13 ms·
Inside the "3 billion people" national public data breach
- janalsncm 2y agoAre there any ways to check the breach to see if my information is there, other than downloading it myself? I’m not sure of the legality of doing so.
- jaderobbins1 2y agoThere is a free service call Have I Been Pwned which uses your email address to see what data breaches you are part of (https://haveibeenpwned.com/ https://haveibeenpwned.com/). While it uses your email to check (not SSN) odds are if they have your SSN in the dataset they also have your email.
- notpushkin 2y agoThe OP post says that emails in this breach are paired with random names and SSNs, so it's not a good indicator.
- jaderobbins1 2y agoOh sorry, I missed that!
- xf5f 2y agoI've seen https://npd.pentester.com/ https://npd.pentester.com/ floating around
- heartbreak 2y agoThe data seems to be at least 15 years old.
- xf5f 2y agoFor me, it matches (DOB, last 2 of SSN) and seems fresh (has newest address, as well as older ones).
- datadrivenangel 2y ago"there were no email addresses in the social security number files. If you find yourself in this data breach via HIBP, there's no evidence your SSN was leaked, and if you're in the same boat as me, the data next to your record may not even be correct. " Seems like Troy is skeptical about this being a real full breach?
- fullspectrumdev 2y agoA lot of these data brokers hold wildly inaccurate information.
- LeifCarrotson 2y agoYou too can be a data broker! for (i = 0; i < 900000000; i++) insert(first: random_firstname(), last: random_lastname(), ssn: i); Does anyone really really care if the name is accurate if the SSN is present? More than half of the SSNs in the above dataset are valid.
- ryanisnan 2y agoYou probably are posting this as a joke, but without a clear technical solution to this problem, flooding the industry with bullshit data seems like a great avenue.
- autoexec 2y agothat was the idea behind certain applications and add-ons that would browse around to popular websites and randomly click ads so that marketers couldn't tell your actual interests from fake ones. Unfortunately that strategy is deeply flawed and dangerous because nobody cares if the data they have on you is accurate or not. They still can, and still will, use it against you at every opportunity. Every scrap of data they have, accurate or not, can be used to hurt you. The only way to flood data brokers with garbage data that can't hurt anyone is to fill it with entirely fictitious people who somehow can't be mistaken for any actual people. Even that runs the risk of hurting real people though. For example, an insurance company might go to a data broker and ask for the number of people within a certain neighborhood or zip code who bought fast food more than once a week in the last year and how many have a gym membership. If the number of frequent fast food buyers is higher than it was last year and/or the number of gym members is lower the insurance company might decide to raise the rates of every single member within that neighborhood or zip code. Even fake people could skew those numbers if their fake data said they lived in those zip codes or neighborhood and ate out a lot or didn't have a gym membership. Indirectly, the fact person is mistaken for being a real one in that community. The best way to deal with data brokers is to regulate them with strong data protection laws. Anything you give them risks hurting someone and gives them another data point to sell.
- CrispyKerosene 2y agoTroy mentions "data opt-out services. Every person who used some sort of data opt-out service was not present." Anyone have experience with these sort of services? A search brings up a lot of scammy looking results. But if services exist to reduce my profile id be interested.
- silisili 2y agoMany seem scammy, and I went through the search before and gave up. Then, as fate would have it, a HNer(tjames7000) mentioned he made EasyOptOuts for this reason, so I signed up. Cheap, seems effective, absolutely no complaints.
- laweijfmvo 2y agoI have used (free trials) and currently use (discounted annual) a service called incogni. It's hard to really verify what's going on, but they at least show the brokers they are contacting on your behalf, and I've directly received confirmations from some. Anecdotally, searching my name on Google pretty much no longer returns those scummy "People Finder" pages that just scrap any public records they can find. That said, I hope incogni is happy enough with my money that they themselves don't do anything scummy. Also, freeze your credit at the big three. do it now.
