Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

201–210 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#202
post #173
post #106

Earlier quoted context omitted.

A post paid phone plan in the US is a contract with a rotating line if credit - that is why the ID is required. If you don't want to show id there's plenty of prepaid options (including with TMobile). You can also pay someone else to put you on their plan - the carrier only has the identification information for the plan owner.

With today's postpaid plans that have almost no way to get an overage, what's the point of setting it up to require credit? The postpaid plans are usually more expensive than prepaid, and they require a SSN and I'm not going to make the difference back by investing the payment for a month.

Because late fees are a primary profit source for cell carriers.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#203
post #47

There is seemingly less and less reason for identities at all. Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password. And before anyone makes the terrorism argument, it would seem that our country has deprioritized that initiative.

If you use sms 2FA it helps a lot of the phone company knows your actual identity.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#204
post #183

Earlier quoted context omitted.

Wow, it exists. I dreamed about having something like this in the US, with the possibility of changing your private key if you visit the DMV. It would make a significant difference in the fight against identity theft, versus our current system of having a number of which only 4 digits are "secret" (and I hear those are sequential too. Worse still, they are the same 4 digits everyone asks you for).

How would the DMV authenticate you? Would you like each state to do it, or a federal system? Many state DMVs sell their whole database to private companies like auto insurers and marketers. What makes you think they should continue to be stewards of this sensitive personal information when they have mishandled it so badly in the past? Why do we need strong ID so often anyway? Most things people demand ID for don't ac…

> Why do we need strong ID so often anyway?

... To prevent identity theft?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#205
post #142

Earlier quoted context omitted.

Things like the Real ID Act seem to be as close as we can get without constitutional changes. Something like the above could potentially be implemented like that, but still would not be as widespread as an SSN.

The Real ID Act has not been tested in court yet because it has not gone into effect, having been delayed a decade now. As soon as it goes into effect, lawsuits will immediately drop on several grounds. Furthermore, many States have declined to implement the part of the Act that requires them to share their identity databases with the Federal government, only complying with the "identity standards" part. Prior Suprem…

Your explanations here are pretty vague and feel like they're trying to say "do your own research (on my claims)." I'm not saying you have to cite chapter and verse, but know that when you're gettin pushback here that actual factual details might help, because it seems clear that force of personality doesn't.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#206

Earlier quoted context omitted.

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

No law so far ever required single form of ID to vote. All voter ID laws require some form of ID, which could be of many forms - driver license, citizenship id, passport, military ID, handgun license, special voter ID, and so on. There are many forms of ID that are accepted (and if you don't have any, as much as a copy of a recent utility bill and a signed affidavit may exempt you from the requirement). This is nowhere even near establishing a single nation-wide ID system, or even a state-wide one.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#207
post #183

Earlier quoted context omitted.

How would the DMV authenticate you? Would you like each state to do it, or a federal system? Many state DMVs sell their whole database to private companies like auto insurers and marketers. What makes you think they should continue to be stewards of this sensitive personal information when they have mishandled it so badly in the past? Why do we need strong ID so often anyway? Most things people demand ID for don't ac…

> Why do we need strong ID so often anyway? ... To prevent identity theft?

Bank fraud (a better name for it) generally does need strong ID, but the vast majority of transactions in which people are demanded to show ID to transact have nothing to do with this.

You only do bank loans, mortgages, lines of credit and the like a few times per year.

Your ID is demanded so often in the USA there is even a hand signal for it that everyone knows (a C shape made with the right hand held up at eye level).

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#208

Earlier quoted context omitted.

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

> It is illegal for the US government to create a mandatory national identity system The system can be voluntary. If you don't need an SSN today, you wouldn't need to use that system. If some bank or health care provider only accepts such a system, just pick another one, or create your own bank / health care provider.

You can not create a bank that does not verify identity according to a myriad of KYC regulations. You'd be heavily fined and most likely jailed if you do. Not sure about healthcare providers, probably if you're something like a massage therapist, there are no such requirements, but for a larger one there are probably regulations too.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#209

Earlier quoted context omitted.

Exactly. I don't dispute government services existing, I'm disputing that the government will do a better job than T-Mobile just because they're the government.

Companies like T-Mobile don't do a better job because their is no incentive to do better. Either the government needs to force company's hands through legislation with real teeth or take over the job themselves. The status quo is a failure.

Why would the government do a better job at digital security than TMobile?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#210
post #183

Earlier quoted context omitted.

Wow, it exists. I dreamed about having something like this in the US, with the possibility of changing your private key if you visit the DMV. It would make a significant difference in the fight against identity theft, versus our current system of having a number of which only 4 digits are "secret" (and I hear those are sequential too. Worse still, they are the same 4 digits everyone asks you for).

How would the DMV authenticate you? Would you like each state to do it, or a federal system? Many state DMVs sell their whole database to private companies like auto insurers and marketers. What makes you think they should continue to be stewards of this sensitive personal information when they have mishandled it so badly in the past? Why do we need strong ID so often anyway? Most things people demand ID for don't ac…

DMVs in the US already have fingerprint scanners; there exist physical documents that verify your identity and associate it with a face and name.

In this case, you'd have the Interior Ministry or equivalent be the certificate authority, and it can issue revocations and new certs based on the normal identity verification systems of the state.

Post reply on HN