18 ms·
Inside the "3 billion people" national public data breach
- datadrivenangel 2y ago"there were no email addresses in the social security number files. If you find yourself in this data breach via HIBP, there's no evidence your SSN was leaked, and if you're in the same boat as me, the data next to your record may not even be correct. " Seems like Troy is skeptical about this being a real full breach?
- fullspectrumdev 2y agoA lot of these data brokers hold wildly inaccurate information.
- LeifCarrotson 2y agoYou too can be a data broker! for (i = 0; i < 900000000; i++) insert(first: random_firstname(), last: random_lastname(), ssn: i); Does anyone really really care if the name is accurate if the SSN is present? More than half of the SSNs in the above dataset are valid.
- ryanisnan 2y agoYou probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.
- autoexec 2y agothat was the idea behind certain applications and add-ons that would browse around to popular websites and randomly click ads so that marketers couldn't tell your actual interests from fake ones. Unfortunately that strategy is deeply flawed and dangerous because nobody cares if the data they have on you is accurate or not. They still can, and still will, use it against you at every opportunity. Every scrap of data they have, accurate or not, can be used to hurt you. The only way to flood data brokers with garbage data that can't hurt anyone is to fill it with entirely fictitious people who somehow can't be mistaken for any actual people. Even that runs the risk of hurting real people though. For example, an insurance company might go to a data broker and ask for the number of people within a certain neighborhood or zip code who bought fast food more than once a week in the last year and how many have a gym membership. If the number of frequent fast food buyers is higher than it was last year and/or the number of gym members is lower the insurance company might decide to raise the rates of every single member within that neighborhood or zip code. Even fake people could skew those numbers if their fake data said they lived in those zip codes or neighborhood and ate out a lot or didn't have a gym membership. Indirectly, the fact person is mistaken for being a real one in that community. The best way to deal with data brokers is to regulate them with strong data protection laws. Anything you give them risks hurting someone and gives them another data point to sell.
- notpushkin 2y ago> might decide to raise the rates of every single member within that neighborhood or zip code Wouldn't that be against redlining laws? https://en.wikipedia.org/wiki/Redlining https://en.wikipedia.org/wiki/Redlining
- autoexec 2y agoI doubt it, since nobody is being denied housing or services. Health insurance companies have plenty of data to back up their practice. Your zip code might be the single most important predictor for longevity (https://time.com/5608268/zip-code-health/ https://time.com/5608268/zip-code-health/). More importantly, your insurance company is never going to tell you that that's why they raised your rates. You're just going to see a high bill. Same way that a potential employer isn't going to tell you that you didn't get the job because of something you said on social media 14 years ago, or because the information they got from a data broker says you drink a lot. You just get ghosted. That's the problem with surveillance capitalism. Even as all that data increasingly impacts your life you're almost never aware that it's happening and have no ability to appeal or correct the record.
- ruthmarx 2y ago> Every scrap of data they have, accurate or not, can be used to hurt you. What are some examples of inaccurate data, as in completely false data, being able to hurt me?
- autoexec 2y agoYou can never know what might prejudice someone else against you. Maybe you get flagged as being gay when you aren't, or as holding certain religious or political views that you don't. Extremists, activists, and protestors can go to a data broker and buy up lists of people to harass or attack. Data brokers have already been caught collecting data on people who visited Planned Parenthood locations and selling that data to anti-abortion groups. You could be incorrectly flagged as having more money than you do, causing companies to charge you more than they charge your neighbors for the exact same items. Discriminatory pricing has been happening for a very long time. Just using a different browser can cause prices for some online services to change. (https://www.bostonglobe.com/business/2014/10/22/online-shopping-yields-different-prices-results-says-northeastern-study/ZbSVnoBxPJtA8STeWbpQ9H/story.html https://www.bostonglobe.com/business/2014/10/22/online-shopp...) For example, Apple users might be seen as having/spending more money and so the prices they get for hotels and airfare can be higher. Increasingly, brick and mortar stores have been trying to get in on the action too. (https://link.springer.com/article/10.1057/s41272-019-00224-3 https://link.springer.com/article/10.1057/s41272-019-00224-3) If you have a browser extension that randomly visits sites and clicks on ads. Maybe it clicks a bunch of ads for alcohol or marijuana. Maybe it clicks on ads for mental health services, addiction/recovery services, or suicide hotlines. That data can be used against you in court during a divorce/child custody case. It might make a company less likely to hire you. It might cause your health insurance company to charge you more. Maybe it clicks on ads for DUI attorneys and suddenly your auto insurance rates go up. The company isn't going to tell that's why. They might not even know why. their algorithm just decided you were more high risk than before. Every data broker is creating a dossier with your name on it, and they are stuffing it with every scrap of data they can get their hands on. That data can cost you a job or a rental contract (see https://nypost.com/2022/12/20/how-employers-spy-on-your-search-history-digital-footprint/ https://nypost.com/2022/12/20/how-employers-spy-on-your-sear... and https://themarkup.org/locked-out/2020/05/28/access-denied-faulty-automated-background-checks-freeze-out-renters https://themarkup.org/locked-out/2020/05/28/access-denied-fa...). The data being collected on you can get you arrested or questioned by police. (see for example https://www.nbcnews.com/news/us-news/police-google-reverse-keyword-searches-rcna35749 https://www.nbcnews.com/news/us-news/police-google-reverse-k... and worse https://www.nbcnews.com/news/us-news/google-tracked-his-bike-ride-past-burglarized-home-made-him-n1151761 https://www.nbcnews.com/news/us-news/google-tracked-his-bike...) Any data for sale, accurate or not, is going to be used against you. The people paying data brokers for information about you aren't doing it because they want to help you. They want to help themselves at your expense. And its insane how many people are buying up that data and using it whenever they feel it might give them even the smallest advantage. Companies are using that data to decide things like how long to leave you on hold when you call them. (https://www.nytimes.com/2019/11/04/business/secret-consumer-score-access.html https://www.nytimes.com/2019/11/04/business/secret-consumer-...)
