Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

271–280 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#271

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

up till late 1990s SSN and DOB were public information, as they were printed on never-secured student IDs in American schools, for instance, and who knows where those unprotected lists went.

This practice went on all the way into the mid-2000s at least (I graduated in 2006 and my SSN (which doubled as a student id) was printed on my student ID back then)

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#272

Earlier quoted context omitted.

Once again, citation please. You seem very sure of these Supreme Court decisions that appear to have slipped past the rest of us. Not saying you are wrong, with the firehose of info these days it's easy to miss things, even really important things.

To be clear, it isn't that a national identity database doesn't exist, they just can't force you to have a national identity token (that is a power divested to the States). Several legislative attempts have been made to link that database to some other token that is de facto mandatory even if they don't control it, like (currently) State ID. The challenge is, then, that they can't deprive citizens of rights for not h…

What in the US Constitution is preventing Congress from passing a law establishing national identity tokens? I’d figure that would be done under Congress’s power “To establish a uniform Rule of Naturalization.”

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#274
post #100

Earlier quoted context omitted.

You're significantly overestimating the amount of pull that type of person has in the US anymore, while simultaneously dramatically (I can only assume willfully) misquoting that bible verse.

"That type of person" accounts for some substantial fraction of the vaccine-hesitant population that accounts for freely available covid-19 vaccines for everyone age 12+ in the US but only 51% of the population being fully vaccinated[1]. So, even if you consider it absurd, this particular belief IS widely-enough held to influence behavior and public policy in the US. [1] https://covid.cdc.gov/covid-data-tracker/#vacc…

That's what I thought you stupid piece of shit.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#275
post #222
post #173

Earlier quoted context omitted.

With today's postpaid plans that have almost no way to get an overage, what's the point of setting it up to require credit? The postpaid plans are usually more expensive than prepaid, and they require a SSN and I'm not going to make the difference back by investing the payment for a month.

Carriers also have financing and/or renting of expensive equipment (phones) as part of their post paid plans. This is a very big deal for many people. Post paid plans can also have a minimum term/termination fees, which the carrier would be interested in collecting. Post-paid plans are also often grandfathered when prices increase for new customers.

So despite small ARM computers costing almost nothing these companies have managed to get everyone to overpay for and finance them then publish their SSN.

Anything that touches the phone network is cursed.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#276
post #208

Earlier quoted context omitted.

> It is illegal for the US government to create a mandatory national identity system The system can be voluntary. If you don't need an SSN today, you wouldn't need to use that system. If some bank or health care provider only accepts such a system, just pick another one, or create your own bank / health care provider.

You can not create a bank that does not verify identity according to a myriad of KYC regulations. You'd be heavily fined and most likely jailed if you do. Not sure about healthcare providers, probably if you're something like a massage therapist, there are no such requirements, but for a larger one there are probably regulations too.

So how do banks verify identity in the US ?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#277

>Can we please have this in the US? No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.

Please stop posting flamewar comments to HN and using HN for political battle. You've done a lot of that and it's not what this site is for. We've also had to ask you this in the past, so please fix this.

Comments like this one in particular make threads nastier, dumber, and more tedious.

We detached this subthread from https://news.ycombinator.com/item?id=28224033.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#279

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

Please keep religious flamewar off HN.

We detached this subthread from https://news.ycombinator.com/item?id=28224033.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#280
post #208

Earlier quoted context omitted.

You can not create a bank that does not verify identity according to a myriad of KYC regulations. You'd be heavily fined and most likely jailed if you do. Not sure about healthcare providers, probably if you're something like a massage therapist, there are no such requirements, but for a larger one there are probably regulations too.

So how do banks verify identity in the US ?

Usually they rely on government documents (driver licenses, passports, such kind of thing). Online banking has been a bit more lax but started having more KYC requirements recently. For an American though it's usually boils down to asking for SSN and driver license.
Post reply on HN