Live data from Hacker News

Confessions of an ID Theft Kingpin

krebsonsecurity.com

11–20 of 29 posts

Re: Confessions of an ID Theft Kingpin

#11
post #2

> (from TFA) stolen identity records that included a consumer’s name, date of birth, Social Security number and email and physical address. Scary how little you need to steal an identity in some places...

Are there places that it would require more to steal an identity? What countries and what type of information do they ask for?

I’m gonna rant here, but a big problem is that SSNs were never designed to be used as an identifier. It was simply used to allow someone to receive Social Security, hence the name. They literally used to have the text “Not to be used for verification.”

As for its problems, there’s quite a few, but the two big ones IMO are (1) no check digits and (2) (up until relatively recently) they’re sequential. I don’t know when the change was, but if you take a SSN issued before 2000, you could add one to your whole SSN and it would be a valid one. They may even have been born on the same day as you in the same hospital. Also, you could find out a general area where someone was living when it was issued (usually birth) using the first 3 digits.

Re: Confessions of an ID Theft Kingpin

#12
post #2

> (from TFA) stolen identity records that included a consumer’s name, date of birth, Social Security number and email and physical address. Scary how little you need to steal an identity in some places...

Are there places that it would require more to steal an identity? What countries and what type of information do they ask for?

Well the modern countries use documents such as ID card or passport, you can't just walk to a bank and start opening accounts from that little data. It's actually insane Americans have that archaic system.

Re: Confessions of an ID Theft Kingpin

#13

Earlier quoted context omitted.

Are there places that it would require more to steal an identity? What countries and what type of information do they ask for?

Brazil would require a "CPF", which is a unique number assigned to individuals. If you are doing something simple such as an online purchase or monetary transfers(to someone else's account), the number alone could be sufficient, coupled with other information like full name and address. Many places will not be happy with just the number and will require at minimum a scan of the actual document - if you are lucky. Mos…

> Brazil would require a "CPF", which is a unique number assigned to individuals. If you are doing something simple such as an online purchase or monetary transfers(to someone else's account), the number alone could be sufficient, coupled with other information like full name and address.

> The main issue in the US is the use of a 'unique ID' which was never meant as ID, can't be changed and has no built-in security measures.

As someone with no knowledge of how Brazil does things, how is the CPF any different than an SSN? Is it the requirement to present a notarized copy of the document the difference? Or something else?

Re: Confessions of an ID Theft Kingpin

#14

Earlier quoted context omitted.

Are there places that it would require more to steal an identity? What countries and what type of information do they ask for?

Well the modern countries use documents such as ID card or passport, you can't just walk to a bank and start opening accounts from that little data. It's actually insane Americans have that archaic system.

> Well the modern countries use documents such as ID card or passport, you can't just walk to a bank and start opening accounts from that little data. It's actually insane Americans have that archaic system.

It's archaic to allow opening bank accounts completely online with no physical presence/authentication required?

Re: Confessions of an ID Theft Kingpin

#15
post #2

> (from TFA) stolen identity records that included a consumer’s name, date of birth, Social Security number and email and physical address. Scary how little you need to steal an identity in some places...

Are there places that it would require more to steal an identity? What countries and what type of information do they ask for?

Some companies are starting to use "knowledge based authentication" like "which of these streets have you lived on?" but of course they get that information from the data brokers so anyone who can access data brokers can still "steal" identities.

Re: Confessions of an ID Theft Kingpin

#16
post #4

Earlier quoted context omitted.

The existence of these databases, especially given how insecure they are is, of course, a real national security threat, but the lack of reaction from the government is telling.

Yet everyone is freaking out and moralizing about nonfinancial data voluntarily given to Facebook. If only the credit bureaus kept our financial and identity data as Facebook kept your list of favorite movies and your selfies.

Facebook sell your favourite movies, friends, political views and anything else they know about you to advertisers. it's a very similar business model.

Re: Confessions of an ID Theft Kingpin

#17

I regularly wonder why we don’t have some form of physical verification token which signs things with our identity, the whole system is broken in that regard.

The closest thing to this are probably the seals or "chops" used in East Asian countries to authenticate contracts, invoices, and financials. Of course it's the seal's imprint you need to authenticate a document, but in practice physical control over the seal tends to be what confers decision-making power.

Re: Confessions of an ID Theft Kingpin

#18
post #13

Earlier quoted context omitted.

Brazil would require a "CPF", which is a unique number assigned to individuals. If you are doing something simple such as an online purchase or monetary transfers(to someone else's account), the number alone could be sufficient, coupled with other information like full name and address. Many places will not be happy with just the number and will require at minimum a scan of the actual document - if you are lucky. Mos…

> Brazil would require a "CPF", which is a unique number assigned to individuals. If you are doing something simple such as an online purchase or monetary transfers(to someone else's account), the number alone could be sufficient, coupled with other information like full name and address. > The main issue in the US is the use of a 'unique ID' which was never meant as ID, can't be changed and has no built-in security…

CPF and SSN are just numbers that uniquely identify a person.

The difference is that in Brazil, because of bureaucracy and fraud prevention, it is a lot harder to use somebody else's data to your benefit. Which is just as well, because most Brazilians are not careful at all and will readily give out their data.

I will give an example of how insane the bureaucracy can be: I once had to show my personal documents to an authority (ID, work card, driver's licence, certificate of birth, and so on). Because I was not born in Brazil, I was asked to show proof that I was Brazilian, to which I replied: how could I possibly have all this documentation and not be Brazilian?

But it is getting better and government offices speak to each other (through databases and webservices) and so they can more easily identify a person and not require so much paperwork. Still, some older folks can't shake their mentality.

Re: Confessions of an ID Theft Kingpin

#19

Earlier quoted context omitted.

Yet everyone is freaking out and moralizing about nonfinancial data voluntarily given to Facebook. If only the credit bureaus kept our financial and identity data as Facebook kept your list of favorite movies and your selfies.

Facebook sell your favourite movies, friends, political views and anything else they know about you to advertisers. it's a very similar business model.

They actually don't, unless you define selling as they allow advertisers to select what demographics/attributes their ads target. But the actual data stays on the Facebook servers. If you're referring to the apps having access to user data, that was not selling at all, but instead a permission originally granted by users by probably forgotten about. Basically, unless you contort the definition of selling to a very different meaning, that's simply not true.

And if you do use that definition of selling, then everyone is selling your data. All the politicians who decry tech companies are selling your data using the same definition. Every advertiser, retail store, bank, basically every large business offers other businesses a way to access a specific subset of their users.

Re: Confessions of an ID Theft Kingpin

#20

Earlier quoted context omitted.

Yet everyone is freaking out and moralizing about nonfinancial data voluntarily given to Facebook. If only the credit bureaus kept our financial and identity data as Facebook kept your list of favorite movies and your selfies.

Facebook sell your favourite movies, friends, political views and anything else they know about you to advertisers. it's a very similar business model.

Yeah, no. They sell the ability to target groups of people based on these characteristics. They don't sell data on individuals.
Post reply on HN