- deleted 2y ago[deleted]
- 0x2a 2y agoAnd turn on the Global Privacy Control header in your browser: https://globalprivacycontrol.org https://globalprivacycontrol.org
- JohnMakin 2y ago> Anyone have experience with these sort of services? Quite a bit. Often if you request removal or opt-out, you'll reappear in a matter of a few months in their system, regardless of whether you use a professional service as a proxy or do it yourself. The data brokers usually go out of their way to be annoying about it and will claim they can't do anything about you showing up in their aggregated sources later on. They'll never tell you what these sources are. A lot of them will share data with each other, stuff that's not public. It's entirely hostile and should be illegal. I am trying to craft a lawsuit angle at the moment but they feel totally unassailable. I'm extremely skeptical of any services that claim they can guarantee 100% removal after any length of time of longer than 6 months. From my technical viewpoint and experience, it is very much an unsolved problem.
- layer8 2y agoTL;DR: > an intriguing story that doesn't require any further action.
- 29athrowaway 2y agoTime for services everywhere to stop using SSNs for identification and for the US to move on to a more advanced form of identification. And lock your credit.
- wood_spirit 2y agoWhat can an attacker who knows your SSN still do with that information nowadays? Genuinely curious, as the SSN is just this strange in distinct password thingy the Europeans like me hear about on HN but have no actual parallels with.
- blackeyeblitzar 2y agoThe SSN is used as a way to genuinely identify someone, unfortunately - it’s like having to give out your password each time you rent an apartment or buy a car or obtain medical care or any number of other transactions. Having this info (along with other basic info like name/address/date of birth) lets you effectively pretend you are them. You can take loans out in their name or call some service to do a password reset (since you have all the info to verify you are them) or whatever else. But it’s not like there is one particular way in which the information can be used - it’s dependent on what businesses LET you do with that info. In 2024, NO business should use SSN to verify identity or authorize sensitive transactions but many do, and what they let you do varies significantly.
- acdha 2y agoI think it’s important to distinguish between identification and authentication. As a unique database primary key, they’re fine. The problem was when a bunch of businesses decided it’d be too expensive to check things like government ID and started using them for authentication purposes. Nobody blinks an eye at using a phone number or email address on an application, but we should treat using your SSN or past addresses for authentication the same way we would if someone says they could approve a loan if you know your phone number and zip code.
- quantumfissure 2y ago
- hypeatei 2y agoDoes anyone else just not give a fuck at this point about their SSN? I feel like maybe early 00s this would be scary but it's clear that everyone's SSN is out there already or waiting to get breached from a shady private data broker. The problem lies in how institutions treat the SSN, not the number itself.
- rolph 2y agoif you know place of birth, and place of ssn application, you can determine most of the ssn. the final 4 are supposed to be random, but are blurted out to rooms full of people and tech, during service. the integrity of SSN security, was lost a long time ago
- enlightens 2y agoas of 2011 they are fully random instead of being based on geographical region and groups https://www.ssa.gov/employer/randomization.html https://www.ssa.gov/employer/randomization.html
- xboxnolifes 2y ago> the integrity of SSN security, was lost a long time ago The security never existed, since they were never intended to be secrets. At best it was theater.
- acdha 2y agoYes. 99% of the time “identity theft” means a huge company cut corners on their security policies and wants us to subsidize their negligence. Every so often there are cases like that guy who pretended to be his former coworker for decades but they’re rare enough that they make the news internationally. Most of the time it used to be things like instant credit applications where they didn’t “slow” purchases with ID checks. The good news is that companies have lost the presumption of competence there. In the 80s if a company said they’d confirmed that an applicant was you using your SSN, a lot of people would falsely believe that was sufficient but by now they’re not going to get far if they sue you unless they can provide better evidence because everyone knows huge breaches have happened many times.
