10 ms·
Hackers may have leaked the Social Security Numbers of every American
- ipython 2y agoWhat’s interesting to me is that the company, “National Public Data” is a wholly owned subsidiary of a company called Jerico Pictures (yes without the h) What the heck business model explains a video production company owning personal data for practically every American? I feel like there is a lot more than meets the eye on this one.
- nerdponx 2y agoI agree that there's probably more to it than meets the eye. But a lot of companies are basically just holding companies that don't actually do anything economically useful on their own, eg IAC (the CEO of which is now lobbying for the removal of the FTC chairman).
- beardyw 2y ago> It's said that the business assembles profiles for individuals by scraping information from public sources and then sells the data ... or a lot less than meets the eye
- ipython 2y agoYes but what’s a production company doing with that data? It seems an odd pairing. And where are ssns posted “publicly”?
- candiddevmike 2y agoGreat, the sooner a 9 digit number stops being significant, the better. They were never meant to be a ubiquitous identifier/authentication token.
- deleted 2y ago[deleted]
- bluGill 2y agoThey are a very useful identifier. However they only prove that someone with such a name exists. They are not enough to prove that the given person with that number is the unique person they say they are.
- ddtaylor 2y agoIt should be harder for you to impersonate someone else via their SSN than it is to take a stolen card and purchase a $5 coffee.
- bluGill 2y agoI agree, but what makes it hard shouldn't be having access to that number, it is verifying the number belongs to the person you are trying to impersonate. There is great need for an impersonal unique id for everyone - there are doesn't of people in the world who share the same name as me. It is possible that some of those people share the same birthday as me as well. For most purposes I want to go by my name, but when you need to be sure you need a unique ID.
- jimbob45 2y agoThey were never meant to be a ubiquitous identifier/authentication token. But they de facto are and have been for longer than they haven’t. At some point, it becomes an abdication of responsibility by the SSA, no matter how much they kvetch about it being “not their problem”.
- Levitz 2y agoThe case against using SSN in unintended ways is not the problem, I don't think there is any serious opposition to that idea. The problem is the case for making a viable replacement for such usages.
- SirMaster 2y agoGreat, more training data for LLMs...
- underseacables 2y agoWhat else is new? It seems every week there is some massive data dump of private information. Until people/CEOs start going to jail for lapses in security, that allow these hacks to happen, things will not improve.
- briffle 2y agoor, we could stop using the SS number that you are required to give to people like employers as a de-facto national ID, and credit ID, and also a secret that just knowing seems to authenticate you.
- next_xibalba 2y agoUnder what law would a CEO go to jail for being hacked?
- deleted 2y ago[deleted]
- ethbr1 2y agoWe could (and should) create a personal criminal liability for management over cybersecurity. Specifically one that flows past the CISO and prevents that role from being a firebreak to insulate the CEO.
- joelfried 2y agoThe "fall guy" problem strikes me as nontrivial. Even if you add to the law that the CEO always has liability for any data leak, a sufficiently well capitalized company run by someone aware of the liability would simply create a shell company that owns all of that data. You could disallow company transmission of said data at all but that is going to cause problems when trying to actually verify said information . . .
- joelfried 2y agoWe'd almost certainly have to write a new one, but there are several straightforward ways to do it if we had the political will. An off the cuff example that could certainly be improved: Definitions: Government Identification Data includes Social Security Number. Bulk Extraction means any removal of data more than element by element. Unauthorized Third party means any person who the Company does not intend to grant access to. Intentionally Retaining means that a company chooses to ask clients to supply information which is then saved in a way accessible to the company for any reason in the future. Law: Any company maintaining Government Identification Data must select someone as personally liable for the security of said data. If the company does not have a person who accepts personally liability, this liability transfers to the Chief Executive Officer of the company. In order for the liability to be considered transferred, the Company most keep on file a notarized copy of an affidavit accepting such liability Any company intentionally retaining any Government Identification Data must do so in a system that does not allow for Bulk Extraction by any Unauthorized Third Party. Failure to do so is considered Willful Negligence on the part of the company. Any company guilty of Willful Negligence herein described must forfeit the greater of 15% of their previous yearly revenue or 5 times the Gross Annual Compensation of the most compensated employee. In addition, whomever the company has selected as outlined above shall be incarcerated for no less than 12 months and no more than 60 months.
