Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

31–40 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#31

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

What are we gonna use instead? Hardware keys, like Ledger but for ID?

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#32
post #15
post #11

Earlier quoted context omitted.

This situation could be greatly improved if these companies didn't have or need to have this data in the first place. Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.

With AT&T at least if you want the highest priority on their towers you have to be on their Elite plan (QCI 7 I believe), which is post-paid only

Yikes. Is that something that AT&T openly advertising?

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#33

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I'm at the point where I just want a tattoo or chip embedded in me. Like I'm integrated in the system at this point. I can't exactly go off grid.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#34

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Yes! SSNs are already not private given the number of hacks that have occured. Today, the real damage comes from the fact that people/businesses still believe they are private. Publish a list of all SSNs would eliminate the misperception once and for all and force people to verify identity in a better way. SSNs should only ever be used for your employer knows how to report who paid what taxes to the IRS. If someone else wants to use my SSN to claim that they paid my taxes, fine with me!

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#35

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I'm at the point where I just want a tattoo or chip embedded in me. Like I'm integrated in the system at this point. I can't exactly go off grid.

"How come no tattoo?!"

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#36
post #8

It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...

Just this week, I had to sign into a service for a very large transaction I'm privy to. My password? The last 4 of my social. It's unbelievable how dumb so many of our systems are.

I'm in Ireland at the moment, where the health system, and vaccination process, appears to use mother's maiden name as a de facto password. There is no option to change it. It is often asked in person, and so can't be used as a placeholder.

For business reasons, my mother has her parents' last name, I have hers, and this fact is easily discovered online with a few minutes research...

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#38

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about a package of other things.

But yes, I wish we could be as modern as some European countries. I haven't heard of these identity theft issues in France, where everyone has a national identity card.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#39
post #9

First T-Mobile, then AT&T (except that AT&T is denying it, which is hopeful). All eyes on Verizon...

The nice thing about using an MVNO (aside from cost reduction) is that the carrier never receives any of that PII. I like the Red Pocket plans on Ebay, and they never asked for an SSN.

How are MVNOs able to offer a lower price than the carriers? I was interested but didn't switch because I was worried they are selling my info or something.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#40

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about…

In Germany the postal service does what GP described by validating someone's identity for various purposes

> Deutsche Post offers a secure identity check service – to millions of users every year.

> On behalf of your contracting party

> To ensure that only identified persons have access to sensitive services

> To sensitive services including those from the financial services sector (such as opening an online bank account), telecommunications (activating a prepaid SIM card), health care (access to health information) or the mobility industry (including car sharing).

https://www.deutschepost.de/en/p/postident.html

Post reply on HN