- uticus 2y agoI’ve finally figured out the play: war of attrition. Eventually enough data will be leaked to make moot the benefits of securing any personal data. At that point everyone stops trying and moves on to more financially rewarding activities. I mean even if I’m an elephant, and data breaches are blind men, eventually enough blind men will draw a true comprehensive picture.
- johnnyballgame 2y agoExtreme Privacy by Michael Bazzell is a great resource to learn how to limit exposure to these aggregator services. https://inteltechniques.com/book7.html https://inteltechniques.com/book7.html
- NoMoreNicksLeft 2y agoCan't the SSA just issue 330 million new social security numbers, and tell people to be more careful with them from this point forward?
- blackeyeblitzar 2y agoThe SSA has shown absolutely no urgency on this issue. Their existing policy is that having your SSN compromised is not enough to issue a new number. You have to actually be a victim of a financial or identity crime that abused your SSN for them to consider a new number. In reality what they should be doing is giving everyone accounts that can generate tokens for use with each transaction, to maintain a trail of where leaks originate and also to expire these temporary tokens. Instead they’ve stuck to this archaic system.
- Dylan16807 2y agoThey can't issue new numbers in bulk without revamping the system because they'd run out. The urgent fix wouldn't work. If the system needs to be revamped, then step one should be pressure/force so that companies stop treating the numbers as secret. And if we do that we don't need new numbers anymore.
- acdha 2y agoThe SSA specifically told people not to misuse SSNs this way and it seems like a poor use of taxpayer funding to spend billions bailing out businesses’ bad decisions, even if that was legal (Congress would have to specifically authorize it), since we’d be back to the same problem with five years. If we were going to do something, we’d make government ID include an NFC token for PKI purposes since public keys can’t be compromised in the same way, but nobody is jumping to pay for that, especially in a country where you have so many people prone to wild conspiracy theories (I am especially amazed by the guys who freak about a national ID as big brother but never say a word about the credit reporting industry) and the enduring “Mark of The Beast” religious fears.
- toomuchtodo 2y ago
- blackeyeblitzar 2y agoIt is crazy to me that data brokers are even a legal form of business. All of these services should be opt in at minimum. If they are obtaining publicly available information and making it easier to access, they should have to maintain insurance or a deposit with the government to compensate victims of cybersecurity incidents. Telling people to get credit monitoring is in NO WAY an acceptable way to make us whole. They need to pay for a lifetime of monitoring and INSURANCE up to the net worth of affected individuals. This needs to become law ASAP.
- SteveNuts 2y agoWe're two decades into "The Digital Millennium" and our laws are still stuck in 1999 (except for the ones that ya know, allow dragnet spying). I'd wholeheartedly support any candidates that push for a data/privacy "Bill of rights".
- acdha 2y agoI’m optimistic for Harris, not just because she’s so much younger and less beholden to industry, but because she created an entire unit for privacy protection when she was the California AG: https://oag.ca.gov/news/press-releases/attorney-general-kamala-d-harris-announces-privacy-enforcement-and-protection https://oag.ca.gov/news/press-releases/attorney-general-kama...
- krageon 2y agoThere has never been a US president that had anything close to ethical behaviour (to wit: the ones that existed after drone strikes became a thing all signed off on drone strikes. Those hit a lot of innocent people. The US has never stopped having slavery. I could go on). It is really the height of fanciful thinking to believe that the flavour of the month US leader will be any different.
- acdha 2y agoThat’s absurdly naive – it’s like saying every picture is the same because they aren’t entirely (255, 255, 255) pixels. If your goal is to do anything other than feel smug, consider the impact such non-serious positions have on how other people will perceive anything more serious you say.
- throwup238 2y ago> While the specifics of the data breach remain unclear, the trove of data was put up for sale on the dark web for $3.5 million in April, the complaint reads. I guess they failed to sell it because links to the leaked data on usdod.io have been available on Breachforum/Leakbase for over a week now. Someone created a magnet link yesterday and it's fully seeded so speeds are fast. The data in the breach is irreversibly public now.