- WarOnPrivacy 2y ago> Hackers may have leaked the Social Security Numbers of every American ...thus making them available to the the only group left without easy access. My larger point being that it's time to shift our concern from privacy - to disproportionate privacy. It isn't randos who routinely harm/exploit us with our own data but those in power. I suggest that equal privacy would serve us far better than privacy laws that target us and few else. For equal privacy, the default starts out somewhere near: If you can see mine, I can see yours. If you're going to restrict just us, 1) you need to openly+clearly justify it and 2) the restrictions need to sunset.
- batch12 2y agoNo, that's just giving up and is, respectfully, silly. How about some kind a right to privacy instead? Maybe I should have the ability to control who can sell my data instead of giving the same data I don't want shared to everyone?
- WarOnPrivacy 2y agoPrivacy equality applies permanent pressure to the powerful to protect everyone's data, instead of just their own. We presently go law by law, and we have a bloody fight for each one with the final result typically varying between ineffective and counterproductive. Eventually the system works as intended; we get exhausted and give up. This is the present state of affairs pretty much all over - and has been for a very long time. There's little reason to believe a different result is soon to manifest.
- DataDive 2y agonot sure what's with the downvotes leaking all SSNs makes relying on SSNs as authentication unfeasible, the only way to stop SSNs being authentication token is to give everyone access to them, but yes that can cause short term troubles The concept of having SSN is de facto wrong, there are situations where one needs to identify oneself unambiguously I went to another country, and what I found is that to get a monthly bus pass I had to fill out a form that asked for: Full Name + Gender + Date of birth + Place of birth + Mother's Maiden name + Mother's DOB + Mother's place of birth (and so on) I forgot the exact details, but it was ludicrously intrusive. Mother's maiden name? Really??? I did not even know some of that info and filled it out with educated guesses. It is not like they were able to check ... all that information is just an unreliable SSN
- fooqux 2y agoThere's been enough leaks from DMVs, credit bureaus, credit cards, and a myriad of businesses that require an SSN for verification checks by now that if every SSN wasn't already in the hands of attackers I would be surprised.
- bee_rider 2y agoHas anybody ever gotten out of a debt by saying “I dunno why you think those credit cards are mine, everybody’s social security number is everywhere.” I’d love to see a case like that. These data broker and credit bureau industries are obviously impossible to run safely and should be destroyed.
- batch12 2y agoThen it's called "Identity Theft", and deflected back to you as your problem to resolve. But, it's no big deal. I'm sure everyone everywhere qualifies for a year's worth of free credit monitoring.
- JumpCrisscross 2y ago> it's called "Identity Theft", and deflected back to you as your problem to resolve Not really. At that point it becomes an open question that both sides will furiously try to resolve in their favour. What you're advocating (and I agree with) is biasing the odds in favour of the allegedly defrauded. For example, if you file an affadavit of identity theft with a credit bureau (or court), collections on that item are suspended for a fixed amount of time.
- batch12 2y agoWhen someone uses my SSN to set up a loan, I'm not the victim, the bank is. There's no such thing as identity theft. That's just good marketing and a genius slight-of-hand to move the responsibility and blame away from the entity that allowed itself to be defrauded.
- stephenitis 2y agoGood maybe we'll finally pass a bill to give us better working public identification numbers.
- loopdoend 2y agoBe careful what you wish for.
- vundercind 2y agoUnlikely. We have terrible, dangerous, expensive, painful de facto national ID, none of which bad elements hinder use of it (with associated government and private databases) for the purposes people worry about, but a huge segment of the right and a fair amount of the left won’t let us fix it because they fear a good version would be misused, and/or that it’s the “mark of the beast”. Never mind that the horse is already out of the barn I guess. So we’re stuck with a bunch of extra lost time and money for no reason.
