Live data from Hacker News

2.9B hit in one of largest data breaches; full names and SSNs exposed

tomsguide.com

71–80 of 88 posts

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#71
post #44

Earlier quoted context omitted.

You freeze your credit by making an account on TransUnion, Experian, and Equifax's websites. It sucks, and they suck, but it's free. Unless you take out loans quite frequently, there's no reason not to do it. My credit has been frozen for years, and I only ever unfreeze it for a month or two at a time when I need to refinance a mortgage or something like that.

This is good as far as it goes, but what about all those times customer support for companies unrelated to your credit asks you for the last four of your SSN (birthrate, address, etc.) to confirm your identity?

I just write that stuff in my password manager.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#72

At what point can we start demanding that SSNs be redefined? I've lost track of how many data breaches I've unwittingly been the victim of, and I'm usually more careful and paranoid than most.

We "just" need to stop pretending they are secret like passwords and using them to authenticate that someone is who they say they are. Banks should not be issuing loans based on a bunch of personal information (including SSN) that the collected and concluded "Yup, that data matches itself--therefore you are actually you!"

They (the government and banks) still use the phone number to authenticate you. I would not be surprised if they consider using SSNs to issue loans, etc.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#73
"National Public Data" sounds like the name of a nonprofit with a nationwide presence, like NPR or PBS, but it's just the trade name for "Jerico Pictures," a small Florida company with (judging from Crunchbase) 1-10 employees. Shouldn't there be regulations for names like this, similar to how the National Bank Act controls the use of "National" in names of financial institutions?

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#74

"National Public Data" sounds like the name of a nonprofit with a nationwide presence, like NPR or PBS, but it's just the trade name for "Jerico Pictures," a small Florida company with (judging from Crunchbase) 1-10 employees. Shouldn't there be regulations for names like this, similar to how the National Bank Act controls the use of "National" in names of financial institutions?

Names like this are so exhausting. See "Patriot Act" and "Americans for Prosperity Action".

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#75
post #49

Earlier quoted context omitted.

No, they should sign you up for free Credit Monitoring for 7 years. All I would get is a letter stating something like this: "Your Credit is being monitored by firm xxxx, you will receive notices from them by Mail when items of concern are noticed" along with a real direct line phone number to call with questions. I should not have to do anything nor give any information. Why 7 years, that is equal to the Statue of L…

(It's a myth that there's an IRS 7 years 'statute of limitations'. It's far more nuanced than that: https://www.irs.gov/businesses/small-businesses-self-employe... ) However, it's still a reasonable time frame, and also, probably coincidentally, 7 years after the last update on any individual record is how long it will take to essentially reboot your U.S. credit report, so seven years sounds quite reasonable.

The time frame should (of course) match how long the information will remain valid.

And SSNs are for life aren't they?

So, it's not like the information is going to expire.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#76
post #18

Earlier quoted context omitted.

You don't get a check, you get a gift card for a credit monitoring service that you will never use because all your data leaks all the time already. Motherfuckers asked my wife her SSN when she was getting a store card the other week. Not a credit card, a store card.

What is a store card in that case, and how does it differ from credit card (other than, I assume, the place you apply)? The store cards I have seen are simply store-branded credit cards.

> What is a store card in that case, and how does it differ from credit card (other than, I assume, the place you apply)?

It's not a credit card, debit card, or any other kind of payment card. It's not even, like, a COSTCO membership card.

It's a tracking card that is used by the store to track your purchases in exchange for a small discount on some items if you swipe it at checkout.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#77
It wasn’t a data breach so much as the owner of this business allowing data fraud and identity theft to occur. The company is guilty of allowing this data theft through their business malpractices. They’re also guilty for having this data wholly in the first place. Punitive damages to bankrupt these companies are needed so that all industries get the message.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#78
post #34

Earlier quoted context omitted.

I had a pawn shop try to take my social to buy a air paint sprayer. They said it was a city ordinance. I left empty handed, even though I think SSN shouldn't be used as a password.

air paint sprayer seems innocuous, but given the problem of graffiti (no matter where you actually live), they likely weren't lying to you.

I said something like "really? for a paint sprayer?"

He said "for anything in the store."

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#79

At what point can we start demanding that SSNs be redefined? I've lost track of how many data breaches I've unwittingly been the victim of, and I'm usually more careful and paranoid than most.

We "just" need to stop pretending they are secret like passwords and using them to authenticate that someone is who they say they are. Banks should not be issuing loans based on a bunch of personal information (including SSN) that the collected and concluded "Yup, that data matches itself--therefore you are actually you!"

I have been arguing for a while that we need to implement some sort of public-key cryptography system for identity verification. It's the obvious solution, though admittedly implementing it will take a lot of effort. But it would at least eliminate a lot of issues with how SSNs are used in practice right now.

Re: 2.9B hit in one of largest data breaches; full names and SSNs exposed

#80
I think that there is potential bipartisan support (among voters, not representatives...) for federal privacy laws that institute heavy fines for leaking personal data based on median household income, as well as requiring chain of custody to be tracked for all personal data. Unfortunately, I don't think our representatives are very interested in implementing this for us.
Post reply on HN