- saintradon 2y agoI have a silly standup joke along these lines, about how I'd Google things crazy things like "circus lawyer" or "giraffe mitigation tactics" to throw the algorithm off every now and then.
- briandear 2y agoMy friend is a thriller writer and is convinced he’s on some FBI list. He’s googling stuff such as “how to dissolve a body with quicklime” and all sorts of other fun stuff while researching for his books.
- H8crilA 2y agoThe quicklime method shouldn't be particularly fast, at least that's what my chemical intuition says (CaOH2 is barely soluble in water). What a bad name!
- thaumasiotes 2y ago> What a bad name! The quick doesn't mean "fast". It means "alive".
- defrost 2y agoIn the most general context it means "with the characteristics of the living" (as seen through a middle ages lens). In the context of "quicklime" the quick refers to the heat of the reaction when making lime for slaking on walls, etc. "Quick" historicaly has been applied to plants and animals (alive), rivers and streams (moving), coals, fires, quicklime (burning, heat producing, glowing), to speeches and pamphlets (Lively, full of vigour or sharp argument), to tastes, to smells, and more. The full blown Oxford English Dictionary entry for quick is a lengthy one, multiple cases and variations over a page and more.
- Sylamore 2y agoThat has been my strategy for the last decade or so, Unless I have a solid reason to I never use my real name when placing orders and generally never the same fake name twice, always use a virtual credit card, if it's a non-physical product I don't even use my real address. I have some old phones I throw pre-paid sim cards into when I need to do number confirmation. The goal is to create a little consistent linkable data to me and at least generate some noise in all these data broker collection processes.
- LeifCarrotson 2y agoI do the same, I worry that eventually someone's going to need to see my driver's license and refuse me because my ancient account info doesn't match. "It says here that this shipment is for Firstname Lastname at 1 Main St, Yourcity, born January 1st in the same year as you. Your license has a different address and different birth day and month, so you're not the same person."
- calvinmorrison 2y agoIn fact there are far fewer valid Socials. They follow a system where guessing a number of digits is fairly determined based on year and state of birth
- deleted 2y ago[deleted]
- __float 2y agoThis is not exactly true; the system _used_ to have a geographic component but SSNs issued since 2011 are random. (Granted, most people here with an SSN should be older than that.)
- LorenPechtel 2y agoYes, but they can also be pretty accurate. While I have never dealt with one of the paid services someone ran one on me as an example of what is out there (nothing malicious about it) and just about everything on it was accurate or close to it. Only one thing on it wasn't at least pretty close to the truth--it had me living in a state I've never set foot in. And quite a few other people seemed to have the same address at one point or another.
- throwup238 2y agoI don't think it's a "full" breach because I assume that would include many tera/petabytes of original source documents rather than just a CSV of PII, but it's definitely a real breach. I looked up several family members and although most of the phone numbers and addresses were out of date, they were accurate as were the listed social security numbers. However, it didn't include any of the more recent immigrants in the family or myself, possibly because I take opsec seriously. Funny enough it looks like it has data for Tom Brady, former FBI director James Comey, Barack Obama, and Donald Trump (just some of the names that popped into my mind to look up).
- Dalewyn 2y ago>the data next to your record may not even be correct. " American Express by way of Experian alerted me to my SSN having been leaked precisely by this incident. The number was seemingly correct, but everything else associated with it such as name and address were nonsense. So assuming we're talking about the same thing... can confirm?
- michaelt 2y agoI'm in the UK so I have no Social Security Number, and I still got the HIBP e-mail. When I looked into it, it turns out the "original" breach is comprised of files named ssn.txt and ssn2.txt which only contains Americans details, and doesn't contain any e-mail addresses. It seems what happened is there was one leak of US SSNs which the leakers attributed to NPD, then some people bundled that leak up with a bunch of other data (including e-mail addresses and details of non-americans) and who knows if the latter data actually came from NPD?
- CrispyKerosene 2y agoTroy mentions "data opt-out services. Every person who used some sort of data opt-out service was not present." Anyone have experience with these sort of services? A search brings up a lot of scammy looking results. But if services exist to reduce my profile id be interested.
