Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

231–240 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#231
post #101

Earlier quoted context omitted.

credit checks (for post-paid plans), I believe.

But why do they store it?

Post-paid plans are a small rotating line of credit - just like a credit card.

If you don't pay your bill or pay off your phone you get reported to the credit bureaus and sent to collections.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#232
post #223
post #207

Earlier quoted context omitted.

Bank fraud (a better name for it) generally does need strong ID, but the vast majority of transactions in which people are demanded to show ID to transact have nothing to do with this. You only do bank loans, mortgages, lines of credit and the like a few times per year. Your ID is demanded so often in the USA there is even a hand signal for it that everyone knows (a C shape made with the right hand held up at eye lev…

As a first step, stop giving in to the demands. I routinely refuse to provide ID when asked by private businesses. About half the time they're OK with proceeding with whatever without it.

First off, you're preaching to the choir. I show ID for many fewer things than the average person, and perhaps even yourself.

There are however many, many things that you are simply entirely barred from doing in the USA without showing ID. It's even worse in Europe.

Many music venues (the vast majority), all federally licensed firearms retailers, almost all hotels and modes of travel.

Perhaps you can live without music, air travel, hotels, and firearms, but I cannot.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#233

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

Or, we just have a natural/historical aversion to centralized power. Much of the nation initially started out believing that power should be local. Or you can simply make up nonsense about 'mark of the beast'. It's crazy how a nation of "religious fundamentalists" created the modern world. Crazy how "religious fundamentalists" created the wealthiest nation. There has always been a backlash against centralized/federal…

America isn't a nation of religious fundamentalists - they're a minority but just incredibly loud.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#234
post #166

Earlier quoted context omitted.

Or, we just have a natural/historical aversion to centralized power. Much of the nation initially started out believing that power should be local. Or you can simply make up nonsense about 'mark of the beast'. It's crazy how a nation of "religious fundamentalists" created the modern world. Crazy how "religious fundamentalists" created the wealthiest nation. There has always been a backlash against centralized/federal…

> Or, we just have a natural/historical aversion to centralized power. And yet support a sprawling state government machinery almost as powerful as the central/federal government so much so that states can dictate terms and laws they want and "local" cities and counties have to abide by it.

and the best (worst) part is that those more-local governments are uniformly less accountable.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#235
post #183

Earlier quoted context omitted.

Wow, it exists. I dreamed about having something like this in the US, with the possibility of changing your private key if you visit the DMV. It would make a significant difference in the fight against identity theft, versus our current system of having a number of which only 4 digits are "secret" (and I hear those are sequential too. Worse still, they are the same 4 digits everyone asks you for).

How would the DMV authenticate you? Would you like each state to do it, or a federal system? Many state DMVs sell their whole database to private companies like auto insurers and marketers. What makes you think they should continue to be stewards of this sensitive personal information when they have mishandled it so badly in the past? Why do we need strong ID so often anyway? Most things people demand ID for don't ac…

"I don't trust the government" is moot. You already use your government issued ID for everything. Asking them to improve their technology is not asking them to takeover any new responsibilities.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#236
post #186

Earlier quoted context omitted.

> What concrete proposals exist for phasing out SSN as proof of identity in the US? > And how can I (as a person in tech) get involved? Wide distribution of name, ssn, dob lists seems to be a good way to reduce the effectiveness of SSN as proof of identity. If you'd like to get involved, you can probably take part in breaches or distribution. /s

/s aside, I wonder if there is evidence showing that breaches really are effective at reducing our reliance on SSN-as-auth.

Well, I just said it was less effective, not that it would reduce our reliance :D

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#238
post #186

Earlier quoted context omitted.

> What concrete proposals exist for phasing out SSN as proof of identity in the US? > And how can I (as a person in tech) get involved? Wide distribution of name, ssn, dob lists seems to be a good way to reduce the effectiveness of SSN as proof of identity. If you'd like to get involved, you can probably take part in breaches or distribution. /s

/s aside, I wonder if there is evidence showing that breaches really are effective at reducing our reliance on SSN-as-auth.

It's not proof of anything much less identity, and not auth either. More like a simple account number.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#240
post #192
post #47

There is seemingly less and less reason for identities at all. Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password. And before anyone makes the terrorism argument, it would seem that our country has deprioritized that initiative.

> Why should T-Mobile care who it is they are giving phone service to? As long as the bills are paid on time, it shouldn't matter. Here's my order ID and my password Therein lies the problem. Phones these days are sold on loans and this is a postpaid service meaning each billing cycle you owe for the prior billing cycle. People defaulting on phone bills is more common than you think. I recall some time about ~25 year…

So just have a prepaid option with the same plethora of plans as postpaid, and not require ID? Cut service instantaneously if not prepaid on time before 1st of the month. Or even add on a $100 deposit which buys you a 1 month grace period any time.

I don't mind paying phone bills upfront at all.

Post reply on HN