Live data from Hacker News

Stripe Atlas Vendor Leaked SSNs

twitter.com

41–50 of 64 posts

Re: Stripe Atlas Vendor Leaked SSNs

#41

Earlier quoted context omitted.

India has a sim card system like this, but it is actually even less secure and shockingly easy to game. That's not even counting for the fact that not everyone has a cell phone (a minority, but still exists).

How do you game it apart from stealing a phone? It may be easy to get another identity but that's a feature. If somebody commits a serious crime, the joined location of the phones will reveal the true identity unless somebody invests an amount of effort that's equal to buying a new passport.

I imagine sim swapping is a thing over there as well, maybe even easier to do than in the US.

Re: Stripe Atlas Vendor Leaked SSNs

#42

Earlier quoted context omitted.

How do you game it apart from stealing a phone? It may be easy to get another identity but that's a feature. If somebody commits a serious crime, the joined location of the phones will reveal the true identity unless somebody invests an amount of effort that's equal to buying a new passport.

I imagine sim swapping is a thing over there as well, maybe even easier to do than in the US.

So you get several identities. How do you game the system?

Intelligent agencies have failed to keep their phone usage cleanly separated. It's not that easy.

E.g. if you want to avoid progressive income taxes by registering several companies, your burner phone stands out because it doesn't have any other contacts. That will be further investigated.

Then you need the name of a living person who doesn't use a mobile phone to register it because otherwise, he would operate two phones at two different places. Another red flag.

Re: Stripe Atlas Vendor Leaked SSNs

#43
As more Social Security Numbers are leaked from security breaches like Equifax et al - I have done a deep dive into all things publicly known about SSNs and published the results on a hobby site (with limited ad revenue to cover the server cost) to both educate myself on the historic data contained in a social security number, how its usage has changed throughout the years (enumeration at birth in the 80's for example) and then how finally the state and date information was removed around 2009 so that numbers are now randomly assigned. For those born before the 2010 - there is a real information encoded (or deduced) from your number beyond what most are aware. If you are curious what types of information a hacker could deduce, or additional ways your SSN could be mis-used if disclosed (or guessed) take a gander at

https://numchk.com/

Re: Stripe Atlas Vendor Leaked SSNs

#44
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

I think we need a worldwide, federated identity system. There should be multiple identity providers, mostly governments and organizations who already have lots of info about you, for example banks. This already works in Poland and several other european countries. Such organizations should verify that you are you the way they currently do, and give you a way of authorizing yourself, i.e. sms, mobile app, one time pas…

If we had a worldwide, federated identity system, there's a problem with this I can already see: what's stopping nation's like China from expanding their social credit system to the population of the world then, against their will for example? For what purpose, I can't know, but it doesn't seem ideal.

On one hand, it would be incredibly useful to only ever have to deal with one service or standard for identities (and that could include the possibility of making things easier for identity theft products to do their job) but it brings with it these other risks around centralizing that kind of information.

Re: Stripe Atlas Vendor Leaked SSNs

#45

Earlier quoted context omitted.

I think we need a worldwide, federated identity system. There should be multiple identity providers, mostly governments and organizations who already have lots of info about you, for example banks. This already works in Poland and several other european countries. Such organizations should verify that you are you the way they currently do, and give you a way of authorizing yourself, i.e. sms, mobile app, one time pas…

If we had a worldwide, federated identity system, there's a problem with this I can already see: what's stopping nation's like China from expanding their social credit system to the population of the world then, against their will for example? For what purpose, I can't know, but it doesn't seem ideal. On one hand, it would be incredibly useful to only ever have to deal with one service or standard for identities (and…

China already has identities for most people in developed countries. Everyone reading this is already in their systems.

Re: Stripe Atlas Vendor Leaked SSNs

#46
post #26

Earlier quoted context omitted.

This is a terrible, TERRIBLE idea. Especially for people who move a lot. Phone numbers get reused. I am currently maintaining 4 SIM cards just to keep services relaying on them active. About 2 months ago I forgot to recharge one of those SIM cards and was locked out of one of my bank accounts.

Why don't you register all services with one SIM and use a Dual-SIM phone to get cheap rates on another card? Since we are talking about introducing a new identity system, isn't it easier to resolve the problems you mentioned than to introduce something new?

Because some services (banks) restrict phone numbers to only local (same country) ones.

Re: Stripe Atlas Vendor Leaked SSNs

#47
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

I think we need a worldwide, federated identity system. There should be multiple identity providers, mostly governments and organizations who already have lots of info about you, for example banks. This already works in Poland and several other european countries. Such organizations should verify that you are you the way they currently do, and give you a way of authorizing yourself, i.e. sms, mobile app, one time pas…

I would love it if emails were typically gathered by OIDC scope requests, and the provider would always provide an email address that could be traced to the audience. Something like mail@{ENC(sub + aud)}.oidcp.com.

Re: Stripe Atlas Vendor Leaked SSNs

#48
post #43

As more Social Security Numbers are leaked from security breaches like Equifax et al - I have done a deep dive into all things publicly known about SSNs and published the results on a hobby site (with limited ad revenue to cover the server cost) to both educate myself on the historic data contained in a social security number, how its usage has changed throughout the years (enumeration at birth in the 80's for exampl…

[deleted]

Re: Stripe Atlas Vendor Leaked SSNs

#49
post #4

I agree with https://twitter.com/constmontague/status/1213309357204688899 "... we need a new personal identifier, SSNs are all stolen at this point" Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead. The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (r…

SSNs are much too short, and were mostly issued in a foolish and predictable way (if you're a kid you might have a random SSN but most Americans still have ones issued the old way). Given the US plausible population load, issuing a randomly chosen 12 digit number incorporating a check digit would have been a better start. But the authentication problem is the tricky part though, governments don't have a reliable way…

The Netherlands has a digital government sign-in ("DigID") which works very well, secured using text messaging or 2 factor auth. With it you view all of your official documents across all branches of government. It allows for delegating permissions (say between a married couple). It's really great and shows that with competence these systems work out great.

Re: Stripe Atlas Vendor Leaked SSNs

#50
The problem with SSNs is how short they are. 9 digits.

Even if you hash them, it's not that hard to make a 10^10 - 1 rainbow table.

It's the same problem with IPs (v4). You simply cannot store them at all if you care about your customers' privacy.

Post reply on HN