- laweijfmvo 2y agoI have used (free trials) and currently use (discounted annual) a service called incogni. It's hard to really verify what's going on, but they at least show the brokers they are contacting on your behalf, and I've directly received confirmations from some. Anecdotally, searching my name on Google pretty much no longer returns those scummy "People Finder" pages that just scrap any public records they can find. That said, I hope incogni is happy enough with my money that they themselves don't do anything scummy. Also, freeze your credit at the big three. do it now.
- deleted 2y ago[deleted]
- 0x2a 2y agoAnd turn on the Global Privacy Control header in your browser: https://globalprivacycontrol.org https://globalprivacycontrol.org
- JohnMakin 2y ago> Anyone have experience with these sort of services? Quite a bit. Often if you request removal or opt-out, you'll reappear in a matter of a few months in their system, regardless of whether you use a professional service as a proxy or do it yourself. The data brokers usually go out of their way to be annoying about it and will claim they can't do anything about you showing up in their aggregated sources later on. They'll never tell you what these sources are. A lot of them will share data with each other, stuff that's not public. It's entirely hostile and should be illegal. I am trying to craft a lawsuit angle at the moment but they feel totally unassailable. I'm extremely skeptical of any services that claim they can guarantee 100% removal after any length of time of longer than 6 months. From my technical viewpoint and experience, it is very much an unsolved problem.
- layer8 2y agoTL;DR: > an intriguing story that doesn't require any further action.
- 29athrowaway 2y agoTime for services everywhere to stop using SSNs for identification and for the US to move on to a more advanced form of identification. And lock your credit.
- wood_spirit 2y agoWhat can an attacker who knows your SSN still do with that information nowadays? Genuinely curious, as the SSN is just this strange in distinct password thingy the Europeans like me hear about on HN but have no actual parallels with.
- blackeyeblitzar 2y agoThe SSN is used as a way to genuinely identify someone, unfortunately - it’s like having to give out your password each time you rent an apartment or buy a car or obtain medical care or any number of other transactions. Having this info (along with other basic info like name/address/date of birth) lets you effectively pretend you are them. You can take loans out in their name or call some service to do a password reset (since you have all the info to verify you are them) or whatever else. But it’s not like there is one particular way in which the information can be used - it’s dependent on what businesses LET you do with that info. In 2024, NO business should use SSN to verify identity or authorize sensitive transactions but many do, and what they let you do varies significantly.
- acdha 2y agoI think it’s important to distinguish between identification and authentication. As a unique database primary key, they’re fine. The problem was when a bunch of businesses decided it’d be too expensive to check things like government ID and started using them for authentication purposes. Nobody blinks an eye at using a phone number or email address on an application, but we should treat using your SSN or past addresses for authentication the same way we would if someone says they could approve a loan if you know your phone number and zip code.
- quantumfissure 2y ago
- hypeatei 2y agoDoes anyone else just not give a fuck at this point about their SSN? I feel like maybe early 00s this would be scary but it's clear that everyone's SSN is out there already or waiting to get breached from a shady private data broker. The problem lies in how institutions treat the SSN, not the number itself.
- rolph 2y agoif you know place of birth, and place of ssn application, you can determine most of the ssn. the final 4 are supposed to be random, but are blurted out to rooms full of people and tech, during service. the integrity of SSN security, was lost a long time ago
- enlightens 2y agoas of 2011 they are fully random instead of being based on geographical region and groups https://www.ssa.gov/employer/randomization.html https://www.ssa.gov/employer/randomization.html
- xboxnolifes 2y ago> the integrity of SSN security, was lost a long time ago The security never existed, since they were never intended to be secrets. At best it was theater.
- acdha 2y agoYes. 99% of the time “identity theft” means a huge company cut corners on their security policies and wants us to subsidize their negligence. Every so often there are cases like that guy who pretended to be his former coworker for decades but they’re rare enough that they make the news internationally. Most of the time it used to be things like instant credit applications where they didn’t “slow” purchases with ID checks. The good news is that companies have lost the presumption of competence there. In the 80s if a company said they’d confirmed that an applicant was you using your SSN, a lot of people would falsely believe that was sufficient but by now they’re not going to get far if they sue you unless they can provide better evidence because everyone knows huge breaches have happened many times.
- uticus 2y agoI’ve finally figured out the play: war of attrition. Eventually enough data will be leaked to make moot the benefits of securing any personal data. At that point everyone stops trying and moves on to more financially rewarding activities. I mean even if I’m an elephant, and data breaches are blind men, eventually enough blind men will draw a true comprehensive picture.
- johnnyballgame 2y agoExtreme Privacy by Michael Bazzell is a great resource to learn how to limit exposure to these aggregator services. https://inteltechniques.com/book7.html https://inteltechniques.com/book7.html
- NoMoreNicksLeft 2y agoCan't the SSA just issue 330 million new social security numbers, and tell people to be more careful with them from this point forward?
