7 ms·
> SSN and DOB data is widely available for sale in the cybercrime underground on almost all U.S. citizens. This has been the reality for years, and was so well
by fhinson 8y ago
> SSN and DOB data is widely available for sale in the cybercrime underground on almost all U.S. citizens. This has been the reality for years, and was so well before Equifax announced its big 2017 breach.
Again, I find that this only reinforces the fact that SSNs are not a useful identification system because there's nothing secure about them. Can someone explain where attackers obtain SSN/DOB data with such a widespread success rate?
- ryanlol 8y agoAccurint is a big one. The people selling SSN lookups have big DB collections, but the primary source tends be realtime access to DBs like these. I'd imagine it's trivial to pretend to be a cop and just purchase access to this stuff, not that it's going to be hard to hack most police departments either.
- rlucas 8y agoHaving looked at getting Accurint and Clear back in 2013, I can tell you the process is not trivial but not comforting either. On the non-trivial side: I was doing a startup where we sublet from a law firm. We had an on-site audit by someone who came in and we were cautioned that we had to have an independently locking door on our office. We also had to give a reasonably thorough explanation of what we wanted to do with the data and certify, as well as convince the auditor, that we would be using it for GLBA (anti-fraud in financial transactions) purposes. We actually failed one of the audits the first time because some paperwork wasn't in place (I think we had changed the Delaware company name and not re-filed something, like our local jurisdiction foreign corporate registration, in the new name). On the not comforting side: the sales reps for these products have full access and will let you do lookups and surf through on whatever. 100% unmasked details on any numbers you want. DMV, aircraft, SSN, judgments, etc., all linked and at the ready. Also, GLBA is a giant Sherman-tank sized loophole that means that essentially anybody can fully legally use these databases as long as there's some cognizable financial transaction that you're protecting from fraud (even proactively / research wise). See https://risk.nexis.com/AMLSolutions/help/GLBA_Permissible_Use.htm https://risk.nexis.com/AMLSolutions/help/GLBA_Permissible_Us... So no, you can't just "pretend to be a cop" but if you actually go to the trouble of being some sort of fraud-prevention business, you can just go wild.
- sevensor 8y agoSo if everybody knows your SSN/DOB, I'd say that makes a very good identity system in the sense that we can all unambiguously refer to the same person. It's just not any use as a means of authenticating that you are the person who has that identity.
- stenioaraujo 8y agoI do agree with you, even though SSN/DOB can be used to identify a person, it should not be used to identify a unique person [1]. As you said, Identity should not be confused with proof of identity. Hopefully it will get better with time. [1] - https://www.pcworld.com/article/3004654/a-tale-of-two-women-same-birthday-same-social-security-number-same-big-data-mess.html https://www.pcworld.com/article/3004654/a-tale-of-two-women-...
- pwg 8y ago> So if everybody knows your SSN/DOB, I'd say that makes a very good identity system in the sense that we can all unambiguously refer to the same person. If that was all it (SSN) was used for, a "unique-id", it would work ok for that usage. The problem is that far too many companies also make use of SSN as a "secret only you know" to authenticate that you are in fact the individual identified by the SSN. I.e, your "login name" is identical to your "password". It is this miss-use that leads to the problems around SSNs.
- orky56 8y agoSSN on its own is sufficient for verifying identity. SSN coupled with a phone verification step is more secure for authenticating than DOB.
- craftyguy 8y ago> SSN on its own is sufficient for verifying identity. No. It's sufficient for identifying someone, but not at all sufficient (not even close) for verifying someone is who they say they are.
- mjevans 8y agoIt's the difference between a user ID (be it a small integer or a long string) and actually authenticating to perform actions AS said user. SSN as a user identifier - to uniquely describe an entity Actual PKI including a secure public/private key with a signature from a trusted agent (like a government ID authority), and maybe also web-of-trust signatures? THAT is what is required to securely sign things.
- Cactus2018 8y agoCollege and University databases.
