Live data from Hacker News

Stripe Atlas Vendor Leaked SSNs

twitter.com

31–40 of 64 posts

Re: Stripe Atlas Vendor Leaked SSNs

#32
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

I think we need a worldwide, federated identity system.

There should be multiple identity providers, mostly governments and organizations who already have lots of info about you, for example banks. This already works in Poland and several other european countries. Such organizations should verify that you are you the way they currently do, and give you a way of authorizing yourself, i.e. sms, mobile app, one time passwords etc. If someone needed to verify your identity, they would go through your chosen org for authentication. This approach has several benefits.

1. You can provide as much or as little info as you want. The info you provide could include true/false assertions. For example, a porn website could just ask the org whether your age >= 18, without the need to know your exact birthdate,. Same for citizenship, disability, criminal record etc.

2. You can easily integrate that with other services, for example payments or even a secure communication channel, letting companies contact you without learning any details about you. There could even be a secure shipping service, where the company selling you the product only gets a special qr code to stick on the package,. Only one shipping company would get your real address, the rest would just know the next leg of the route.

3. You could provide instant "not a robot" verification, without any captchas, without any personal data and without any hassle. The authorizing org would just give the requestor a token, different for each visit, that they could send with a "add to blacklist request". The next time a blacklisted user would try to log in to that service, their org would refuse to provide the token.

4. Ability to provide legal accountability without rewealing anything. The authenticating org would just provide a token to a service. The user could do whatever they wished, but, in case they'd do something illegal, the police could just force the org to actaully reveal who was behind that token.

Of course, the system would have to be regulated by a global body of governments or organizations. Each org would have certain resoponsibilities, i.e. allowing you to port your id to somewhere else, not requesting more data than necessary, honoring blacklists etc. If that system existed, implementing a safe, seamless online and real0-life experience would be trivial. Just imagine if it would be trivial to trace each website, each comment, everything to a real person with a court order, while not giving most companies any data whatsoever.

Re: Stripe Atlas Vendor Leaked SSNs

#33
post #19

Earlier quoted context omitted.

Secure enclave like with Ios is an option. You never give your biometrics away.

Sure, I'm all for a key based solution. My opposition is against using biometrics for anything beyond convenience features.

Biometrics are relatively convenient and very safe when they're used in place (not remotely) with a human agent overseeing. No cops have ever let a suspect pop out to buy a 3D printer and some custom moulds before taking their prints. The airbase's gate guard isn't going to let you substitute a custom-made adversarial JPEG image for your face after asking you to roll down the window even though her normal job is statistical analysis and she has never fired that weapon she's carrying in anger.

They're not great without supervision and they're completely hopeless remotely.

Re: Stripe Atlas Vendor Leaked SSNs

#34
post #13

Odds are that all these SSNs had been leaked from a bunch of other sources anyways. Why the “fuuuuuuuck”? This doesn’t seem like a big deal at all.

Presence on this list potentially indicates individuals of higher net worth and credit history, making it more valuable than other sources?

You can just buy 1000s of high-credit profiles located in the wealthiest zip codes for $1/pc max (I’ve seen prices below $0.1/pc but I suppose this is a special request)

Re: Stripe Atlas Vendor Leaked SSNs

#35
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

SSNs are much too short, and were mostly issued in a foolish and predictable way (if you're a kid you might have a random SSN but most Americans still have ones issued the old way). Given the US plausible population load, issuing a randomly chosen 12 digit number incorporating a check digit would have been a better start.

But the authentication problem is the tricky part though, governments don't have a reliable way to authenticate their citizens today and even if you have a good will intent to fix this, that can be hijacked by people with less saintly motives. See India or China for how that might not go well.

Re: Stripe Atlas Vendor Leaked SSNs

#36

Earlier quoted context omitted.

Sure, I'm all for a key based solution. My opposition is against using biometrics for anything beyond convenience features.

Biometrics are relatively convenient and very safe when they're used in place (not remotely) with a human agent overseeing. No cops have ever let a suspect pop out to buy a 3D printer and some custom moulds before taking their prints. The airbase's gate guard isn't going to let you substitute a custom-made adversarial JPEG image for your face after asking you to roll down the window even though her normal job is stat…

> Biometrics are relatively convenient and very safe when they're used in place (not remotely) with a human agent overseeing.

In your estimate, how large a percentage of biometric security implementations follow your description?

Re: Stripe Atlas Vendor Leaked SSNs

#37

Earlier quoted context omitted.

It already exists, it's your phone. There are some limits in linking it to existing identifiers like names or SSNs. However, that doesn't matter because due to its nature, the phone leaves a trail. Any serious abuse can be punished.

India has a sim card system like this, but it is actually even less secure and shockingly easy to game. That's not even counting for the fact that not everyone has a cell phone (a minority, but still exists).

How do you game it apart from stealing a phone? It may be easy to get another identity but that's a feature.

If somebody commits a serious crime, the joined location of the phones will reveal the true identity unless somebody invests an amount of effort that's equal to buying a new passport.

Re: Stripe Atlas Vendor Leaked SSNs

#38

Strange to not see an official statement and post Mortem from Stripe mentioned anywhere. Can someone who got a letter post a (redacted as necessary) scan of it?

For whatever reason there seems to be a semi-official version hosted by Vermont: https://ago.vermont.gov/blog/2019/12/31/stripe-legalinc-noti...

Oh jesus

https://ago.vermont.gov/blog/category/security-breaches/

There's 63 pages.

Re: Stripe Atlas Vendor Leaked SSNs

#39
post #26

Earlier quoted context omitted.

It already exists, it's your phone. There are some limits in linking it to existing identifiers like names or SSNs. However, that doesn't matter because due to its nature, the phone leaves a trail. Any serious abuse can be punished.

This is a terrible, TERRIBLE idea. Especially for people who move a lot. Phone numbers get reused. I am currently maintaining 4 SIM cards just to keep services relaying on them active. About 2 months ago I forgot to recharge one of those SIM cards and was locked out of one of my bank accounts.

Why don't you register all services with one SIM and use a Dual-SIM phone to get cheap rates on another card?

Since we are talking about introducing a new identity system, isn't it easier to resolve the problems you mentioned than to introduce something new?

Re: Stripe Atlas Vendor Leaked SSNs

#40
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

I think we need a worldwide, federated identity system. There should be multiple identity providers, mostly governments and organizations who already have lots of info about you, for example banks. This already works in Poland and several other european countries. Such organizations should verify that you are you the way they currently do, and give you a way of authorizing yourself, i.e. sms, mobile app, one time pas…

> There should be multiple identity providers

I think we already have that: Google ;)

The only difference is that Google doesn't provide identity verification, only identity validation when you have previous knowledge of a Google account being associated to a user account.

Post reply on HN