Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

81–90 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#81

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing reasons) but I always try not to fill it out.

Also why are these phone companies persisting SSNs in database ? Why can't they run the credit check initially and discard the SSN. There should be laws around this and enforced. It is time to hold these companies accountable. We are so tired of being worried that our ID may get stolen.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#82

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about…

[deleted]

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#83
post #57

I bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use). Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked". Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to…

Interesting - I've always wondered if something like this is possible.

Even just if privacy.com or someone would let me signup with a fake identity to t-mobile. Then who cares if these folks get hacked?

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#84
post #12

Interestingly, I stopped being an AT&T customer 4 years ago but just this morning I received a phishing SMS containing my real name and a mention of AT&T overpayment or some-such. Could be a coincidence, or it could be the data is already out and being used.

The seller hasn't sold the data yet. Unless it has already been available behind the scenes and changed hands, I don't think the breach is related.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#85
post #62

Someone posts eight SSNs on a hacking forum and some wild claims, and reporters run it as a legitimate 70 million hack. And people wonder why the term fake news exists.

except these companies are crap at security and the folks posting have a relatively good reputation? That said - yeah, maybe post 500? This could just be trash as you say.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#86
post #57

I bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use). Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked". Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to…

Can you elaborate on "The enabling factor is that Visa/MC do not actually verify cardholder name"? Are you saying that you've got a credit card under an assumed name?

No, of course not.

I am saying that merchants do not have the ability to verify card holder name.

Your transaction will process properly with Mickey mouse as first last.

Only amex verifies cardholder name.

EDIT: relevant stackexchange is here: https://security.stackexchange.com/questions/220724/i-can-pa...

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#87

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Should have it where your social security is a public key and government has your private key. You're given a device that has your private key to confirm things but you don't know it directly. Public key is used in replace of discussi security number. If your public key gets compromised the government blacklists it and gives you a new one.

This is just a knee-jerk thought and I'm sure it can be improved, but I believe asymmetric keys are the solution.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#88

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Should have it where your social security is a public key and government has your private key. You're given a device that has your private key to confirm things but you don't know it directly. Public key is used in replace of discussi security number. If your public key gets compromised the government blacklists it and gives you a new one. This is just a knee-jerk thought and I'm sure it can be improved, but I believ…

If your public key gets compromised...

Do you mean private key? Or am I about to have a TIL moment? Because your public key is, well, public so I wonder what a compromise of that would look like.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#89

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Proposed alternative - you get your own private-key as an identifier. Nobody ever can ask for the private key, they can only ask for a signed message that proves identity. Thus a lot of categories of fraud are no longer possible because there is no shared reusable number in the event of a leak.
Post reply on HN