- blackeyeblitzar 2y agoThe SSA has shown absolutely no urgency on this issue. Their existing policy is that having your SSN compromised is not enough to issue a new number. You have to actually be a victim of a financial or identity crime that abused your SSN for them to consider a new number. In reality what they should be doing is giving everyone accounts that can generate tokens for use with each transaction, to maintain a trail of where leaks originate and also to expire these temporary tokens. Instead they’ve stuck to this archaic system.
- Dylan16807 2y agoThey can't issue new numbers in bulk without revamping the system because they'd run out. The urgent fix wouldn't work. If the system needs to be revamped, then step one should be pressure/force so that companies stop treating the numbers as secret. And if we do that we don't need new numbers anymore.
- acdha 2y agoThe SSA specifically told people not to misuse SSNs this way and it seems like a poor use of taxpayer funding to spend billions bailing out businesses’ bad decisions, even if that was legal (Congress would have to specifically authorize it), since we’d be back to the same problem with five years. If we were going to do something, we’d make government ID include an NFC token for PKI purposes since public keys can’t be compromised in the same way, but nobody is jumping to pay for that, especially in a country where you have so many people prone to wild conspiracy theories (I am especially amazed by the guys who freak about a national ID as big brother but never say a word about the credit reporting industry) and the enduring “Mark of The Beast” religious fears.
- toomuchtodo 2y ago
- blackeyeblitzar 2y agoIt is crazy to me that data brokers are even a legal form of business. All of these services should be opt in at minimum. If they are obtaining publicly available information and making it easier to access, they should have to maintain insurance or a deposit with the government to compensate victims of cybersecurity incidents. Telling people to get credit monitoring is in NO WAY an acceptable way to make us whole. They need to pay for a lifetime of monitoring and INSURANCE up to the net worth of affected individuals. This needs to become law ASAP.
- SteveNuts 2y agoWe're two decades into "The Digital Millennium" and our laws are still stuck in 1999 (except for the ones that ya know, allow dragnet spying). I'd wholeheartedly support any candidates that push for a data/privacy "Bill of rights".
- acdha 2y agoI’m optimistic for Harris, not just because she’s so much younger and less beholden to industry, but because she created an entire unit for privacy protection when she was the California AG: https://oag.ca.gov/news/press-releases/attorney-general-kamala-d-harris-announces-privacy-enforcement-and-protection https://oag.ca.gov/news/press-releases/attorney-general-kama...
- krageon 2y agoThere has never been a US president that had anything close to ethical behaviour (to wit: the ones that existed after drone strikes became a thing all signed off on drone strikes. Those hit a lot of innocent people. The US has never stopped having slavery. I could go on). It is really the height of fanciful thinking to believe that the flavour of the month US leader will be any different.
- acdha 2y agoThat’s absurdly naive – it’s like saying every picture is the same because they aren’t entirely (255, 255, 255) pixels. If your goal is to do anything other than feel smug, consider the impact such non-serious positions have on how other people will perceive anything more serious you say.
- throwup238 2y ago> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly public now.
- bhaney 2y ago> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.
- flockonus 2y agofyi that is likely to be a crime, at the very least has been cases of websites being punished for linking to illegally distributed IP (even if not hosting it).
- bhaney 2y agoI'd be worried about legal repercussions if we were talking about the latest Disney movie, but this is merely the private information of a billion people. Never seen IP law give much of a crap about that before.
- quantumfissure 2y agoFor non-Americans (and Americans) that don't quite understand what SSN is and why it's a problem, CGP Grey [1] has a great (and short) video about the history and why it's not technically an identifier, but has become one. [1] https://www.youtube.com/watch?v=Erp8IAUouus https://www.youtube.com/watch?v=Erp8IAUouus
- fragmede 2y agoThe video doesn't quite get into the problem of identity theft, which is when someone uses your stolen creds to claim they are you, and then go on a shopping spree which may include buying a car under your name. You shouldn't be liable for debts incurred after having your identity stolen but proving that is a lot of work.
- adamomada 2y agoI never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense https://en.wikipedia.org/wiki/Shaggy_defense
- jandrese 2y agoThe reason the Shaggy defense doesn't work is the default assumption of the courts is that you're a deadbeat trying to game the system. This assumption comes about because in the majority of cases it is the truth. The system would be a lot nicer if there weren't people trying to scam it every hour of every day of the week.
- pocketarc 2y ago> This assumption comes about because in the majority of cases it is the truth. Are we saying that if you can show you have enough income / assets, it'll be that much more likely that you'll be fine in those cases?
- jpcookie 2y agoAnd where is this information that this random group supposedly has? I have yet to see proof of that being real
- seanw444 2y agoBreachForums I believe.
- lynndotpy 2y agoI was able to get a hand on it, and I was able to confirm that some records of loved ones are indeed present (although mine was not.)
- banana_giraffe 2y agoIt's real. A few people I know are in the dataset. The SSN is problematic, but personally to me, the more troubling data is a seemingly complete, or at least complete enough, address history for the people I checked for. It doesn't have dates, but just having the addresses could cause major problems for spear phishing attempts.