- bhaney 2y ago> Someone created a magnet link yesterday Are you against simply sharing the infohash here? I'd like to download the leak to see what information it has on myself and my family, but I don't really relish the idea of signing up for a breachforums account and sifting though its posts if I can avoid it.
- flockonus 2y agofyi that is likely to be a crime, at the very least has been cases of websites being punished for linking to illegally distributed IP (even if not hosting it).
- bhaney 2y agoI'd be worried about legal repercussions if we were talking about the latest Disney movie, but this is merely the private information of a billion people. Never seen IP law give much of a crap about that before.
- quantumfissure 2y agoFor non-Americans (and Americans) that don't quite understand what SSN is and why it's a problem, CGP Grey [1] has a great (and short) video about the history and why it's not technically an identifier, but has become one. [1] https://www.youtube.com/watch?v=Erp8IAUouus https://www.youtube.com/watch?v=Erp8IAUouus
- fragmede 2y agoThe video doesn't quite get into the problem of identity theft, which is when someone uses your stolen creds to claim they are you, and then go on a shopping spree which may include buying a car under your name. You shouldn't be liable for debts incurred after having your identity stolen but proving that is a lot of work.
- adamomada 2y agoI never really understood why the onus is on any person to prove they didn’t do something. Shouldn’t the shaggy defence be sufficient? e.g. You get hauled into court for a lawsuit demanding the loan repayment, for a loan someone else used your name to get? - It wasn’t me. https://en.wikipedia.org/wiki/Shaggy_defense https://en.wikipedia.org/wiki/Shaggy_defense
- jandrese 2y agoThe reason the Shaggy defense doesn't work is the default assumption of the courts is that you're a deadbeat trying to game the system. This assumption comes about because in the majority of cases it is the truth. The system would be a lot nicer if there weren't people trying to scam it every hour of every day of the week.
- pocketarc 2y ago> This assumption comes about because in the majority of cases it is the truth. Are we saying that if you can show you have enough income / assets, it'll be that much more likely that you'll be fine in those cases?
- jpcookie 2y agoAnd where is this information that this random group supposedly has? I have yet to see proof of that being real
- lynndotpy 2y agoI was able to get a hand on it, and I was able to confirm that some records of loved ones are indeed present (although mine was not.)
- seanw444 2y agoBreachForums I believe.
- banana_giraffe 2y agoIt's real. A few people I know are in the dataset. The SSN is problematic, but personally to me, the more troubling data is a seemingly complete, or at least complete enough, address history for the people I checked for. It doesn't have dates, but just having the addresses could cause major problems for spear phishing attempts.
- toomuchtodo 2y agoAhh, cool, pour the corpus through GPTs and start tweeting Congressional rep personal info at them until they pass a law to outlaw data brokers (in keeping with historical precedent [1] [2]). [1] https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act [2] https://jolt.law.harvard.edu/digest/dodging-the-thought-police-privacy-of-online-video-and-other-content-under-the-bork-bill https://jolt.law.harvard.edu/digest/dodging-the-thought-poli...
- conductr 2y agoFor argument sake, instead of outlawing data brokers wouldn’t it be better to design a better ID system that renders one’s name, dob, and SSN as harmless information? I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that.
- toomuchtodo 2y agohttps://news.ycombinator.com/item?id=41249568 https://news.ycombinator.com/item?id=41249568 https://news.ycombinator.com/item?id=40961834 https://news.ycombinator.com/item?id=40961834 TLDR Login.gov, and publishing a circular to allow businesses to use it to identity proof. Push all liability onto the business for losses if this method is not used to identity proof. ID card as ljm mentions, such as a passport card. Very similar to credit card EMV chips and the liability shift from magstripe. > I don’t know what that would look like but if I had congresses attention I’d like them to fix the problem rather than playing whack-a-mole with banning data sources. I don’t think any actual solutions come from that. Aggregating data means it can be lost. You must therefore make aggregating and storing data toxic, and impossible to be leaked through eventual mismanagement.
