Claimed AT&T hack of 70M customer records including SSN, name, address
9to5mac.com
9to5mac.com
As an aside: When it comes to an authentication source to take the place of silly shared public "secrets" I think it would be great if the United States Postal Service "pivoted" into issuing digital certificates to individuals. They already have infrastructure and procedures in place for identity verification and physical delivery. I suppose that's too much like a federally-issued ID to ever fly, though our "REAL ID" drivers licenses are, in effect, a federal ID anyway. I'd rather have a digital certificate out of the deal too.
- It's inobtrusive enough to wear all, or very nearly all of the time. Contrast cards or similar carried-but-not-worn tokens.
- It can be readily use to tap a sensor for identification purposes. Contrast cards or similar tokens (e.g., USB keys), which are far less immediate.
- It is replaceable. That is, if it's compromised, stolen, or lost, it can be replaced. If it becomes unadvisable to possess, it's readily discarded and reasonably easily destroyed. This contrasts with biometrics or permanently embedded sensors.
- Its absence is reasonably immediately determinable. Again, contrast carried-but-not-worn tokens.
- The existing prevalence of ring-wearing makes use of an NFC ring less obvious or evident (mostly a concern in early-adoption periods), or the opting-out of wearing one (which ring is the NFC ring?), without directly querying each individual, which ... might not work regardless (depending on implementations).
- There are relatively few people who would be entirely unable to use such a device. Ready alternatives for most such cases exist: wrist bands
- Unintentional validation (e.g., surveillance) is relatively easily avoided, if devices require immediate contact with a sensor/receiver. That is, a surveillance entity couldn't mass scan a crowd or region quickly, but would have to individually query rings in close proximity. (This might be achieved through high-volume transit points already, but this already raises the ante.)
- It's possible with a query/response system that multiple identities with the same root, but not immediately correlated, could be supported. (Deanonymisation or identity linking remains a significant problem, however.) Ideally, such a system could be limited to only satisfying minimum qualifying criteria (e.g., "I've paid a fare for this trip"), rather than transmitting either a full personal dossier or an absolute identity.
Key (so to speak) challenges are in agreeing on a single standard, ensuring crytpgraphic robustness, and protecting privacy, surveillance, and other concerns, as well as distributing the detector infrastructure for desired uses.
There are cases (e.g., mass-transit turnstiles) where this isn't desirable --- the intent is to maximise throughput. (The quesiton of whether or not validating or fares are a net benefit is also open.)
For a more secure facility, or payment system, tag + pin (and potentially other identifiers) would be preferred.
I believe the direct quote is "Why come you got no tattoo?"
Guess who ends up footing the bill when a bank gives a loan to someone pretending to be you? Hint: It’s not you, and it’s not the fraudster either.
That could go the other way, with someone else filing their income under your SSN without any corresponding withholding. This, too, needs better authentication than a mere SSN can provide.
But yes, I wish we could be as modern as some European countries. I haven't heard of these identity theft issues in France, where everyone has a national identity card.
> Deutsche Post offers a secure identity check service – to millions of users every year.
> On behalf of your contracting party
> To ensure that only identified persons have access to sensitive services
> To sensitive services including those from the financial services sector (such as opening an online bank account), telecommunications (activating a prepaid SIM card), health care (access to health information) or the mobility industry (including car sharing).
It's kind of like the feeling I get looking at somebody with a very nice car or house: "Oh, it would be neat to have such a thing but there's no way I'd ever splurge and get that." It's difficult for me to conceive of some things other countries have as just being "normal".
second, many systems of law treat individuals quite differently.. many systems that are not repeated in detail, on YNews, do not give much choice to an individual by design
It could be better in so many ways, though, too. It would be nice if younger people (say, sub-70) would (and could be permitted to) take up the mantles of leadership.
I'd really like to read a speculative fiction/scifi where every generation operates under its own system of laws, and you can opt in to a neighboring generation's laws instead once every N years or something.
Compare this with, say, Estonia where practically everything can be handled through the keys in the ID card.
Which is exactly why it will be :(
For instance, when I was looking for an appartment, the State had a service to both authenticate and watermark some documents (id and proof of income, among others).
The watermark was a bunch of big bars with "this is intended for rental search" written on them. Kinda low-tech, and it feels like a creative attacker could use software to strip them out, but it's cool they did that.
In theory, we have some very good APIs for securely authenticating someone (France Connect in particular), in practice administrations are slow to adopt them.
First, let's assume the identity would be backed by a somewhat decentralized system; e.g. the identity could be backed by any state/territory's existing ID cards.
