Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

201–210 of 472 posts

Re: Inside the "3 billion people" national public data breach

#201

Earlier quoted context omitted.

I will say that their list of reasons is deeply flawed. > Human beings can't read a bar code. - they can, and more importantly they almost never have to > A lot of our product comes from cottage industries in Asia that couldn't mark their goods with bar codes if they tried. - They can be added at the store/warehouse level, not every product needs one, and I've never seen a store that worked entirely on bar codes 100%…

How about this: without barcodes, you can't replace your clerks with self-checkout machines

I'm not sure that's true, but it would make it more difficult since it'd be easier for customers to cheat. You'd need more monitoring than most stores at the very least.

Re: Inside the "3 billion people" national public data breach

#202

Earlier quoted context omitted.

In the US, the government could help alot if they simply moved to a national ID system and dismantled social security numbers. The national ID systems I've seen proposed have alot more security from the ground up, and could replace the passport system.

"Wow, the government is so catastrophically bad at managing IDs; what should we do?" "Hmmm. I know! Lets get the government to manage a mandatory ID system, and require it for all aspects of citizen's lives! In fact, lets centralize all of their medical, financial and personal data using this ID, and ensure that it can all be accessed using this ID! What could possibly go wrong?"

I wonder if you could create a national or federated ID system that takes advantage of blind signatures/ZKP to improve privacy. For example, you could create an unlimited number of identities to hand out to different buisnesses, and they could use ZKP to prove that you are above 18, a non-felon, or an organ donor etc. Dunno how something like photo ID would work.

Re: Inside the "3 billion people" national public data breach

#203

Ahh, cool, pour the corpus through GPTs and start tweeting Congressional rep personal info at them until they pass a law to outlaw data brokers (in keeping with historical precedent [1] [2]). [1] https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act [2] https://jolt.law.harvard.edu/digest/dodging-the-thought-poli...

For argument sake, instead of outlawing data brokers wouldn’t it be better to design a better ID system that renders one’s name, dob, and SSN as harmless information? I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that.

We should be doing both, for different reasons. Ban data brokers because they allow anyone with a credit card to stalk people, more or less legally. Fix the SSN identity system because even if you ban data broker businesses, dark web brokers don't abide by the laws anyways.

Re: Inside the "3 billion people" national public data breach

#204
post #116

Earlier quoted context omitted.

I've seen https://npd.pentester.com/ floating around

The data seems to be at least 15 years old.

For me, it matches (DOB, last 2 of SSN) and seems fresh (has newest address, as well as older ones).

Re: Inside the "3 billion people" national public data breach

#206
post #79

Earlier quoted context omitted.

I never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense

"Identity Fraud" is institutionalized victim blaming. The claim is that the person who's identity was stolen was defrauded (and they should protect themselves or fight back), but in reality it was the creditor that got defrauded.

And in turn libeled the person who they thought had borrowed from them.

Re: Inside the "3 billion people" national public data breach

#207
This sort of stuff will continue happening until the regulatory framework acknowledges a fundamental consumer right to privacy.

If a data broker collects data without the consent of the consumer, then their only real risk is a class action lawsuit which drags on for six years, gets settled for a few days profit, and the consumer gets $13.50 after the legal fees. This massive skew in the risk reward calculus of data brokers is why we have the problem. Because there's little to no real downside, the trend is automatically collect as much data on as many people as possible.

Fixing this means big, mandatory, cash penalties in the law code - say $5k per consumer data leak, directly to the affected consumer, with added penalties if the company lies about the leak or delays payment. The fine must be big, mandatory, and paid directly to the consumer. Only that changes the risk reward ratio.

In that new world, companies would have to re assess their risks. They'd either build invulnerable systems and hire a lot more people reading HN to protect their golden goose, or better still they'd decide to exit the business entirely. That sounds bad, but the only reason the industry exists is because regulators failed to foresee massive leaks like this happening every three months.

We need a consumer data privacy law, with massive fines, to force companies to change their behavior. What we're doing now clearly does not work.

Re: Inside the "3 billion people" national public data breach

#208
post #78

Earlier quoted context omitted.

In many countries in Europe, your ID card contains a chip with a cryptographic key, much like chip&pin on a debit or credit card. Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. If the card is lost or stolen they can just remove your old one from the keyserver. It's literally just public key crypto. Identity theft is rampant…

The US has three dumb points pushing back on this. The first is religious nuts who think it would be a "mark of the beast" The second is anti-government types who are, well, anti-government anything. The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work.

There is another group: those of us who think the trend of requiring ID to transact is a dangerous one.

One doesn’t need to be anti-government to fear governmental intrusion on one’s rights without due process. Our current government does that now.

Re: Inside the "3 billion people" national public data breach

#209
post #24

Earlier quoted context omitted.

if you know place of birth, and place of ssn application, you can determine most of the ssn. the final 4 are supposed to be random, but are blurted out to rooms full of people and tech, during service. the integrity of SSN security, was lost a long time ago

as of 2011 they are fully random instead of being based on geographical region and groups https://www.ssa.gov/employer/randomization.html

Yes, but 100% of adults today were born before 2011, and that will continue to be (ever so slowly less and less true as we die out) true for decades. It's good and all, but.

Re: Inside the "3 billion people" national public data breach

#210

"there were no email addresses in the social security number files. If you find yourself in this data breach via HIBP, there's no evidence your SSN was leaked, and if you're in the same boat as me, the data next to your record may not even be correct. " Seems like Troy is skeptical about this being a real full breach?

I don't think it's a "full" breach because I assume that would include many tera/petabytes of original source documents rather than just a CSV of PII, but it's definitely a real breach.

I looked up several family members and although most of the phone numbers and addresses were out of date, they were accurate as were the listed social security numbers. However, it didn't include any of the more recent immigrants in the family or myself, possibly because I take opsec seriously.

Funny enough it looks like it has data for Tom Brady, former FBI director James Comey, Barack Obama, and Donald Trump (just some of the names that popped into my mind to look up).

Post reply on HN