Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

211–220 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#211
post #186
post #12

These breaches keep happening, and I’m super pissed how little I can do. What concrete proposals exist for phasing out SSN as proof of identity in the US? And how can I (as a person in tech) get involved?

> What concrete proposals exist for phasing out SSN as proof of identity in the US? > And how can I (as a person in tech) get involved? Wide distribution of name, ssn, dob lists seems to be a good way to reduce the effectiveness of SSN as proof of identity. If you'd like to get involved, you can probably take part in breaches or distribution. /s

/s aside, I wonder if there is evidence showing that breaches really are effective at reducing our reliance on SSN-as-auth.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#212
post #11

There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.

The problem is you can't easily change your SSN. Recently I got a new state id and reported it as lost. They sent me a new license and it has the same DL number and everything. Why can't we rotate things? Is it a slow convergence thing into other systems or something? It's really concerning.

I had a coworker lose their Drivers license and later get arrested because the person who found it decided to rob a bank and drop it on the floor to send the cops elsewhere.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#214

Earlier quoted context omitted.

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

Voting is not a constitutional right. Voting Rights Act is statutory like most of our laws.

15th Amendment:

Section 1. The right of citizens of the United States to vote shall not be denied or abridged by the United States or by any State on account of race, color, or previous condition of servitude.

Section 2. The Congress shall have power to enforce this article by appropriate legislation.

The 19th Amendment has identical language for "on account of sex", the 24th Amendment has "by reason of failure to pay a poll tax or any other tax", the 26th Amendment has "on account of age" for 18 years and older.

Like many other things in the Constitution, the constitutional text defines the general principle and the power of the federal government to enforce it, and normal legislation establishes the actual enforcement mechanisms.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#215
post #173
post #106

Earlier quoted context omitted.

A post paid phone plan in the US is a contract with a rotating line if credit - that is why the ID is required. If you don't want to show id there's plenty of prepaid options (including with TMobile). You can also pay someone else to put you on their plan - the carrier only has the identification information for the plan owner.

With today's postpaid plans that have almost no way to get an overage, what's the point of setting it up to require credit? The postpaid plans are usually more expensive than prepaid, and they require a SSN and I'm not going to make the difference back by investing the payment for a month.

When I asked about this on AT&T I was told that prepaid plans do not qualify for some type of peering system that increases coverage and reception by using other carrier's towers: I haven't looked into it more, but if this is true this would be a potential factor in choosing post-paid over pre-paid. Would love to know if this is true for AT&T or all carriers as if I can get pre-paid service of the same level as a post-paid plan I would make the switch.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#216

>Can we please have this in the US? No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.

Are these the same people who want to vote without showing their ID?

No, they're largely (the Venn diagram isn't a circle) the ones who want to require it.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#217
post #183

Earlier quoted context omitted.

Wow, it exists. I dreamed about having something like this in the US, with the possibility of changing your private key if you visit the DMV. It would make a significant difference in the fight against identity theft, versus our current system of having a number of which only 4 digits are "secret" (and I hear those are sequential too. Worse still, they are the same 4 digits everyone asks you for).

How would the DMV authenticate you? Would you like each state to do it, or a federal system? Many state DMVs sell their whole database to private companies like auto insurers and marketers. What makes you think they should continue to be stewards of this sensitive personal information when they have mishandled it so badly in the past? Why do we need strong ID so often anyway? Most things people demand ID for don't ac…

Doesn't particularly matter how the DMV would authenticate you, the point of the electronic ID is to get rid of the exchange of full copies of the identifying information. More careful re-assignment of identifying information is nice to pursue but also a completely independent issue.

Same with state vs federal question. Right now SSNs are assigned federally and drivers licenses and birth certificates by state. It doesn't much matter which it comes from as long as the identification is trusted nationally (as it is currently with the above examples).

What DMVs are able to sell varies by state, many can't sell drivers license photos for example. SSNs are also illegal to sell based on federal law. Ultimately that comes down to the content of the law relating to creating said ID not past actions with other information.

As for why we need to identify ourselves so often it often comes down to the public use case of credit checks and various forms of identification for governmental reasons (e.g. applying for official licenses or forms or travel documents or so on). It's perfectly fine to do these 2 separate but as-is we are already tying the 2 together so why not answer both in one go with something like eIDAS.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#218
post #207

Earlier quoted context omitted.

> Why do we need strong ID so often anyway? ... To prevent identity theft?

Bank fraud (a better name for it) generally does need strong ID, but the vast majority of transactions in which people are demanded to show ID to transact have nothing to do with this. You only do bank loans, mortgages, lines of credit and the like a few times per year. Your ID is demanded so often in the USA there is even a hand signal for it that everyone knows (a C shape made with the right hand held up at eye lev…

Maybe ID is asked to feed marketing database so they can sell data about you ?

In Europe we aren't asked IDs but usually email/phone numbers and that's for marketing reason (spamming and being able to identify customers cross businesses).

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#219
post #101

Earlier quoted context omitted.

credit checks (for post-paid plans), I believe.

But why do they store it?

Postpaid plans are a rotating line of credit- you are credited the upcoming charges and pay off previous charges.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#220

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

What if you lose your card? How do you prove your identity to get a replacement? How do you prevent someone from reporting your card as stolen, representing themselves as you, and getting a new card (with a new PIN) issued in your name? What if you forget your PIN, how do you reset it?

You make it seem like the EU has an ideal system, but the truth of the matter is that identity verification, in a way that is both reliable enough to allow it to be used for making legal commitments (that cannot be backed out of), is flexible enough to suit a long tail of edge cases (the intellectually disabled, the elderly, children, etc.), and is secure enough against loss or theft is a very hard problem.

Post reply on HN