The problem is making the request signing step secure and accessible to... well, anyone, tech-savvy folks included. Software for installation to a computer is an obvious no-go. A mobile app is probably a good idea but in any case I think we can assume a website will be a necessity. You've got to be able to give that website your private key. Guess what, you've already lost - as soon you tell people to type their key into this website, people will type their private key into any old website now. (I remember when my mom, with the best of intentions but without my prior knowledge, filled out my FAFSA info, SSN and all, on a scam .com site despite how many times we were told "fafsa.gov" or whatever.)
But let's pretend that's a solvable problem, just for the same of argument. Let's assume it's a federal government provided site which you can provide with your private key on demand to do signing on your behalf and it's relatively secure actually keeping the key in your browser. And there's a mobile app option which can store the key locally with better security and do signing in memory which can actually be wiped after. Fine. Now convince the public that this site/app do not constitute a Federal database of identities. You and I know it wouldn't, as described, but I would not blame anyone who objected on those grounds one bit, because without the necessary knowledge it absolutely would seem like a Federal ID, and folks are right to be wary of a single source of identity information. After all, all that does is take the SSN problem and add to it civil liberties problems. The distinction between SSNs and a [somewhat] decentralized PKI scheme with a centralized signing app for security/anti-phishing reasons is a distinction essentially impossible to convey to any but the most tech-savvy.
Worried about "mark of the beast" based objections? Make it optional. Those who wish can retire their SSN and receive their public / private keys and then the government publishes their SSN as a trashed SSN. Everyone who still wants just a SSN can take their chances.
USA passport for my children didn't require SSN. And a passport complies with TSA id checks.
Also why are these phone companies persisting SSNs in database ? Why can't they run the credit check initially and discard the SSN. There should be laws around this and enforced. It is time to hold these companies accountable. We are so tired of being worried that our ID may get stolen.
Possibly even more secure than that same doctor having it in their system.
Doctor's offices are so archaic at times. Only a handful let me do the forms online in advance. And even those have more paper for me to waste when I arrive.
In almost all cases, someone is entering what you hand wrote into a system; and then they discard the paper copy.
If they shred it that's great, but dumpster diving at medical offices has made the news many many times.
I hope them asking for it didn't discourage someone without an SSN from getting their shot, since immigration status isn't relevant to eligibility.
People volunteered the leaked info. Just say no.
People were rightfully worried in recently emerging computer age that these credit agencies would have secret dossiers on everyone. At least this law let people look at them and in theory correct them.
It probably time to revisit that 50 year old act. I'm not sure how much lenders even use the standard scores anymore. Many calculate their own scores and probably include all sorts of info that we would be mad about them using if we knew what it was.
This is just a knee-jerk thought and I'm sure it can be improved, but I believe asymmetric keys are the solution.
Do you mean private key? Or am I about to have a TIL moment? Because your public key is, well, public so I wonder what a compromise of that would look like.
On the other hand, you can't really expect the average citizen to properly curate a private key, and a private key also doesn't work for verification purposes.
I think the problem would be easily solved without encryption or keys by using the social security number in combination with a user-selected PIN number.
Any time you apply for credit somewhere, you should have to provide the social and a PIN. There should also be an easy way to generate single-use PIN numbers that can be used when applying for credit.
They already have a lot of the infrastructure for doing this. You can already put a credit freeze on your social security number and protect the credit freeze with a PIN, for example.
Whenever I am applying for credit, I simply "thaw" out my social security number for a couple of days. This works pretty well, but it's a hassle because you have to do it for all three agencies. It also suffers from the problem that my credit could get compromised if I left it thawed out too long.
Who issues the private key? "get" implies it comes from somewhere, i.e. a CA system.
If the government is the CA system, and your private key is your identity, how do you establish your identity in the event that you lost your key?
The nice thing about SSNs being immutable is that none of these are concerns. (It's also the bad thing about SSNs being immutable.)
We do have one thing in the US that’s physical proof, and that’s your birth certificate. But I’m sure people lose them and they can be pretty easily fabricated.
In that case, third parties could use a government website to get a row/col and ask you to verify, and the website could say yes/no. Yes, there is a risk of your one-time pad being stolen, but it is no greater than the current risk that any US citizen's tax documents or SS card can be stolen.
Not recommending anyone do this as it's obviously illegal, but..
lol. How do you think it works right now?
The party who accepted the SSN (or their insurance) is liable for footing the bill for the fraud, except in the ridiculously unlikely scenario where they’d manage to collect money from the fraudster.
