Live data from Hacker News

2.9B hit in one of largest data breaches; full names and SSNs exposed

tomsguide.com

41–50 of 88 posts

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#42

At what point can we start demanding that SSNs be redefined? I've lost track of how many data breaches I've unwittingly been the victim of, and I'm usually more careful and paranoid than most.

We "just" need to stop pretending they are secret like passwords and using them to authenticate that someone is who they say they are. Banks should not be issuing loans based on a bunch of personal information (including SSN) that the collected and concluded "Yup, that data matches itself--therefore you are actually you!"

Is there some reason my bank needs this information in the first place? I want them to verify that I am the owner of the account, I do NOT need them to verify my precise federal identity.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#44

When can we move away from SSNs being a pseudo secret? They have obviously been leaked everywhere at this point. Relatedly, is there an up to date guide on how I am supposed to freeze my credit? Last I looked, it required handing over all of my PII, which I found super distasteful, but I should accept none of it is secret and do the minimum to protect myself from ~financial institutions falling for fraud~ identity th…

You freeze your credit by making an account on TransUnion, Experian, and Equifax's websites. It sucks, and they suck, but it's free. Unless you take out loans quite frequently, there's no reason not to do it. My credit has been frozen for years, and I only ever unfreeze it for a month or two at a time when I need to refinance a mortgage or something like that.

This is good as far as it goes, but what about all those times customer support for companies unrelated to your credit asks you for the last four of your SSN (birthrate, address, etc.) to confirm your identity?

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#45

It's amazing to me how just getting your name and SSN leaked opens you up to much risk. It's equally amazing how this is a decades-long problem that hasn't been addressed. I have to wonder what systems other countries use for identifying citizens and how secure they are compared to SSNs.

In Poland you have a national ID card you carry with you if you don't have it with you won't get anything done anywhere. If you lose it/it gets stolen you have an obligation to report it. We have something like SSN number (personal id number) assigned at birth but it's not enough to get a loan or anything.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#46

At what point can we start demanding that SSNs be redefined? I've lost track of how many data breaches I've unwittingly been the victim of, and I'm usually more careful and paranoid than most.

I'd love to see the government force companies to stop treating them like an ID number that's secret.

Maybe they should allow people to request a new number any time they wish and even hold multiple SSNs. Or create a virtual number system like some credit cards have where you would give every company that asks for a SSN a unique number that only they have. It would be cool to be able to tell exactly who had the data breach when your number shows up in a dump.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#47
post #21
post #3

>As reported by Bloomberg, news of this massive new data breach was revealed as part of a class action lawsuit that was filed at the beginning of this month. I am so looking forward to getting my 2.99 USD check from this suit. Of course I need to apply for that check via an on-line site and give them all my personal information. Great time to be alive.

Here's a fun thought experiment. How much should National Public Data have to pay the people affected by this breach? The article says there are 2.9 billion people impacted. Let's take that at face value and assume that there are no duplicates in there. How much should each person receive? The article also says that USDoD tried to sell the data for only $3.5 million, so they value it at roughly $830/person. Now, in c…

A fun thought experiment: the company loses the suit, with both actual damages and punitive damages large enough to bankrupt the company. The company is sold for parts and other companies become a little more wary of repeating the same mistakes (hopefully better security around their core business value).

This suit opens the company to discovery in which several jurisdictions get access to their books and methods, opening them up to litigation and prosecution in places like the EU.

The $2.99 check is not the only benefit I get from a class-action lawsuit.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#48

At what point can we start demanding that SSNs be redefined? I've lost track of how many data breaches I've unwittingly been the victim of, and I'm usually more careful and paranoid than most.

I'm more and more convinced that the only way to do this is the "Swedish way", make all SSNs public and/or available on request.

Until that happens, companies will still pretend they're private information.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#49
post #21
post #3

>As reported by Bloomberg, news of this massive new data breach was revealed as part of a class action lawsuit that was filed at the beginning of this month. I am so looking forward to getting my 2.99 USD check from this suit. Of course I need to apply for that check via an on-line site and give them all my personal information. Great time to be alive.

Here's a fun thought experiment. How much should National Public Data have to pay the people affected by this breach? The article says there are 2.9 billion people impacted. Let's take that at face value and assume that there are no duplicates in there. How much should each person receive? The article also says that USDoD tried to sell the data for only $3.5 million, so they value it at roughly $830/person. Now, in c…

No, they should sign you up for free Credit Monitoring for 7 years. All I would get is a letter stating something like this: "Your Credit is being monitored by firm xxxx, you will receive notices from them by Mail when items of concern are noticed" along with a real direct line phone number to call with questions.

I should not have to do anything nor give any information. Why 7 years, that is equal to the Statue of Limitations for saving US Tax Documents.

That alone will end these breaches almost over night.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#50

It's amazing to me how just getting your name and SSN leaked opens you up to much risk. It's equally amazing how this is a decades-long problem that hasn't been addressed. I have to wonder what systems other countries use for identifying citizens and how secure they are compared to SSNs.

In Finland banks are the ones who usually handle the strong authentication (not necessarily just the initial one). They are required by law to know the customer. In-person authentication in the branch is required to be done via either ID card or passport, those can be requested from police and expire after 5 years. Driver's license is not official ID card. Logging into you bank account requires 2FA (I'm not sure if any bank sends codes via text messages, at least it's not very common).

It can also be done with ID card (which is a smartcard) or mobile certificate (https://mobiilivarmenne.fi/en/) if the service supports it.

Post reply on HN