19 ms·
Why are identifiers being treated as passwords? It's 2017 and my mind is boggled that we continue to use SSNs and thumbprints as passwords. These are more akin
by chrisabrams 9y ago
Why are identifiers being treated as passwords? It's 2017 and my mind is boggled that we continue to use SSNs and thumbprints as passwords. These are more akin to usernames. Why is our most important information not protected by passwords, or better yet, 2 factor authentication?
If I try to spend $1000 on my credit card at IKEA, my bank usually calls me to confirm the transaction. However, we don't have such a system when handling our most important information? Why is this allowed to happen? How many people have to be damaged before they stop watching Tom Brady throw touchdowns and get out there to make a difference?
- emodendroket 9y agoFixing it costs them more money than leaving it alone, is the reason.
- knz 9y ago> If I try to spend $1000 on my credit card at IKEA, my bank usually calls me to confirm the transaction. However, we don't have such a system when handling our most important information? Why is this allowed to happen? It's allowed to happen for the same reason the US uses credit cards without PIN numbers - a lack of desire to spend money on security/upgrades (it's easier to pass on the cost of fraud via the transaction fees), a weak regulatory structure for protecting consumers, a glacial rate of technology adoption in banking systems, and ignorance/unwillingness to evolve by customers/businesses/executives etc.
- skybrian 9y agoAt least we have cards with chips in them now, so there's some movement on this. Maybe gas stations will have them by 2020.
- gambiting 9y agoEven if they have newer terminals, they are still going to accept signature, so essentially there's zero security. The only way forward is to stop accepting the magnetic strip + signature altogether.
- a-priori 9y agoAre you sure about this? In Canada we've had chip-and-PIN for almost a decade now (2009 I believe?), and almost all merchants have chip-capable POS terminals. (Yes, really! I don't know what the delay is in the US.) These terminals still have a mag stripe reader, and our cards have mag stripes as well. But they're just for compatibility: if you try to use the mag stripe of a chip-capable card on a chip-capable terminal, it beeps at your angrily and tells you to use the chip.
- gambiting 9y agoYeah, and you just put some paint over the chip, it will beep 3 times and then let you use the signature, even for cards which are marked "electronic use only". It's a failsafe for situations when the chip is genuinely damaged, the terminal lets you sign for the transaction.
- redblacktree 9y agoWhy would you want to disable the chip?
- gambiting 9y agoI wouldn't - I'm saying someone can trivially damage the chip on a stolen card and just use the mag stripe and signature instead.
- redblacktree 9y agoAh, I get it. Thanks for the explanation.
- nucleardog 9y agoMy interac card doesn't - if the chip fails the terminal will occasionally tell me to use the magstripe but the transaction is always declined.
- 9y ago
- _jal 9y agoThe chip implementation in the US provides zero incremental security. It was done as part of a liability struggle between shops and credit card providers, not to improve your life.
- snuxoll 9y agoI wouldn't say it provides NO incremental security, EMV defeats skimmers which is a pretty big issue - but until everywhere has it deployed and magstrips are no more we're still in a phase where the benefits are partial at best.
- _jal 9y ago> and magstrips are no more There is zero incremental security because of this. Why pick the lock on the door when the window is open?
- skybrian 9y agoSigh. You have to deploy the new stuff before getting rid of the old stuff. If everyone had this impatient attitude, instead of taking many years to improve credit card security it wouldn't happen at all.
- _jal 9y agoI don't know what to do with comments like this. I made a statement of fact. I'm making no normative claims, I'm describing reality. At this point in time, there is zero additional security provided by the implementation. Am I supposed to ignore reality and lie about it, because someday things will be better?
- cma 9y agoThere are already less skim targets as some stores only accept chip.
- nickbauman 9y agochips have just become another salvo in an arms race between merchants/consumers and fraudsters. A chip card is more prized than a non-chip card so the rewards for capturing one is higher so more work is justified in cracking into one.
- masklinn 9y agoDon't forget the odd US anti-fed/anti-state bend which led to your identity being smeared across thousands of untrustable private companies linked through a something never originally intended as an identification token (SSN) but having become done so for the sole reason of being nigh-universal. Had the US implemented a proper citizen's registry it could be managed as that with all the security and personal details isolation that entails, including but not limited to biometric and chipped ID cards.
- agentdrtran 9y agoThe US cannot implement a proper registry, large sections of the country would freak out.
- dforrestwilson 9y agoInteresting. What sections?
- querulous 9y agoevangelicals. they believe any sort of government issued identifier is synonymous with the biblical 'number of the beast' and a step towards biblical armageddon
- michel-slm 9y agodon't forget libertarians too.
- microcolonel 9y agoThe sane. Frankly people who use this kind of language to insist that the only way to achieve this is through the state are just looking for excuses to be mean to people who don't trust the state. We've had public key infrastructure for a long time, we have also had legal attestation; the reason we don't use these things to secure this information is that nobody cares. When the state does it, you get breaches, but nobody gets all that upset. Just look at what happened with the data breach and subsequent coverup in Sweden. One person had half a month's salary docked, and that was it.
