Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
much thanks to @gary_host_laptop for the logo design :)
whoopsie doopsie!
ssns are probably useless by this point. cant wait for these people to leak our biometric data next, so we cant even change our ‘passwords’ anymore.
removed by mod
Or maybe they just need to practice better security. Never assume malice when something can be explained with inconfidence.
To be fair the threat actors are getting much harder to defend against
removed by mod
You also sound like you have never worked in cyber. As it turns out we are in the middle of a massive cyberwar
The SSA should just set a time limit, (let’s say 3 years,) and then publish a database of every single name, DOB, and SSN. Force the banks to figure out a new system of identification, by making the current system useless.
The current system is already insecure; SSNs were never intended to be secure. So why has the SSA tolerated this for so long? Just make the “in three years we’ll publish this live database for anyone to search” announcement, so banks are forced to develop a better system. It gives them the time to work on a new system, eliminates the need to keep SSNs secret, and the SSA can keep operating as normal.
This is one of those ideas I’d love to agree with, but I know the reality of the situation would mean negative consequences for the most vulnerable and disadvantaged, just like how current ID systems are now.
Really the US needs federal ID that are free and accessible through all post offices. The use of birth certificates and SSNs for the private sector is a failure of the federal government.
Identification for some reason is a cobbled-together mess of systems never designed for identification.
Granted: needs an implanted microchip connected via Bluetooth to a phone app to work properly.
I keep reading “social security number”, but still don’t understand why it’s possible to steal a person’s identity with their SSN. Is that all that’s required for identification? Some number?
Basically. It wasn’t meant to act as an identification, but people kept using it that way (probably because every citizen gets one at birth, so it’s the easiest proof of citizenship).
Getting names, emails, addresses, etc is pretty available. If you can link those up + an SSN you can open accounts pretty easily
Damn… that seems like a pretty bad system. Have there not been attempts to remedy that?
CC BY-NC-SA 4.0
It’s a key component. You need other information, but the SSN is supposed to be secret.
State-assigned unchangeable passwords that you hand out to 20-100 companies throughout your life (every job, every loan, every credit card, every financial account, every background check, every…)
This was 70 million people in 1 breach.
Keep in mind there are only 340 million people in the US, many of which are under 18.
We need a better system.
Wasn’t it India that leaked all of its citizens data?
Compensations should be paid out, watch how security grows
I have so much “free credit monitoring” from data breaches, I could leave it to my grandkids and they’d be set for life.
I have been informed my SSN, DOB, and payment information have been “compromised” at least 50 times in my life.
Just keep your credit frozen
Everyone’s data is now public knowledge
Why exactly did a telecom company need SSNs anyway?
Edited to add, this was a rhetorical question and more a comment on the awful series of systems in the USA that leads a SSN to be used by telecom companies.
It could be worse, companies could be asking for phones and then treating them as a SSN. Oh wait…
To run credit checks and be in compliance with anti-terrorism regulations.
But there’s no need to store them in what I assume to be plain text, this is negligence
I don’t remember that being part of the question I was answering. The question was why, not how. So the “But” seems confrontational in this context.
Is it dumb that they might have been in plain text or something close enough to it that it didn’t matter: of course. But that wasn’t the question.
Alright Mr snarky pants calm down, I was adding onto your comment not attacking it
That’s fine. In the future I’d start with “Also” instead of “But.” It completely changes the tone.
“Also” doesn’t make sense in context.
I think this miscommunication is more on you for taking it as an attack towards yourself when it was pretty clearly suspicious towards at&t, not you. In the future, I suggest trying to read things as charitably as possible. It will make forums a much more pleasant place if you don’t immediately assume aggression based on pretty innocuous words.
I didn’t see it as an attack. I saw it as very poor communication. “Also” would have worked way better as it would have been a “yes, and” instead of a literal “but.” I’m all about charitable readings. That’s why I didn’t attack them but pointed out their choice in wording. It was, as pointed out, snarky, not defensive.
Most people get suckered into signing a contract and using a “postpaid” plan, where you get the service for a month and then pay for it. That requires a credit check and credit reporting, since you get the service before payment. You don’t have to give out your SSN if you sign up for “prepaid” cell phone plans, which offer less discounts and benefits but are generally cheaper for the service they provide. The only catch is you pay for the month before you use it, but this makes canceling as easy as stopping payment.
Problem is all prepaid plans are MVNOs that throttle speeds
The main carriers offer prepaid plans, and there is no postpaid plan that doesn’t throttle speeds after you go over a certain amount when the towers a busy.
The MVNOs throttle and deprioritise in high traffic times too.
Also, throttling at 30GB is a lot Different than at 300GB which is what I went from on Visible to Verizon (visible is Verizon’s prepaid service, and it still worked like an MVNO by slowing down during the day and rush hour while Verizon clicked along streaming 4K)
I’m on a prepaid plan, and got in on a really good deal. They were offering $25/month off indefinitely for signing up for auto-pay (Basically 35% off, lol). It made the plan cheaper and better than most of their monthly plans. I’m happy to know it also saved me from giving out my SSN.
To collaborate more effectively with the NSA and CIA.
Oh, so that explains where the cocaine comes from.
Credit checks.
Nowadays they offer financing for devices. But even in the past it was required. They would determine the maximum number of lines you had available, and if there were any deposits to open new lines of service. Even before phone financing, those phone contracts came with hundreds of dollars of phone discounts at time of purchase and had hundreds of dollars worth of early termination fees and they want to make sure their customers had a good chance of paying if they left.
