Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

141–150 of 472 posts

Re: Inside the "3 billion people" national public data breach

#141
post #78

Earlier quoted context omitted.

In many countries in Europe, your ID card contains a chip with a cryptographic key, much like chip&pin on a debit or credit card. Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. If the card is lost or stolen they can just remove your old one from the keyserver. It's literally just public key crypto. Identity theft is rampant…

The US has three dumb points pushing back on this. The first is religious nuts who think it would be a "mark of the beast" The second is anti-government types who are, well, anti-government anything. The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work.

Correct. But not insurmountable.

Make the ID card optional, so that it simplifies things if you have it, but still allows operation without it. If 80% of law-abiding population has the card, only the stubborn deniers will remain targets of easy identity theft and fraud based on it. Partly it will stop being worth the effort, partly it will serve as a good control group.

Allow but do not require to use the card for employee identification. Whoever insists on hiring undocumented immigrants, could continue. Most industries don't do that, and would reap the benefits of a more secure identification.

Don't make the card universal. A bank card with a chip does not identify you for governmental agencies, but prevents a lot of PoS fraud. It could prevent credit fraud if banks allowed me to require the card to take a loan in my name, or to make a transfer larger than $10, and provided the card identity check service to each other and to credit unions. Phones with NFC can read bank cards, so it's a good way to say "it's me, I confirm" in a secure way.

Evolutionary, opt-in, piecemeal solutions often have higher chances to succeed than abrupt all-at-once changes.

Re: Inside the "3 billion people" national public data breach

#142

Earlier quoted context omitted.

I never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense

When someone named adamomada comes to the bank for a loan, the presumption is that adamomada will repay the loan. If they knew it wasn't you, they wouldn't have written the loan in the first place. They're asking you to repay it because they really do think it was you. If "it wasn't me" was all anyone had to do to get out of paying a loan, many people would do it.

It's much more subtle, fraud is accepted and part of the business. Even if you are not 100% certain of the identity of the person, what matters is how likely you are going to get paid back.

For example, when you purchase online, some merchants do not check who is the owner of the card, or the address. It's done on purpose, because some people borrow the card of the others, some people don't want to use their card, etc. And overall it's all about risk management, but if the holder is really the one in front of you is just one factor among others.

Re: Inside the "3 billion people" national public data breach

#143

Earlier quoted context omitted.

You too can be a data broker! for (i = 0; i Does anyone really really care if the name is accurate if the SSN is present? More than half of the SSNs in the above dataset are valid.

In fact there are far fewer valid Socials. They follow a system where guessing a number of digits is fairly determined based on year and state of birth

[deleted]

Re: Inside the "3 billion people" national public data breach

#144

> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly…

Do you know if the Rhysida ones get torrented?

https://www.ransomlook.io/group/rhysida

Re: Inside the "3 billion people" national public data breach

#145
post #129
post #78

Earlier quoted context omitted.

In many countries in Europe, your ID card contains a chip with a cryptographic key, much like chip&pin on a debit or credit card. Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. If the card is lost or stolen they can just remove your old one from the keyserver. It's literally just public key crypto. Identity theft is rampant…

> Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. That depends on the type of attack you're protecting against. It might prevent an attacker from filing your taxes for you, but many companies are still going to use this kind of information as primary key. But it's not going to stop an attacker from pretending to be a bank emp…

As a potential Mr. Doe, I'd love to have an ability to opt in to a stricter mode of banking. I would voluntarily ask my bank to refuse certain types of transactions in my name unless my identity can be confirmed by secure machine-readable means at my presence; internal phone calls should not qualify. It could be a bank card, or a passport — yes, both can be physically stolen, but it's much harder to pull off, and I would immediately warn my bank when I notice.

Re: Inside the "3 billion people" national public data breach

#146

Ahh, cool, pour the corpus through GPTs and start tweeting Congressional rep personal info at them until they pass a law to outlaw data brokers (in keeping with historical precedent [1] [2]). [1] https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act [2] https://jolt.law.harvard.edu/digest/dodging-the-thought-poli...

For argument sake, instead of outlawing data brokers wouldn’t it be better to design a better ID system that renders one’s name, dob, and SSN as harmless information? I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that.

Plenty of countries have smart cards with chips and RSA keys that can be used to verify ID with much higher level of certainty, but then they usually don't use it.

Even just name, DOD and last 4 of the SS number and you are done.

It's ridiculous.

Re: Inside the "3 billion people" national public data breach

#147
post #78

Earlier quoted context omitted.

In many countries in Europe, your ID card contains a chip with a cryptographic key, much like chip&pin on a debit or credit card. Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. If the card is lost or stolen they can just remove your old one from the keyserver. It's literally just public key crypto. Identity theft is rampant…

The US has three dumb points pushing back on this. The first is religious nuts who think it would be a "mark of the beast" The second is anti-government types who are, well, anti-government anything. The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work.

> The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work.

Big one, but even though employing illegal immigrants is a crime, it's almost never prosecuted.

Re: Inside the "3 billion people" national public data breach

#148

Earlier quoted context omitted.

The US has three dumb points pushing back on this. The first is religious nuts who think it would be a "mark of the beast" The second is anti-government types who are, well, anti-government anything. The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work.

The "mark of the beast" types are pretty much fine with cards that have chips in them, but they really hate it when you threaten to implant those chips into people and they want cash to remain an option - same as the anti-government types. I don't share their apocalyptic or anti-government concerns, but I'm actually kind of grateful for their passionate opposition to both of those things anyway. I don't really want a…

Eh, depending on the flavor, the mark of the beast types don’t even really like barcodes. Allegedly Hobby Lobby does not use a barcode inventory system for this reason.

Re: Inside the "3 billion people" national public data breach

#149
post #141

Earlier quoted context omitted.

The US has three dumb points pushing back on this. The first is religious nuts who think it would be a "mark of the beast" The second is anti-government types who are, well, anti-government anything. The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work.

Correct. But not insurmountable. Make the ID card optional, so that it simplifies things if you have it, but still allows operation without it. If 80% of law-abiding population has the card, only the stubborn deniers will remain targets of easy identity theft and fraud based on it. Partly it will stop being worth the effort, partly it will serve as a good control group. Allow but do not require to use the card for em…

>Most industries don't do that

They absolutely do, but most of the immigrants have a form of ID that gives the companies some measure of deniability. As long as the I-9 goes through, not my problem. If it doesn't, well that's where contractors come in. Official numbers say around 14 million illegal immigrants. Reasonable estimates are closer to 22 and some non-hyperbolic estimates go as high as 40 million.

Post reply on HN