- toomuchtodo 2y agoAhh, cool, pour the corpus through GPTs and start tweeting Congressional rep personal info at them until they pass a law to outlaw data brokers (in keeping with historical precedent [1] [2]). [1] https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act [2] https://jolt.law.harvard.edu/digest/dodging-the-thought-police-privacy-of-online-video-and-other-content-under-the-bork-bill https://jolt.law.harvard.edu/digest/dodging-the-thought-poli...
- conductr 2y agoFor argument sake, instead of outlawing data brokers wouldn’t it be better to design a better ID system that renders one’s name, dob, and SSN as harmless information? I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that.
- toomuchtodo 2y agohttps://news.ycombinator.com/item?id=41249568 https://news.ycombinator.com/item?id=41249568 https://news.ycombinator.com/item?id=40961834 https://news.ycombinator.com/item?id=40961834 TLDR Login.gov, and publishing a circular to allow businesses to use it to identity proof. Push all liability onto the business for losses if this method is not used to identity proof. ID card as ljm mentions, such as a passport card. Very similar to credit card EMV chips and the liability shift from magstripe. > I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that. Aggregating data means it can be lost. You must therefore make aggregating and storing data toxic, and impossible to be leaked through eventual mismanagement.
- ljm 2y agoIn many countries in Europe, your ID card contains a chip with a cryptographic key, much like chip&pin on a debit or credit card. Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. If the card is lost or stolen they can just remove your old one from the keyserver. It's literally just public key crypto. Identity theft is rampant in the countries that don't have such a system and basically require you give them increasing amounts of private information to prove who you are. In the UK that's every address you've lived in for 5 years, your council tax bill, your energy bill, your bank statement for a month... all because British people think an ID card means you'll get stopped on the street to show your papers.
- tmaly 2y agoI sure wish the US had a version of GDPR. I get a data breach notice at least a few times a year. I got one for my kids two months ago for their medical data. I thought HIPPA had huge penalties but I guess not.
- dgellow 2y agoDoesn’t California have a similar set of regulations?
- EvanAnderson 2y agoFor years I've said the entire SSN database just needs to be published alongside legislation strictly assigning liability to any company who defrauded as a result of using the SSN as a "secret". That would fix the problem with SSN's and "identity theft" quickly. Part 1 has been accomplished. Let's get part 2 going! Aside: It amazes me how the American public has allowed defrauded companies to assign the company's loss as a liability to innocent individuals (in the form of "identity theft"). It would be great if we could get that changed in the minds of the public. A well-informed public could collectively turn "identity theft" into the "bank's problem" (from the old adage "If you owe the bank a billion dollars they have a problem..."). The insurance industry would swoop in as the defrauded parties start making claims and shoddy security practices would get tightened-up. (Edit: I fear insurance companies coming in to "fix this" to some extent-- citing my experiences with PCI DSS compliance auditing and Customers who have had 'cyber insurance' policies coming with ridiculous security theatre requirements. Maybe we can end up with something like a 'cyber' Underwriters Labs in the end.) (Also: Yikes! I hate that I just typed 'cyber' un-ironically.)
- sorokod 2y agoThe obligatory Mitchell & Webb sketch https://m.youtube.com/watch?v=CS9ptA3Ya9E https://m.youtube.com/watch?v=CS9ptA3Ya9E
- EvanAnderson 2y agoYES! I couldn't remember their names and absolutely was thinking of this.
- janalsncm 2y agoIdentity theft is a very clever term to shift blame from the company to the consumer. https://youtu.be/CS9ptA3Ya9E https://youtu.be/CS9ptA3Ya9E It’s a comedy bit but I take its point seriously: if the bank gives away money, it’s the bank’s job to make sure it is repaid. Not mine, unless I was actually a party to the agreement.
- 2y ago
- janalsncm 2y agoAre there any ways to check the breach to see if my information is there, other than downloading it myself? I’m not sure of the legality of doing so.
- jaderobbins1 2y agoThere is a free service call Have I Been Pwned which uses your email address to see what data breaches you are part of (https://haveibeenpwned.com/ https://haveibeenpwned.com/). While it uses your email to check (not SSN) odds are if they have your SSN in the dataset they also have your email.
- notpushkin 2y agoThe OP post says that emails in this breach are paired with random names and SSNs, so it's not a good indicator.
- jaderobbins1 2y agoOh sorry, I missed that!
- xf5f 2y agoI've seen https://npd.pentester.com/ https://npd.pentester.com/ floating around
- heartbreak 2y agoThe data seems to be at least 15 years old.
- xf5f 2y agoFor me, it matches (DOB, last 2 of SSN) and seems fresh (has newest address, as well as older ones).
- ghm2180 2y agoI am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A person's profile will be used to attack the most vulnerable things: - Their families will get fake calls to create confusion. - Their financial services will be frozen or worst weak 2fac auth ones will be compromised. 4. Deep fake image and videos will be created from compromised accounts to sow further mayhem. This already happens in targeted and one startegy of teh other fashion. Imagine what one could do with a bit more compute and completed profiles and orchestrate this kind of terrible vengeance.
- kurthr 2y agoLuckily, there aren't multiple hostile nation states capable of this. /s All that I can see preventing it is deniability and eco-political risk.