- ljm 2y agoIn many countries in Europe, your ID card contains a chip with a cryptographic key, much like chip&pin on a debit or credit card. Those bits of information are worthless when you need to create a cryptographic signature with your ID card to do almost anything important. If the card is lost or stolen they can just remove your old one from the keyserver. It's literally just public key crypto. Identity theft is rampant in the countries that don't have such a system and basically require you give them increasing amounts of private information to prove who you are. In the UK that's every address you've lived in for 5 years, your council tax bill, your energy bill, your bank statement for a month... all because British people think an ID card means you'll get stopped on the street to show your papers.
- tmaly 2y agoI sure wish the US had a version of GDPR. I get a data breach notice at least a few times a year. I got one for my kids two months ago for their medical data. I thought HIPPA had huge penalties but I guess not.
- dgellow 2y agoDoesn’t California have a similar set of regulations?
- EvanAnderson 2y agoFor years I've said the entire SSN database just needs to be published alongside legislation strictly assigning liability to any company who defrauded as a result of using the SSN as a "secret". That would fix the problem with SSN's and "identity theft" quickly. Part 1 has been accomplished. Let's get part 2 going! Aside: It amazes me how the American public has allowed defrauded companies to assign the company's loss as a liability to innocent individuals (in the form of "identity theft"). It would be great if we could get that changed in the minds of the public. A well-informed public could collectively turn "identity theft" into the "bank's problem" (from the old adage "If you owe the bank a billion dollars they have a problem..."). The insurance industry would swoop in as the defrauded parties start making claims and shoddy security practices would get tightened-up. (Edit: I fear insurance companies coming in to "fix this" to some extent-- citing my experiences with PCI DSS compliance auditing and Customers who have had 'cyber insurance' policies coming with ridiculous security theatre requirements. Maybe we can end up with something like a 'cyber' Underwriters Labs in the end.) (Also: Yikes! I hate that I just typed 'cyber' un-ironically.)
- sorokod 2y agoThe obligatory Mitchell & Webb sketch https://m.youtube.com/watch?v=CS9ptA3Ya9E https://m.youtube.com/watch?v=CS9ptA3Ya9E
- EvanAnderson 2y agoYES! I couldn't remember their names and absolutely was thinking of this.
- janalsncm 2y agoIdentity theft is a very clever term to shift blame from the company to the consumer. https://youtu.be/CS9ptA3Ya9E https://youtu.be/CS9ptA3Ya9E It’s a comedy bit but I take its point seriously: if the bank gives away money, it’s the bank’s job to make sure it is repaid. Not mine, unless I was actually a party to the agreement.
- 2y ago
- ghm2180 2y agoI am just dreading the day when a near simultaneous cyberattack on a high number of(more vulnerable like middle-lower income individuals) start in a DDoS fashion: 1. Credit histories will be(unlocked) used to file multiple credit applications and tax credits will be applied for. 2. Multiple Cell phones will be hijacked through Sim Hijacking or other zeroday attacks to make it very difficult to get back in. 3. A person's profile will be used to attack the most vulnerable things: - Their families will get fake calls to create confusion. - Their financial services will be frozen or worst weak 2fac auth ones will be compromised. 4. Deep fake image and videos will be created from compromised accounts to sow further mayhem. This already happens in targeted and one startegy of teh other fashion. Imagine what one could do with a bit more compute and completed profiles and orchestrate this kind of terrible vengeance.
- kurthr 2y agoLuckily, there aren't multiple hostile nation states capable of this. /s All that I can see preventing it is deniability and eco-political risk.
- njarboe 2y agoI wonder how many governments have this capability right now? I would guess at least three.