- mschuster91 2y ago> because they fear a good version would be misused, and/or that it’s the “mark of the beast” I'm aware of and share the concerns about misuse (it has happened, see the tax ID debate in Germany), but what the fuck is that with "mark of the beast" relating to ID cards?!
- vundercind 2y agoI know it seems crazy but it’s a real thing. There’s been litigation related to it over social security numbers, even. I’ve known people IRL who are sure any ID improvements are a move toward the rise of the Antichrist, and these were otherwise “normal” Christian folks. It’s fairly widespread, as nutty concerns go.
- actionfromafar 2y agoWell, there's a Venn diagram where there is overlap of legitimate concern over tracking people and these religious beliefs. OTOH SSNs are like the least of problems compared to how tracking is all over our digital lives.
- breadwinner 2y agoSadly, financial institutions will continue to use knowledge of your SSN and DOB as proof that you are who you claim you are. And if you're not, that's the problem of the sucker whose identity got stolen. Financial institutions in America prioritize convenience over security.
- ethbr1 2y agoThis is trivializing the amount of backend system migration that's required to change core identifiers. If they could push a button and use new identifiers, they'd do that today. However, in reality that means cracking open 50 years of code and systems.
- kbolino 2y agoYou don't need to change the core identifiers. You just need to stop treating (at an institutional and broader system level) mere knowledge of those identifiers alone as sufficient proof of a user's authenticity. For the most part, the 50-year-old hard-to-change code is already surrounded by other systems which can be adapted more easily anyway.
- ethbr1 2y agoPoint, in internal vs external sense. What else would you use though? (in the US) I can't think of any broadly-existing alternatives. You could perhaps have people opt-in to a newly-created, cryptographically-secure ID replacement.
- kbolino 2y agoThis is the real and hard problem to solve. As far as I know, there are identity-verification services using other, semi-publicly-available data, which can still be spoofed for a lot of people, and some that use just-in-time photography (of your face, driver's license, passport, etc.), but that relies on more on-device security (and thus less end-user ownership of their devices). It ultimately falls to the government to provide a more robust solution.
- trentnix 2y agoFortunately Social Security numbers aren't used for anything other than Social Security! Right? Right???
- PopAlongKid 2y agoMedicare replace SSNs with a Medicare-specific ID, seems like a move in the right direction.
- deleted 2y ago[deleted]
- rjmunro 2y agoIt's fine to use them for disambiguation purposes. It's not fine to assume that just because I know someone's SSN (and maybe their DOB) I am that person.
- hiatus 2y agoThe owner of Jerico Pictures, Salvatore Jr. Verini, also registered a new company this year called National Criminal Data LLC. https://search.sunbiz.org/Inquiry/CorporationSearch/SearchResultDetail?inquirytype=OfficerRegisteredAgentName&directionType=Initial&searchNameOrder=VERINISALVATOREJR%20L240001569030&aggregateId=flal-l24000156903-42a649b5-7886-4267-a903-f7e9fe1782e7&searchTerm=VERINI%20SALVATORE%20JR&listNameOrder=VERINISALVATOREJR%20L140001289031 https://search.sunbiz.org/Inquiry/CorporationSearch/SearchRe...
- donatj 2y agoThe small private college I attended in the early aughts used your SSN as your student ID and it was printed on everything. Transcripts, official records, basically any piece of paper with your name on it. You'd even speak it aloud to the worker at the book store to pick up your books for the semester. It was everywhere. As a kid twenty years ago, I was mildly bothered by it but imagined they must know what they are doing. Looking back at near 40, with the hindsight of years, I'm flummoxed. Like, what the hell, who's absolutely terrible idea was this?
- bshep 2y agoSlightly related, my uni id was a prefix for the campus + year of admission + serial number the serial number was sequential based on last name, you could essentially guess anyones student id if you had a couple of data points of last name : serial number As far as I know no one used it for nefarious purposes, but it was a cool party trick to guess someone’s number.
- soneil 2y agoTo be fair, that's pretty much the intended usage. The SSN is supposed to enable them to figure out exactly which John Smith they're looking at. It's a serial number, not a shared secret. It sounds like your college treated it as such. The real problem with SSN is the prevalence of unintended usage.
