Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

51–60 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#51
post #8

It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...

Just this week, I had to sign into a service for a very large transaction I'm privy to. My password? The last 4 of my social. It's unbelievable how dumb so many of our systems are.

On a similar note, I setup my utility account this week. It was suggested by the representative that I use the last 4 digits of my SSN as a pin for my account. Pretty disappointing how short sighted many companies are when it comes to security practices.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#52

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

Our government is run by a gerontocracy born decades prior to PCs and the internet. They have no idea what the root problem is or how to fix it. How many of them even know the absolute basics? What a for loop is? Or Postgres? Or http vs https? Anything they actually do will be written by lobbyists on behalf of tech giants and other multinational corporations and big donors. Between that and the increasingly fundament…

There's a both sidesism here - one party that's demanding censorship (because misinformation, danger, etc.) when they used to fight it, the other party seemingly defenders of classic big corporate entities, yes it does seem hopeless.

I think it has to get worse before it gets better. If almost everyone's personal information, SS and so forth, even IMEI's, addresses, mother's maiden, you name it, is available on the dark web, then that'll basically mean the corporate world will have to create a new mechanism. For example, the most obvious is the entire system in which credit worthiness is determined.

I know two people with identity theft issues, and in both cases people opened up accounts that impacted credit worthiness. That's really lousy if you spend a long time searching for a home to buy, and when you're in contract something like this happens and your credit gets dinged. Blame the banks and the credit industry as much as the hackers. They made this impossible-to-contain information literally the key determinant of your ability to get a loan in order to purchase a home.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#53

Earlier quoted context omitted.

Yes! SSNs are already not private given the number of hacks that have occured. Today, the real damage comes from the fact that people/businesses still believe they are private. Publish a list of all SSNs would eliminate the misperception once and for all and force people to verify identity in a better way. SSNs should only ever be used for your employer knows how to report who paid what taxes to the IRS. If someone e…

Not sure if it's a problem of perception or just the lack of legal responsibility. As long as the legal and financial risk isn't owned by the party using the SSN for a purpose they shouldn't (identification), nothing will change.

100%. The very concept of "identity theft" feels like corporate newspeak to shift the onus of remediation from the party that actually got defrauded (the company) to someone uninvolved in the transaction.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#54

What AT&T service compels consumer SSN disclosure to begin with?

I think it's any contract with a carrier. They want the ability to go after you and hurt your credit if you refuse to pay, is my guess. It's disgusting.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#55
post #47

Earlier quoted context omitted.

Our government is run by a gerontocracy born decades prior to PCs and the internet. They have no idea what the root problem is or how to fix it. How many of them even know the absolute basics? What a for loop is? Or Postgres? Or http vs https? Anything they actually do will be written by lobbyists on behalf of tech giants and other multinational corporations and big donors. Between that and the increasingly fundament…

Of course they understand. The issue is that they don't care. They don't care about you or me. They don't care about whether you have Internet access and if you do whether it is slow or fast. They don't care whether you are homeless or rich or if you are high on drugs or a personal trainer to the stars. If you make a big enough issue about how they apparently don't understand, they will create a committee to study th…

I think the takeaway is that government represents too many people and you cant satisfy everyone, so leaders listen to citizen action groups and lobbyists who are able to aggregate all these different viewpoints into more broadly popular legislation and show with their supporters that these ideas would be popular among a given electorate.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#56
post #26

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

A converstation earlier this week pointed out the EU system: eIDAS [0]. it looks pretty interesting how its decentralized. I could see something like this running from each state's DMV (or the postal service if you didn't want to use your local state DMV) to help ensure you are you. It would be interesting to hear what people that use it say, because i'm sadly stuck in a very US world :) [0] https://en.wikipedia.org/…

We already have systems for notarization, perhaps we could try to leverage that, updating it for more modern purposes. I could see them issuing things like smart cards. Then again we have some pretty hardcore religious zealots who refuse to do anything even remotely resembling a national ID system, so it will continue to be fragmented and subject to each state's implementation.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#57
I bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use).

Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked".

Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to email for a day or three. Yes, of course twilio has an assumed name.

None of this was difficult nor illegal nor expensive.

The enabling factor is that Visa/MC do not actually verify cardholder name (even though everyone thinks they do).

So my bank sort of knows who all the providers are, but they'd need to collude with (MVNO or twilio or Apple) to have any real PII which could then be stolen ...

My threat model is PII theft via hacks (like this one) and wayward employees at each provider. My threat model is not state actors or LEAs.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#58
post #47

Earlier quoted context omitted.

Of course they understand. The issue is that they don't care. They don't care about you or me. They don't care about whether you have Internet access and if you do whether it is slow or fast. They don't care whether you are homeless or rich or if you are high on drugs or a personal trainer to the stars. If you make a big enough issue about how they apparently don't understand, they will create a committee to study th…

I think the takeaway is that government represents too many people and you cant satisfy everyone, so leaders listen to citizen action groups and lobbyists who are able to aggregate all these different viewpoints into more broadly popular legislation and show with their supporters that these ideas would be popular among a given electorate.

After having interacted with politicians, I am firm in my belief that most of them don't care about their constituents.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#59
post #11

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

This situation could be greatly improved if these companies didn't have or need to have this data in the first place. Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.

I've been using Liberty for a while now and it's been fine. It's 2G but I'm like 90% of the time always around wifi I trust so not a major deal. No reason to blow tons on data I don't use.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#60
Interestingly it looks like T-Mobile US also had a very similar data breach a couple days ago.

> We have determined that the types of impacted information include: names, drivers’ licenses, government identification numbers, Social Security numbers, dates of birth, T-Mobile prepaid PINs (which have already been reset to protect you), addresses and phone number(s).

https://www.t-mobile.com/brand/data-breach-2021

Post reply on HN