Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

111–120 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#111

Earlier quoted context omitted.

> None of this was difficult nor illegal nor expensive. Is giving a false name to the CC companies not illegal in some way? At the very least I'm certain it is a breach of contract.

I think OP is saying that they give a fake name to the vendor, not the CC card company. Walmart (maybe?) isn't checking that the billing name you give them matches the name on the card. I don't know how true this is across all vendors.

This is correct.

I have the same, real-name relationship with my bank and card issuers that you or anyone else has.

Rando-web-merchant, on the other hand, never gets my real name.

"I don't know how true this is across all vendors."

Almost 100%.

There is a rarely used program called "verified by visa" that takes you through an additional verification step and encourages you to create some sort of account linked to your issuing bank (or something) but I have only run into that once in the years I have adopted this practice.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#112
post #3

> Here is the data that is available in this leak: Name Phone number Physical address Email address Social security number Date of birth Not only the phone number but the physical address? If this is true, absolutely outrageous. > The hacker has said he is willing to reach “an agreement” with AT&T to remove the data from sale. Might as well pay the hacker's ransom, AT&T to remove the data from sale otherwise if leake…

>a massive fine (probably larger than the hacker's ransom) awaits you. Based on past experience, unlikely.

https://krebsonsecurity.com/2015/11/fcc-fines-cox-595k-over-...

Cox had to pay up over a few social engineering calls.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#113

Why is it so much harder and costlier for companies to be able to store credit card numbers, but not SSNs? I mean there is a whole certification process that costs hundreds of thousands of dollars to get pci certified, but you could say an SSN has the same of not larger risk profile. You can cancel credit cards, can’t get a new SSN. What is stopping government from implementing the same requirements? No one asks for…

A globally unique id is incredibly useful to many businesses, particularly since half of America changes their names. Often repeatedly. So there will be incredible back pressure at implementing this.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#114

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Interesting point of view. Maybe ssn should be used for authentication purposes.

Give SSN. Get email txt or notification to verify. SSN service replies back with a real Id number. Real id number is used for banking.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#115

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about…

There's still some identity theft issues, because "everyone asks your SSN for no reason" becomes "everyone asks for a scan of your id for no reason".

For instance, when I was looking for an appartment, the State had a service to both authenticate and watermark some documents (id and proof of income, among others).

The watermark was a bunch of big bars with "this is intended for rental search" written on them. Kinda low-tech, and it feels like a creative attacker could use software to strip them out, but it's cool they did that.

In theory, we have some very good APIs for securely authenticating someone (France Connect in particular), in practice administrations are slow to adopt them.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#116
post #100

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

It seems like someone could do us all a public service by combining a few of these lists and making a very public and hard to take down website with them all listed. Create a forcing function for a replacement. Not recommending anyone do this as it's obviously illegal, but..

I still doubt much would come of it until someone began to target lawmakers with it.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#118

Earlier quoted context omitted.

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

Ironically, having it in plain text on a piece of paper in some random doctor’s office is much more secure than having it hashed in some website’s database. Possibly even more secure than that same doctor having it in their system.

Good point. But realize it's only on that paper for a few mins before being typed into their system.

Doctor's offices are so archaic at times. Only a handful let me do the forms online in advance. And even those have more paper for me to waste when I arrive.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#119
post #100

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

It seems like someone could do us all a public service by combining a few of these lists and making a very public and hard to take down website with them all listed. Create a forcing function for a replacement. Not recommending anyone do this as it's obviously illegal, but..

I'm not sure if it is illegal since the US expends a lot of energy keeping privacy rights out of its civil rights.. But it would be a chore to process gdpr requests from dual citizens, etc.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#120

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

When I got my Covid shot at Safeway they asked for it. I just didn't fill it out and no one even asked for it. I still had the record show up in Washington's vaccination DB, so it wasn't for that either.

I hope them asking for it didn't discourage someone without an SSN from getting their shot, since immigration status isn't relevant to eligibility.

Post reply on HN