Antifraud
I think it’s related maybe to some anti terrorism law? In certain EU countries for example it’s impossible to get an anonymous SIM due to some anti terrorism legislation. SSNs are the only legal identification I guess?
This is a random guess off the top of my head. IANAL or know anything specific on US law.
What’s IANAL? Is it some new Apple product I don’t know about yet?
I am not a lawyer*
No, no:
iMac
iBook
iPhone
iAnal
It’s a joke, I guess.
SSN isn’t supposed to be used as a form of ID. Even says so on an SS card.
Yeah, about that.
It’s almost like the gov should replace the SSN system with something that addresses modern security concerns.
It baffles the mind the the USA doesn’t have a plain old photo ID
There is, just on a state level which does nothing for a nation with 50 of the fuckers
https://en.wikipedia.org/wiki/Real_ID_Act
Oh yeah, the federal identification card you can only get by… providing your social security card.
Not a federal ID, but a federal standard for State IDs. And not “only”, but SocSec card is one of the several forms of ID you could use. Not required and not enough by itself.
Tell me how I can get a star ID or a passport without a Social Security card
I can’t even donate plasma without my Social Security card
Social Security Numbers were never meant to be used for anything other than Social Security itself. Credit agencies use the SSN because they view it as an easy identifier and they didn’t have to create anything themselves.
It’s ridiculous how something that is supposed to be very confidential and kept private is asked everywhere you need services.
It was never supposed to be confidential. That need arose as a direct result of using it as an ID. If the SSA was the only organization using the number, (as originally intended,) then it wouldn’t need to be kept confidential.
But when the SSA gave every single person a unique number, other organizations went “hmm this sure would be convenient for differentiating individuals with similar names and DOBs.” So other organizations started using it for identification, and suddenly you needed to keep the number secret because anyone with your number could ID themselves as you.
The SSA needs to publish a public database of every single name, DOB, and SSN. Force organizations to figure out a new system of identification, instead of relying on an insecure and outdated system.
Like fingerprints
Oh wait…
But then I can’t google my number when I forget.
Will there be consequences??
SSNs are not secure and were never intended to be used that way. Just because companies misuse it for security to cut costs and apply credit ratings we never voted for doesn’t mean we should necessarily punish someone for leaking that data that is already like 99% public data because of all the previous leaks. It would be better if everyone treated it as public data and not some secret identity key. They should be punished for poor security and fix their shit, but SSNs are not private, not intended to be used for identity, and not secure.
and this is why i refused to give you my social back when i lived in your service area and had a land line installed.
Tried to delete my shit from their website, but they make it impossible to do so. I tried for about 20 minutes then eventually the site straight up refused to let me continue. I don’t even have AT&T anymore, I had their cellular back in 2013 and left them then, but the fuckers kept my info in their system this whole fucking time. No accountability for big corporations when they fuck up big like this. If it were one of us peasants, we would have been in prison for life.
I think the problem is there isn’t any law protecting your data
And that’s a huge problem. Only form of protection I have is freezing my credit with the three credit reporting assholes. I know it’s not much, but at least no one can apply for shit with my social.
It actually gives you quite a bit of protection. If you don’t have a open credit they can’t open cards in your name.
Just remember it is frozen
I do have 5 cards already, two cars and a mortgage. I just hope that whomever they call will ask for more info beside only the SSN. I have some companies nowadays like Amazon send me a text message for verification.
Fight Club had it backwards. Instead of attacking the banks to wipe out people’s credit someone should release everyone’s SSN. The mass fraud will make credit useless.
You first. Feel free to post it here.
420-69-8008
This is brilliant. The government could put out a searchable database.
Isn’t 70 million like 1/4 anyway?
Between this Anthem, Target, and OPM, it seems likely that most Americans have their SSN out there for criminals to buy.
deleted by creator
Is there any way we could do some sort of certificate based authentication? Instead of a social security number. I know people get really dodgy whenever you talk about ways to identify them but there has to be a better way than this.
Identity fraud can ruin your life permanently and at this point I’m pretty sure more people have been compromised than haven’t.
World coin!
(Not really world coin is a terrible idea)
Something like a ssh key or what they are now calling passkeys could work. The question is then who holds the verification database and how do individuals (especially those who can’t turn on their pc) keep their part of the key safe and do we also have some other kind of verification questions like we do now to make sure that it’s the right person when so many small details are shared or similar across people.
The problem is that something like this would end up being poorly designed in the real world.
I know. But we need a system better than what we have. Or a modification of the current system to make it a bit tougher for people to use someone else’s credit. I have a few ideas but they would only work for those of us who can handle the idea of ssh keys, crypto, etc. The average idiot isn’t going to be able to keep easy access to the data they need to prove they are who they say they are. And I’m definitely against going with DNA, fingerprints, facial rec, etc because of where that leads.
As it stands, way more kids than you may expect grow up to find their credit completely fucked because their parents are assholes. Anyone close enough to you can probably answer most of the questions about where you lived, what car you owned, etc. We need a drastically different system if we want to minimize identity theft but as I said above, the average person can’t handle the ways to do it right.
In theory it could be based on cryptos open ledger but with encryption instead of being open to the public, accessible only when the person holding the private key unlocks it in conjunction with the public key. Data stored and accessed in a DB that can be hosted anywhere and isn’t under the control of any one organization or agency.
Bill Gates has been trying for awhile.