With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.
T-Mobile: Breach Exposed SSN/DOB of 40M+ People
31–40 of 282 posts
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#32Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#33There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.
Serious question, how would that be any different than a SSN?
In any case, the private key is stored on a plastic ID, only released with a PIN, and the databases only store the corresponding public key.
A leak of a public key without the private key is harmless.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#34There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.
Serious question, how would that be any different than a SSN?
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#35With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#36In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only store the corresponding public key.
A leak of a public key without the private key is (relative to SSN) harmless.
https://en.m.wikipedia.org/wiki/EIDAS
Can we please have this in the US?
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#37There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.
Fantastic. Let's centralize all records from everybody in one central location that totally won't get hacked, by the same government that screwed up Healthcare.gov, your DMV, and just recently a war against militants wearing sandals.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#38With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.
Check a photo ID. Check a public cert. Take a fingerprint.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#39With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.
Would that situation persist for decades?
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#40There should be zero reason for a phone company to even have our SSNs. We really need a public national ID system in the US.