Live data from Hacker News

Inside the "3 billion people" national public data breach

troyhunt.com

341–350 of 472 posts

Re: Inside the "3 billion people" national public data breach

#341
post #13

Earlier quoted context omitted.

Permission Slip by Consumer Reports (automated): https://permissionslipcr.com Simple Opt Out (manual list): https://simpleoptout.com

I use permission slip and I am not in the breach as far as I can tell

"Not available in your region" bloody hell.

Re: Inside the "3 billion people" national public data breach

#342

Earlier quoted context omitted.

Hash-based solutions aren't as easy as we might hope. You store a hashed version of my SSN, or my phone number, to represent my opt-out? Someone can just hash every number from 000-00-0000 to 999-99-9999 and figure out mine from that. You hash the entire contents of the profile - name+address+phone+e-mail+DOB+SSN - and the moment a data source provides them with a profile only containing name+address+email - the miss…

> Someone can just hash every number from 000-00-0000 to 999-99-9999 and figure out mine from that. That's what salts are for, right? It wouldn't be too hard to issue a very large, known, public salt alongside each SSN. > And of course none of the data brokers have much reason to make opt-outs work well, in the absence of legislation and strict enforcement - it's in their commercial interests to say they "can't stop…

If the salt is public, what’s the point, then you can get all the salts, and combine them with every possible ssn, and you’re back where you were before.

Re: Inside the "3 billion people" national public data breach

#343
post #107
post #84

Earlier quoted context omitted.

I'd be worried about legal repercussions if we were talking about the latest Disney movie, but this is merely the private information of a billion people. Never seen IP law give much of a crap about that before.

Private information on people is Equifax's IP.

which has yet to leak. as far as we know, the equifax data never became public.

Re: Inside the "3 billion people" national public data breach

#344
post #35

Earlier quoted context omitted.

> Anyone have experience with these sort of services? Quite a bit. Often if you request removal or opt-out, you'll reappear in a matter of a few months in their system, regardless of whether you use a professional service as a proxy or do it yourself. The data brokers usually go out of their way to be annoying about it and will claim they can't do anything about you showing up in their aggregated sources later on. Th…

my understanding is that there's a bit of a catch-22 with data removal - if you request that a data broker remove ALL of your information, it's impossible for them to keep you from reappearing in their sources later on because that would require them to retain your information (so they can filter you out if you appear again).

1. They could be required to store a private copy of the removal requests, data that they can't sell (not ideal)

2. Sounds like "data brokers" that sell private information just shouldn't exist...

Re: Inside the "3 billion people" national public data breach

#345
It's worth remembering that the main reason this kind of data breach is a real problem is mostly due to the incompetence of the IRS. For any serious financial organization, knowing a person's SSN, name, address, etc doesn't allow you to access or withdraw that person's finances.

But the stupidity of the IRS means that people are easily targeted by false tax return attacks. File a fake tax return for someone, using their SSN/name/address, but tell the IRS you changed address. Then the IRS sends your tax refund to the new address, and boom, you just collected some poor sod's refund. To add insult to injury, the IRS is probably going to audit the person whose refund you stole.

Re: Inside the "3 billion people" national public data breach

#346

Anything the average SSN holder should be doing proactively?

You could freeze your credit, it you wanted to be careful. Realistically though, you should have already been monitoring to check if unexpected things were being done in your name. I’ve presumed that all our SSNs have been out there for years now due to one hack or another, that this hack just makes it indisputable doesn’t change much.

What's required to freeze/unfreeze your credit? Your SSN and address info? All of that is in the breach for millions of people.

Re: Inside the "3 billion people" national public data breach

#347

Earlier quoted context omitted.

that was the idea behind certain applications and add-ons that would browse around to popular websites and randomly click ads so that marketers couldn't tell your actual interests from fake ones. Unfortunately that strategy is deeply flawed and dangerous because nobody cares if the data they have on you is accurate or not. They still can, and still will, use it against you at every opportunity. Every scrap of data th…

> might decide to raise the rates of every single member within that neighborhood or zip code Wouldn't that be against redlining laws? https://en.wikipedia.org/wiki/Redlining

I doubt it, since nobody is being denied housing or services. Health insurance companies have plenty of data to back up their practice. Your zip code might be the single most important predictor for longevity (https://time.com/5608268/zip-code-health/).

More importantly, your insurance company is never going to tell you that that's why they raised your rates. You're just going to see a high bill. Same way that a potential employer isn't going to tell you that you didn't get the job because of something you said on social media 14 years ago, or because the information they got from a data broker says you drink a lot. You just get ghosted.

That's the problem with surveillance capitalism. Even as all that data increasingly impacts your life you're almost never aware that it's happening and have no ability to appeal or correct the record.

Re: Inside the "3 billion people" national public data breach

#348

Earlier quoted context omitted.

that was the idea behind certain applications and add-ons that would browse around to popular websites and randomly click ads so that marketers couldn't tell your actual interests from fake ones. Unfortunately that strategy is deeply flawed and dangerous because nobody cares if the data they have on you is accurate or not. They still can, and still will, use it against you at every opportunity. Every scrap of data th…

Isn't something like regulation with strong data protection laws a bit late at this point? It seems fair to say that most people alive are already scooped up in 1 large data breach or another. And that data has been made public likely in some form, and is probably replicated to dark corners of the planet. Don't get me wrong, regulation on these industries seems like a no-brainer, but it seems unlikely to remediate th…

That's kind of true. Preventing the sale of it will make it harder for it to be used against you. Even if scammers can still buy or download your data from the darkweb your future employers and the companies you interact with are a lot less likely to go that far to get their hands on it, so all that data being out there will impact your life less and less. Even better, fewer places will be collecting new data about you. Your social security number and date of birth don't really change, but your income, medical conditions, home address, spending habits, sex life, and location history do.

Re: Inside the "3 billion people" national public data breach

#349

Earlier quoted context omitted.

You too can be a data broker! for (i = 0; i Does anyone really really care if the name is accurate if the SSN is present? More than half of the SSNs in the above dataset are valid.

You probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.

That has been my strategy for the last decade or so, Unless I have a solid reason to I never use my real name when placing orders and generally never the same fake name twice, always use a virtual credit card, if it's a non-physical product I don't even use my real address. I have some old phones I throw pre-paid sim cards into when I need to do number confirmation. The goal is to create a little consistent linkable data to me and at least generate some noise in all these data broker collection processes.

Re: Inside the "3 billion people" national public data breach

#350

It's worth remembering that the main reason this kind of data breach is a real problem is mostly due to the incompetence of the IRS. For any serious financial organization, knowing a person's SSN, name, address, etc doesn't allow you to access or withdraw that person's finances. But the stupidity of the IRS means that people are easily targeted by false tax return attacks. File a fake tax return for someone, using th…

I agree. The IRS should be better funded so they can afford to update their systems and hire more tech experts.
Post reply on HN