Earlier quoted context omitted.
I will say that their list of reasons is deeply flawed. > Human beings can't read a bar code. - they can, and more importantly they almost never have to > A lot of our product comes from cottage industries in Asia that couldn't mark their goods with bar codes if they tried. - They can be added at the store/warehouse level, not every product needs one, and I've never seen a store that worked entirely on bar codes 100%…
How about this: without barcodes, you can't replace your clerks with self-checkout machines
Inside the "3 billion people" national public data breach
201–210 of 472 posts
Re: Inside the "3 billion people" national public data breach
#202Earlier quoted context omitted.
In the US, the government could help alot if they simply moved to a national ID system and dismantled social security numbers. The national ID systems I've seen proposed have alot more security from the ground up, and could replace the passport system.
"Wow, the government is so catastrophically bad at managing IDs; what should we do?" "Hmmm. I know! Lets get the government to manage a mandatory ID system, and require it for all aspects of citizen's lives! In fact, lets centralize all of their medical, financial and personal data using this ID, and ensure that it can all be accessed using this ID! What could possibly go wrong?"
Re: Inside the "3 billion people" national public data breach
#203Ahh, cool, pour the corpus through GPTs and start tweeting Congressional rep personal info at them until they pass a law to outlaw data brokers (in keeping with historical precedent [1] [2]). [1] https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act [2] https://jolt.law.harvard.edu/digest/dodging-the-thought-poli...
For argument sake, instead of outlawing data brokers wouldn’t it be better to design a better ID system that renders one’s name, dob, and SSN as harmless information? I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that.
Re: Inside the "3 billion people" national public data breach
#204Re: Inside the "3 billion people" national public data breach
#205Re: Inside the "3 billion people" national public data breach
#206Earlier quoted context omitted.
I never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense
"Identity Fraud" is institutionalized victim blaming. The claim is that the person who's identity was stolen was defrauded (and they should protect themselves or fight back), but in reality it was the creditor that got defrauded.
Re: Inside the "3 billion people" national public data breach
#207If a data broker collects data without the consent of the consumer, then their only real risk is a class action lawsuit which drags on for six years, gets settled for a few days profit, and the consumer gets $13.50 after the legal fees. This massive skew in the risk reward calculus of data brokers is why we have the problem. Because there's little to no real downside, the trend is automatically collect as much data on as many people as possible.
Fixing this means big, mandatory, cash penalties in the law code - say $5k per consumer data leak, directly to the affected consumer, with added penalties if the company lies about the leak or delays payment. The fine must be big, mandatory, and paid directly to the consumer. Only that changes the risk reward ratio.
In that new world, companies would have to re assess their risks. They'd either build invulnerable systems and hire a lot more people reading HN to protect their golden goose, or better still they'd decide to exit the business entirely. That sounds bad, but the only reason the industry exists is because regulators failed to foresee massive leaks like this happening every three months.
We need a consumer data privacy law, with massive fines, to force companies to change their behavior. What we're doing now clearly does not work.
Re: Inside the "3 billion people" national public data breach
#208Earlier quoted context omitted.
In many countries in Europe, your ID card contains a chip with a cryptographic key, much like chip&pin on a debit or credit card. Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. If the card is lost or stolen they can just remove your old one from the keyserver. It's literally just public key crypto. Identity theft is rampant…
The US has three dumb points pushing back on this. The first is religious nuts who think it would be a "mark of the beast" The second is anti-government types who are, well, anti-government anything. The third is many business owners, because it would become much harder/risky to hire illegal immigrants to work.
One doesn’t need to be anti-government to fear governmental intrusion on one’s rights without due process. Our current government does that now.
Re: Inside the "3 billion people" national public data breach
#209Earlier quoted context omitted.
if you know place of birth, and place of ssn application, you can determine most of the ssn. the final 4 are supposed to be random, but are blurted out to rooms full of people and tech, during service. the integrity of SSN security, was lost a long time ago
as of 2011 they are fully random instead of being based on geographical region and groups https://www.ssa.gov/employer/randomization.html
Re: Inside the "3 billion people" national public data breach
#210"there were no email addresses in the social security number files. If you find yourself in this data breach via HIBP, there's no evidence your SSN was leaked, and if you're in the same boat as me, the data next to your record may not even be correct. " Seems like Troy is skeptical about this being a real full breach?
I looked up several family members and although most of the phone numbers and addresses were out of date, they were accurate as were the listed social security numbers. However, it didn't include any of the more recent immigrants in the family or myself, possibly because I take opsec seriously.
Funny enough it looks like it has data for Tom Brady, former FBI director James Comey, Barack Obama, and Donald Trump (just some of the names that popped into my mind to look up).