Live data from Hacker News

2.9B hit in one of largest data breaches; full names and SSNs exposed

tomsguide.com

61–70 of 88 posts

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#61

It's amazing to me how just getting your name and SSN leaked opens you up to much risk. It's equally amazing how this is a decades-long problem that hasn't been addressed. I have to wonder what systems other countries use for identifying citizens and how secure they are compared to SSNs.

The problem isn’t the SSN but corporate responsibility shirking: they don’t want to check ID because that costs more, they want things like instant credit applications to allow impulse purchases, etc.

This seems to slowly be improving because so many people have been breached by now that they don’t enjoy the assumption of security. In the 90s, if they took you to court saying you weren’t paying a loan it’d be assumed that a crook wouldn’t have known your SSN but now it’s at least a lot more likely that nobody will believe that without additional proof.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#62
post #21
post #3

>As reported by Bloomberg, news of this massive new data breach was revealed as part of a class action lawsuit that was filed at the beginning of this month. I am so looking forward to getting my 2.99 USD check from this suit. Of course I need to apply for that check via an on-line site and give them all my personal information. Great time to be alive.

Here's a fun thought experiment. How much should National Public Data have to pay the people affected by this breach? The article says there are 2.9 billion people impacted. Let's take that at face value and assume that there are no duplicates in there. How much should each person receive? The article also says that USDoD tried to sell the data for only $3.5 million, so they value it at roughly $830/person. Now, in c…

Only 450 million SSNs have been assigned (and only 1 billion are theoretically possible...)

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#64
post #30
post #24

Earlier quoted context omitted.

> The article also says that USDoD tried to sell the data for only $3.5 million, so they value it at roughly $830/person. When I divide 3,500,000 USD by 2,900,000,000 people, I get $0.0012/person. How do you get $830/person?

I think it was suppose to be 830 persons / $1.

It was supposed to be 830 persons per dollar.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#65

It's amazing to me how just getting your name and SSN leaked opens you up to much risk. It's equally amazing how this is a decades-long problem that hasn't been addressed. I have to wonder what systems other countries use for identifying citizens and how secure they are compared to SSNs.

Usually an identity card. In the EU this is an authentication mean but in order to be liable you must be present with the card at transaction time (i.e. a scan is not enough).

Then you have solutions of increasing robustness such as certificates for e-signature.

The national "id" (of there is one) is just to make it easier to find you. Poland has one, France does not have any for instance.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#66
post #3

>As reported by Bloomberg, news of this massive new data breach was revealed as part of a class action lawsuit that was filed at the beginning of this month. I am so looking forward to getting my 2.99 USD check from this suit. Of course I need to apply for that check via an on-line site and give them all my personal information. Great time to be alive.

[deleted]

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#67
post #39

Earlier quoted context omitted.

I don’t want their $3 or even $3000, if I am eligible for payout. Instead, I’d like to force this company (and others similarly) to put all kinds of precautions in place. Also warn them that the next breach would result in severe penalties, assuming they could’ve prevented the breach in the first place.

I would rather put these clowns out of business, as they obviously can't be trusted in the first place, and are undeserving of a second chance after causing one of the largest leaks of PII in history. They should not have an option of paying a fine, putting in whatever "mitigating controls" a useless audit lets them skirt by with, and continuing business serving our data they never should have been allowed to posses…

There is a big effort from people like Reid Hoffman to get rid of Lina Khan. Hopefully it fails.

Yeah, I suppose just shutting them down is a better idea. In that case, we also need to make sure they don’t pop up with a different name and do the same thing all over again

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#68
post #59

Earlier quoted context omitted.

Is there some reason my bank needs this information in the first place? I want them to verify that I am the owner of the account, I do NOT need them to verify my precise federal identity.

They are legally required to know your identity and, I believe, report interest to the IRS. If they don’t check your government ID, they’ll be popular with organized crime. Now, I’m sure banks also love that for data mining purposes but it’s not entirely without a valid reason.

This is so the IRS can keep track of the $15.40 of interest I earned on savings?

What mechanism causes KYC/ID checks to make banks unusable to organized crime? What purpose was organized crime using banks for? Is the government unable to get search warrants for bank accounts?

These are probably not what most people would consider valid reasons. The problems created outweigh the value of the solution.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#69
post #59

Earlier quoted context omitted.

They are legally required to know your identity and, I believe, report interest to the IRS. If they don’t check your government ID, they’ll be popular with organized crime. Now, I’m sure banks also love that for data mining purposes but it’s not entirely without a valid reason.

This is so the IRS can keep track of the $15.40 of interest I earned on savings? What mechanism causes KYC/ID checks to make banks unusable to organized crime? What purpose was organized crime using banks for? Is the government unable to get search warrants for bank accounts? These are probably not what most people would consider valid reasons. The problems created outweigh the value of the solution.

They're less interested in things like verifying your couple dollars of interest and more interested in things like money laundering and identifying assets to seize. Particularly setting money limits leads to what is known as "smurfing" to try to hide the activity. Not that I'm saying you must therefore consider these reasons good enough but throwing out strawment like a couple dollars interest is not highlighting what you'd like it to.
Post reply on HN