40 ms·
I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private
by fps 11y ago
I think the bigger problem is that public information like your name and address is sufficient for proving your identity. If we make whois information private, what about phone books, property records, direct mail databases, etc. etc.
- VeilEm 11y agoIf someone has your public name and address you're already at significant risk if you ever say anything controversial that gets attention. You're liable to being swatted, getting fake pizza orders, having people show up at your house, harassing you and much more. See Zoe Quinn, Brian Krebs, lots of less well known individuals, etc.
- thephyber 11y agoWhich only proves your comment's parent's point even more. {SWAT, pizza orders, etc} assume that the phone number that shows up on caller ID is authentication of the identity of the phone line on the other end. They could call back the number on caller ID to verify the original caller matched the person who picked up, but they don't. Having knowledge of a Social Security number was assumed to be authentication, but it's increasingly obvious that such an authentication scheme is antiquated and was destined to fail from the beginning. When an identity thief can get a mortgage under my name with little more than credit bureau data on me, it costs only a little more than $15 to destroy my credit, my time, and my future because transactions don't have sufficient authentication. These awfully designed authentication schemes will only magnify the problems as more companies (especially credit bureaus and data marketers) pass around data on me and make it easier for someone to buy it on demand.
- bigiain 11y agoKeep in mind too that Caller ID is trivially blockable (and blocked caller id isn't remarkable enough to be super suspicious), and it's also easily within the capability of many of the 4chan/gg griefers to spoof "correct" Caller ID numbers as well.
- hollerith 11y agoBy "gg" you mean what? Gamer gate?
- Karunamon 11y agoI assume so. The "gamergate are women-hating harassers" misconception is still alive and well.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- XorNot 11y agoCaller ID shouldn't be blockable, these days. It's a big ridiculous problem that we've defaulted to "you can intrude with communications anonymously" - and phone calls are definitely intrusive. I'm pretty much a hair away from blocking all calls without caller ID at my house so I can reliably lock out the remaining spam callers.
- rplnt 11y agoNot that I order pizza more than once a few months, but I would probably switch the pizza place that would call back to confirm order each time.
- the_ancient 11y ago>Having knowledge of a Social Security number was assumed to be authentication No the people that designed and implemented Social Security knew it was not secure for identification purposes, the first few decades of the program even had "Not to be used for Identification" on the card. Then the government, and financial industry got lazy and said "well since the majority of people already have these numbers assigned to them lets just use them for Identification as well" and made it a defacto National ID. Something it was never designed for, nor secure enough to be,
- TeMPOraL 11y agoAs a counterpoint, see billions of people every day. This is getting to the point of paranoia at this point. You're already at significant risk if you ever say anything that gets attention by virtue of living in a society. But it comes with benefits, too...
- ams6110 11y agoAgree. Your contact info in whois adds little to any number of other public records that will contain your name, address, phone number. It does make good sense to not use your primary "personal" email address in whois, nor your home address. PO Box rentals are fairly cheap and that's what I use for whois registrations.
- detaro 11y agoSadly, you can't even use PO boxes for all domains, some registries require a "full" address.
- bigiain 11y ago"The street finds its own uses for things." Where I am (Australia) theres a whole bunch of places that'll provide "non Post Office PO boxes" who're perfectly happy for you to address things to "Suite 306" or "Apartment 306" as well as "PO Box 306" at whatever address the box is located. Fools _most_ of the "must be a real address, not a PO Box" restrictions. (Interestingly StartSSL failed me on that once when I gave one of those as a personal address - they mailed me saying "that looks like a business address, we need a personal home address for personal identity validation") - I dunno of they Google Street-viewed it or of they've got some automated system that flagged it...)
- MaikuMori 11y agoMost likely more than x accounts used the same address.
- DrScump 11y agoUSA is a little different. To get mail using the street address of the PO, boxholders have to sign an additional agreement, BUT: 1) it's free, and 2) they will also accept UPS/FedEx/DHL/etc shipments on your behalf for no charge! (they will sign for packages, but if "Direct" signature (the named recipient) is required, they can't accept those.) If you just try using "UNIT #" or "APT #" or whatever, or you don't have this additional agreement signed, they can and will return to sender.
- akerro 11y agohttps://news.ycombinator.com/item?id=7525198 https://news.ycombinator.com/item?id=7525198 His daughter was also attacked...
- Your_Creator 11y agoIt's not just about proving who is who, it can also be about wanting to distance yourself from random people and their nonsense problems.