Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

41–50 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#41
post #9

Earlier quoted context omitted.

The nice thing about using an MVNO (aside from cost reduction) is that the carrier never receives any of that PII. I like the Red Pocket plans on Ebay, and they never asked for an SSN.

How are MVNOs able to offer a lower price than the carriers? I was interested but didn't switch because I was worried they are selling my info or something.

They usually spend less on advertising/store presence/... (e.g. around here the large mobile networks have branded shops and such, the MVNOs almost never have and either sell only online or a supermarket brand and piggybacking on that store network), their plans might have restrictions the main network ones don't have, ...

And in reverse, better brand recognition/(impression of) service quality allows the network operators to charge more and still get customers, the MVNOs need to be cheaper to compete with that.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#42
Given that legislation will realistically never keep pace with technology, would it be crazy to implement whitelist data collection law, i.e., no data can be collected unless explicitly allowed? Hypothetically, of course — congress actually putting something like this into law is a different story.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#43

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Yes! SSNs are already not private given the number of hacks that have occured. Today, the real damage comes from the fact that people/businesses still believe they are private. Publish a list of all SSNs would eliminate the misperception once and for all and force people to verify identity in a better way. SSNs should only ever be used for your employer knows how to report who paid what taxes to the IRS. If someone e…

Not sure if it's a problem of perception or just the lack of legal responsibility. As long as the legal and financial risk isn't owned by the party using the SSN for a purpose they shouldn't (identification), nothing will change.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#44
post #25
post #23

Earlier quoted context omitted.

I received the exact same thing. I was also a customer of AT&T around 4 or so years ago. The odd thing to me was the phishing text said to CALL ATT's very own number. No links or anything.

Mine included a link. I already removed it so can't look at it now, but it definitely included one of those minified links that immediately scream "phishing".

I received the same thing yesterday.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#45

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about…

Third world country here. Even we have ID cards and no identity theft issues. I don't get why the US doesn't get on with the times. Same for the metric system.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#46
post #31

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

What are we gonna use instead? Hardware keys, like Ledger but for ID?

That's basically what some countries have: IDs with a smartcard built in which functions like a HSM

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#47

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

Our government is run by a gerontocracy born decades prior to PCs and the internet. They have no idea what the root problem is or how to fix it. How many of them even know the absolute basics? What a for loop is? Or Postgres? Or http vs https? Anything they actually do will be written by lobbyists on behalf of tech giants and other multinational corporations and big donors. Between that and the increasingly fundament…

Of course they understand. The issue is that they don't care. They don't care about you or me. They don't care about whether you have Internet access and if you do whether it is slow or fast. They don't care whether you are homeless or rich or if you are high on drugs or a personal trainer to the stars.

If you make a big enough issue about how they apparently don't understand, they will create a committee to study the issue then ignore the findings. They don't care about you or your problems.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#48

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about…

It's infuriating, because with the proper messaging, this is a bipartisan issue. Righ, left and everyone between have had identities stolen. Stolen identities cost businesses money - I'd wager millions, maybe billions collectively every year. There's literally no reason why a more secure form of identify verification needs to be a partisan issue.

Which is exactly why it will be :(

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#49
post #23
post #12

Interestingly, I stopped being an AT&T customer 4 years ago but just this morning I received a phishing SMS containing my real name and a mention of AT&T overpayment or some-such. Could be a coincidence, or it could be the data is already out and being used.

I received the exact same thing. I was also a customer of AT&T around 4 or so years ago. The odd thing to me was the phishing text said to CALL ATT's very own number. No links or anything.

An SMS can be crafted to attack your phone if you view the message.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#50

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Maybe we need to tell each individual company that our SSN is public when they ask for it and why they rely on it to identify me... another form of ID that they like to use when you apply for credit is previous addresses/cars/etc... as if that isn't public.
Post reply on HN