- njarboe 2y agoI wonder how many governments have this capability right now? I would guess at least three.
- nc0 2y agoAs far as I know, most of the developed and in development countries have this kind of database, I also know some poor countries does too, but they often lack security measures
- lifeisstillgood 2y agoI am wondering what the numbers are like for this to be realistic. I am not too sure of the end goal other than general chaos. Let’s say it’s 2 days of an attack, (that’s about how long any co-ordinated response would need at minimum). So attackers need to sow chaos across the USA. They apply for a million unsecured loans of say 20k each. That’s 20 billion. I honestly don’t know what the daily personal loan application rate is, but america has about 150M adults, 1% of them applying on the same day will not only raise flags but would basically grind the system to a halt - each loan office would have daily maximums and a massive spike coukd not be handled. And once the massive crowd is noticed and made public then the financial immune system comes into play. I can imagine taking out the cell network through a sort of SS7 ddos, but I suspect that cell towers might have a dose more vulnerabilities (probably not as basic as all the admin passwords are ComC4astSux but close) In general Chaos seems to come from attacking the limited services that act as our safety net (ambulance, police, sewage, electricity). We know these are vulnerable in non obvious ways - crowdstrike for example. Making otherwise fit and healthy citizens have a shitty day is less impactful than we might think - it will be the “blip” day - as I say 48 hours later the Treasury secretary goes on TV and announces all personal loans that day got cancelled or some other fix - finance has a fairly good immune system when it sees the need. But overall, if we are going to worry about some attacks, let’s look at the ones that attack our freshwater supplies - and that might not mean some terrorist - in the UK our sewage handling has been under attack by Private Equity for decades and SWAT teams are not allowed to shoot people in Belgravia
- velcrovan 2y agoEven before this, anyone operating a service who isn't treating SSNs as public knowledge in 2024 needs to be, well, shamed or penalized or something.
- JumpCrisscross 2y ago“The database DOES NOT contain information from individuals who use data opt-out services. Every person who used some sort of data opt-out service was not present.” Like what?
- fnord77 2y agoFrom the NPD website: > Please be advised that we will not collect, use, disclose, sell, or share the sensitive personal information or sensitive data of California, Virginia, Colorado, or Connecticut residents as those terms are defined by the CCPA/CPRA, VCDPA, CPA, or CTDPA, respectively.
- smcin 2y agoDiscussion from last week: https://news.ycombinator.com/item?id=41184420 https://news.ycombinator.com/item?id=41184420
- puzzledobserver 2y agoSeveral other commenters have brought about the sneaky wordplay involved in saying "identity theft" instead of simply calling it "fraud on the bank", and somehow turning the person into the victim rather than the bank that has been defrauded. Has anyone tried to argue this point in court? Has this survived / how did this terminology shift survive judicial scrutiny?
- left-struck 2y ago> The problem with verifying breaches sourced from data aggregators is that nobody willingly - knowingly - provides their data to them This is a bit of a tangent but I feel like if we can prove this statement then these data aggregators should be made illegal. How can you consent to something that you don’t know you’re consenting to? Likewise why do these entities have the right to collect detailed personal information like SSN without your explicit, beyond reasonable doubt, consent? To me this is the most obvious failure of the legal system, it clearly goes against well established legal principles that a basic requirement of an agreement is that all parties know what they are agreeing to. Obviously there is some leeway with agreements where it’s not possible to clarify every eventuality but lets say if you’re applying to rent a place through an online form and that form shares your SSN to a data aggregator, it should be extremely clear about that, and possible to out out while still allowing you to complete the rental application without discrimination. It’s like, it should be possible to show that no one, with in reason, consented to sharing their data with this aggregator because no one is able to confirm that they did. Sure one person could forget, or lie, but 100s of millions of people? No. Clearly almost zero people knowingly consents.
- deleted 2y ago[deleted]
- Hnrobert42 2y agoI have been using a different site@mydomain email address for every service I've used for the past 15 years. I can point to exactly which site breach furnished my email address to the aggregators.
- al_borland 2y agoCare to call out some bad actors so others know to avoid business with them? I recently started using unique emails for everything I sign up for. Thankfully I haven’t seen anything yet, but I have little hope it will stay that way.
- klabb3 2y ago
- blindriver 2y agoWhy are data aggregators legal? In California can we create a proposition to shut them down in the state?
- idontknowtech 2y agoThis sort of stuff will continue happening until the regulatory framework acknowledges a fundamental consumer right to privacy. If a data broker collects data without the consent of the consumer, then their only real risk is a class action lawsuit which drags on for six years, gets settled for a few days profit, and the consumer gets $13.50 after the legal fees. This massive skew in the risk reward calculus of data brokers is why we have the problem. Because there's little to no real downside, the trend is automatically collect as much data on as many people as possible. Fixing this means big, mandatory, cash penalties in the law code - say $5k per consumer data leak, directly to the affected consumer, with added penalties if the company lies about the leak or delays payment. The fine must be big, mandatory, and paid directly to the consumer. Only that changes the risk reward ratio. In that new world, companies would have to re assess their risks. They'd either build invulnerable systems and hire a lot more people reading HN to protect their golden goose, or better still they'd decide to exit the business entirely. That sounds bad, but the only reason the industry exists is because regulators failed to foresee massive leaks like this happening every three months. We need a consumer data privacy law, with massive fines, to force companies to change their behavior. What we're doing now clearly does not work.