- nc0 2y agoAs far as I know, most of the developed and in development countries have this kind of database, I also know some poor countries does too, but they often lack security measures
- lifeisstillgood 2y agoI am wondering what the numbers are like for this to be realistic. I am not too sure of the end goal other than general chaos. Let’s say it’s 2 days of an attack, (that’s about how long any co-ordinated response would need at minimum). So attackers need to sow chaos across the USA. They apply for a million unsecured loans of say 20k each. That’s 20 billion. I honestly don’t know what the daily personal loan application rate is, but america has about 150M adults, 1% of them applying on the same day will not only raise flags but would basically grind the system to a halt - each loan office would have daily maximums and a massive spike coukd not be handled. And once the massive crowd is noticed and made public then the financial immune system comes into play. I can imagine taking out the cell network through a sort of SS7 ddos, but I suspect that cell towers might have a dose more vulnerabilities (probably not as basic as all the admin passwords are ComC4astSux but close) In general Chaos seems to come from attacking the limited services that act as our safety net (ambulance, police, sewage, electricity). We know these are vulnerable in non obvious ways - crowdstrike for example. Making otherwise fit and healthy citizens have a shitty day is less impactful than we might think - it will be the “blip” day - as I say 48 hours later the Treasury secretary goes on TV and announces all personal loans that day got cancelled or some other fix - finance has a fairly good immune system when it sees the need. But overall, if we are going to worry about some attacks, let’s look at the ones that attack our freshwater supplies - and that might not mean some terrorist - in the UK our sewage handling has been under attack by Private Equity for decades and SWAT teams are not allowed to shoot people in Belgravia
- velcrovan 2y agoEven before this, anyone operating a service who isn't treating SSNs as public knowledge in 2024 needs to be, well, shamed or penalized or something.
- JumpCrisscross 2y ago“The database DOES NOT contain information from individuals who use data opt-out services. Every person who used some sort of data opt-out service was not present.” Like what?
- fnord77 2y agoFrom the NPD website: > Please be advised that we will not collect, use, disclose, sell, or share the sensitive personal information or sensitive data of California, Virginia, Colorado, or Connecticut residents as those terms are defined by the CCPA/CPRA, VCDPA, CPA, or CTDPA, respectively.
- smcin 2y agoDiscussion from last week: https://news.ycombinator.com/item?id=41184420 https://news.ycombinator.com/item?id=41184420
- puzzledobserver 2y agoSeveral other commenters have brought about the sneaky wordplay involved in saying "identity theft" instead of simply calling it "fraud on the bank", and somehow turning the person into the victim rather than the bank that has been defrauded. Has anyone tried to argue this point in court? Has this survived / how did this terminology shift survive judicial scrutiny?
- left-struck 2y ago> The problem with verifying breaches sourced from data aggregators is that nobody willingly - knowingly - provides their data to them This is a bit of a tangent but I feel like if we can prove this statement then these data aggregators should be made illegal. How can you consent to something that you don’t know you’re consenting to? Likewise why do these entities have the right to collect detailed personal information like SSN without your explicit, beyond reasonable doubt, consent? To me this is the most obvious failure of the legal system, it clearly goes against well established legal principles that a basic requirement of an agreement is that all parties know what they are agreeing to. Obviously there is some leeway with agreements where it’s not possible to clarify every eventuality but lets say if you’re applying to rent a place through an online form and that form shares your SSN to a data aggregator, it should be extremely clear about that, and possible to out out while still allowing you to complete the rental application without discrimination. It’s like, it should be possible to show that no one, with in reason, consented to sharing their data with this aggregator because no one is able to confirm that they did. Sure one person could forget, or lie, but 100s of millions of people? No. Clearly almost zero people knowingly consents.
- deleted 2y ago[deleted]
- Hnrobert42 2y agoI have been using a different site@mydomain email address for every service I've used for the past 15 years. I can point to exactly which site breach furnished my email address to the aggregators.