- user3939382 2y ago> the intended usage IMHO, as the name suggests, the intended usage is for social security. We're not supposed to have Citizen ID numbers which is why the number has been shoe-horned into this role.
- Dalewyn 2y ago>The real problem with SSN is the prevalence of unintended usage. There is nothing more permanent than a temporary solution, and nothing more temporary than a permanent solution.
- bjtitus 2y ago
- jmclnx 2y agoI hate to be this way. Good! When Congress Critter's little blond granddaughter gets pwned (someone takes her identity), maybe Congress will get real serious about really punishing these Companies when a breach happens. But we know what will really happen in this scenario, the Company will get funding (bailout) from the Feds, the CEO will resign with millions of USD, the CEO will become a lobbyist. And in reality, the granddaughter will get special treatment from the Company due to who she is.
- focusgroup0 2y ago>little blond granddaughter what does an imaginary young woman's hair color have to do with cybersecurity?
- practicemaths 2y agoSimple. American society tends to value blond white girls more. Notice you didn't question what the gender of the grandchild.
- shrubble 2y agoMaybe that occurred since the post specified “granddaughter“?
- samier-trellis 2y agoThe post also specified the hair color
- stavros 2y agoThey questioned the hair color ("why blonde") but not the gender ("why a woman").
- crtasm 2y agoSeems to be clearly questioning the entire premise to me.
- BoredPositron 2y agoI have identity protection from three different leaks now...
- bloomingeek 2y agoMost of my life my SSN was also my drivers license number. Then my state a few years ago changed the numbers. Great! Now some hotels want to copy both sides of your license before renting you a room. My doctors office and local hospitals copy them too. A few years ago, Capital One credit cards wouldn't let us pay our bill online, which we had done for several years, unless we sent them a copy of both sides of our DL's! I called them and said no thanks and they said I would have to began paying through the mail. We paid off both cards and canceled them. Have said all this, it's prob just a matter of time before my DL number is hacked by someone through some weakly secured site.
- op00to 2y agoMy DL number is predictable if you know my name and birthdate and when I got my drivers license. :D
- nesky 2y agoWhat state has drivers license numbers the same as your social security number?
- ezfe 2y agoMany states have done all or part of the social security number on drivers licenses. Thankfully not ones I've lived in, but a Google search will yield lists.
- 5555624 2y agoNow? None. I believe they've all done away with it. In the past, quite a number of states. Mine was originally; but, I was able to change it in 1995, when Virginia began offering people the choice of SSN or a DMV number. (It was the result of efforts by the ACLU and others.)
- dhosek 2y agoBack in the 80s, University of Illinois at Chicago used SSNs as student ID numbers. Until you memorized your five-digit userid (I was U10754) you could login with your social security number, so I would type [just kidding].
- op00to 2y agoI do not care. My SSN has been leaked for a decade at least. I have freezes on all my credit history. I file my taxes with a PIN. I need photo ID to get medical treatment and get it billed to my insurance. SSN is not the secret thing it once seemed to be (but never really was).
- neilv 2y ago> The data, which is unencrypted, is believed to have been obtained from a broker called National Public Data. I'd be happy to join a trillion-dollar class action lawsuit against whomever assembled this data without securing it.
- OJFord 2y agoI've never really understood why it's supposed to be considered secret but also has to be given out sometimes and also can't be changed unless in witness protection. (Information all from Hollywood.) Other countries don't seem to have this problem? You can have my bank account number, driving licence number, passport number, national insurance number if you want?
- BobaFloutist 2y agoIt's because Americans have a libertarian streak and instinctively mistrust the government, so we've historically resisted any sort of federal ID program. Because the federal government has to keep track of you somehow, and every American (more or less) already had a unique identifying number, the government started using those unique identifying numbers to identify us for tax purposes. This started being a convenient way for private corporations to ask the government "Wait, who's supposed to be identified by this number?" for employment and loans, and then people decided that it would be better to use this instead of any sort of, you know, online ID, to identify people for credit card applications.
