6 ms·
Just skimmed the table of contents. Looks like the vast majority of the report is investigating their patch policy. Okay. Fine. It was bad. But really, I think
by JaRail 7y ago
Just skimmed the table of contents. Looks like the vast majority of the report is investigating their patch policy. Okay. Fine. It was bad. But really, I think they missed the point.
What I really wanted to see was some discussion about how vulnerable the entire US identity system is in the first place. The data is mostly valuable to hackers because there's an assumption that anyone with a birthday, social security number, etc is the person they claim to be.
A verified twitter account shouldn't be more secure than the best the government can offer. Governments need to step up with an modern identity system. Having one secret social security number for life is ridiculous. Having to do financial transactions in-person at a bank so you can present your driver's license and sign with a pen is ridiculous.
You shouldn't need to use a social security number directly. There should be a token system where you authorize companies to reference your data. Just like using twitter to sign into another service. You verify that you're actually the owner of that identity.
The US needs to learn that social security numbers were never meant to be used as identifiers. It's awful. Just fix the real problem.
- u801e 7y ago> Having to do financial transactions in-person at a bank so you can present your driver's license and sign with a pen is ridiculous. If you replace the signature with a CSR along with the drivers license/passport, then the bank can then give the new account holder the certificate. Then the account holder can use it for future online transactions.
- greedy_buffer 7y agoWhile this may be a serious problem it doesn't actually seem relevant to this breach - if a CRA has an incident of this severity, most ID schemes are still going to end up with a pretty large leak of PII that can be traced back to the individuals involved.
- rando444 7y agoThe point your parent is making is that in the US this information can be used to impersonate people. In countries with modern identity solutions, this is not possible.
- asdfasgasdgasdg 7y agoWhat is required to impersonate someone in, e.g., Belgium or Switzerland? To get a credit card or something, I mean.
- JaRail 7y agoNot from either of those countries but I was curious. https://www.gemalto.com/govt/customer-cases/belgium https://www.gemalto.com/govt/customer-cases/belgium Belgium has a digital ID card. It's a smart card that contains fingerprint info. So you can put the card in a fingerprint reader to verify you match the card. Cryptographically secure so you can only get them from the government. Second, they have an online identification service and mobile app that can be used to verify your identity to banks online. There's also an under 12 kids version of the card that includes emergency contact info, etc. Looking up info for Switzerland has a bit of a language barrier. It looks like it's still mostly just a national number similar to a SSN and national identification card. Documents from as far back as 2016 have their government planning a biometric id card and an electronic id. Some docs said they were aiming for a 2019 rollout but I couldn't find any recent updates.
- g051051 7y agoYes, exactly. None of that information has ever been secret or secure. It's ludicrous that it's used to establish identity.
- sly010 7y agoI just tried to create an online account with the IRS today and failed to do so because they couldn't verify that my phone number is registered under my name. (Why they can't deal with Google Fi but can with AT&T is a different problem). I was annoyed, but also positively surprised with the process. They even ask you for an anti phishing phrase.
- maxerickson 7y agoSocial Security numbers are explicitly identifiers. What they are not is authentication. The Real ID act was aimed at making driver's licenses more useful as authentication/proof of identity. Whether it constructively did that is a separate question.
- bootlooped 7y agoFingerprints are also identifiers, but that doesn't stop them from (properly or improperly) being used as authentication. SSNs are definitely used as authentication, whether you like it or not.
- maxerickson 7y agoI didn't claim they were not used as authentication, I claimed that they don't provide it. They don't.
- JaRail 7y agoSorry, I might not have been clear. What I was referencing there is that they were never meant to be used as identifiers for people outside of the social security system. People are not born with social security numbers. A lot of people in the US don't have them. If you ran a daycare, you couldn't use social security numbers to track the kids in your customer database. You wouldn't be able to use them with the parents either because they (should) be afraid to give them to you. If they did give them to you, you'd have no way to verify them. It's not the intended purpose. Real ID was basically just adding citizenship info to your driver's license so you didn't need to also carry your passport. It didn't fix any financial fraud issues.
- toast0 7y ago> People are not born with social security numbers. A lot of people in the US don't have them. If you're born in a US hospital, you kind of are born with a SSN; through a program called Enumeration at Birth [1]. It's not mandatory, and many people aren't born in a hospital, and certainly a great many people aren't born in a US hospital. Enumeration at Birth wasn't around when I was born, I believe my parents had my siblings and I enumerated at the same time; I'd guess when it was requested for school enrollment. [1] https://secure.ssa.gov/poms.nsf/lnx/0110205505 https://secure.ssa.gov/poms.nsf/lnx/0110205505
- deleted 7y ago[deleted]
- ssnistfajen 7y agoThere's a trade-off between convenience and privacy. Identity verification will be a nightmare without a universal unique identifier (of which the US SSN is not because it isn't compulsory) because cross-comparing other personal info is too complex. Although I know having a unique compulsory personal identity number (as many countries in the world have done) will have these so-called "privacy advocates" in the U.S. screaming at the top of their lungs. So either deal with it or leave it.
- godelski 7y agoWhat's funny is that I usually need my passport for HR when I get hired. Somehow my drivers license isn't good enough. I honestly see this as a failure. (Considering you also write down your social) Also social security numbers were never intended to be use as unique identifiers. There's no code or anything. Add one to yours and you get someone else's number. Only thing hackers are doing are matching numbers with other identifiers. It is odd to me how much we rely on SSNs when they are so bad.