Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

131–140 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#131
post #100

As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…

It seems like someone could do us all a public service by combining a few of these lists and making a very public and hard to take down website with them all listed. Create a forcing function for a replacement. Not recommending anyone do this as it's obviously illegal, but..

What laws make it illegal for a regular person to republish a list of SSNs and corresponding names?

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#132

Earlier quoted context omitted.

I agree, but I am afraid that our two party system, which is incentivized to 'politicize' (I dislike that broad term) everything, it would be quite hard. The one party proposes it, the other party will find "reasons" why it's either government overreach, or discriminatory, or something something something depending on the ideology. Purported ideology. Most likely it's another horse that gets debated in debates about…

There's still some identity theft issues, because "everyone asks your SSN for no reason" becomes "everyone asks for a scan of your id for no reason". For instance, when I was looking for an appartment, the State had a service to both authenticate and watermark some documents (id and proof of income, among others). The watermark was a bunch of big bars with "this is intended for rental search" written on them. Kinda l…

This is the problem with having the public and private key be the same. Anyone should be able to access your public key, and anyone you deal with should be able to ask you to use your private key to verify your identity. The problem is when that entire process is reduced to "give us the number the government uses to ensure you're you. Don't worry, we won't use it to convince anyone else we're you ;) Or leak it so anyone else can do the same ;) ;) ;)"

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#133
post #121

Earlier quoted context omitted.

Blame the insurance companies - most major insurance companies use your SSN as a mechanism for identifying the patient. The member ID #'s can be used but it's quicker to just input the SSN.

But they already get a copy of our Insurance Cards. Shouldn't that be enough ?

[deleted]

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#134
post #126

In the US many companies publicly share their EIN (the equivalent of SSN for companies), and somehow the laws are set up that this isn't a source of identity theft.

You cannot get a loan with a company's EIN, nor can you (easily?) get money from the government by filing tax returns with a company's EIN.

Therefore there is not much value in fraudulent use of EINs.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#135
post #90

TMobile: 100M ATT : 70M suffice to say nearly all adults of USA. I am surprised how come not a single high profile person faces ID Theft and related troubles from these many data leaks !

Tmobile was 40M.

It is all small pickles anyway compared to Sep 2017's Experian leak of 147M people's records:

https://www.consumer.ftc.gov/blog/2019/07/equifax-data-breac...

A credit reporting agency's information is all the important information you would need about someone to do something fraudulent with their identity.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#136
post #51

Earlier quoted context omitted.

Just this week, I had to sign into a service for a very large transaction I'm privy to. My password? The last 4 of my social. It's unbelievable how dumb so many of our systems are.

On a similar note, I setup my utility account this week. It was suggested by the representative that I use the last 4 digits of my SSN as a pin for my account. Pretty disappointing how short sighted many companies are when it comes to security practices.

That's because if somebody gets in, it's not their problem for having lax authorization, it's your problem for being "victim of identity theft" and all the burden of proving it wasn't you rests on you. It costs them nothing to give out horrible advice, so they do it.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#137

What AT&T service compels consumer SSN disclosure to begin with?

I think it's any contract with a carrier. They want the ability to go after you and hurt your credit if you refuse to pay, is my guess. It's disgusting.

How is it disgusting for a lender to be able to look up someone's credit history and determine if they are an appropriate credit risk for them?

The alternative is everyone gets (or does not get at all) credit on the same terms without regards to personal behavior or risk profiles, which is a valid option, but I would still think "disgusting" is a strong word to describe the prior scenario.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#138
post #30

Earlier quoted context omitted.

The hackers selling the info are well known for providing fresh data, to the point that they’ve given away old data for free. I doubt they’d risk their reputation on reselling a different leak.

Ah, thanks...not mentioned in the linked article. There's more info in the source article: https://restoreprivacy.com/att-data-breach-70-million-custom... The hacker group is "ShinyHunters".

I wonder if the price of leaked data dropped after Experian's data leak from Sep 2017 that included basically everyone in the US that uses credit.

I imagine the difference in data since the Experian leak are for people that became adults since Sep 2017 or immigrants or some information about new addresses/names from moves/marriages, etc.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#139
post #123

Earlier quoted context omitted.

In Denmark, you are issued a one-time pad. You get a new one with some frequency. If you lose it, you are issued a new one. In that case, third parties could use a government website to get a row/col and ask you to verify, and the website could say yes/no. Yes, there is a risk of your one-time pad being stolen, but it is no greater than the current risk that any US citizen's tax documents or SS card can be stolen.

How do they bootstrap the verification when you say you lost your key?

You can read more here: https://www.wikiprocedure.com/index.php/Denmark_-_Replace_Lo...

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#140
post #123

Earlier quoted context omitted.

In Denmark, you are issued a one-time pad. You get a new one with some frequency. If you lose it, you are issued a new one. In that case, third parties could use a government website to get a row/col and ask you to verify, and the website could say yes/no. Yes, there is a risk of your one-time pad being stolen, but it is no greater than the current risk that any US citizen's tax documents or SS card can be stolen.

How do they bootstrap the verification when you say you lost your key?

That's an annoying denial of service attack; and you would typically do this by making the burn require very little authentication and the recovery a visit to a local government office, such as the police or a court.
Post reply on HN