- bbarn 2y agoThe lack of a federal ID is almost irrelevant at this point. Most states have moved to "Real ID" which requires almost as much if not the same to get as a passport (federal ID). Requirement to have that has been coming (and admittedly pushed back several times) for a long time.
- OJFord 2y agoI'm British, we've also resisted it, which is why the closes thing to a national identity document I listed was a driving licence or passport. It's not uncommon to have a provisional driving licence (learners' permit to you I think) purely for the purpose of being IDd for alcohol or whatever. For tax I would use my national insurance number and any form of photo ID to register for an online account, or you can do a paper form but I don't know how they verify identity if you're claiming a refund in that case. A credit card application would similarly want a copy of photo ID and probably a proof of address (like a bank statement or utility bill). There's nothing wrong with having the number, I have a national insurance number, I have Self-Assessment Tax Return numbers (I think it's unique each year), it's the secret bit I don't get.
- juanani 2y ago[dead]
- _yb2s 2y agoMaybe we can finally stop using the SSN as if it were both a public and private key...
- agpl3141592 2y agoAnd why is one magic number so critical? No one checks who uses that number? How is that even a thing?
- doctoboggan 2y agoA few weeks ago I started receiving notices that my SSN was detected online by the identity monitoring company I use. I guess this is the source of that. Around a year ago my identity was stolen (new CCs opened in my name). At that time I froze my credit on all 3 of the agencies. It's easy to turn it off/on with a switch so I have left it frozen. Its a good feeling knowing that no one can open a new CC in my name.
- nytesky 2y agoI had mine frozen and after a few years they seemed to forget my keys to unfreeze it. I use a password manager so maybe I messed it up, but it is very fragile. Another credit bureau says I don’t exist despite dozens of credit cards, 4 mortgages, and student debt. They need me to fax a copy of my license to prove I’m a real person.
- xyst 2y agoand a state license is very easy spoof/fake especially over lossy formats like email/fax
- barkerja 2y agoWhat service are you using that provides a single "switch" for all 3 agencies?
- doctoboggan 2y agoUnfortunately, you have to make accounts on each agency. You need to find the way to "freeze" on each site. They will try to sell you a "lock" option, but the "freeze" option is free (federally mandated).
- gosub100 2y agoThat may stop someone from opening a CC in your name, but not someone impersonating you to get a driver's license or sign up for government benefits or rent an apartment (not all of them run a credit check).
- 2y ago
- yoyohello13 2y agoOh No! \s As if SSN wasn't already the most insecure form of identification on the planet. Maybe now we can stop pretending it's a valid form of identification.
- ddtaylor 2y agoI'm from the USA so I don't have great perspective here. Don't other countries have basic secure chips in their cards? Don't they attenuate or whatever similar to how NFC works? I mention it because I have little hope in going after the scammers legally or playing cleanup later.
- deleted 2y ago[deleted]
- itslennysfault 2y agoMine has been leaked so many times at this point that I'll openly share it with anyone that wants it. Anyone here want my SSN? Just DM me. <3
- breaker-kind 2y agowhen i went to jail in boston (peaceful protest), BPD wouldn't release us until we gave them our social security numbers. when we showed up to court, they gave everyone a packet that contained the name, home address, mugshot, and social security number of everyone that was arrested. half of the time of the court proceedings was the NLG saying hey, what the fuck are you doing? can you please redact this?
- geor9e 2y agomirror of the leaked data: awk 'BEGIN{for(i=0;i<=999999999;i++)printf"%03d-%02d-%04d\n",i/1000000,i/10000%100,i%10000}'
- bananapub 2y agowhy has the US government never forbidden anyone else using it? is it just the usual "the US government is catastrophically compromised by the private data monetisation industry"?
- ldehaan 2y ago[dead]
- thenumchk 2y agoThe distribution of SSN numbers in the US is well known including the special use for railroad and US territories with sequential numbers. I dissected much of that through historical publication of the death master database and made a lookup for it at https://numchk.com/ https://numchk.com/ as a fun side project.
- patrick451 2y agoSocial Security numbers should simply be banned.
- bankcust08385 2y agoThe sooner Americans don't have an unauthenticated, reused, primary key and serial number, the better.