Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

91–100 of 472 posts

Re: Inside the "3 billion people" national public data breach

#91
post #87

For years I've said the entire SSN database just needs to be published alongside legislation strictly assigning liability to any company who defrauded as a result of using the SSN as a "secret". That would fix the problem with SSN's and "identity theft" quickly. Part 1 has been accomplished. Let's get part 2 going! Aside: It amazes me how the American public has allowed defrauded companies to assign the company's los…

The obligatory Mitchell & Webb sketch https://m.youtube.com/watch?v=CS9ptA3Ya9E

YES!

I couldn't remember their names and absolutely was thinking of this.

Re: Inside the "3 billion people" national public data breach

#92
post #69

> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly…

> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.

BitTorrent uses something called a "distributed hash table", for which there exist services to search it (btdig, etc). You can use one of those alongside the torrent name (NPD) to find it.

I haven't downloaded it, but my understanding is that the data comes compressed and with a (weak) password.

Re: Inside the "3 billion people" national public data breach

#93
post #46

Earlier quoted context omitted.

The SSA specifically told people not to misuse SSNs this way and it seems like a poor use of taxpayer funding to spend billions bailing out businesses’ bad decisions, even if that was legal (Congress would have to specifically authorize it), since we’d be back to the same problem with five years. If we were going to do something, we’d make government ID include an NFC token for PKI purposes since public keys can’t be…

> If we were going to do something, we’d make government ID include an NFC token for PKI purposes since public keys can’t be compromised in the same way, but nobody is jumping to pay for that, especially in a country where you have so many people prone to wild conspiracy theories (I am especially amazed by the guys who freak about a national ID as big brother but never say a word about the credit reporting industry)…

The problem with login.gov is that nobody can use it outside of the US government. I can't use my login.gov account to attest my identity to my bank.

So my bank will continue to use my SSN as proof of identity for loans.

Re: Inside the "3 billion people" national public data breach

#94
post #46

Can't the SSA just issue 330 million new social security numbers, and tell people to be more careful with them from this point forward?

The SSA specifically told people not to misuse SSNs this way and it seems like a poor use of taxpayer funding to spend billions bailing out businesses’ bad decisions, even if that was legal (Congress would have to specifically authorize it), since we’d be back to the same problem with five years. If we were going to do something, we’d make government ID include an NFC token for PKI purposes since public keys can’t be…

Painting those of us concerned with privacy as "people prone to wild conspiracy theories" is a very bad faith take.

Please do not give the government any more power over me than they already have, thanks.

Re: Inside the "3 billion people" national public data breach

#96

For years I've said the entire SSN database just needs to be published alongside legislation strictly assigning liability to any company who defrauded as a result of using the SSN as a "secret". That would fix the problem with SSN's and "identity theft" quickly. Part 1 has been accomplished. Let's get part 2 going! Aside: It amazes me how the American public has allowed defrauded companies to assign the company's los…

Identity theft is a very clever term to shift blame from the company to the consumer. https://youtu.be/CS9ptA3Ya9E It’s a comedy bit but I take its point seriously: if the bank gives away money, it’s the bank’s job to make sure it is repaid. Not mine, unless I was actually a party to the agreement.

Well then you're up against the wall of digital verification.

I know there's a fuck load of situations where the banks are 100% screwing the customer to their benefit, but there's a legit conversation about people who give out their passwords, or claim they did, when money gets wiped out.

If you meet all the requirements to identify yourself to the bank, at what point does the bank have to say "this is that person, and that transaction is legal".

Now granted:

1. With passkeys and biometrics and 2FA we've got a lot of better ways to make these accounts secure, and hopefully more idiot proof. I'm hoping we start getting rid of email/phone for 2FA as a valid option though.

2. The moment the police are treating it as an identity theft case, the bank should be required to pony up. I don't know if that's the case (and wouldn't be surprised if they fight it tooth and nail), but at that point you have a state or federal entity acknowledging this is not a legit transaction, and therefore you should be compensated by the bank, and they can get their money back from the insurance companies that insure against this kind of thing.

Re: Inside the "3 billion people" national public data breach

#97
post #89

Earlier quoted context omitted.

I never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense

Is that even a Shaggy defense? The whole point of the Shaggy defense was that it's saying it wasn't you despite overwhelming evidence ("She even caught me on camera - it wasn't me") But in this scenario, there is basically zero evidence it was you

I thought it was, they would have to have some sort of evidence of your name, dob, ssn, blood type, etc. But in the end it was just your information used fraudulently; you the person did not authorize the loan and therefore it really isn’t your loan.

Re: Inside the "3 billion people" national public data breach

#98

Earlier quoted context omitted.

Which would never work because real life data is messy so the hashes would not match. Even something as simple as SSN + DOB runs into loads of potential formatting and data entry issues you'll have to perfectly solve before such a system could work, and even that makes assumptions as to what data will be available from each dataset. Some may be only name and address. Some may include DoB, but the person might have li…

> Even something as simple as SSN + DOB runs into loads of potential formatting and data entry issues you'll have to perfectly solve You don’t have to solve it perfectly to be an improvement. Also this is BS. Not every bit of data is perfectly formatted and structured but both of your examples are structured data. You can 100% reliably and deterministically hash this data. There’s so much in your argument that can be…

> You don’t have to solve it perfectly to be an improvement.

https://en.wikipedia.org/wiki/Nirvana_fallacy

Re: Inside the "3 billion people" national public data breach

#99
post #96

Earlier quoted context omitted.

Identity theft is a very clever term to shift blame from the company to the consumer. https://youtu.be/CS9ptA3Ya9E It’s a comedy bit but I take its point seriously: if the bank gives away money, it’s the bank’s job to make sure it is repaid. Not mine, unless I was actually a party to the agreement.

Well then you're up against the wall of digital verification. I know there's a fuck load of situations where the banks are 100% screwing the customer to their benefit, but there's a legit conversation about people who give out their passwords, or claim they did, when money gets wiped out. If you meet all the requirements to identify yourself to the bank, at what point does the bank have to say "this is that person, a…

Banks should get insurance to cover their negligence. They weren't careful.

Re: Inside the "3 billion people" national public data breach

#100
post #93

Earlier quoted context omitted.

> If we were going to do something, we’d make government ID include an NFC token for PKI purposes since public keys can’t be compromised in the same way, but nobody is jumping to pay for that, especially in a country where you have so many people prone to wild conspiracy theories (I am especially amazed by the guys who freak about a national ID as big brother but never say a word about the credit reporting industry)…

The problem with login.gov is that nobody can use it outside of the US government. I can't use my login.gov account to attest my identity to my bank. So my bank will continue to use my SSN as proof of identity for loans.

Not yet, but we’ll get there.

https://beeckcenter.georgetown.edu/wp-content/uploads/2021/1...

Post reply on HN