Give SSN. Get email txt or notification to verify. SSN service replies back with a real Id number. Real id number is used for banking.
Except that the problem isn't which party is legally liable. The problem is that the legal system is almost entirely inaccessible to the vast majority of people.
At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...
For business reasons, my mother has her parents' last name, I have hers, and this fact is easily discovered online with a few minutes research...
And orgs (gov and private) will continue to just ask for completely unnecessary information because, why not? Throw it in some database with root:root as the pw and shrug when it gets breached. It really needs to stop. The only person that loses is the person that now has to potentially deal with identity theft or getting doxxed for the rest of their life...
Yes, I am a pessimist and I believe that. Why should website x care that there is a probability that the ISP is going to be hacked.
I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.
Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.
I don't know if there is an impact on call availability as well.
I could see something like this running from each state's DMV (or the postal service if you didn't want to use your local state DMV) to help ensure you are you.
It would be interesting to hear what people that use it say, because i'm sadly stuck in a very US world :)
all companies do not need better security. banks need better processes so my ssn and address cant be used to mess up my life.
the banks have the money to fix this.
Between that and the increasingly fundamentalist, censorious, puritan, social justice takeover of tech companies, I also feel like I'm being forced to become a luddite despite my life long love for technology.
If you make a big enough issue about how they apparently don't understand, they will create a committee to study the issue then ignore the findings. They don't care about you or your problems.
If politicians represented fewer constituents I think they'd be forced to care more about their constituents, if only because each individual voter wields more power. I certainly think that I have more power to influence my local politicians than I do my state representatives (let alone my federal representatives). My local politicians also live more proximate to me, and share more in the physical problems of the region. My US Senators live in my state, and that's about all they have in common with me.
I agree with you, but I also think there are many disparate problems we can point at. Ultimately, it all boil down to - we get the results of our efforts.
I think it has to get worse before it gets better. If almost everyone's personal information, SS and so forth, even IMEI's, addresses, mother's maiden, you name it, is available on the dark web, then that'll basically mean the corporate world will have to create a new mechanism. For example, the most obvious is the entire system in which credit worthiness is determined.
I know two people with identity theft issues, and in both cases people opened up accounts that impacted credit worthiness. That's really lousy if you spend a long time searching for a home to buy, and when you're in contract something like this happens and your credit gets dinged. Blame the banks and the credit industry as much as the hackers. They made this impossible-to-contain information literally the key determinant of your ability to get a loan in order to purchase a home.
Could be a coincidence, or it could be the data is already out and being used.
The odd thing to me was the phishing text said to CALL ATT's very own number. No links or anything.
Same thing with medical records. The current design is abhorrent. Every medical provider has an independent copy of your records. You should be the only one with a copy (or with a storage provider you designate) with strict timely access controls (eg doctor gets the records for 30 days for review or something). That I have to fill out a form to get my own medical records is retarded.
This stuff isn’t hard, but it’s hard to make money on so there’s perverse incentives to keep the status quo.
Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked".
Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to email for a day or three. Yes, of course twilio has an assumed name.
None of this was difficult nor illegal nor expensive.
The enabling factor is that Visa/MC do not actually verify cardholder name (even though everyone thinks they do).
So my bank sort of knows who all the providers are, but they'd need to collude with (MVNO or twilio or Apple) to have any real PII which could then be stolen ...
My threat model is PII theft via hacks (like this one) and wayward employees at each provider. My threat model is not state actors or LEAs.
I am saying that merchants do not have the ability to verify card holder name.
Your transaction will process properly with Mickey mouse as first last.
Only amex verifies cardholder name.
EDIT: relevant stackexchange is here: https://security.stackexchange.com/questions/220724/i-can-pa...
Is giving a false name to the CC companies not illegal in some way? At the very least I'm certain it is a breach of contract.
I have the same, real-name relationship with my bank and card issuers that you or anyone else has.
Rando-web-merchant, on the other hand, never gets my real name.
"I don't know how true this is across all vendors."
Almost 100%.
There is a rarely used program called "verified by visa" that takes you through an additional verification step and encourages you to create some sort of account linked to your issuing bank (or something) but I have only run into that once in the years I have adopted this practice.
Merchants can request Address Verification (AVS) from the network, but the result is purely advisory: the merchant can ignore a mismatch if they choose. In my experience, most do ignore it.
This is also true of the CVV/CVV2/CSC/etc. Most web vendors require it, but it is not required to complete a transaction. Theoretically the provision of a correct CVV indicates that the consumer has the card in-hand. Chargeback appeals are somewhat more likely to succeed if the transaction included the CVV.
