Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

121–130 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#121

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

Blame the insurance companies - most major insurance companies use your SSN as a mechanism for identifying the patient. The member ID #'s can be used but it's quicker to just input the SSN.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#122
post #72

Earlier quoted context omitted.

In Germany the postal service does what GP described by validating someone's identity for various purposes > Deutsche Post offers a secure identity check service – to millions of users every year. > On behalf of your contracting party > To ensure that only identified persons have access to sensitive services > To sensitive services including those from the financial services sector (such as opening an online bank acc…

Why is activating a pre-paid sim card a "sensitive service"?

To mitigate criminal activity ranging from stolen phones, to cellphone-activated bombs to evading wiretaps. I’m not arguing this is a good reason, but likely the reason this exists as a requirement.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#123
post #89

Earlier quoted context omitted.

Proposed alternative - you get your own private-key as an identifier. Nobody ever can ask for the private key, they can only ask for a signed message that proves identity. Thus a lot of categories of fraud are no longer possible because there is no shared reusable number in the event of a leak.

In Denmark, you are issued a one-time pad. You get a new one with some frequency. If you lose it, you are issued a new one. In that case, third parties could use a government website to get a row/col and ask you to verify, and the website could say yes/no. Yes, there is a risk of your one-time pad being stolen, but it is no greater than the current risk that any US citizen's tax documents or SS card can be stolen.

How do they bootstrap the verification when you say you lost your key?

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#124
post #121

Earlier quoted context omitted.

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

Blame the insurance companies - most major insurance companies use your SSN as a mechanism for identifying the patient. The member ID #'s can be used but it's quicker to just input the SSN.

But they already get a copy of our Insurance Cards. Shouldn't that be enough ?

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#125

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

Our government is run by a gerontocracy born decades prior to PCs and the internet. They have no idea what the root problem is or how to fix it. How many of them even know the absolute basics? What a for loop is? Or Postgres? Or http vs https? Anything they actually do will be written by lobbyists on behalf of tech giants and other multinational corporations and big donors. Between that and the increasingly fundament…

I am becoming less luddite, but way more partial to older technology.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#127
post #57

I bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use). Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked". Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to…

Can you elaborate on "The enabling factor is that Visa/MC do not actually verify cardholder name"? Are you saying that you've got a credit card under an assumed name?

When I use a privacy.com virtual card, I can use any name/address and the transaction is approved.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#128

Earlier quoted context omitted.

it is selection bias -- the people with miserable and oppressive systems do not report it in detail, in English, on YNews right? second, many systems of law treat individuals quite differently.. many systems that are not repeated in detail, on YNews, do not give much choice to an individual by design

I'm not suggesting that the United States is particularly bad. There are definitely many places in the world that are much worse off from so many perspectives (lack of rule of law, system of governance, economy, social safety net, class mobility, corruption, etc). It could be better in so many ways, though, too. It would be nice if younger people (say, sub-70) would (and could be permitted to) take up the mantles of…

It would be nice if younger people (say, sub-70) would (and could be permitted to) take up the mantles of leadership.

I'd really like to read a speculative fiction/scifi where every generation operates under its own system of laws, and you can opt in to a neighboring generation's laws instead once every N years or something.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#129

Earlier quoted context omitted.

In Germany the postal service does what GP described by validating someone's identity for various purposes > Deutsche Post offers a secure identity check service – to millions of users every year. > On behalf of your contracting party > To ensure that only identified persons have access to sensitive services > To sensitive services including those from the financial services sector (such as opening an online bank acc…

Stories about foreign countries and their societal infrastructure, as an American, make me really envious and sad for my country's state of affairs. It's kind of like the feeling I get looking at somebody with a very nice car or house: "Oh, it would be neat to have such a thing but there's no way I'd ever splurge and get that." It's difficult for me to conceive of some things other countries have as just being "norma…

only issue with Postident is that they are annoying and weren't accepting certain passports for foreign nationals for a time. also, they have an online system you can sort-of use now but also not really, and you cannot use a valid permanent residence card even tho it's issued by the german govt... it _is_ pretty alright though

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#130
post #120

Earlier quoted context omitted.

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

When I got my Covid shot at Safeway they asked for it. I just didn't fill it out and no one even asked for it. I still had the record show up in Washington's vaccination DB, so it wasn't for that either. I hope them asking for it didn't discourage someone without an SSN from getting their shot, since immigration status isn't relevant to eligibility.

I always leave it blank on the forms at doctor's offices and other medical facilities, no one has ever brought it up and asked for it.
Post reply on HN