Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

241–250 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#241

Earlier quoted context omitted.

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

There are cases spanning a century across several creative legislative attempts by the US Congress to create a de facto mandatory national identity system. This information is not difficult to find. All of them tried to workaround the fact that States can create mandatory identity systems but the Federal government cannot. (It is one of the reasons SSN cards go out of their way to assert they are not to be used as an…

"This information is not difficult to find"

Then please find and supply it. -I- have had difficulty finding it. It certainly isn't so easy to find as "here is a linked citation supporting my claim", since you've yet to provide one.

"The Real ID Act is the latest attempt but it has been delayed for many years by State non-compliance and general unwillingness to share their identity databases with the Federal government." - not at all. Everything you said just in this post is incorrect, but more egregiously (and why I'm not even bothering to point out why it's incorrect), it's also -irrelevant-. Real ID...isn't mandatory. Not at the state level, not at the federal level.

"The ID required to vote is a State ID, which is perfectly Constitutional" - there isn't an ID required to vote according to the Constitution. In practice, most states also don't require any form of ID. Hence all the bills by the GOP to try and require one, while also doing nothing to ensure it is affordable and convenient (i.e., creating a form of poll tax); the GOP doesn't even care about it as an ID system, just as a form of voter suppression.

Which is my point; no legislature, not even the people trying to require ID for things, is pushing for mandatory IDs. It's not against the Constitution as far as I can tell, and you've done nothing to convince me; it just isn't politically worth pushing for given the resistance it would face so has never happened.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#242
post #94

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

But Canada, Australia, and uk doesn't have them either, and they can't really be described as fundamentalist like the US is. Maybe it's just an anglo thing?

you might be right - there's certainly a cultural thread that the 666-worriers are just being triggered by.

it's really a belief that the state is malign - and the further away (ie, federal), the worse. which is ironic because feds get vastly more scrutiny than some podunk local government.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#243

Earlier quoted context omitted.

The Real ID Act has not been tested in court yet because it has not gone into effect, having been delayed a decade now. As soon as it goes into effect, lawsuits will immediately drop on several grounds. Furthermore, many States have declined to implement the part of the Act that requires them to share their identity databases with the Federal government, only complying with the "identity standards" part. Prior Suprem…

Once again, citation please. You seem very sure of these Supreme Court decisions that appear to have slipped past the rest of us. Not saying you are wrong, with the firehose of info these days it's easy to miss things, even really important things.

To be clear, it isn't that a national identity database doesn't exist, they just can't force you to have a national identity token (that is a power divested to the States). Several legislative attempts have been made to link that database to some other token that is de facto mandatory even if they don't control it, like (currently) State ID. The challenge is, then, that they can't deprive citizens of rights for not having a token over which the Federal government has no control. The States have not been cooperative in this regard across the political spectrum, albeit for different reasons. So at the national level we either have optional ID tokens, like passports, or mandatory IDs that are not tokens, like SSN.

There isn't one court case that informs the boundaries of the Federal government and ID, and how the government may facilitate the linking of an existing identity token to their database, it is diffused across many. The policy and regulatory practice in the Federal government threads a convoluted path through this precedent, with myriad loopholes and workarounds, and exploiting gray areas that have not been adjudicated. I've worked in this environment, which is the only reason I know about it. Every time they create a database on US citizens, they must articulate the title authority that both allows that database to exist and to be used (use and existence are, somewhat dubiously, deemed separate authorities which notionally allows them to collect data if they don't look at it -- this reasoning is not well-tested).

In practice, the US government outsources identity stuff to companies like Lexis-Nexis, which rely on duck-typing to determine identity since this doesn't require the person being identified to carry a token. Just about everyone carries an ensemble of tokens that are sufficient for identity purposes if you have fewer database building prohibitions than the US government.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#244

I just signed up for TMobile last month. They asked me for my SSN. I said seriously?? They said yes we need it for a credit check to see if we can offer you service. I said sure... it's 123456789. "One moment sir..." "Congratulations! you have very good credit, Welcome to TMobile." ...It's baloney, I think they just try to get it for leverage if you have a bill outstanding. Anyway, very glad I gave them a fake SSN. E…

Never been so happy to be on a prepaid plan.

Kinda funny the plan I bought from walmart because I'm cheap had no credit check so no dob/ssn and it turned out to be significantly more secure than what was available if you shared your credit info with tmobile.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#245
post #70

Earlier quoted context omitted.

except that eIDAS is basically not in use in germany.

These things take time to implement. It's slowly getting rolled out. Germany in particular is.. digitally challenged as a country.

Great documentary about this subject (German): https://www.zdf.de/dokumentation/zdfzoom/zdfzoom-digitale-di...

Personally I'm not even that sad about this German situation because often "improving" things digitally means centralizing them so you suddenly have one big database of 80 million germans containing all their data. A hack of that is way more dangerous than a hack of a single municipality's database. The larger the database, the larger the payoff for the hackers.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#246
post #206

Earlier quoted context omitted.

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

No law so far ever required single form of ID to vote. All voter ID laws require some form of ID, which could be of many forms - driver license, citizenship id, passport, military ID, handgun license, special voter ID, and so on. There are many forms of ID that are accepted (and if you don't have any, as much as a copy of a recent utility bill and a signed affidavit may exempt you from the requirement). This is nowhe…

I said "require issued IDs to vote". Countering with "there are many forms of ID that are accepted" doesn't really feel like you're arguing against what I said.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#247

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

up till late 1990s SSN and DOB were public information, as they were printed on never-secured student IDs in American schools, for instance, and who knows where those unprotected lists went.

My university used it as the student id, so who knows how many hundreds of places that got copied. Including smeared all over the virtual desktop systems as it was your login identifier.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#248
post #184

Earlier quoted context omitted.

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

Real ID is a backdoor national ID, just administrated piecemeal by the states. The feds have all of the secure flight data and all of the Real ID license/state ID card data, linked to SSN.

Yes, this was the intent. However, many States have refused to implement the requirement to give the Feds access to their databases, even if though the ID conforms to standards, and the Feds don't have a lot of leverage to force compliance.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#249

Previous discussion from two days ago: https://news.ycombinator.com/item?id=28202399 This article does seem to report different numbers - 47M instead of 100M.

Thanks! Here's that one and another:

T-Mobile Confirms It Was Hacked - https://news.ycombinator.com/item?id=28202399 - Aug 2021 (248 comments)

T-Mobile investigating claims of 100M customer data breach - https://news.ycombinator.com/item?id=28192423 - Aug 2021 (191 comments)

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#250

I just signed up for TMobile last month. They asked me for my SSN. I said seriously?? They said yes we need it for a credit check to see if we can offer you service. I said sure... it's 123456789. "One moment sir..." "Congratulations! you have very good credit, Welcome to TMobile." ...It's baloney, I think they just try to get it for leverage if you have a bill outstanding. Anyway, very glad I gave them a fake SSN. E…

I'm kind of curious, did you use "123..." and they didn't care/notice, or did you give a random number?
Post reply on HN