Even just if privacy.com or someone would let me signup with a fake identity to t-mobile. Then who cares if these folks get hacked?
ATT : 70M
suffice to say nearly all adults of USA.
I am surprised how come not a single high profile person faces ID Theft and related troubles from these many data leaks !
It is all small pickles anyway compared to Sep 2017's Experian leak of 147M people's records:
https://www.consumer.ftc.gov/blog/2019/07/equifax-data-breac...
A credit reporting agency's information is all the important information you would need about someone to do something fraudulent with their identity.
Name
Phone number
Physical address
Email address
Social security number
Date of birth
Not only the phone number but the physical address?If this is true, absolutely outrageous.
> The hacker has said he is willing to reach “an agreement” with AT&T to remove the data from sale.
Might as well pay the hacker's ransom, AT&T to remove the data from sale otherwise if leaked; a massive fine (probably larger than the hacker's ransom) awaits you.
First T-Mobile and now (if true) AT&T. Let's see who is next to unveil another hidden breach... maybe Verizon has something to hide?
Based on past experience, unlikely.
Cox had to pay up over a few social engineering calls.
If we're just making stuff up, then maybe Verizon is the hacker trying to take down the competition? It's as likely as ATT being fined anything significant
If you mean, massive executive bonuses, and zero policy response by the government, then yes.
> We have determined that the types of impacted information include: names, drivers’ licenses, government identification numbers, Social Security numbers, dates of birth, T-Mobile prepaid PINs (which have already been reset to protect you), addresses and phone number(s).
Given the recent T-Mobile hack, if they can tag the data as coming from AT&T and being fresh, it might fetch a higher price either from AT&T, or data buyers. In other words, it could be a re-label of some older exposed data.
The hacker group is "ShinyHunters".
I imagine the difference in data since the Experian leak are for people that became adults since Sep 2017 or immigrants or some information about new addresses/names from moves/marriages, etc.
It's probably time to replace the old social security number system.
1. $10 off a new AT&T phone. When you sign a 5 year contract. Excludes all other offers.
2. A free month of AT&T limited service. When you sign a 5 year contract. Excludes all other offers.
3. Or absolutely nothing, like the last bazillion times.
The suspense is killing me. I hope it lasts.
EDIT: And who knows, maybe after insurance payouts and tax write offs and the usual corporate B.S., it’s still as profitable if they just sold it directly
That’s like saying “the house is on fire but there’s little smoke which is hopeful.” Of course they’re denying it!
I like the Red Pocket plans on Ebay, and they never asked for an SSN.
And in reverse, better brand recognition/(impression of) service quality allows the network operators to charge more and still get customers, the MVNOs need to be cheaper to compete with that.
I ported my landline to Page Plus in the late 2000s (which took over a week). I still have that number, and I have never spoken to a person when porting it between MVNOs (always over chat or email). My last port to Red Pocket took two days to get right. This can be a frustrating procedure, and many people prefer the major carriers for in-presence customer service for issues like this.
I have repeatedly switched between Verizon and AT&T when necessary due to phone hardware or coverage, and MVNOs usually allow this to be done (a limited number of times) through automated simcard changes with no customer service interaction.
The one surprising thing about my recent move to Red Pocket is the lack of voicemail in the included plan (it's available with a surcharge). I'm not certain if I miss it.
Also since it takes a few days to remove the lock, you can't impulse buy a car ( or another big ticket item).
At this point the only thing I'll ever need to do a credit check for is a new apartment.
The alternative is everyone gets (or does not get at all) credit on the same terms without regards to personal behavior or risk profiles, which is a valid option, but I would still think "disgusting" is a strong word to describe the prior scenario.
The disgusting part is the whole reason the providers demanded SS # is to defend their own interests to threaten clients with collection agencies and credit score dips. The neglect of these same now cause clients to risk getting credit score dips through no fault of their own.
Which part of this sits well with you?
> The disgusting part is the whole reason the providers demanded SS # is to defend their own interests to threaten clients with collection agencies and credit score dips. The neglect of these same now cause clients to risk getting credit score dips through no fault of their own.
I do not expect un-hackable systems and organizations to exist, so I would not find this “disgusting”, without knowing how the leak happened. It might be disgusting if there was a complete disregard for handling of the data, which might be true in this case, but I was responding to your comment as is there very idea that a mobile carrier can lend to a customer was disgusting.
Therefore there is not much value in fraudulent use of EINs.