- Someone1234 8y agoThe US government should replace SSNs. SSNs were never meant to be used this way. Any good replacement should start with a set of APIs specifically targeting financial institutions/credit. Give the consumer a random, easily rotatable, numeric key (e.g. "14830-29928-8921-29"). The key + API can return a unique ID, but a unique ID cannot return its corresponding key (i.e. single directional flow). The unique ID never changes for a given individual. If the consumer's key is lost, stolen, or breached the key can be re-issued and old one expired. Make it illegal to store the numeric key itself in a database for long periods. Only the resultant Unique ID can be held. You'd never request from the consumer the Unique ID itself (otherwise it itself would become the new SSN); only their key for API verification. Why is this a secure system? The information companies would store (Unique ID) is not the same information they need to process a new credit requests (Key). Meaning the piece of information that identity thieves need to steel is short lived, and the long lived info cannot convert back to the short lived.
- jdmichal 8y agoAren't you basically just describing a more complex, weaker form of RSA SecurID hard tokens or Authenticator-app soft tokens? With a centralized API for validating a generated key vs identification details? EDIT: Thinking about this more, it seems like a much harder problem than this quipped solution gives credit for. The agency wishing to validate a generated key would need to have enough identifying information to isolate a single row in the centralized database to validate the token. Because we don't want every token assigned to John Smith to validate every John Smith. So now this centralized database needs to have something that's unique to every single row... Or, in other words, the same problem as SSNs have to start with.
- Someone1234 8y agoNo, and the fact you think it is anything like SecureID means I did a poor job explaining it. It replaces cardboard cards with a SSN on them, with a cardboard card with a longer randomly generated key on it. There's no electronics involved from the consumer's perspective at all. The key is provided on your e.g. loan application. The financial institution sends that key to the government via API, and receives back a Unique ID assigned to you as an individual that never changes. The financial institution should then dispose of the key you provided them. The Unique ID is essentially used like an SSN; but the major differences are: - The consumer never provides it directly - The consumer's version of it (key) can be rotated freely - If the Unique ID itself leaks it has no value, since the API Cycle (i.e. Key -> Unique ID) is part of the system that financial institutions would use, supplying the Unique ID would just throw an error (since it isn't a valid key). So it completely different from SecurID, and is more akin to SSNs with most of the core issues resolved. Issuing cardboard cards with numbers on them isn't inherently complex, and is what we're already doing. The most challenging part is getting financial institutions to implement the API calls and update application forms. You'd also have to remain vigilant that they aren't storing the Keys themselves longer than absolutely necessary.
- philwelch 8y agoSSNs are used widely enough that they can leak from anywhere. For example, my wife made an appointment with the eye doctor the other day and they needed to look up her vision care insurance. Since she's on my insurance, that means they needed my SSN. I asked my HR department what's up with that and where I can just get a plan number for the vision plan instead of having them look it up by SSN, and they said, "oh yeah, your plan number is just the last four digits of your SSN." So, yeah. I bet you could obtain tons of SSNs from fucking Lenscrafters if you wanted to.
- astura 8y agoID-Theft as a service with the source being stolen and otherwise illegitimately obtained data https://krebsonsecurity.com/2013/10/experian-sold-consumer-data-to-id-theft-service/ https://krebsonsecurity.com/2013/10/experian-sold-consumer-d... >An identity theft service that sold Social Security and drivers license numbers — as well as bank account and credit card data on millions of Americans — purchased much of its data from Experian, one of the three major credit bureaus, according to a lengthy investigation by KrebsOnSecurity. >An individual who read a story about the operators of a similar ID theft service online having broken into the networks of LexisNexis and other major data brokers wrote to say that he’d gone back and reviewed my previous stories on this topic, and that he’d identified the source of the data being resold by Superget.info. The reader said the abbreviations matched data sets produced by Columbus, Ohio-based USInfoSearch.com. >Contacted about the reader’s claim, U.S. Info Search CEO Marc Martin said the data sold by the ID theft service was not obtained directly through his company, but rather via Court Ventures, a third-party company with which US Info Search had previously struck an information sharing agreement. Martin said that several years ago US Info Search and CourtVentures each agreed to grant the other company complete access to its stores of information on US consumers. >Founded in 2001, Court Ventures described itself as a firm that “aggregates, repackages and distributes public record data, obtained from over 1,400 state and county sources.” Cached, historic copies of courtventures.com are available through archive.org. >In March 2012, Court Ventures was purchased by Costa Mesa, Calif.-based Experian, one of the three major consumer credit bureaus. According to Martin, the proprietors of Superget.info had gained access to Experian’s databases by posing as a U.S.-based private investigator. In reality, Martin said, the individuals apparently responsible for running Superget.info were based in Vietnam.