MOVEit Hack at AutoZone
securityweek.com
securityweek.com
What damage could an individual suffer because the data a dealer of auto parts holds about them got in the wrong hands?
And is this just a theoretical danger "Someone could use the pieces of data to impersonate you and then run some kind of social engineering attack against you for which the involved companies will reject to compensate you" or did something like this ever happen to someone here among us and resulted in real financial loss?
UPDATE:
So far all answers are of the form "With the SSN, theoretically, someone could impersonate you".
That is what I meant with my "is this just a theoretical danger" question.
But what concrete harm could someone do with your SSN?
Did anybody here on HN ever had something happen to them because someone got hold of their SSN?
Very few companies have any way to differentiate between "person who has a SSN" vs "someone else who knows that SSN".
> some kind of social engineering attack
It's not really even social engineering at that point. It would take a lot of work to convince a company that person was not who they claimed to be.
Why is USA like this? The SSN thing has felt ridiculous ever since I moved here. “This is your SSN! It is super top secret important information, do not share with anyone ever” … “Oh also please give this number in plaintext to every company under the sun”
X.509 certs still have an authority issue with managing their life cycle, something I personally beleive a competent goverment could figure out, though, but I know there are security experts who are skeptical.
Biometrics offer another possible solution, but privacy advocates have been pretty, leery, perhaps for good reason, of mass biometric collection. What countries have successfully adopted a nationwide biometric identification system?
Other soltions?
I certainly agree SSNs as identification is a.complete.joke, but I am not sure the identification problem is completely a solved solution, either.
Growing up in Europe you never hear about identity theft as a thing that exists. I think it’s because you have to present official photo ID when signing any serious contracts.
And the liability for checking your identity falls on companies instead of individuals. This makes them care enough that the problem simply goes away.
PS: SSNs get recycled so they’re not only bad as passwords, they also aren’t very good at identification
> And the liability for checking your identity falls on companies instead of individuals. This makes them care enough that the problem simply goes away.
What nonsense, to claim identity theft is a thing that doesn't happen in Europe! People pretend to be other people to access things they shouldn't almost everywhere. It's not a problem that gets solved at a continent level either - the EU alone has 27 separate States with their own legal systems and rules.
Forging a government issued identity card or passport to fit your description and biometrics is a very different beast than skimming someone's SSN. You'd only go to that much trouble for some very serious payout potential.
According to this official EU website, identity theft is certainly a thing in Europe. https://www.enisa.europa.eu/publications/enisa-threat-landsc...
>>>Very few companies have any way to differentiate between "person who has a SSN" vs "someone else who knows that SSN".
that seems like a them problem, not a me problem. If they accept that as an ID, and then are defrauded for money why can than them make that my problem?
They will have lots of help making it your problem, from collections agents and courts and eventually the police.
> SSN should not be used for Identification
I agree that it shouldn't, but it is.
But the guys in the kitchen didn't flinch. They just went over to the run down part of town, and the next day all came back with fresh new SSNs. These guys had no idea what an SSN was, just that they needed one and that you can pay a guy to give you one. The owner doesn't care because it's not on him to police the legitimacy of the provided ssns.
So you end up with a bunch of people whose IDs were stolen having to wrangle with the IRS to not get taxed on the pay for a line cook or dishwasher. Totally idiotic and outdated system.
I think there is an employer obligation: https://www.uscis.gov/i-9-central/form-i-9-resources/handboo...
> AutoZone revealed that cybercriminals have stolen information, including social security numbers
So it’s more than just information about purchases.
With the exception of current and ex. employees (for which Autozone needs the SSN to withhold tax for the IRS) why would Autozone have the SSN of any customer?
I don't believe I've ever bought any car parts or supplies from Autozone, but I do buy from Advance Auto (they have retail stores near me) and I have never given Advance Auto my SSN to make a purchase (and if the clerk were to have asked, I'd refuse in any case).
Or, does Autozone have an Autozone co-branded credit card with a bank, and these 187k are those who have the Autozone credit card? That would be the only reason I can think of why Autozone would have customer SSN's. The SSN's of those customers that applied for the co-branded credit card.
I doupt they had been collecting retail customers SSNs on a large scale.
Consider those questions many services use to verify identity...things like cars you used to own, past addresses, banking relationships, etc. The leak could have exposed some of that directly or indirectly (like cc# include BIN, which gives a name of a bank you're associated with).
https://www.vice.com/en/article/43kxzq/dmvs-selling-data-pri...
Separately, I think the general public now has really high "cyber incident fatigue". It happens so often that nobody cares anymore.
Generating paper trails, arguing with call center people, waiting in line at the courthouse, etc. And that's just what I tracked for myself, not other related people like clerks and bankers that needed to research my case.
While I was swimming in that circle I heard about people who suddenly found warrants out for their arrest and shit, too. Don't let other people do fraud with your name, fraud is a crime and the man wants to nail someone for that crime.
Also protip: If you aren't with a 'dedicated internet bank', then change banks to somewhere local after you move. I thought I was sitting pretty with PNC's special out of market HYSA rates until they decided they needed me in their branch which was not very convenient since the nearest branch is about 400 miles away. This turned out not to be a very good security boundary because they also told my thief to come to the branch, and he did and got everything squared away for himself. Still resulted in PTO usage for no good reason on my end.
What would you do instead of SSN? Or how would you change the process of providing a number for income tax purposes?
I have no ideas for implementation, I just think we're having the wrong conversation.
As for what I’d do instead: create an application that is fully managed by the IRS and let me login with some combination of a client certificate, password, U2F device, TOTP, et. al. Have the IRS securely implement something like OAuth (I hear “securely” doesn’t quite fit with “OAuth” but they could implement something custom-built if they want to) so I can get the IRS to tell whoever I need them to tell that I am me.
Ideally, replace IRS with a purposeful identification organization for these purposes and let the IRS use what this new organization gives them.
We could easily avoid this mess of PII honeypots by repealing the federal income tax. The country was not founded with a claim on your labor.
Why is this so hard?
We need laws with teeth similar to HIPAA for personal data usage.
For example I replaced some kind of ignition pack on my car that had a multi year warranty. I had moved since I bought it an long lost the receipt. It started to go out, and I went to the store, gave them my name, and they were able to swap the unit out then and there.