Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

251–260 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#251
post #194

Earlier quoted context omitted.

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

> everyone asks why don't we just thing that looks like a national identity system Aren't passports national/federal identity systems?

But not mandatory. You don’t need to get a passport unless you want to travel internationally.

The question is whether the U.S. federal government can require all U.S. residents to get, carry, and provide a national form of identification. To my knowledge it cannot, but I’m not handy with a case citation to prove it. Watching the rest of this thread to see what people turn up.

Note that Social Security numbers are explicitly not intended to be such IDs, although many services do use SSN as a key to distinguish people from one another.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#252

Earlier quoted context omitted.

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

There are cases spanning a century across several creative legislative attempts by the US Congress to create a de facto mandatory national identity system. This information is not difficult to find. All of them tried to workaround the fact that States can create mandatory identity systems but the Federal government cannot. (It is one of the reasons SSN cards go out of their way to assert they are not to be used as an…

> There are cases spanning a century across several creative legislative attempts by the US Congress to create a de facto mandatory national identity system.

Then it should be easy to present one, preferably the most applicable one to modern proposals.

> This information is not difficult to find.

Its not easy to find the arguments of the people opposed to national ID, and its not easy to verify that the cases they cite are not about national IDs.

> All of them tried to workaround the fact that States can create mandatory identity systems but the Federal government cannot

None of the national ID debates have been about a mandatory ID (a mandatory-for-specific-purposes ID, yes, but the feds already issue a number of those.)

> (It is one of the reasons SSN cards go out of their way to assert they are not to be used as an ID.)

No, social security cards say that because they aren’t designed to validate identity, since all they contain is a name and a number and no way other than possession (which is extremely problematic) to associate that with a particular person.

> Past attempts included things like withholding tax disbursements to non-compliant States

[citation needed]

> but the US Supreme Court deemed that coercive and therefore illegal.

[citation needed]

> The Real ID Act is the latest attempt

Real ID is not a mandatory ID, but a required-for-enumerated purposes ID. The enumerated purposes are ones for which the federal government already establishes acceptable ID standards without any Constitutional challenge, under various Article I, Sec. 8 powers, Real ID is just a change to the standards. And all phases of it but for Phase 4 involving (notably) the mandated to use Real ID for commercial air travel have already gone into effect. Starting in 2014.

but it has been delayed for many years by State non-compliance and general unwillingness to share their identity databases with the Federal government.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#253
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

I can agree. At one of my previous employers, IT management was adamant that no password vaults of any kinds could be used. It was a bigger company with tons of various systems to get into all with different sets of requirements. So what was the result? Average user ended up storing passwords info in excel and text files. Yay. I think only recently there was some movement to approve a vendor there.

One of my coworkers just convinced our IT dept to add a password vault to the preapproved list of software! I was very happy about that small victory.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#255
post #206

Earlier quoted context omitted.

No law so far ever required single form of ID to vote. All voter ID laws require some form of ID, which could be of many forms - driver license, citizenship id, passport, military ID, handgun license, special voter ID, and so on. There are many forms of ID that are accepted (and if you don't have any, as much as a copy of a recent utility bill and a signed affidavit may exempt you from the requirement). This is nowhe…

I said "require issued IDs to vote". Countering with "there are many forms of ID that are accepted" doesn't really feel like you're arguing against what I said.

What I am trying to emphasize here is that there's a difference between "a myriad of disjoined systems which can be used to identify somebody" and "a single system that includes data about everybody". The difference is a bit like being able to hire a PI to follow somebody and having everybody's whereabouts in a single centralized database 24/7. Not the same thing, wouldn't you agree?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#256
post #194

Earlier quoted context omitted.

> everyone asks why don't we just thing that looks like a national identity system Aren't passports national/federal identity systems?

But not mandatory. You don’t need to get a passport unless you want to travel internationally. The question is whether the U.S. federal government can require all U.S. residents to get, carry, and provide a national form of identification. To my knowledge it cannot, but I’m not handy with a case citation to prove it. Watching the rest of this thread to see what people turn up. Note that Social Security numbers are ex…

> But not mandatory.

Even state IDs aren’t generally mandatory in theory, they are mandatory for specific purposes. Like most proposed national IDs. Like Passports. Like Real ID. Like EDL. Like Military ID. Like…

> The question is whether the U.S. federal government can require all U.S. residents to get, carry, and provide a national form of identification.

No, its not. Literally no one is advocating that. Its actually pretty well established that even states, while they can require you to use ID for a whole lot of purposes, but can’t mandate that you carry and produce one generally.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#257
post #245

Earlier quoted context omitted.

These things take time to implement. It's slowly getting rolled out. Germany in particular is.. digitally challenged as a country.

Great documentary about this subject (German): https://www.zdf.de/dokumentation/zdfzoom/zdfzoom-digitale-di... Personally I'm not even that sad about this German situation because often "improving" things digitally means centralizing them so you suddenly have one big database of 80 million germans containing all their data. A hack of that is way more dangerous than a hack of a single municipality's database. The larg…

well depends while corona vaccinate-priority (right word?) was underway it was possible to send a FAX! to the healthcare insurer (not everybody allowed that) and you would've gotten a certificate for your priorty. I mean... fax is most often not encrypted. also deutsche telekom still does not support SRTP for sip (for most of their contracts, if you want SRTP you need to have a pretty expensive business contract), besides that they killed of analog phone lines, thats just stupid and most often if you have a sip trunk or some kind of cloud pbx you would need to pay double to get it...

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#258

Earlier quoted context omitted.

It is illegal for the US government to create a mandatory national identity system or coerce the States into creating one. The limits of this have been pretty thoroughly tested in the US Supreme Court. Every time things like this come up, everyone asks why don't we just thing that looks like a national identity system to fix the issue, as if that never occurred to anyone in Congress. This is why: it violates the Cons…

Citation needed. "It's against the constitution" - where? Cite an article, quote a paragraph, something. You say the Supreme Court has decided this; fine, quote a court case. I'm not saying you're wrong, but I have no idea what you're talking about. We have plenty of de facto ID systems. But I'd argue they aren't mandatory because -there is no political will to make them mandatory-. What is achieved by doing so? Hell…

The anti commandeering doctrine, from the 10th amendment is what prohibits the federal government forcing states to implement a mandatory federal ID requirement for things like applying for credit or opening a bank account

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#259

Earlier quoted context omitted.

Well, Germany is not the entire EU. I have such card and it comes in handy from time to time, though the implementation could be much better.

Haven’t seen it in Ireland either.

I think that it exist under the name electronic signature. Here is a pdf that might talk about it in IE:

https://www.lawsociety.ie/globalassets/documents/committees/...

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#260

Earlier quoted context omitted.

And other people think you should have to present proof of vaccination to go outside but no ID vote. Neither group is thinking past the propaganda their side presents.

Are there really people that want to require proof of vaccination to go outside? I haven’t heard that one.

[dead]
Post reply on HN