Missouri website that leaked SSN
web.archive.org
web.archive.org
[1] [PDF] https://www.regeringen.se/4a76f3/contentassets/2c767a1ae4e84...
Edit: I read through your link and did some light browsing of my own (later stonewalled by the fact that I don't speak any of the Scandinavian languages). I don't see anywhere that a citizen can re-assert their right to privacy but that would seem to be necessary in some cases (e.g. Twitch streamers wanting to remain incognito to avoid getting SWATted or otherwise frequently visited by police).
It’s Jane Smith
Later that day…
Btw his place of residence was hardly secret, but it wouldn’t have been if he were prime minister of any other particular country either.
But if the case is officially resolved, well that's all good then. Nobody followed the Prime Minister to the theater and waited for him to leave in the dark of night. No stalking to see here, because Sweden. Move along.
That's because you usually can't.
In extreme cases you may be eligible for protected identity[1], but that status is not easily achieved.
[1] https://skatteverket.se/servicelankar/otherlanguages/inengli...
Rights depend on jurisdiction. I’m not aware of any right to privacy regarding place of residence or tax returns in Sweden.
A resident is entitled to file for a “protected identity” which would obscure their address, phone number and person number on these types of services. Even celebrities tend to avoid doing that unless they have a persistent stalker, because it leads to all sorts of practical problems when dealing with everyday administration.
Anyway, I'm pretty sure there's no such thing as a "high trust" society.
I'd argue this has a lot more to do with high trust local communities, rather than high trust "societies". Maybe I'm nitpicking, but the implication seems to be that somehow "American society" (whatever that means) is inherently low-trust. But the fact is America is so diverse, trying to create a useful comparative analysis there is difficult.
You can see addresses, if they own dogs, which cars they own, what salary they have (the site I linked needs payment for that, but there's other ways to get it for free), the companies they own or own a part of.
[1] https://www-svt-se.translate.goog/nyheter/inrikes/jurist-tar...
Whereas in Sweden the “person number” is public information and identity is authenticated and authorized in other ways (by showing a driving license or using a “bank id” app etc).
In the nordics how much tax you pay (meaning for most people you can just divide by twelve to determine salary) is also public info. As is how much houses sell for etc.
The wage secrecy in the US must be one of the factors contributing to the perpetual inequality.
We should have a kind of username / password system instead, where everyone has a unique ID and a separate private ID. We could even use something like RSA so you never have to give out your private ID to anyone.
https://www.todayifoundout.com/index.php/2019/01/how-exactly...
Kind of interesting how this HN post shows that transparency is important, because fixing an error like erroneous death in other countries isn't as bad as it is in the US.
Anyway I ended up writing about it as a use case for crypto, because the blockchain part of a transparent ledger is important for being a companion to the public memory: your birth, your marriage, your relationships with relatives, and your death.
https://www.dyingtowrite.com/posts/2021/33_crypto-isnt-what-...
I wouldn’t call those subtle.
Now, if you’re referring to only those politicians in your own country, then I have no reference for levels of subtlety involved.
BTW, California has a similar website that allows employers to put in SSN and DOB to lookup a teacher's license: https://www.ctc.ca.gov/commission/lookup
It seems that Missouri had a similar setup that required a teacher's last name and the last 4 SSN digits.
The SSN wasn't supposed to be used for identification at all, at first. [1] But the government decided that didn't apply to them, and then they decided that it didn't apply to anyone else.
1: https://www.nytimes.com/1998/07/26/weekinreview/the-nation-n...
We have bespoke solutions to keep passwords and numbers out of logs by obscuring certain key, value pairs, but that’s exactly what it is. Bespoke.
Those fields should be protected at all levels. I don’t know if I would go so far as calling it a cross cutting concern, but there is definitely a problem with stringly typed data that is a mix of PII, privileged data and common knowledge.
Any time our model is to be exposed to an unsecure context, it is reflected for these PII attributes and mapped into a special redacted variant of the same model.
For purposes of troubleshooting, the redacted model properties receive the sensitive data as a hash after it has been passed through salted SHA256. This allows for us to correlate sensitive things like SSNs between multiple log entries for the same work item, but unable to correlate across different work items.
If you haven't worked in a large company in recent years, maybe you haven't seen it, but it feels fairly standard these days.
Edit: that massive string on line 203 is awfully suspicious...
Double edit: there's another massive string a few lines above that, and the script on line 1188 is pretty interesting too
> Though no private information was clearly visible nor searchable on any of the web pages, the newspaper found that teachers’ Social Security numbers were contained in the HTML source code of the pages involved.
And the layout of that site - I suspect when you clicked through to look at a teacher, it would display the Name + last 4 of their social security number with their teaching credentials. I suspect that if you viewed source on that page, the full SSN was in the retrieved data but the page was just displaying the last 4 digits.
Can't confirm without the Archive site actually pulling live data but it seems to line up.
There's a bunch of <input type="hidden"> elements in the search page, so I guess they did something similar to hide the information from their `select *` that wasn't meant for public consumption.
Edit: looking at the code (directly referencing XMLHttpRequest etc.) it might also be raw HTML being injected into a table somewhere...
Edit 2: based on the "base64" comments, I'm guessing the "view state" (ASP term?) was not encrypted and contained some secret info. There are other systems from other states running on similar tech, but they seem to encrypt their viewstates...
And the source seems to indicate this is the "public ssn search", and that a "search by full ssn" probably also exists.
E.g.:
let SSNSearch = document.querySelector("#pnlSSNSearchHeader");
let SSNPublicSearch = document.querySelector("#pnlSSNPublicSearchContent"); cpeSearchOne_ClientState: false
ctlYearList$ddlYear: 2022
cpnlDistrict_ClientState: false
ddlDistrict: 096098
cpnlEducator_ClientState:
cpnlSSN_ClientState:
cpnlSSNPublic_ClientState: true
txtLastNamePublic:
txtSSNPublic:
I suspect the real problem is with the page that would be rendered as the results if it weren't currently shut off. <option value="081097">PHELPS CO. R-III - 081097</option>
Am i missing something here?From the original Post-Dispatch article: "Though no private information was clearly visible nor searchable on any of the web pages, the newspaper found that teachers’ Social Security numbers were contained in the HTML source code of the pages involved."
I presume this is a poorly executed attempt to be fast and responsive by "pre-loading" all of the data required and then using the search box as a filter on the client.
Edit: My mistake - I misinterpreted wrong IDs, these are not immediately here.
<option value="048914">ACADEMIE LAFAYETTE - 048914</option>
etc.The original stltoday article said the information was "contained in the HTML source code" but that seems to be not the case.
In my opinion, the "html source" means the document as it was sent over the wire before JavaScript modifies the document.
It’s easy to imagine that ssns are in search results. Eg it’s plausible that when you search for a teacher, the returned html contains tags with id where that is the primary key in the DB, which happens to be the Ssn etc.
Still interesting, but this page doesn't answer many questions.