- esalman 2y agoThey should tax companies so that operating data centers become more expensive. Increase price of electricity or property tax. That will inherently force companies to collect and store less data, hence less damage from breaches.
- deleted 2y ago[deleted]
- luxuryballs 2y agothe government should have put out honey pots or something, or maybe it’s time to get new numbers and just invalidate all the stolen data, there is clearly money for fixing this kind of thing but they’re using it to spy on us and do who knows what else instead
- albert_e 2y agooff topic does HIBP automatically cover plus addressing variants of an email example I submit johndoe@example.com but a breach had johndoe+verizon@example.com will it match
- deleted 2y ago[deleted]
- kalleboo 2y agohttps://haveibeenpwned.com/FAQs#PlusAliasing https://haveibeenpwned.com/FAQs#PlusAliasing
- seydor 2y agoWhat if we just made all this data free , some AI is going to compile them anyway (and probably already has). Deterrence is the best defense, right ?
- fy20 2y agoIt depends on the country. Where I live now even if I leak my name, date of birth, bank details, national id number, etc. you couldn't do much. We have a country wide 2FA system that all important businesses use (bank, utilities, health, government) to authenticate users. I'm from the UK though, and previously was a 'victim' of identify theft where a few years ago someone walked into a phone store, and walked out with a new iPhone and contract in my name.
- Freebytes 2y agoIs the country wide 2FA implemented by the country or a private company? While rare, what if a person does not have access to the 2FA mechanism, and what mechanisms are permitted to confirm an identity?
- sergiotapia 2y agoDownloaded the torrent, and it's a 164GB text file. What's a quick way to search if my SSN is in the file? I ask before diving in, it's currently extracting and ETA is 40 minutes.
- ivanjermakov 2y agoUse grep with some optimizations: LC_ALL=C fgrep 'ssn' file.txt https://stackoverflow.com/a/13913220 https://stackoverflow.com/a/13913220
- themaninthedark 2y agoHey, if I give you my SSN can you check to see if it is in there for me?
- hn72774 2y agoAnything the average SSN holder should be doing proactively?
- NineStarPoint 2y agoYou could freeze your credit, it you wanted to be careful. Realistically though, you should have already been monitoring to check if unexpected things were being done in your name. I’ve presumed that all our SSNs have been out there for years now due to one hack or another, that this hack just makes it indisputable doesn’t change much.
- tmountain 2y agoWhat's required to freeze/unfreeze your credit? Your SSN and address info? All of that is in the breach for millions of people.
- gosub100 2y agoJust like a lock on the door, it raises the barrier to a non trivial level. It does not give you a ft Knox level impenetrable fortress. I recently froze my credit with the big 3 and it was easier than I pictured. I don't know if they slow you down if you try to unfreeze it immediately after clicking "forgot password".
- mherkender 2y agoFreeze your credit with the three major credit agencies. Set up an IRS pin.
- d_burfoot 2y agoIt's worth remembering that the main reason this kind of data breach is a real problem is mostly due to the incompetence of the IRS. For any serious financial organization, knowing a person's SSN, name, address, etc doesn't allow you to access or withdraw that person's finances. But the stupidity of the IRS means that people are easily targeted by false tax return attacks. File a fake tax return for someone, using their SSN/name/address, but tell the IRS you changed address. Then the IRS sends your tax refund to the new address, and boom, you just collected some poor sod's refund. To add insult to injury, the IRS is probably going to audit the person whose refund you stole.
- daveguy 2y agoI agree. The IRS should be better funded so they can afford to update their systems and hire more tech experts.
- grepexdev 2y agoI hope this is meant to be satirical. The IRS has a massive budget. Maybe just reallocate their current funds instead of giving them more is a better idea.
- boston_clone 2y agoI don’t think the parent is satirical at all; as an enumerated power, the IRS needs modernization and better funding. Recent hiring expansions have increased audits for high earners and generated additional revenue. Turbotax’s lobbyists are losing influence and we’re enjoying free filing options for individuals in some states. It’s also reasonable to say that a revenue service is not responsible for defining authentication security standards. Why do you think reallocating funds is worth it as a response to this issue? Where would those funds go?
- sporkland 2y agoI'm sure you've seen teams that have bad leadership / a culture of dysfunction. They're always asking for more headcount and no much how much you add they don't get any better. I assume parent was pointing out that no matter how many resources you give to the IRS they won't get functionally better. You need to change the leadership/incentives/culture, which is hard with govt agencies but resources also won't make the problem go away.
- farceSpherule 2y agoI worked incident response for years, logging thousands of hours of actual on site work with impacted clients. No on cares. Clients see this as the cost of doing business and have no incentive to do better. Even after Equifax and OPM. Until we have a GDPR style law in the U.S. it will continue to be status quo.
