Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

101–110 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#102
post #24
post #11

Earlier quoted context omitted.

This situation could be greatly improved if these companies didn't have or need to have this data in the first place. Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.

I don't know about the US, but here in the UK prepaid mobile isn't necessarily looked down upon, but it's significantly more expensive than a contract. It's the main reason why people just go with a contract despite being locked in for 2 or more years. Even sim-only contracts are considerably cheaper.

In the US, prepaid is a much cheaper option for all but the highest volume users. The drawback is that you get deprioritized on the cell towers making mobile data nearly unusable in many cities or at large gatherings like sporting events.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#103
post #98
post #15

Earlier quoted context omitted.

With AT&T at least if you want the highest priority on their towers you have to be on their Elite plan (QCI 7 I believe), which is post-paid only

What does the “priority on the towers” do?

If you want to use your mobile data, you get sent to the back of the queue. Higher priority users might get 50mbps. You will be lucky to get 1mbps and in some cases less than that.

I don't know if there is an impact on call availability as well.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#104
post #57

I bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use). Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked". Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to…

My hero!

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#105
post #8

It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...

SMS as 2FA is so stupid. So many banks and financial institutions are doing it in America and it amazes me. I mean what are they spending million of dollars in compliance/security/SOC etc on if they can't get a basic 2FA done correctly ? And don't get me started on stupid password requirements where a more secure password generated in keypass etc won't be valid. Who builds this stuff today ?

sms as 2fa raises the bar signifigantly for non organized attackers. You'd be amazed how much of the meth crowd that encompases.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#106
post #86

Earlier quoted context omitted.

No, of course not. I am saying that merchants do not have the ability to verify card holder name. Your transaction will process properly with Mickey mouse as first last. Only amex verifies cardholder name. EDIT: relevant stackexchange is here: https://security.stackexchange.com/questions/220724/i-can-pa...

> None of this was difficult nor illegal nor expensive. Is giving a false name to the CC companies not illegal in some way? At the very least I'm certain it is a breach of contract.

I think OP is saying that they give a fake name to the vendor, not the CC card company. Walmart (maybe?) isn't checking that the billing name you give them matches the name on the card. I don't know how true this is across all vendors.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#107

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

Should have it where your social security is a public key and government has your private key. You're given a device that has your private key to confirm things but you don't know it directly. Public key is used in replace of discussi security number. If your public key gets compromised the government blacklists it and gives you a new one. This is just a knee-jerk thought and I'm sure it can be improved, but I believ…

You have it totally backwards. Public keys are called public keys because they are intended to be public. You should be able to freely advertise a public key on a billboard.

On the other hand, you can't really expect the average citizen to properly curate a private key, and a private key also doesn't work for verification purposes.

I think the problem would be easily solved without encryption or keys by using the social security number in combination with a user-selected PIN number.

Any time you apply for credit somewhere, you should have to provide the social and a PIN. There should also be an easy way to generate single-use PIN numbers that can be used when applying for credit.

They already have a lot of the infrastructure for doing this. You can already put a credit freeze on your social security number and protect the credit freeze with a PIN, for example.

Whenever I am applying for credit, I simply "thaw" out my social security number for a couple of days. This works pretty well, but it's a hassle because you have to do it for all three agencies. It also suffers from the problem that my credit could get compromised if I left it thawed out too long.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#108

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

I think that we need to somehow make it harder for companies to request SSN if that continues to be a "secret". I cannot tell you how many times a Doctor's office casually asks for an SSN on a sheet of paper in plain text and I am like Why. I always fight that and found out that in a lot of cases, they just have it there and they didn't care when I didn't fill it. Some of them do force me (probably for credit/billing…

Ironically, having it in plain text on a piece of paper in some random doctor’s office is much more secure than having it hashed in some website’s database.

Possibly even more secure than that same doctor having it in their system.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#109

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

> After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication".

lol. How do you think it works right now?

The party who accepted the SSN (or their insurance) is liable for footing the bill for the fraud, except in the ridiculously unlikely scenario where they’d manage to collect money from the fraudster.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#110
Why is it so much harder and costlier for companies to be able to store credit card numbers, but not SSNs? I mean there is a whole certification process that costs hundreds of thousands of dollars to get pci certified, but you could say an SSN has the same of not larger risk profile. You can cancel credit cards, can’t get a new SSN. What is stopping government from implementing the same requirements? No one asks for your card number that is not certified, and certainly you would not give it if asked, even if they said it’s mandatory. So why the SSN leniency?
Post reply on HN