposure to my credit card info was made (meaning they have no real idea). As part of their serious concern over protecting their customers and to protect my account, they changed my PIN. I'm no so worried about my credit card number as I am about all my personal info (name, address, ssn) being comprised to the point where identity theft becomes a significant concert. Somehow, changing my PIN doesn't instill a warm, fuzzy feeling in me.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#196
post #167
post #148

Earlier quoted context omitted.

SSN should not be used for ID.

And yet it is used as such, in banking, healthcare and everywhere that matters. An alternative ought to be made.

A better alternative would be user accounts with the credit companies but then people would realize how sloppy they are.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#197

Earlier quoted context omitted.

I thought it was a joke at first but maybe not. Of course many of these people I'm sure are in favor of requiring ID at the ballot box...

And other people think you should have to present proof of vaccination to go outside but no ID vote. Neither group is thinking past the propaganda their side presents.

Are there really people that want to require proof of vaccination to go outside? I haven’t heard that one.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#198
If someone waited to make uncharacteristic high priced purchases exactly when these breaches happened, do you think the credit card companies would simply write down the amount without further investigation, being at capacity with legitimate fraud investigations due to the breech?

As in, could someone go out, buy things that would get flagged as fraud on their own card, then say they didn't make the purchase when called by the fraud investigator, and Visa/Mastercard would be too busy tracking down the bigger ticket frauds at the moment and then just let it slide and reverse the charges?

My personal integrity stops me from attempting this crime, but I believe it would work.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#199

>Can we please have this in the US? No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.

Are these the same people who want to vote without showing their ID?

I think the concerns around voting are based on who and how the ID is issued. Honestly if the Feds would issue one to every citizen this issue would go away. Most who are pushing the hardest for voters to show ID would have to give up power for that to happen, because the political calculation is that they can write the laws in such a way as their supporters can easily vote, and their opponents less easily.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#200

Earlier quoted context omitted.

up till late 1990s SSN and DOB were public information, as they were printed on never-secured student IDs in American schools, for instance, and who knows where those unprotected lists went.

my email address at the university from 2000-2003 had the last 4 of my SSN in it.

I had orders in the military listing hundreds of people’s name and SSN. This was ~2007
Post reply on HN