Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

171–180 of 472 posts

Re: Inside the "3 billion people" national public data breach

#171

Earlier quoted context omitted.

In the US, the government could help alot if they simply moved to a national ID system and dismantled social security numbers. The national ID systems I've seen proposed have alot more security from the ground up, and could replace the passport system.

The US has done itself a disservice with their actions because few people trust the government. A national ID system means a database of all Americans that would very likely be used for surveillance and monitoring. I'm saying this as someone who has Global Entry so it's not like I'm afraid of being in a US database but I see the concerns.

That surveillance already exists with insignificant additional work on the part of the government. The cost of not establishing a best ID system has been clearly more costly. That's why the Real ID system was pushed onto state governments.

Re: Inside the "3 billion people" national public data breach

#172

Earlier quoted context omitted.

The US has done itself a disservice with their actions because few people trust the government. A national ID system means a database of all Americans that would very likely be used for surveillance and monitoring. I'm saying this as someone who has Global Entry so it's not like I'm afraid of being in a US database but I see the concerns.

Pretty sure the FBI and equivalent agencies already have access to every state’s DMV records so it’s sort of a distinction without a difference.

Correct

Re: Inside the "3 billion people" national public data breach

#173
post #162

Earlier quoted context omitted.

I am wondering what the numbers are like for this to be realistic. I am not too sure of the end goal other than general chaos. Let’s say it’s 2 days of an attack, (that’s about how long any co-ordinated response would need at minimum). So attackers need to sow chaos across the USA. They apply for a million unsecured loans of say 20k each. That’s 20 billion. I honestly don’t know what the daily personal loan applicati…

You’d need to pick a day of importance to launch the chaos-sowing attack against information and social services. I’m sure there’s a useful one in early November.

Thanksgiving is at the end of the month though

Re: Inside the "3 billion people" national public data breach

#174

I am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A perso…

SSNs can be used to disconnect utility service, too. Doing some amount of that would surely add to the "fog of war". It often takes phone calls but the tools have been created to automate that on a massive scale.

Re: Inside the "3 billion people" national public data breach

#175

I am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A perso…

In the US, the government could help alot if they simply moved to a national ID system and dismantled social security numbers. The national ID systems I've seen proposed have alot more security from the ground up, and could replace the passport system.

The US doesn't need a national ID. It needs a national PKI.

The US Postal Service is in a great position to be the one who executes it. They have access to delivery physical goods to the entire country. They have the staff and procedures to do identity verification for their current products that could be extended to a PKI offering.

It'll never fly, politically.

Re: Inside the "3 billion people" national public data breach

#176

I am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A perso…

In the US, the government could help alot if they simply moved to a national ID system and dismantled social security numbers. The national ID systems I've seen proposed have alot more security from the ground up, and could replace the passport system.

"Wow, the government is so catastrophically bad at managing IDs; what should we do?"

"Hmmm. I know! Lets get the government to manage a mandatory ID system, and require it for all aspects of citizen's lives! In fact, lets centralize all of their medical, financial and personal data using this ID, and ensure that it can all be accessed using this ID! What could possibly go wrong?"

Re: Inside the "3 billion people" national public data breach

#177

> The problem with verifying breaches sourced from data aggregators is that nobody willingly - knowingly - provides their data to them This is a bit of a tangent but I feel like if we can prove this statement then these data aggregators should be made illegal. How can you consent to something that you don’t know you’re consenting to? Likewise why do these entities have the right to collect detailed personal informati…

[deleted]

Re: Inside the "3 billion people" national public data breach

#178

I am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A perso…

[deleted]

Re: Inside the "3 billion people" national public data breach

#179

Earlier quoted context omitted.

Eh, depending on the flavor, the mark of the beast types don’t even really like barcodes. Allegedly Hobby Lobby does not use a barcode inventory system for this reason.

Hobby Lobby's CEO provided a handy list of reasons why they do not use bar codes, none of which have anything to do with them being marks of beasts https://www.snopes.com/fact-check/hobby-lobby-mark-of-the-be...

I will say that their list of reasons is deeply flawed.

> Human beings can't read a bar code.

- they can, and more importantly they almost never have to

> A lot of our product comes from cottage industries in Asia that couldn't mark their goods with bar codes if they tried.

- They can be added at the store/warehouse level, not every product needs one, and I've never seen a store that worked entirely on bar codes 100% of the time anyway.

> Inventory control by computer is not as accurate as you think.

- This assumes what I think, and it only needs to be more accurate than your current method. If it actually weren't more accurate, I don't think they'd have to fall back on "as you think" in their argument.

> Employees take more pride in their work when they know they are in charge, not some faceless machine.

- this doesn't even make sense.

> Customer service is better.

- questionable, but not impossible to support

> The time savings at check-out is minimal — and easily squandered.

- possible, but time savings at checkout is only one benefit.

- Reprogramming the computer for sales would take a huge effort in our case, because we put so many individual items on sale each week.

- It would take effort, but stores with much more inventory manage it just fine, even when new products are constantly coming in and sales are weekly.

> Twenty million dollars is a lot of money.

- I have no idea from the article what this is in reference to. Maybe the amount it would take for them to make the the switch? It's hard to say how much money it would save them so it's fair to say cost is a concern. I will say that over a long enough time period, it'd probably save more than it costs.

None of this means that concern over "the mark of the beast" is really the reason, but the reasons they gave don't make a lot of sense either. It could just as easily be that poor record keeping and manual entry at the register allow them commit fraud or something.

I suspect that if the mark of the beast plays any role at all, it's that no having barcodes panders to the christian customer base they've always heavily pandered to. Even just the rumor is basically viral marketing for them to that crowd.

Re: Inside the "3 billion people" national public data breach

#180

Earlier quoted context omitted.

You too can be a data broker! for (i = 0; i Does anyone really really care if the name is accurate if the SSN is present? More than half of the SSNs in the above dataset are valid.

In fact there are far fewer valid Socials. They follow a system where guessing a number of digits is fairly determined based on year and state of birth

This is not exactly true; the system _used_ to have a geographic component but SSNs issued since 2011 are random.

(Granted, most people here with an SSN should be older than that.)

Post reply on HN