Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

221–230 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#221
post #70

Earlier quoted context omitted.

except that eIDAS is basically not in use in germany.

Well, Germany is not the entire EU. I have such card and it comes in handy from time to time, though the implementation could be much better.

Haven’t seen it in Ireland either.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#222
post #173
post #106

Earlier quoted context omitted.

A post paid phone plan in the US is a contract with a rotating line if credit - that is why the ID is required. If you don't want to show id there's plenty of prepaid options (including with TMobile). You can also pay someone else to put you on their plan - the carrier only has the identification information for the plan owner.

With today's postpaid plans that have almost no way to get an overage, what's the point of setting it up to require credit? The postpaid plans are usually more expensive than prepaid, and they require a SSN and I'm not going to make the difference back by investing the payment for a month.

Carriers also have financing and/or renting of expensive equipment (phones) as part of their post paid plans. This is a very big deal for many people.

Post paid plans can also have a minimum term/termination fees, which the carrier would be interested in collecting.

Post-paid plans are also often grandfathered when prices increase for new customers.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#223
post #207

Earlier quoted context omitted.

> Why do we need strong ID so often anyway? ... To prevent identity theft?

Bank fraud (a better name for it) generally does need strong ID, but the vast majority of transactions in which people are demanded to show ID to transact have nothing to do with this. You only do bank loans, mortgages, lines of credit and the like a few times per year. Your ID is demanded so often in the USA there is even a hand signal for it that everyone knows (a C shape made with the right hand held up at eye lev…

As a first step, stop giving in to the demands.

I routinely refuse to provide ID when asked by private businesses. About half the time they're OK with proceeding with whatever without it.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#224
post #183

Earlier quoted context omitted.

Wow, it exists. I dreamed about having something like this in the US, with the possibility of changing your private key if you visit the DMV. It would make a significant difference in the fight against identity theft, versus our current system of having a number of which only 4 digits are "secret" (and I hear those are sequential too. Worse still, they are the same 4 digits everyone asks you for).

How would the DMV authenticate you? Would you like each state to do it, or a federal system? Many state DMVs sell their whole database to private companies like auto insurers and marketers. What makes you think they should continue to be stewards of this sensitive personal information when they have mishandled it so badly in the past? Why do we need strong ID so often anyway? Most things people demand ID for don't ac…

Well the databases are already there whether we like it or not.

Generally, with eIDAS, various websites can use an API to access the identity stored on your ID (public key) when you allow it.

Crucially, every time you want to make a legally binding change or sign a document, you need to ask your ID to use its private key to cryptographically sign it. Typically this operation needs a PIN. Without such a valid signature, you won't be able to use someone's credit line.

With a well designed system, the government can provide an API to give institutions/apps unique, but app-specific people identifiers. Those can be trusted to each be tied to a unique person, without making it possible to track the services they use (unlike the easily trackable SSN).

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#225

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

What if you lose your card? How do you prove your identity to get a replacement? How do you prevent someone from reporting your card as stolen, representing themselves as you, and getting a new card (with a new PIN) issued in your name? What if you forget your PIN, how do you reset it? You make it seem like the EU has an ideal system, but the truth of the matter is that identity verification, in a way that is both re…

Not sure what they do in the EU, but these seem solveable.

> What if you lose your card?

Each country could keep a log of revoked publishable keys. Countries do more complex things to validate VAT IDs today, so this wouldn't be out of the blue.

> How do you prove your identity to get a replacement? How do you prevent someone from reporting your card as stolen, representing themselves as you, and getting a new card (with a new PIN) issued in your name?

Governments need to solve the same issue with lost passports today. In some cases you can have other people to vouch for you, putting their own identities on the line. In other cases, you use other forms of ID (including immutable things like biometrics). Society has generally made this not a problem, and a new form of ID won't make it worse.

> What if you forget your PIN, how do you reset it?

At the worst, it's treated as a lost card and get a replacement. There are probably ways to make this better but my point is: solveable.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#226

Earlier quoted context omitted.

The only reason companies get away with using it as proof of identity is because the government allows them to hit your credit report with a debt without having to prove you engaged in a transaction, and then make it your problem to prove you never did what someone else is claiming you did. The solution is pretty simple, the government should require others to prove they engaged in a transition with you before being…

> government allows them to hit your credit report with a debt You appear to be operating under a misunderstanding: The government doesn't organize credit reports. Credit reports (in the US, at least) are compiled by independent companies, who operate with very little oversight or recourse (and occasionally leak lots of data themselves).

You have the misunderstanding. Credit reports in the United States are compiled by independent companies regulated under the FCRA. This is a federal act that basically whitewashes all the trashy behavior by credit bureaus.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#227

Earlier quoted context omitted.

The ID is not always on a plastic id card, for example BankID (at least the swedish variant) is eIDAS compliant and is instead an app where the identity is issued by your bank. I have the ID card with smartcard capabilities too but I've never seen any place in sweden where they are used, but it's good to know I have it if I need to identify in the rest of europe.

Here's hoping they at least store the key on Secure Enclave [1]/Secure Element so it's inaccessible to the operating system in case of a breach. [1] https://developer.apple.com/documentation/security/certifica...

Smart cards are essentially a big Secure Enclave themselves.

The whole point of a smart card (same as a military CAC, and almost the same as a TPM chip on computers) is to sign operations using the private key, without allowing export of that private key. They're still made of atoms, like all objects, and susceptible to physical key extraction attacks.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#228
I just signed up for TMobile last month. They asked me for my SSN. I said seriously?? They said yes we need it for a credit check to see if we can offer you service. I said sure... it's 123456789.

"One moment sir..."

"Congratulations! you have very good credit, Welcome to TMobile."

...It's baloney, I think they just try to get it for leverage if you have a bill outstanding.

Anyway, very glad I gave them a fake SSN.

EDIT: I did learn they use the last four digits as an initial pin in some cases, so good to remember whatever nonsense number you tell them.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#229
post #208

Earlier quoted context omitted.

> It is illegal for the US government to create a mandatory national identity system The system can be voluntary. If you don't need an SSN today, you wouldn't need to use that system. If some bank or health care provider only accepts such a system, just pick another one, or create your own bank / health care provider.

You can not create a bank that does not verify identity according to a myriad of KYC regulations. You'd be heavily fined and most likely jailed if you do. Not sure about healthcare providers, probably if you're something like a massage therapist, there are no such requirements, but for a larger one there are probably regulations too.

I suspect that for healthcare providers, the ID requirement is driven more by insurance fraud prevention (including Medicare/Medicaid); i.e. the insurers require the providers to perform due diligence to ensure that the patient being treated is the patient who is covered.

I don't know of any examples, but perhaps a provider who did not take insurance would be able to avoid the requirement.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#230
post #206

Earlier quoted context omitted.

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

No law so far ever required single form of ID to vote. All voter ID laws require some form of ID, which could be of many forms - driver license, citizenship id, passport, military ID, handgun license, special voter ID, and so on. There are many forms of ID that are accepted (and if you don't have any, as much as a copy of a recent utility bill and a signed affidavit may exempt you from the requirement). This is nowhe…

the topic here is a national mechanism, and states could (asininely) allow lesser forms, even exclude the national one.
Post reply on HN