Live data from Hacker News

No, I did not hack your MS Exchange server

krebsonsecurity.com

61–70 of 74 posts

Re: No, I did not hack your MS Exchange server

#61

That's exactly what someone who did hack my server would say.

No its not. Why on earth would someone hack you, tell you their name and then deny it later. Why not either own it or never share it?

We're not talking about the "tell you their name" part, we're talking about the denial specifically.

Re: No, I did not hack your MS Exchange server

#62

thoughts specific to SSN: Seems like the SSA will will run out of 9-digit usable numbers in about 1 generation (~70 years). Then what ? Is this software's next Y2K ? https://www.quora.com/Why-havent-we-run-out-of-Social-Securi...

There would need to be a billion people in the US for us to run out of SSNs. I find it highly unlikely that our population will triple in 70 years. The Census Bureau finds it unlikely, too, considering they expect us to add only 76m by 2060. They could also decide to re-use the SSNs of those who have been dead for decades.

> They could also decide to re-use the SSNs of those who have been dead for decades.

That will definitely NOT cause a new bunch of issues!

Re: No, I did not hack your MS Exchange server

#63
post #15

Earlier quoted context omitted.

The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…

I live in Denmark so also Europe. Our social security number (which can be guessed with enough information and a few tries) has been incorrectly used as a password instead of a key just like you describe. You make a call, provide this number and the clerk on the phone believes that you are who you claim to be. Nowadays things are better because computers are used everywhere We have a national ID system using 2FA whic…

Ditto in Finland. Just like in Denmark, the social security number is being used for authentication by some actors, even though it's inherently insecure to do so. The Swedish way of handling those numbers seems more reasonable; they're just used as unique identifiers and you still need to show some other kind of ID.

When I lived in Denmark, airlines occasionally did identity spot checks on domestic flights. I was always horrified to notice that everyone just pulled up (picture-less) social security cards and used them as identification.

Re: No, I did not hack your MS Exchange server

#64
post #25

Earlier quoted context omitted.

It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.

The story of how this happened is quite interesting. CGP Grey did a video about how it evolved [0]. I'm not American so I can't judge how likely it is to ever change because it seems to be politically radioactive to propose a government mandated ID. We had a similar issue in Australia, but our workaround is that your drivers license (or ID card from the equivalent of the DMV) typically acts as your ID. [0] https://ww…

We have in France ID Cards that are not compulsory. It is just such a hassle to use something else that everyone has one.

Alternatively, for minor things, you can make a declaration on your honor. This is super useful in, say, a library where you need to enroll.

Re: No, I did not hack your MS Exchange server

#65
post #17

Earlier quoted context omitted.

US Social Security cards used to say "NOT FOR IDENTIFICATION" but I guess it's just too hard to pass up a good primary key.

When I was first enrolled at University of Illinois of Chicago in 1985, your SSN was your student ID. You could log in to the mainframe using your SSN in the username field (although thankfully, the actual user ID was a sequentially assigned five-digit number and not the SSN. I was U10754). I think around 1986 or 1987, universities were instructed to stop using SSNs as student ID numbers.

My university (back in the early 2000s) used your initials and last 4 of SSN as your student ID number. I think they finally stopped a year or two after I graduated.

Re: No, I did not hack your MS Exchange server

#67
post #60

Earlier quoted context omitted.

When your identity gets stolen enough times, the IRS assigns you an identity protection PIN and mails you a new one every year. Too bad it's only useful for your taxes.

Just the fact that there is a process for that, and you have people whose "identity gets stolen enough times", is worth an Onion headline...

The thieves filed a fake tax return in my name so they could steal the refund. The IRS takes that stuff pretty seriously, fortunately.

Re: No, I did not hack your MS Exchange server

#68

Earlier quoted context omitted.

I thought for quite awhile that the whole list should be made public on a pre-announced date to "scorch the earth". On that date, liability for any fraud committed using the data would be placed on the party improperly using SSNs for authentication tokens. The Equifax breach did the publishing part, but nothing changed with liability. A golden opportunity missed to fix this particular bullshit.

100% agree with this. Our SSNs are fully “compromised” many times over at this point. Scare quotes because—as far as I know—they weren’t originally regarded as a secret to begin with. But the fiction of a secret SSN still persists. You're told to protect it; sensitive financial documents ask for it as part of proving you’re you; forgotten password pages use the last 4 digits as some sort of 2nd factor. The best thing…

I was required to write my SSN on all my checks and had to use it to get food in the chow hall whilst in the military. It was a very public number.

Re: No, I did not hack your MS Exchange server

#69

Earlier quoted context omitted.

100% agree with this. Our SSNs are fully “compromised” many times over at this point. Scare quotes because—as far as I know—they weren’t originally regarded as a secret to begin with. But the fiction of a secret SSN still persists. You're told to protect it; sensitive financial documents ask for it as part of proving you’re you; forgotten password pages use the last 4 digits as some sort of 2nd factor. The best thing…

I was required to write my SSN on all my checks and had to use it to get food in the chow hall whilst in the military. It was a very public number.

Ha, you just reminded me of my student ID number in college. Also used to purchase snacks and meals at the commons. In the strangest of coincidences, it was my SSN.

Re: No, I did not hack your MS Exchange server

#70
post #59

Earlier quoted context omitted.

It’s not just direct carers and it’s still an identity theft, what identity theft can be used for ranges between different countries based on financial incentives in some countries getting a loan or credit is far more easier than others in others state pensions and benefits are higher. In the US stealing the identity of a 30 year old with decent credit can allow you to rack up a decent bill in their name. In Italy th…

No, it's identity fraud which is a superset of identity theft.

All identity theft is fraud... you are grasping at straws here.
Post reply on HN