- calvinbhai 9y agoCost of repercussions due to lapse of security <<< cost of fixing it. Until Equifax and the like get sued out of business, Equifax and its shareholders won't feel the heat.
- zentiggr 9y agoTime for the class action suit to dwarf all other class actions... liquefy Equifax and turn its assets over to the 143 million.
- _jal 9y agoDon't fall for the "credit monitoring" bait they're offering then - accepting it nullifies your class-action rights.
- mlrtime 9y agoThe monitoring benefits (Do to their negligence) is probably worth more than the $10 you'll get out of the CAS. It would be better if we could get the monitoring from one of their competitors on Equifax's dime.
- xraystyle 9y ago"Worth more" in the sense that they probably charge more for it, but I doubt it would cost Equifax as much to provide that service as it would if they actually were forced to cough up real money. They've already built out the infrastructure necessary for the monitoring product. The marginal cost of every additional person they add to it is probably quite low.
- actsasbuffoon 9y agoI bet the other two credit bureaus would be much more careful about security if that happened.
- ConceptJunkie 9y agoAnd as is the case for every class action suit ever, some lawyers make a lot of money and everybody whose information was compromised by Equifax gets a check for 24 cents.
- mafellows 9y agoIn fairness, Tom Brady had zero touchdowns last night.
- ddlatham 9y agoBecause it's not a simple problem. If you ask me for a loan, how do I know who I'm loaning the money to, who will be accountable for paying it back to me? If we have no prior relationship, then there's no pre-existing password I can use to authenticate you. What's your solution? A government provided security token of some sort, backed by a government database? A lot of people have all kinds of problems with those, from trusting government's intent, to their competency, to their security. A private party identity provider? Go start it.
- burntrelish1273 9y agoJust like bikeshedding and risk perception decreasing near sources of catastrophic risk, never discount the powers of rationalization and cognitive dissonance. Ultimately a major cause is that America doesn't have a national ID, PKI or 2FA systems. And, as such, there is the de-facto, cargo-cult tradition of ultimate reliance on inadequate systems designed for retirement pensions and drivers' licenses. People must give up the "states rights," delusions of privacy and other similar fallacies already and demand proper authenticated and authorized identity, banking and credit systems that require positive, possibly-interactive authorization to use details or complete transactions. Such tokens/documents could be physically enrolled/administered just like passports at USPS.
- deleted 9y ago[deleted]
- michel-slm 9y agoSSNs are not even supposed to be used as identifiers in the first place -- that it is being used as the key identifier to determine your creditworthiness is already mind-boggling.
- GuB-42 9y agoThat's because the US government doesn't provide a convenient and reliable way of proving physical identity. And that's mostly because the people don't want it. Most countries have some form of universal photo ID, and a copy of it is usually required, along with a signature that matches. Not perfect but better than a simple number. Some countries like Estonia include a cryptographic token in their ID, protected by a PIN. That's the 2 factor security you wanted. But people in the US tend not to like the idea of government IDs. But when such a thing is needed, they use the closest thing they have, and that's the SSN.
- mindcrime 9y agoThat's because the US government doesn't provide a convenient and reliable way of proving physical identity. And that's a Good Thing. Government should exist to protect property rights, provide rule of law, and maybe to enforce contracts. Managing everyone's identity is clearly not something that the State should be involved in.
- wyager 9y agoAgreed. Any company worth its salt should allow me to authenticate myself purely cryptographically if I want to do so. This is easier, more secure, and more human-friendly than a centralized government ID registry. Unfortunately, most companies aren't worth their salt.
- spiralpolitik 9y agoHow do you enforce such things without being able to identify and validate that the parties in the dispute are who they say they are ? Example how do you make sure that the crime ends up being recorded against the right John Smith ? The US government actually does have a a convenient and reliable way of proving physical identity (a Green Card for example serves the purpose of identifying permanent residents), they've just declined to deploy it more widely.
- Amezarak 9y agoUS citizens can legally exist without any government identification or documentation whatsoever - no SSN, no birth certificate, no driver's license, no state ID, no nothing. It deals with them the way the government dealt with such cases before government identification ever existed - who do you say you are, and who do other people say you are? Where do you and other people say you live? In your example, in the modern age, "John Smith" would have an arrest mugshot to aid with identification. Whatever criminal records are kept would probably just have the missing information blank. It's not as if there's a big database of citizens with Felon? Y/N as one of the fields, making you run the risk of marking the wrong John Smith as a felon. The world is a very messy place - the US system does an okay job of treating it as one.
- quarkral 9y agoHow would you implement 2FA without making your personal phone number publicly available for anyone to attempt to authenticate with? It's not the same as your bank calling you when you already have an account with them - we're talking about a new bank, who you have no relationship with, trying to call you to verify your identity. A true public key system opens up each individual user to malicious spam. Given the current prevalence of phone, mail, and email spammers, such a system would create more problems than solve. SSNs could technically be passwords. The problem then is that data servers need to not store SSNs in plaintext, but rather store hashes of them, just like passwords should not be stored in plaintext.