Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

91–100 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#91
post #89

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Proposed alternative - you get your own private-key as an identifier. Nobody ever can ask for the private key, they can only ask for a signed message that proves identity. Thus a lot of categories of fraud are no longer possible because there is no shared reusable number in the event of a leak.

What do you do when you lose your private key?

Who issues the private key? "get" implies it comes from somewhere, i.e. a CA system.

If the government is the CA system, and your private key is your identity, how do you establish your identity in the event that you lost your key?

The nice thing about SSNs being immutable is that none of these are concerns. (It's also the bad thing about SSNs being immutable.)

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#92
post #89

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Proposed alternative - you get your own private-key as an identifier. Nobody ever can ask for the private key, they can only ask for a signed message that proves identity. Thus a lot of categories of fraud are no longer possible because there is no shared reusable number in the event of a leak.

In Denmark, you are issued a one-time pad. You get a new one with some frequency. If you lose it, you are issued a new one.

In that case, third parties could use a government website to get a row/col and ask you to verify, and the website could say yes/no. Yes, there is a risk of your one-time pad being stolen, but it is no greater than the current risk that any US citizen's tax documents or SS card can be stolen.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#93

Earlier quoted context omitted.

I'm strongly partial to a wearable token. The NFC Ring is one highly attractive option. - It's inobtrusive enough to wear all, or very nearly all of the time. Contrast cards or similar carried-but-not-worn tokens. - It can be readily use to tap a sensor for identification purposes. Contrast cards or similar tokens (e.g., USB keys), which are far less immediate. - It is replaceable. That is, if it's compromised, stole…

This all sounds very reasonable, albeit I'm partial to chip-and-PIN for preventing unintentional validation and to render the token useless if lost or stolen. The ring form factor doesn't lend itself to PIN entry, but otherwise it sounds reasonable compelling. (Granted I can't make myself wear a ring without taking it off, fidgeting with it, and ultimately losing it. I've tried, failed, and lost three as a result.)

An NFC ring can still require secondary authentication (e.g., pin) in some contexts. That would be application-dependent.

There are cases (e.g., mass-transit turnstiles) where this isn't desirable --- the intent is to maximise throughput. (The quesiton of whether or not validating or fares are a net benefit is also open.)

For a more secure facility, or payment system, tag + pin (and potentially other identifiers) would be preferred.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#94

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Should have it where your social security is a public key and government has your private key. You're given a device that has your private key to confirm things but you don't know it directly. Public key is used in replace of discussi security number. If your public key gets compromised the government blacklists it and gives you a new one. This is just a knee-jerk thought and I'm sure it can be improved, but I believ…

Nah, one-time pad with government verification for third parties. Keep it rolling.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#95
post #89

Earlier quoted context omitted.

Proposed alternative - you get your own private-key as an identifier. Nobody ever can ask for the private key, they can only ask for a signed message that proves identity. Thus a lot of categories of fraud are no longer possible because there is no shared reusable number in the event of a leak.

What do you do when you lose your private key? Who issues the private key? "get" implies it comes from somewhere, i.e. a CA system. If the government is the CA system, and your private key is your identity, how do you establish your identity in the event that you lost your key? The nice thing about SSNs being immutable is that none of these are concerns. (It's also the bad thing about SSNs being immutable.)

That and I can memorize my SSN.

We do have one thing in the US that’s physical proof, and that’s your birth certificate. But I’m sure people lose them and they can be pretty easily fabricated.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#96
post #8

It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...

SMS as 2FA is so stupid. So many banks and financial institutions are doing it in America and it amazes me. I mean what are they spending million of dollars in compliance/security/SOC etc on if they can't get a basic 2FA done correctly ? And don't get me started on stupid password requirements where a more secure password generated in keypass etc won't be valid. Who builds this stuff today ?

It provides good security for most people and is a big ease of use trade off. Hardware can be lost, software is difficult for most people to install and use. You need solutions that account for 95% of people. Ideally there’s non SMS for the other 5%, but unless Apple/Google/telcos come out with something better that’s built in, integrated, and dead simple, we’re stuck with SMS for a long time. Security is a spectrum.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#97

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Yes! SSNs are already not private given the number of hacks that have occured. Today, the real damage comes from the fact that people/businesses still believe they are private. Publish a list of all SSNs would eliminate the misperception once and for all and force people to verify identity in a better way. SSNs should only ever be used for your employer knows how to report who paid what taxes to the IRS. If someone e…

> SSNs should only ever be used for your employer knows how to report who paid what taxes to the IRS. If someone else wants to use my SSN to claim that they paid my taxes, fine with me!

That could go the other way, with someone else filing their income under your SSN without any corresponding withholding. This, too, needs better authentication than a mere SSN can provide.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#98
post #15
post #11

Earlier quoted context omitted.

This situation could be greatly improved if these companies didn't have or need to have this data in the first place. Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.

With AT&T at least if you want the highest priority on their towers you have to be on their Elite plan (QCI 7 I believe), which is post-paid only

What does the “priority on the towers” do?

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#99
post #86

Earlier quoted context omitted.

Can you elaborate on "The enabling factor is that Visa/MC do not actually verify cardholder name"? Are you saying that you've got a credit card under an assumed name?

No, of course not. I am saying that merchants do not have the ability to verify card holder name. Your transaction will process properly with Mickey mouse as first last. Only amex verifies cardholder name. EDIT: relevant stackexchange is here: https://security.stackexchange.com/questions/220724/i-can-pa...

> None of this was difficult nor illegal nor expensive.

Is giving a false name to the CC companies not illegal in some way? At the very least I'm certain it is a breach of contract.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#100

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

It seems like someone could do us all a public service by combining a few of these lists and making a very public and hard to take down website with them all listed. Create a forcing function for a replacement.

Not recommending anyone do this as it's obviously illegal, but..

Post reply on HN