Hacker steals government ID database for Argentina's entire population
therecord.media
therecord.media
When national IDs were issued each one got a "tramite number" that I'm guessing was sequentially assigned when the physical ID cards where issued.
Because this number is vaguely random and is printed on the actual physical ID card, it was used as a password on government apps (for example, for getting authorization to move around during covid). To log into the app, you enter your national ID number and then the "tramite number" that is printed on your physical ID card.
Of course, the number can't be changed, and is stored in plaintext in a large database somewhere. It therefore makes for a horrible password.
The database in question just got stolen, and the aforementioned apps now include all sorts of sensitive PII.
If you are asked to provide your SSN and you ask "For what purpose?" and the requester lies and says "So I can choose my lottery numbers", it's not clear that you have broken the rule by revealing your SSN. However, perhaps the requester is breaking the rule (and perhaps they should know the rule, assuming they have a card themselves) in this scenario, but it's also not clear what action they would have to carry out with the SSN in order to have used it "for identification".
For example, if a system designer uses SSNs as a primary key in a database, they can claim that's just for simple indexing, and that they are still using name and address or photo to identify someone. A system designer could also claim that they were only using the SSN as a (weak) "something you know" factor (among many other factors) in authentication, which may not amount to using it "for identification". Asking someone their date of birth (to be checked against another source, or on a later interaction) doesn't mean that your date of birth identifies you, since millions of humans share the same birthday.
These are in no way secret, I have no idea how people are okay with this. You can easily social engineer so many critical services if you know somebody's SSN.
And entire country just got doxxed. That's insane.
That on top of the fact that having two separate databases means twice the probability of different bugs in two different systems.
We must all move away from using PI as passwords, that's all we need to do. Then this problem will go away.
You make it sound like it's an easily solved problem, which it apparently isn't.
So as to... I don't know, brag that you're collecting all this information, that is to be inevitably leaked in a while? To make people feel safe, while clearly indicating the highway exits to avoid if you actually steal a car?
This is done in France when it catches you driving too fast. "ABC 123" you're going too fast! It's a bit jarring your plate up on a screen so it works kind of well against speeding. They don't need to store your plate to use this feature.
Of course plates are being scanned (and probably stored) all over the place now (toll booths, big roads in & out of the cities), not denying that.
Also in a not very surprising turn of events, a lot of the screens just show a fixed plate these days which makes you wonder which component broke (is it the screen, or the scanner?)
It's very likely that this data is also stored in some government database, which I hope will never get breached.
However are the regional governments supposed to develop their own solutions, or are they using a centrally developed database, just with local unconnected instances?
https://en.wikipedia.org/wiki/Resident_registration#Germany
I was also told something on identity cards only lives on the cards, but cannot find the source or details on that.
edit: Looking it up [0] it looks like there is far more data there, all in a central database since at least 2015 (not sure how it worked before).
[0]: https://de.wikipedia.org/wiki/Melderegister#Deutschland
From your link it seems i was not entirely misinformed: "Contrary to popular belief, there is no central administration of resident registration in Germany. The exception is the registration of resident aliens (see Central Register of Foreign Nationals). Registration is organized by 5283 local offices throughout Germany.[18] "
I'm unable to find the part about cards. will edit or reply more if i do find it.
There is something about sharing that information, but I can’t say I understand the legalese ;)
However, there here is a standard API which allows some entities to query all those decentralized registers. It is designed to make it hard to siphon out all data at once (which hopefully trips audit systems in enough places that someone cares to look into).
The only centralized database of that kind is the one at BZSt, which contains far less data. For the moment access is limited to tax-related issues but it will be soon expanded to a centralized base data registry (Registermodernisierung).
Japan is really good in this, they store everything on paper and fax it around.
They’re also starting with a national ID now though.
This is a predictable outcome of a government creating then storing long term secrets in a database. Governments are not good at keeping secrets. The data will leak.
All of this information is in multiple single databases maintained by insurance companies in the US. And that data is in turn linked to all sorts of behavioral and affinity data. GEICO knows more about you than DMV.
The alternative is for government to have 90% subsets of the same data in a a thousand different databases, one per-department, per-jurisdiction.
Yeah, I can see a few problems with that.
The only non-obvious information is the labor identification code. Except for that, it's just "who exists and how do we call them?"
My guess is that this was slightly afterwards - I know if I had access to the db and saw some information being posted on twitter, I might want to cross-check (well that make more sense, than the poster looking up these people and doxing them instantaneously)
Hope he serves as a lesson of how to not behave as a public servant.
IT talked to Twitter and found a very narrow amount of people with the ability to do this.
> However, The Record contacted the individual who was renting access to the RENAPER database on hacking forums.
> In a conversation earlier today, the hacker said they have a copy of the RENAPER data, contradicting the government’s official statement.
> The individual proved their statement by providing the personal details, including the highly sensitive Trámite number, of an Argentinian citizen of our choosing.
Based solely on the exposed field names those are not typical for government databases either, so this might have been reconstructed from a report or something.
It also looks like the underlying permissions scheme is garbage, as there is literally no reason for this volume of data to be exportable by a random -even authorized!- user at the reported location.
The Turkish IDs have a "national ID number" (assigned to each citizen, is for life and is unchangeable) and a serial number for the ID itself. You need the national ID number to do certain things, similar to SSNs in the US. Similar to SSNs in the US, it's an absolutely horrible form of identity verification/authorization.
OPM subsequently confirmed that investigators had "a high degree of confidence that OPM systems containing information related to the background investigations of current, former, and prospective federal government employees, to include U.S. military personnel, and those for whom a federal background investigation was conducted, may have been exfiltrated." The Central Intelligence Agency, however, does not use the OPM system; therefore, it may not have been affected.
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
Instead, give everyone a digital certificate with the private key stored in smartcards that don't allow anyone to copy the key, only to use it.
You could, of course, use real passwords, like every single service out there on the internet. Force some level of 2FA for security as well and you should be fine security wise.
Incremental plaintext numbers are not passwords, though. European countries have solved this problem in a variety of ways (that have been made cross-compatible and federated, even) and none of them use numbers on identification as a security number.
It can be done. Not everything must be electronic, and not everything must be centralized.
Only problem is you have to install a browser plugin that has to be compatible with your browser version and some non-technical people get confused. Apart from that it's actually a pretty good system.
It's now being replaced with a smartphone app, one that uses servers in the USA which poses all kinds of GDPR / privacy issues.
The smartphone app has significantly improved the user experience and can rely on biometric functionality, SMS and other verifications.
Overall, I think it's worth the risk if it's sufficiently defended cyber-security wise
And btw ID cards in the EU have chips with all the basic information on it as well, for use at airports and similar, and there are plans to use e.g. an app which reads from the chip to confirm possession of the card, and compare the photo on it with a selfie you take and confirm your identity digitally.
With any luck, the leak forces them to abandon it. But given people reporting on other comments that the leak was already denied, I'm not holding my breath.
https://www-lanacion-com-ar.translate.goog/sociedad/tras-un-... (via Google Translate)
Consequences like these just demonstrate the case.