Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

151–160 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#151

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

> After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem.

Except that the problem isn't which party is legally liable. The problem is that the legal system is almost entirely inaccessible to the vast majority of people.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#152

Earlier quoted context omitted.

Ironically, having it in plain text on a piece of paper in some random doctor’s office is much more secure than having it hashed in some website’s database. Possibly even more secure than that same doctor having it in their system.

Good point. But realize it's only on that paper for a few mins before being typed into their system. Doctor's offices are so archaic at times. Only a handful let me do the forms online in advance. And even those have more paper for me to waste when I arrive.

A public system to enter data into, probably some sort of SAS or COT for most practices, has got to introduce far more insecurities than having the clerical staff enter it into the same backend the public system has to interact with.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#153

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about…

The 'ideology' is that the Democrats will oppose any form of better federal id for citizens because a big part of the party strategy is simping for illegal immigrants to cash in on their children's votes. This isn't some mysterious both sides issue, the Republicans have discussed the idea before.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#154

Earlier quoted context omitted.

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

Ironically, having it in plain text on a piece of paper in some random doctor’s office is much more secure than having it hashed in some website’s database. Possibly even more secure than that same doctor having it in their system.

Dumpster diving is a thing.

In almost all cases, someone is entering what you hand wrote into a system; and then they discard the paper copy.

If they shred it that's great, but dumpster diving at medical offices has made the news many many times.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#155

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

The solution to not being "worried that our ID may get stolen" is penalize companies who report false information to credit bureaus and penalize credit bureaus that give out false information. You don't care if someone impersonates you to a lender and a bank or mattress store loses money to a fraudster. You care that the company that lost the money can erroneously report that you defaulted on a loan to the credit bureaus and then the credit bureaus mark down your credit worthiness. This affects your cost on loans, ability to rent an apartment, get a job, etc. The "Fair Credit Act of 1970" gave credit bureaus immunity from liability from reporting false information as long as they don't to it on purpose and in exchange they have to give people access to the reports and fix errors (very hard to do in practice).

People were rightfully worried in recently emerging computer age that these credit agencies would have secret dossiers on everyone. At least this law let people look at them and in theory correct them.

It probably time to revisit that 50 year old act. I'm not sure how much lenders even use the standard scores anymore. Many calculate their own scores and probably include all sorts of info that we would be mad about them using if we knew what it was.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#156

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

It's really simple to those of us who do any work at all with authentication. If you share it with anyone, it's not a secret.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#158

Earlier quoted context omitted.

Yes! SSNs are already not private given the number of hacks that have occured. Today, the real damage comes from the fact that people/businesses still believe they are private. Publish a list of all SSNs would eliminate the misperception once and for all and force people to verify identity in a better way. SSNs should only ever be used for your employer knows how to report who paid what taxes to the IRS. If someone e…

Not sure if it's a problem of perception or just the lack of legal responsibility. As long as the legal and financial risk isn't owned by the party using the SSN for a purpose they shouldn't (identification), nothing will change.

How is the financial risk not owned by the party using the SSN for identification?

Guess who ends up footing the bill when a bank gives a loan to someone pretending to be you? Hint: It’s not you, and it’s not the fraudster either.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#159
post #132

Earlier quoted context omitted.

There's still some identity theft issues, because "everyone asks your SSN for no reason" becomes "everyone asks for a scan of your id for no reason". For instance, when I was looking for an appartment, the State had a service to both authenticate and watermark some documents (id and proof of income, among others). The watermark was a bunch of big bars with "this is intended for rental search" written on them. Kinda l…

This is the problem with having the public and private key be the same. Anyone should be able to access your public key, and anyone you deal with should be able to ask you to use your private key to verify your identity. The problem is when that entire process is reduced to "give us the number the government uses to ensure you're you. Don't worry, we won't use it to convince anyone else we're you ;) Or leak it so any…

How much would it cost to give everyone a device from which the private key could not be removed?

Worried about "mark of the beast" based objections? Make it optional. Those who wish can retire their SSN and receive their public / private keys and then the government publishes their SSN as a trashed SSN. Everyone who still wants just a SSN can take their chances.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#160
post #120

Earlier quoted context omitted.

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

When I got my Covid shot at Safeway they asked for it. I just didn't fill it out and no one even asked for it. I still had the record show up in Washington's vaccination DB, so it wasn't for that either. I hope them asking for it didn't discourage someone without an SSN from getting their shot, since immigration status isn't relevant to eligibility.

Cable and phone and electric seem trained to ask for SSN. I politely say no, and we move on.

People volunteered the leaked info. Just say no.

Post reply on HN