- araes 2y agoI was wondering why Google suddenly turned on "prompt authentication" on zero-security feature accounts yesterday. Now I "must" have a phone nearby to use Gmail... Tap to authenticate every time you want to look at ... ad spam. With this, Ticketmaster, and the CDK Global car theft, is there anybody on Earth who doesn't need data protection? Poor people in Somalia need data breach notices. People who are not even on the WWW need data breach notices...
- robustcollector 2y agoPerhaps HN readers would appreciate a detailed account of what the NPD torrents contain. The torrent deliver two files like so: NPD202401.7z 33,456,912,010 bytes (32GB) NPD202402.7z 20,548,499,322 bytes (20GB) Uncompressing NPD202401.7z results in: ssn.txt 176,806,109,779 bytes (165GB) wc -l ssn.txt ==>> 1,698,302,005 lines Uncompressing NPD202402.7z results in: ssn2.txt 120,722,361,611 bytes (113GB) wc -l ssn2.txt ==>> 997,379,508 lines This is a total of 1698302005+997379508 = 2,695,681,513 lines. Each line is a comma separated record with these fields: ID,firstname,lastname,middlename,name_suff,dob,address,city,county_name,st,zip,phone1,aka1fullname,aka2fullname,aka3fullname,StartDat,alt1DOB,alt2DOB,alt3DOB,ssn Generally records have ID, firstname, lastname, middlename, address, city, county_name, st, zip, and ssn. Most records do not have the fields for name_suff (name suffix), phone1, aka1fullname, aka2fullname, aka3fullname, StartDat, alt1DOB, alt2DOB, and alt3DOB. There are no emails at all. There is no "@" in the files anywhere. Phone numbers are very rare. I don't know what the ID number at the head of each line represents. I presume it is an internal index used by the organization that compiled the data. The SSN is at the end of each line. The files have U.S. addresses only as far as I can tell. Nothing from Mexico, Canada, or other foreign countries. Many of the lines (records) concern the same person at various addresses. Of 7 random people who I personally know that I checked on, all had entries. There were between 3 and 20 lines (records) for these 7 persons, averaging about 10. They usually differed only in the address field. Going by an estimate of 10 records per person, the 2.6 billion lines represents about 2695681513/10 = 269,568,151 distinct persons in the U.S. The U.S. population is about 337M where 78% is over 18 years of age. In other words, 337000000*0.78 = 262,860,000 Americans are adults. This is pretty close to my estimate of 269,568,151 distinct individuals in the NPD data files. Of the 7 persons I checked on, the names were spelled correctly, although the middle name was sometimes just an initial. I searched each person by multiple methods (address, last name, birth date) so I believe I would have detected names that were spelled slightly wrong. The addresses appeared correct but there was no way to tell which was the current address and the order in which they lived at each address. There is a StartDat field but it was almost never filled in. The latest entry was not always the most current address. In a couple cases, the current address, where the person has been living for several years, was absent. The birth dates were correct in a couple cases, were abbreviated in three cases (that is, instead of showing 19800704, meaning July 4 1980, it showed 19800700, meaning July 1980 without an exact day), and was wrong for one person by a wide margin. All 7 persons I checked had SSN numbers. It was correct for 1 person but I don't know for the other 6. The SSN numbers were consistent for each of the 7 persons I checked on. By this I mean that a person did not have more than 1 SSN number, at least among the 7 persons I checked on.
- peterbecich 2y agoi.m.o. "National Public Data" in title should be capitalized; it is a proper noun https://en.wikipedia.org/wiki/National_Public_Data https://en.wikipedia.org/wiki/National_Public_Data
- zephyra334 2y ago[dead]
- USDoD 2y agoDoes anyone know the correct password?
- dimgl 2y agoI used Robokiller to remove myself from data broker lists. I'm extremely impressed with it. I pay yearly. My only annoyance with Robokiller is that A) It's necessary. When is the government going to start creating laws to help us and prosecute this? B) It's expensive. Most people cannot afford this. I can barely afford it but my information has been leaked online. C) It's inconvenient. A majority of calls are spam, but I'll often miss important calls from unknown numbers because Robokiller acts as a proxy and for some reason the call is routed through the Internet. Anyhow, my wife and I are not on this list. I'm wondering if using Robokiller saved us from a lot of pain here.
- esmeraldametteo 2y agoI recently hired the experts of {hacker11tech (@) gmail com} to help me track my spouse's GPS location, as I suspected infidelity. They provided me with accurate and timely information, revealing that my spouse was frequently visiting another person's location instead of going to work as claimed. Their expertise and professionalism were very impressive, and their ethical approach ensured a discreet and confidential process. The evidence gathered was comprehensible and reliable, giving me clarity that I needed to address the situation. I highly appreciate the {hacker11tech (@) gmail com} dedication helping to uncover the truth while maintaining ethical standards, their services was valuable in helping me make decisions about my relationship. I highly recommend this team {hacker11tech (@) gmail com} for anyone seeking reliable ethical practices and their commitment is reassuring.
- itamblyn 2y agoIs there a straightforward way to download this file for research purposes?