Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

61–70 of 472 posts

Re: Inside the "3 billion people" national public data breach

#62

Earlier quoted context omitted.

A lot of these data brokers hold wildly inaccurate information.

You too can be a data broker! for (i = 0; i Does anyone really really care if the name is accurate if the SSN is present? More than half of the SSNs in the above dataset are valid.

You probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.

Re: Inside the "3 billion people" national public data breach

#63
post #44

Earlier quoted context omitted.

If they have your address; birthday; and SSN a whole lot. Generally, they could apply for credit cards; loans; set something to bill to you; etc... Fortunately, it's getting harder without previous addresses or other verification methods. For non-Americans that don't know, our Social Security number is generally assigned at birth or when you become a citizen by the Social Security Administration. Social Security is a…

> It's the only number we all get, since not everyone gets a driver's license; ID; passport; or other identifier. Unfortunately, it's been used to identify us for everything, and until recently was typically in plaintext on most forms (medical; tax; student; etc...). I fail to see the problem with that. As you said, it's an identifier , like an username or your full name. There should be no issue with everyone knowin…

> why there should be an issue with everyone knowing your SSN, or it being in plaintext everywhere

Because far too many businesses, esp. financial ones (banks/credit unions/etc.) have also incorrectly used it as a password to authenticate that "voice on phone" is really John Q. Public and/or that "grifter in chair across desk" is really John Q. Public. I.e., they used the fact that "person X" knew number Y as proof that person X was really person X.

We can argue that it was never intended to be used this way (a true statement), that knowledge of it provides no such proof (also true), and that using it as such was always wrong on the part of these businesses (also true), but the fact is, many did use it this way, and, sadly, many still do use it this way. And it is this misuse that is the "issue" with everyone knowing everyone's SSN.

Re: Inside the "3 billion people" national public data breach

#64
post #41

Earlier quoted context omitted.

> It's hard to make collection, aggregation, and sharing of facts illegal. Sure, but the US has a precedent in HIPAA. Not saying it's copy-paste, but... maybe it should be. I would prefer the law be more restrictive than less, because I don't believe this is true: > law is justifiably looking for a scalpel treatment here to address the specific problem without putting the quest to understand reality on the wrong side…

As someone who helps care for elderly relatives with widely-dispersed out-of-state families, I can point to HIPAA as an excellent example of why crafting this kind of law is difficult. I think we are going to discover, once people do the research, that HIPAA has done net harm by delaying flow of information for critical-care patients resulting in lack of patient compliance, confusion, and treatment error. Yes, there…

Huh, I wasn't aware of such a viewpoint. I've never had or heard of problems with HIPAA preventing timely or accurate care, even with my father going in and out of hospice toward the end of his fight with cancer. I'm really sorry to hear it. At the same time, I do have to wonder if that kind of problem genuinely outweighs the protection HIPAA has given millions of people against harms small and large. (I guess with the state of data privacy today, HIPAA may be basically useless, but that isn't exactly HIPAA's fault.)

Re: Inside the "3 billion people" national public data breach

#65
post #61

I sure wish the US had a version of GDPR. I get a data breach notice at least a few times a year. I got one for my kids two months ago for their medical data. I thought HIPPA had huge penalties but I guess not.

Doesn’t California have a similar set of regulations?

Re: Inside the "3 billion people" national public data breach

#66

Earlier quoted context omitted.

I never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense

The reason the Shaggy defense doesn't work is the default assumption of the courts is that you're a deadbeat trying to game the system. This assumption comes about because in the majority of cases it is the truth. The system would be a lot nicer if there weren't people trying to scam it every hour of every day of the week.

> This assumption comes about because in the majority of cases it is the truth.

Are we saying that if you can show you have enough income / assets, it'll be that much more likely that you'll be fine in those cases?

Re: Inside the "3 billion people" national public data breach

#67

For non-Americans (and Americans) that don't quite understand what SSN is and why it's a problem, CGP Grey [1] has a great (and short) video about the history and why it's not technically an identifier, but has become one. [1] https://www.youtube.com/watch?v=Erp8IAUouus

The video doesn't quite get into the problem of identity theft, which is when someone uses your stolen creds to claim they are you, and then go on a shopping spree which may include buying a car under your name. You shouldn't be liable for debts incurred after having your identity stolen but proving that is a lot of work.

In many other places SSNs are non-sensitive data. There is not much one can do just knowing a SSN. Usually one has to do some kind of verification (eg using some sort of authentication app, if online). Which is why it is so confusing.

Re: Inside the "3 billion people" national public data breach

#68

Troy mentions "data opt-out services. Every person who used some sort of data opt-out service was not present." Anyone have experience with these sort of services? A search brings up a lot of scammy looking results. But if services exist to reduce my profile id be interested.

Since it is Troy I assume it is legit, and I haven't read the link yet. But... How does he know that?

Has the opt-out services leaked as well? Or is noone using them? How would we know?

Re: Inside the "3 billion people" national public data breach

#69

> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly…

> Someone created a magnet link yesterday

Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

Re: Inside the "3 billion people" national public data breach

#70
post #24

Does anyone else just not give a fuck at this point about their SSN? I feel like maybe early 00s this would be scary but it's clear that everyone's SSN is out there already or waiting to get breached from a shady private data broker. The problem lies in how institutions treat the SSN, not the number itself.

if you know place of birth, and place of ssn application, you can determine most of the ssn. the final 4 are supposed to be random, but are blurted out to rooms full of people and tech, during service. the integrity of SSN security, was lost a long time ago

> the integrity of SSN security, was lost a long time ago

The security never existed, since they were never intended to be secrets. At best it was theater.

Post reply on HN