Live data from Hacker News

2.9B hit in one of largest data breaches; full names and SSNs exposed

tomsguide.com

51–60 of 88 posts

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#52

I am not sure how to approach it anymore. Frankly, since equifax breach and settlement I mostly gave up on hoping for any real change[1]. Whatever the catalyst will be for a shake up, it clearly won't be another -- sufficiently big -- breach. I was too optimistic about that. It will need to be something public, scandalous and, ideally, affecting someone powerful enough to effect change and privacy-conscious enough to…

Ashley Maddison happened just under 10 years ago, that's as scandalous as it gets, and nobody cared either.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#53

I am not sure how to approach it anymore. Frankly, since equifax breach and settlement I mostly gave up on hoping for any real change[1]. Whatever the catalyst will be for a shake up, it clearly won't be another -- sufficiently big -- breach. I was too optimistic about that. It will need to be something public, scandalous and, ideally, affecting someone powerful enough to effect change and privacy-conscious enough to…

I'm with you on this. At this point the only thing I think that could happen to change the status quo is a full blown war against a country that's going to use hacked data against the United States in such a disruptive way that the legislators would have to react due to national security concerns.

I think the opposite is a lot more likely.

WHen it comes to it, the US gov has incredible leverage with the data they have access to. If they forced all the major tech companies to release everything they have on the most powerful politicians of some country, including email contents, text messages, full search and location history and so on, they could cause quite a scandal.

You can probably overthrow quite a few governments with a judicious use of that power alone.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#54
post #39
post #21

Earlier quoted context omitted.

Here's a fun thought experiment. How much should National Public Data have to pay the people affected by this breach? The article says there are 2.9 billion people impacted. Let's take that at face value and assume that there are no duplicates in there. How much should each person receive? The article also says that USDoD tried to sell the data for only $3.5 million, so they value it at roughly $830/person. Now, in c…

I don’t want their $3 or even $3000, if I am eligible for payout. Instead, I’d like to force this company (and others similarly) to put all kinds of precautions in place. Also warn them that the next breach would result in severe penalties, assuming they could’ve prevented the breach in the first place.

I would rather put these clowns out of business, as they obviously can't be trusted in the first place, and are undeserving of a second chance after causing one of the largest leaks of PII in history. They should not have an option of paying a fine, putting in whatever "mitigating controls" a useless audit lets them skirt by with, and continuing business serving our data they never should have been allowed to posses in the first place.

Where do these scumbags even begin to get this information on every human's most intimate data, and what allows them to operate as a trusted source of protecting this information?

I also want to know who does their audits, and who regulates them?

It is unbelievable organizations can appoint themselves resellers of OUR information without any of us even knowing who they are or how many there are.

This is an industry the FTC should be involved in regulating heavily. Lina Khan always needs a new degenerate company to kick around, let's start with these guys.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#56

At what point can we start demanding that SSNs be redefined? I've lost track of how many data breaches I've unwittingly been the victim of, and I'm usually more careful and paranoid than most.

We "just" need to stop pretending they are secret like passwords and using them to authenticate that someone is who they say they are. Banks should not be issuing loans based on a bunch of personal information (including SSN) that the collected and concluded "Yup, that data matches itself--therefore you are actually you!"

The whole system is broken in hilarious ways.

Unrelated but similar: I live in a rural area, so we don't get street delivery of mail. Instead, we need to apply for a PO Box. Every year, to verify that only residents are using the PO Boxes, the Post Office sends out a renewal form, and you have to show up with a current bill and your driver's license. The latter makes sense—the State, presumably, goes through the validation of your address, and you sign their forms under penalty of perjury, etc., the the former is hilarious.

So, to receive the very bill used to authenticate "current residency," the bill has to go through the Post Office (remember what I said about no street delivery? anything that's mailed to our street address goes... to our PO Box!), and then we show it to them to validate that we are receiving email to that address—which cannot be independently validated outside the driver's license.

The PO Box we're renewing is therefore used to validate itself. And the fun part is that if you delay in returning the form, they'll block off your box.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#57

At what point can we start demanding that SSNs be redefined? I've lost track of how many data breaches I've unwittingly been the victim of, and I'm usually more careful and paranoid than most.

SSNs have always been clear that they’re identifiers, not authenticators - it’s printed on the card! The problem are the businesses who tried to skimp by treating them as secrets, and they invented the mainstream concept of identity theft to make it sound like their negligence should be your problem.

The fix should be simple: stop taking companies seriously when they only used an SSN for authentication. Ideally there’d be a law adding penalties: try to bill someone for a loan authenticated only by common metadata and they have to pay the target a penalty fine, allow insurers to deny claims, etc. As soon as it costs them money, they’d suddenly find the money to check ID like everyone else.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#58
post #49
post #21

Earlier quoted context omitted.

Here's a fun thought experiment. How much should National Public Data have to pay the people affected by this breach? The article says there are 2.9 billion people impacted. Let's take that at face value and assume that there are no duplicates in there. How much should each person receive? The article also says that USDoD tried to sell the data for only $3.5 million, so they value it at roughly $830/person. Now, in c…

No, they should sign you up for free Credit Monitoring for 7 years. All I would get is a letter stating something like this: "Your Credit is being monitored by firm xxxx, you will receive notices from them by Mail when items of concern are noticed" along with a real direct line phone number to call with questions. I should not have to do anything nor give any information. Why 7 years, that is equal to the Statue of L…

(It's a myth that there's an IRS 7 years 'statute of limitations'. It's far more nuanced than that: https://www.irs.gov/businesses/small-businesses-self-employe... )

However, it's still a reasonable time frame, and also, probably coincidentally, 7 years after the last update on any individual record is how long it will take to essentially reboot your U.S. credit report, so seven years sounds quite reasonable.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#59

Earlier quoted context omitted.

We "just" need to stop pretending they are secret like passwords and using them to authenticate that someone is who they say they are. Banks should not be issuing loans based on a bunch of personal information (including SSN) that the collected and concluded "Yup, that data matches itself--therefore you are actually you!"

Is there some reason my bank needs this information in the first place? I want them to verify that I am the owner of the account, I do NOT need them to verify my precise federal identity.

They are legally required to know your identity and, I believe, report interest to the IRS. If they don’t check your government ID, they’ll be popular with organized crime.

Now, I’m sure banks also love that for data mining purposes but it’s not entirely without a valid reason.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#60
post #34
post #18

Earlier quoted context omitted.

You don't get a check, you get a gift card for a credit monitoring service that you will never use because all your data leaks all the time already. Motherfuckers asked my wife her SSN when she was getting a store card the other week. Not a credit card, a store card.

I had a pawn shop try to take my social to buy a air paint sprayer. They said it was a city ordinance. I left empty handed, even though I think SSN shouldn't be used as a password.

air paint sprayer seems innocuous, but given the problem of graffiti (no matter where you actually live), they likely weren't lying to you.
Post reply on HN