Live data from Hacker News

Stripe Atlas Vendor Leaked SSNs

twitter.com

21–30 of 64 posts

Re: Stripe Atlas Vendor Leaked SSNs

#21
post #15
post #10

Earlier quoted context omitted.

Maybe it would be more clear if I used some examples. Identity: mjevans on news.ycombinator.com Authentication: is allowed to post as (Identity), is allowed to vote on things, etc. Identity alone should not imply authorization, when someone is asking for a proof of identity what they really want is a record that you are actually an identity (authorization).

I think you may have authentication and authorization swapped.

You're correct in that I'm grouping authentication and authorization.

The three types of tuples would include:

An identity (E.G. a person at an address).

Proof that you are that person at that address.

A list of things you're allowed to do at that address (IRL laws, or for a computer account publishing as that address/etc).

Re: Stripe Atlas Vendor Leaked SSNs

#22
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

Can we calculate reproducible cryptographic private keys from fingerprints? If you solve that, you'll unlock an entire business model centered around "anonymous entities that can be regenerated at any time using a biometrics booth at the mall and a secret passphrase known only to you".

Yea but you'd literally be leaving your private key everywhere you are.

Re: Stripe Atlas Vendor Leaked SSNs

#23
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

It already exists, it's your phone.

There are some limits in linking it to existing identifiers like names or SSNs. However, that doesn't matter because due to its nature, the phone leaves a trail. Any serious abuse can be punished.

Re: Stripe Atlas Vendor Leaked SSNs

#24
post #22

Earlier quoted context omitted.

Can we calculate reproducible cryptographic private keys from fingerprints? If you solve that, you'll unlock an entire business model centered around "anonymous entities that can be regenerated at any time using a biometrics booth at the mall and a secret passphrase known only to you".

Yea but you'd literally be leaving your private key everywhere you are.

If you seared your passphrase into your fingertips, sure. There's a reason it's not just 'fingerprints only' or 'passphrase only'.

Re: Stripe Atlas Vendor Leaked SSNs

#25
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

It already exists, it's your phone. There are some limits in linking it to existing identifiers like names or SSNs. However, that doesn't matter because due to its nature, the phone leaves a trail. Any serious abuse can be punished.

India has a sim card system like this, but it is actually even less secure and shockingly easy to game. That's not even counting for the fact that not everyone has a cell phone (a minority, but still exists).

Re: Stripe Atlas Vendor Leaked SSNs

#26
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

It already exists, it's your phone. There are some limits in linking it to existing identifiers like names or SSNs. However, that doesn't matter because due to its nature, the phone leaves a trail. Any serious abuse can be punished.

This is a terrible, TERRIBLE idea. Especially for people who move a lot. Phone numbers get reused. I am currently maintaining 4 SIM cards just to keep services relaying on them active. About 2 months ago I forgot to recharge one of those SIM cards and was locked out of one of my bank accounts.

Re: Stripe Atlas Vendor Leaked SSNs

#28

Strange to not see an official statement and post Mortem from Stripe mentioned anywhere. Can someone who got a letter post a (redacted as necessary) scan of it?

Found one on Twitter: https://twitter.com/dercentralist/status/1213216360630759431...

Looks like it was the vendor ‘Legalinc’.

Re: Stripe Atlas Vendor Leaked SSNs

#29
post #13

Odds are that all these SSNs had been leaked from a bunch of other sources anyways. Why the “fuuuuuuuck”? This doesn’t seem like a big deal at all.

Presence on this list potentially indicates individuals of higher net worth and credit history, making it more valuable than other sources?

Re: Stripe Atlas Vendor Leaked SSNs

#30

Strange to not see an official statement and post Mortem from Stripe mentioned anywhere. Can someone who got a letter post a (redacted as necessary) scan of it?

For whatever reason there seems to be a semi-official version hosted by Vermont: https://ago.vermont.gov/blog/2019/12/31/stripe-legalinc-noti...
Post reply on HN