6 ms·
The "tramite number" mentioned in the article is quite funny. "Tramite number" translates loosely to "filing number". When national IDs were issued each one go
by gomox 5y ago
The "tramite number" mentioned in the article is quite funny. "Tramite number" translates loosely to "filing number".
When national IDs were issued each one got a "tramite number" that I'm guessing was sequentially assigned when the physical ID cards where issued.
Because this number is vaguely random and is printed on the actual physical ID card, it was used as a password on government apps (for example, for getting authorization to move around during covid). To log into the app, you enter your national ID number and then the "tramite number" that is printed on your physical ID card.
Of course, the number can't be changed, and is stored in plaintext in a large database somewhere. It therefore makes for a horrible password.
The database in question just got stolen, and the aforementioned apps now include all sorts of sensitive PII.
- rtkwe 5y agoSame problem happened with SSN in the US. It was too convenient of a unique, quasi-secret identifier so it became a password too.
- riffraff 5y agoI never understood the SSN-as-quasi-secret bit: isn't it widely dispersed anytime you need some medical stuff?
- vmception 5y agoYeah, and people within earshot are not the issue, it’s the place that has thousands of SSNs getting hacked that the issue, so there is no reason to be secret about it.
- puglr 5y agoTo add to this, prior to the internet it really wasn't that bad of a "password". Once upon a time vacuuming up batches of SSNs for nefarious purposes wasn't a realistic attack scenario, let alone a "just assume every criminal has your SSN" one.
- throaway46546 5y agoThey were always a terrible password. https://www.usrecordsearch.com/ssn.htm https://www.usrecordsearch.com/ssn.htm
- rtkwe 5y agoIt's mostly a terrible password because it's immutable if it weren't it's a quasi random 9 digit code that's hard to map from a person's current information back to what their SSN is.
- throaway46546 5y agoIf you know when and where someone was born you can figure out the first 5 digits.
- macksd 5y agoYes. It even used to say on the card "not to be used for identification", but various agencies at all levels of government ask for it all the time.
- dane-pgp 5y agoAside from the obvious problem that this message appears to merely be a suggestion rather than a requirement with legal penalties attached, it doesn't seem to be an actionable instruction. If you are asked to provide your SSN and you ask "For what purpose?" and the requester lies and says "So I can choose my lottery numbers", it's not clear that you have broken the rule by revealing your SSN. However, perhaps the requester is breaking the rule (and perhaps they should know the rule, assuming they have a card themselves) in this scenario, but it's also not clear what action they would have to carry out with the SSN in order to have used it "for identification". For example, if a system designer uses SSNs as a primary key in a database, they can claim that's just for simple indexing, and that they are still using name and address or photo to identify someone. A system designer could also claim that they were only using the SSN as a (weak) "something you know" factor (among many other factors) in authentication, which may not amount to using it "for identification". Asking someone their date of birth (to be checked against another source, or on a later interaction) doesn't mean that your date of birth identifies you, since millions of humans share the same birthday.
- macksd 5y agoNo I wasn't under the impression it was a rule with legal penalties attached, but I mostly hear this as "can you confirm the last 4 numbers to verify your identity". It's a pretty clear cut case of using it for authentication. And rule or not - it's effectively a 4-digit PIN that probably half the services I have to call into re-use, so it's just plain stupid.
- chrisco255 5y agoNo, it's typically used for credit services, however.
- macksd 5y agoI've been asked for it by my health insurance companies, providers, and when donating blood. On the latter I saw they had a policy of issuing a different ID number to you on request, but it was a royal pain in the ass and a supervisor came out to ask me what my problem was
- chrisco255 5y agoInteresting, I've never been asked that when donating blood or going to a clinic, but yes, my insurance plan did (as that is a financial service). It's worth noting that medical clinics will service people without social security numbers just fine.
- penagwin 5y agoYes, as well as applying for jobs (or at minimum when hired), renting an apartment, and lots of financial things including any type of KYC crypto exchange or investment accounts. I've also had utility companies ask for it. These are in no way secret, I have no idea how people are okay with this. You can easily social engineer so many critical services if you know somebody's SSN.
- smsm42 5y agoOr financial stuff. Or job stuff. Or getting a cell phone or cable subscription stuff. It's pretty much as much of a secret as your middle name in the US - it's not like everybody knows it, but it's not very hard to find out.
- op00to 5y agoOh it’s better than that. For those born before a certain year, it is trivial to guess their social security number if you know their general date of birth and location as they were assigned sequentially.
- matheusmoreira 5y agoSimilar situation here in Brazil. People use these IDs as passwords. When system administrators set up accounts for users, there's a good chance the default password will be the user's ID and that it will never be changed. Every school I've ever attended did this for school portals, wifi logins. It's insane. There used to be a website where I could look up anybody's ID number by name, that's how public these things were. With this ID number, I could perpetrate all sorts of electronic crimes under the cover of somebody else's identity. I could dox anyone by consulting services such as credit score databases.