- al_borland 2y agoCare to call out some bad actors so others know to avoid business with them? I recently started using unique emails for everything I sign up for. Thankfully I haven’t seen anything yet, but I have little hope it will stay that way.
- klabb3 2y ago
- blindriver 2y agoWhy are data aggregators legal? In California can we create a proposition to shut them down in the state?
- idontknowtech 2y agoThis sort of stuff will continue happening until the regulatory framework acknowledges a fundamental consumer right to privacy. If a data broker collects data without the consent of the consumer, then their only real risk is a class action lawsuit which drags on for six years, gets settled for a few days profit, and the consumer gets $13.50 after the legal fees. This massive skew in the risk reward calculus of data brokers is why we have the problem. Because there's little to no real downside, the trend is automatically collect as much data on as many people as possible. Fixing this means big, mandatory, cash penalties in the law code - say $5k per consumer data leak, directly to the affected consumer, with added penalties if the company lies about the leak or delays payment. The fine must be big, mandatory, and paid directly to the consumer. Only that changes the risk reward ratio. In that new world, companies would have to re assess their risks. They'd either build invulnerable systems and hire a lot more people reading HN to protect their golden goose, or better still they'd decide to exit the business entirely. That sounds bad, but the only reason the industry exists is because regulators failed to foresee massive leaks like this happening every three months. We need a consumer data privacy law, with massive fines, to force companies to change their behavior. What we're doing now clearly does not work.
- esalman 2y agoThey should tax companies so that operating data centers become more expensive. Increase price of electricity or property tax. That will inherently force companies to collect and store less data, hence less damage from breaches.
- deleted 2y ago[deleted]
- luxuryballs 2y agothe government should have put out honey pots or something, or maybe it’s time to get new numbers and just invalidate all the stolen data, there is clearly money for fixing this kind of thing but they’re using it to spy on us and do who knows what else instead
- albert_e 2y agooff topic does HIBP automatically cover plus addressing variants of an email example I submit johndoe@example.com but a breach had johndoe+verizon@example.com will it match
- deleted 2y ago[deleted]
- kalleboo 2y agohttps://haveibeenpwned.com/FAQs#PlusAliasing https://haveibeenpwned.com/FAQs#PlusAliasing
- seydor 2y agoWhat if we just made all this data free , some AI is going to compile them anyway (and probably already has). Deterrence is the best defense, right ?
- fy20 2y agoIt depends on the country. Where I live now even if I leak my name, date of birth, bank details, national id number, etc. you couldn't do much. We have a country wide 2FA system that all important businesses use (bank, utilities, health, government) to authenticate users. I'm from the UK though, and previously was a 'victim' of identify theft where a few years ago someone walked into a phone store, and walked out with a new iPhone and contract in my name.
- Freebytes 2y agoIs the country wide 2FA implemented by the country or a private company? While rare, what if a person does not have access to the 2FA mechanism, and what mechanisms are permitted to confirm an identity?
- sergiotapia 2y agoDownloaded the torrent, and it's a 164GB text file. What's a quick way to search if my SSN is in the file? I ask before diving in, it's currently extracting and ETA is 40 minutes.
- ivanjermakov 2y agoUse grep with some optimizations: LC_ALL=C fgrep 'ssn' file.txt https://stackoverflow.com/a/13913220 https://stackoverflow.com/a/13913220
- themaninthedark 2y agoHey, if I give you my SSN can you check to see if it is in there for me?
- hn72774 2y agoAnything the average SSN holder should be doing proactively?
- NineStarPoint 2y agoYou could freeze your credit, it you wanted to be careful. Realistically though, you should have already been monitoring to check if unexpected things were being done in your name. I’ve presumed that all our SSNs have been out there for years now due to one hack or another, that this hack just makes it indisputable doesn’t change much.
- tmountain 2y agoWhat's required to freeze/unfreeze your credit? Your SSN and address info? All of that is in the breach for millions of people.
