As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…
I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…
Claimed AT&T hack of 70M customer records including SSN, name, address
121–130 of 167 posts
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#122Earlier quoted context omitted.
In Germany the postal service does what GP described by validating someone's identity for various purposes > Deutsche Post offers a secure identity check service – to millions of users every year. > On behalf of your contracting party > To ensure that only identified persons have access to sensitive services > To sensitive services including those from the financial services sector (such as opening an online bank acc…
Why is activating a pre-paid sim card a "sensitive service"?
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#123Earlier quoted context omitted.
Proposed alternative - you get your own private-key as an identifier. Nobody ever can ask for the private key, they can only ask for a signed message that proves identity. Thus a lot of categories of fraud are no longer possible because there is no shared reusable number in the event of a leak.
In Denmark, you are issued a one-time pad. You get a new one with some frequency. If you lose it, you are issued a new one. In that case, third parties could use a government website to get a row/col and ask you to verify, and the website could say yes/no. Yes, there is a risk of your one-time pad being stolen, but it is no greater than the current risk that any US citizen's tax documents or SS card can be stolen.
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#124Earlier quoted context omitted.
I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…
Blame the insurance companies - most major insurance companies use your SSN as a mechanism for identifying the patient. The member ID #'s can be used but it's quicker to just input the SSN.
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#125When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.
Our government is run by a gerontocracy born decades prior to PCs and the internet. They have no idea what the root problem is or how to fix it. How many of them even know the absolute basics? What a for loop is? Or Postgres? Or http vs https? Anything they actually do will be written by lobbyists on behalf of tech giants and other multinational corporations and big donors. Between that and the increasingly fundament…
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#126Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#127I bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use). Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked". Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to…
Can you elaborate on "The enabling factor is that Visa/MC do not actually verify cardholder name"? Are you saying that you've got a credit card under an assumed name?
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#128Earlier quoted context omitted.
it is selection bias -- the people with miserable and oppressive systems do not report it in detail, in English, on YNews right? second, many systems of law treat individuals quite differently.. many systems that are not repeated in detail, on YNews, do not give much choice to an individual by design
I'm not suggesting that the United States is particularly bad. There are definitely many places in the world that are much worse off from so many perspectives (lack of rule of law, system of governance, economy, social safety net, class mobility, corruption, etc). It could be better in so many ways, though, too. It would be nice if younger people (say, sub-70) would (and could be permitted to) take up the mantles of…
I'd really like to read a speculative fiction/scifi where every generation operates under its own system of laws, and you can opt in to a neighboring generation's laws instead once every N years or something.
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#129Earlier quoted context omitted.
In Germany the postal service does what GP described by validating someone's identity for various purposes > Deutsche Post offers a secure identity check service – to millions of users every year. > On behalf of your contracting party > To ensure that only identified persons have access to sensitive services > To sensitive services including those from the financial services sector (such as opening an online bank acc…
Stories about foreign countries and their societal infrastructure, as an American, make me really envious and sad for my country's state of affairs. It's kind of like the feeling I get looking at somebody with a very nice car or house: "Oh, it would be neat to have such a thing but there's no way I'd ever splurge and get that." It's difficult for me to conceive of some things other countries have as just being "norma…
Re: Claimed AT&T hack of 70M customer records including SSN, name, address
#130Earlier quoted context omitted.
I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…
When I got my Covid shot at Safeway they asked for it. I just didn't fill it out and no one even asked for it. I still had the record show up in Washington's vaccination DB, so it wasn't for that either. I hope them asking for it didn't discourage someone without an SSN from getting their shot, since immigration status isn't relevant to eligibility.