Interestingly, I stopped being an AT&T customer 4 years ago but just this morning I received a phishing SMS containing my real name and a mention of AT&T overpayment or some-such. Could be a coincidence, or it could be the data is already out and being used.
Claimed AT&T hack of 70M customer records including SSN, name, address
61–70 of 167 posts
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#62Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#63Earlier quoted context omitted.
I'm at the point where I just want a tattoo or chip embedded in me. Like I'm integrated in the system at this point. I can't exactly go off grid.
"How come no tattoo?!"
I believe the direct quote is "Why come you got no tattoo?"
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#64As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…
What are we gonna use instead? Hardware keys, like Ledger but for ID?
- It's inobtrusive enough to wear all, or very nearly all of the time. Contrast cards or similar carried-but-not-worn tokens.
- It can be readily use to tap a sensor for identification purposes. Contrast cards or similar tokens (e.g., USB keys), which are far less immediate.
- It is replaceable. That is, if it's compromised, stolen, or lost, it can be replaced. If it becomes unadvisable to possess, it's readily discarded and reasonably easily destroyed. This contrasts with biometrics or permanently embedded sensors.
- Its absence is reasonably immediately determinable. Again, contrast carried-but-not-worn tokens.
- The existing prevalence of ring-wearing makes use of an NFC ring less obvious or evident (mostly a concern in early-adoption periods), or the opting-out of wearing one (which ring is the NFC ring?), without directly querying each individual, which ... might not work regardless (depending on implementations).
- There are relatively few people who would be entirely unable to use such a device. Ready alternatives for most such cases exist: wrist bands
- Unintentional validation (e.g., surveillance) is relatively easily avoided, if devices require immediate contact with a sensor/receiver. That is, a surveillance entity couldn't mass scan a crowd or region quickly, but would have to individually query rings in close proximity. (This might be achieved through high-volume transit points already, but this already raises the ante.)
- It's possible with a query/response system that multiple identities with the same root, but not immediately correlated, could be supported. (Deanonymisation or identity linking remains a significant problem, however.) Ideally, such a system could be limited to only satisfying minimum qualifying criteria (e.g., "I've paid a fare for this trip"), rather than transmitting either a full personal dossier or an absolute identity.
Key (so to speak) challenges are in agreeing on a single standard, ensuring crytpgraphic robustness, and protecting privacy, surveillance, and other concerns, as well as distributing the detector infrastructure for desired uses.
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#65Earlier quoted context omitted.
How are MVNOs able to offer a lower price than the carriers? I was interested but didn't switch because I was worried they are selling my info or something.
They usually spend less on advertising/store presence/... (e.g. around here the large mobile networks have branded shops and such, the MVNOs almost never have and either sell only online or a supermarket brand and piggybacking on that store network), their plans might have restrictions the main network ones don't have, ... And in reverse, better brand recognition/(impression of) service quality allows the network ope…
I ported my landline to Page Plus in the late 2000s (which took over a week). I still have that number, and I have never spoken to a person when porting it between MVNOs (always over chat or email). My last port to Red Pocket took two days to get right. This can be a frustrating procedure, and many people prefer the major carriers for in-presence customer service for issues like this.
I have repeatedly switched between Verizon and AT&T when necessary due to phone hardware or coverage, and MVNOs usually allow this to be done (a limited number of times) through automated simcard changes with no customer service interaction.
The one surprising thing about my recent move to Red Pocket is the lack of voicemail in the included plan (it's available with a surcharge). I'm not certain if I miss it.
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#66I bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use). Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked". Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to…
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#67I bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use). Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked". Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to…
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#68Earlier quoted context omitted.
The nice thing about using an MVNO (aside from cost reduction) is that the carrier never receives any of that PII. I like the Red Pocket plans on Ebay, and they never asked for an SSN.
How are MVNOs able to offer a lower price than the carriers? I was interested but didn't switch because I was worried they are selling my info or something.
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#69Earlier quoted context omitted.
What are we gonna use instead? Hardware keys, like Ledger but for ID?
I'm strongly partial to a wearable token. The NFC Ring is one highly attractive option. - It's inobtrusive enough to wear all, or very nearly all of the time. Contrast cards or similar carried-but-not-worn tokens. - It can be readily use to tap a sensor for identification purposes. Contrast cards or similar tokens (e.g., USB keys), which are far less immediate. - It is replaceable. That is, if it's compromised, stole…
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#70Earlier quoted context omitted.
I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about…
In Germany the postal service does what GP described by validating someone's identity for various purposes > Deutsche Post offers a secure identity check service – to millions of users every year. > On behalf of your contracting party > To ensure that only identified persons have access to sensitive services > To sensitive services including those from the financial services sector (such as opening an online bank acc…
It's kind of like the feeling I get looking at somebody with a very nice car or house: "Oh, it would be neat to have such a thing but there's no way I'd ever splurge and get that." It's difficult for me to conceive of some things other countries have as just being "normal".