Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

51–60 of 472 posts

Re: Inside the "3 billion people" national public data breach

#51
Ahh, cool, pour the corpus through GPTs and start tweeting Congressional rep personal info at them until they pass a law to outlaw data brokers (in keeping with historical precedent [1] [2]).

[1] https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act

[2] https://jolt.law.harvard.edu/digest/dodging-the-thought-poli...

Re: Inside the "3 billion people" national public data breach

#52
post #44

Earlier quoted context omitted.

If they have your address; birthday; and SSN a whole lot. Generally, they could apply for credit cards; loans; set something to bill to you; etc... Fortunately, it's getting harder without previous addresses or other verification methods. For non-Americans that don't know, our Social Security number is generally assigned at birth or when you become a citizen by the Social Security Administration. Social Security is a…

> It's the only number we all get, since not everyone gets a driver's license; ID; passport; or other identifier. Unfortunately, it's been used to identify us for everything, and until recently was typically in plaintext on most forms (medical; tax; student; etc...). I fail to see the problem with that. As you said, it's an identifier , like an username or your full name. There should be no issue with everyone knowin…

I heard there was a similar problem with the bank account number in the US - that you could use it to withdraw money without an actual password or strong identification. Hence the popularity of cheques, PayPal and similar services that weren't needed that much in Europe.

Re: Inside the "3 billion people" national public data breach

#53
post #46

Can't the SSA just issue 330 million new social security numbers, and tell people to be more careful with them from this point forward?

The SSA specifically told people not to misuse SSNs this way and it seems like a poor use of taxpayer funding to spend billions bailing out businesses’ bad decisions, even if that was legal (Congress would have to specifically authorize it), since we’d be back to the same problem with five years. If we were going to do something, we’d make government ID include an NFC token for PKI purposes since public keys can’t be…

> If we were going to do something, we’d make government ID include an NFC token for PKI purposes since public keys can’t be compromised in the same way, but nobody is jumping to pay for that, especially in a country where you have so many people prone to wild conspiracy theories (I am especially amazed by the guys who freak about a national ID as big brother but never say a word about the credit reporting industry) and the enduring “Mark of The Beast” religious fears.

Login.gov gets us pretty far until NFC can get baked into credentials. Would love to see passport cards evolve into this [2], but again, lots of work and political will to make that happen. In the meantime, remote and in person proofing to bind IRL gov credentials to digital identity must do.

(As of December 31, 2023, over 111 million people have signed up to use Login.gov to date, with over 324 million sign-ins in 2023; this is ~1/3rd US population; no affiliation)

[1] https://login.gov/

[2] https://travel.state.gov/content/travel/en/passports/need-pa...

Re: Inside the "3 billion people" national public data breach

#54
post #44

Earlier quoted context omitted.

If they have your address; birthday; and SSN a whole lot. Generally, they could apply for credit cards; loans; set something to bill to you; etc... Fortunately, it's getting harder without previous addresses or other verification methods. For non-Americans that don't know, our Social Security number is generally assigned at birth or when you become a citizen by the Social Security Administration. Social Security is a…

> It's the only number we all get, since not everyone gets a driver's license; ID; passport; or other identifier. Unfortunately, it's been used to identify us for everything, and until recently was typically in plaintext on most forms (medical; tax; student; etc...). I fail to see the problem with that. As you said, it's an identifier , like an username or your full name. There should be no issue with everyone knowin…

> username

Think of it as being the username and password. That's how many institutions have treated it for a long time.

Re: Inside the "3 billion people" national public data breach

#56

For non-Americans (and Americans) that don't quite understand what SSN is and why it's a problem, CGP Grey [1] has a great (and short) video about the history and why it's not technically an identifier, but has become one. [1] https://www.youtube.com/watch?v=Erp8IAUouus

The video doesn't quite get into the problem of identity theft, which is when someone uses your stolen creds to claim they are you, and then go on a shopping spree which may include buying a car under your name. You shouldn't be liable for debts incurred after having your identity stolen but proving that is a lot of work.

I never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient?

e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get?

- It wasn’t me.

https://en.wikipedia.org/wiki/Shaggy_defense

Re: Inside the "3 billion people" national public data breach

#57
post #44

Earlier quoted context omitted.

If they have your address; birthday; and SSN a whole lot. Generally, they could apply for credit cards; loans; set something to bill to you; etc... Fortunately, it's getting harder without previous addresses or other verification methods. For non-Americans that don't know, our Social Security number is generally assigned at birth or when you become a citizen by the Social Security Administration. Social Security is a…

> It's the only number we all get, since not everyone gets a driver's license; ID; passport; or other identifier. Unfortunately, it's been used to identify us for everything, and until recently was typically in plaintext on most forms (medical; tax; student; etc...). I fail to see the problem with that. As you said, it's an identifier , like an username or your full name. There should be no issue with everyone knowin…

Because it was used as BOTH an identifier AND proof of identity, for a long time. If it were used properly as simply an identifier, you'd be right, but there are still many cases where knowledge of the number is used as proof (or partial proof, along with birthdate/address/etc) of identity.

Re: Inside the "3 billion people" national public data breach

#58

Earlier quoted context omitted.

The video doesn't quite get into the problem of identity theft, which is when someone uses your stolen creds to claim they are you, and then go on a shopping spree which may include buying a car under your name. You shouldn't be liable for debts incurred after having your identity stolen but proving that is a lot of work.

I never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense

The reason the Shaggy defense doesn't work is the default assumption of the courts is that you're a deadbeat trying to game the system. This assumption comes about because in the majority of cases it is the truth. The system would be a lot nicer if there weren't people trying to scam it every hour of every day of the week.

Re: Inside the "3 billion people" national public data breach

#59

"there were no email addresses in the social security number files. If you find yourself in this data breach via HIBP, there's no evidence your SSN was leaked, and if you're in the same boat as me, the data next to your record may not even be correct. " Seems like Troy is skeptical about this being a real full breach?

A lot of these data brokers hold wildly inaccurate information.

You too can be a data broker!

    for (i = 0; i 
Does anyone really really care if the name is accurate if the SSN is present? More than half of the SSNs in the above dataset are valid.

Re: Inside the "3 billion people" national public data breach

#60
post #35

Earlier quoted context omitted.

my understanding is that there's a bit of a catch-22 with data removal - if you request that a data broker remove ALL of your information, it's impossible for them to keep you from reappearing in their sources later on because that would require them to retain your information (so they can filter you out if you appear again).

They could store a hash.

Which would never work because real life data is messy so the hashes would not match. Even something as simple as SSN + DOB runs into loads of potential formatting and data entry issues you'll have to perfectly solve before such a system could work, and even that makes assumptions as to what data will be available from each dataset. Some may be only name and address. Some may include DoB, but the person might have lied about their DoB when filling out the form. The people entering it might have misspelled their name. It might be a person who put in a fake SSN because they're an illegal immigrant without a real one. Data correlation in the real world is a nightmare.

When you tell a data broker to delete all of the data about you, how can you be sure they get ALL of the data about you, including the ones where your name is misspelled or the DoB is wrong or it lists and old address or something? Even worse if someone comes around later and discovers the orphan data when adding new data about you and fixes the glitch, effectively undoing the data delete.

It's a catch-22 that if you want them to not collect data about you they need a full profile on you in order to be able to reject new data. A profile that they will need to keep up-to-date, which is what they were doing already.

Post reply on HN