Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

161–167 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#161
post #132

Earlier quoted context omitted.

This is the problem with having the public and private key be the same. Anyone should be able to access your public key, and anyone you deal with should be able to ask you to use your private key to verify your identity. The problem is when that entire process is reduced to "give us the number the government uses to ensure you're you. Don't worry, we won't use it to convince anyone else we're you ;) Or leak it so any…

How much would it cost to give everyone a device from which the private key could not be removed? Worried about "mark of the beast" based objections? Make it optional. Those who wish can retire their SSN and receive their public / private keys and then the government publishes their SSN as a trashed SSN. Everyone who still wants just a SSN can take their chances.

SSN already is optional. Nobody forced your parents to register you, but your parents wanted to claim you on the IRS tax form each year so they sold you out.

USA passport for my children didn't require SSN. And a passport complies with TSA id checks.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#163

Earlier quoted context omitted.

I think it's any contract with a carrier. They want the ability to go after you and hurt your credit if you refuse to pay, is my guess. It's disgusting.

How is it disgusting for a lender to be able to look up someone's credit history and determine if they are an appropriate credit risk for them? The alternative is everyone gets (or does not get at all) credit on the same terms without regards to personal behavior or risk profiles, which is a valid option, but I would still think "disgusting" is a strong word to describe the prior scenario.

You're asking this question in the following context: getting a cell mobile provider contract requires a social security number. Social security number is used to pin a score on someone's credit worthiness. Mobile provider gets hacked, exposing clients to bad actors using social security number and associated data to open credit lines fraudulently and hurting users' credit worthiness scores.

The disgusting part is the whole reason the providers demanded SS # is to defend their own interests to threaten clients with collection agencies and credit score dips. The neglect of these same now cause clients to risk getting credit score dips through no fault of their own.

Which part of this sits well with you?

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#164
Anybody who has ever worked in finance or any number of Finance adjacent industries realizes how easily accessible social Security numbers actually are. Anyone can sign up for a skip tracing service or an identity validation service and reverse search a name and City to find your social security number if they want to.

It's probably time to replace the old social security number system.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#165

Earlier quoted context omitted.

How is it disgusting for a lender to be able to look up someone's credit history and determine if they are an appropriate credit risk for them? The alternative is everyone gets (or does not get at all) credit on the same terms without regards to personal behavior or risk profiles, which is a valid option, but I would still think "disgusting" is a strong word to describe the prior scenario.

You're asking this question in the following context: getting a cell mobile provider contract requires a social security number. Social security number is used to pin a score on someone's credit worthiness. Mobile provider gets hacked, exposing clients to bad actors using social security number and associated data to open credit lines fraudulently and hurting users' credit worthiness scores. The disgusting part is th…

The only disgusting part is the one where vendors get to claim someone owes them without adequate proof and makes it a random person’s obligation to prove they do not owe the vendor rather than a vendor having to prove they did their due diligence in confirming someone’s identity.

> The disgusting part is the whole reason the providers demanded SS # is to defend their own interests to threaten clients with collection agencies and credit score dips. The neglect of these same now cause clients to risk getting credit score dips through no fault of their own.

I do not expect un-hackable systems and organizations to exist, so I would not find this “disgusting”, without knowing how the leak happened. It might be disgusting if there was a complete disregard for handling of the data, which might be true in this case, but I was responding to your comment as is there very idea that a mobile carrier can lend to a customer was disgusting.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#166
The only difference between what the cell carriers consider business as usual and a “hack” is getting paid for your data.

EDIT: And who knows, maybe after insurance payouts and tax write offs and the usual corporate B.S., it’s still as profitable if they just sold it directly

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#167
post #113

Why is it so much harder and costlier for companies to be able to store credit card numbers, but not SSNs? I mean there is a whole certification process that costs hundreds of thousands of dollars to get pci certified, but you could say an SSN has the same of not larger risk profile. You can cancel credit cards, can’t get a new SSN. What is stopping government from implementing the same requirements? No one asks for…

A globally unique id is incredibly useful to many businesses, particularly since half of America changes their names. Often repeatedly. So there will be incredible back pressure at implementing this.

Then make it both unique and worthless. Every other country has national ids, and you gain nothing by stealing it, you actually present it almost everywhere, same value as a driver's license. In fact, when pulled over, you are asked for the license and the card, to make sure the license is really yours. What you cannot definitely do is transact with only your nacional id, that's silly. Its identification, not authentication. Your pins, passwords, signatures, presence are required in addition to your ID number to do anything. While in the US, I always thought it was weird the importance that such a document was given, to the point that even laminating it is taboo, complete with a notice written on it. They tell you to not walk around with it. Never understood how it got to this point.
Post reply on HN