- gosub100 2y agoJust like a lock on the door, it raises the barrier to a non trivial level. It does not give you a ft Knox level impenetrable fortress. I recently froze my credit with the big 3 and it was easier than I pictured. I don't know if they slow you down if you try to unfreeze it immediately after clicking "forgot password".
- mherkender 2y agoFreeze your credit with the three major credit agencies. Set up an IRS pin.
- d_burfoot 2y agoIt's worth remembering that the main reason this kind of data breach is a real problem is mostly due to the incompetence of the IRS. For any serious financial organization, knowing a person's SSN, name, address, etc doesn't allow you to access or withdraw that person's finances. But the stupidity of the IRS means that people are easily targeted by false tax return attacks. File a fake tax return for someone, using their SSN/name/address, but tell the IRS you changed address. Then the IRS sends your tax refund to the new address, and boom, you just collected some poor sod's refund. To add insult to injury, the IRS is probably going to audit the person whose refund you stole.
- daveguy 2y agoI agree. The IRS should be better funded so they can afford to update their systems and hire more tech experts.
- grepexdev 2y agoI hope this is meant to be satirical. The IRS has a massive budget. Maybe just reallocate their current funds instead of giving them more is a better idea.
- boston_clone 2y agoI don’t think the parent is satirical at all; as an enumerated power, the IRS needs modernization and better funding. Recent hiring expansions have increased audits for high earners and generated additional revenue. Turbotax’s lobbyists are losing influence and we’re enjoying free filing options for individuals in some states. It’s also reasonable to say that a revenue service is not responsible for defining authentication security standards. Why do you think reallocating funds is worth it as a response to this issue? Where would those funds go?
- sporkland 2y agoI'm sure you've seen teams that have bad leadership / a culture of dysfunction. They're always asking for more headcount and no much how much you add they don't get any better. I assume parent was pointing out that no matter how many resources you give to the IRS they won't get functionally better. You need to change the leadership/incentives/culture, which is hard with govt agencies but resources also won't make the problem go away.
- farceSpherule 2y agoI worked incident response for years, logging thousands of hours of actual on site work with impacted clients. No on cares. Clients see this as the cost of doing business and have no incentive to do better. Even after Equifax and OPM. Until we have a GDPR style law in the U.S. it will continue to be status quo.
- araes 2y agoI was wondering why Google suddenly turned on "prompt authentication" on zero-security feature accounts yesterday. Now I "must" have a phone nearby to use Gmail... Tap to authenticate every time you want to look at ... ad spam. With this, Ticketmaster, and the CDK Global car theft, is there anybody on Earth who doesn't need data protection? Poor people in Somalia need data breach notices. People who are not even on the WWW need data breach notices...
- robustcollector 2y agoPerhaps HN readers would appreciate a detailed account of what the NPD torrents contain. The torrent deliver two files like so: NPD202401.7z 33,456,912,010 bytes (32GB) NPD202402.7z 20,548,499,322 bytes (20GB) Uncompressing NPD202401.7z results in: ssn.txt 176,806,109,779 bytes (165GB) wc -l ssn.txt ==>> 1,698,302,005 lines Uncompressing NPD202402.7z results in: ssn2.txt 120,722,361,611 bytes (113GB) wc -l ssn2.txt ==>> 997,379,508 lines This is a total of 1698302005+997379508 = 2,695,681,513 lines. Each line is a comma separated record with these fields: ID,firstname,lastname,middlename,name_suff,dob,address,city,county_name,st,zip,phone1,aka1fullname,aka2fullname,aka3fullname,StartDat,alt1DOB,alt2DOB,alt3DOB,ssn Generally records have ID, firstname, lastname, middlename, address, city, county_name, st, zip, and ssn. Most records do not have the fields for name_suff (name suffix), phone1, aka1fullname, aka2fullname, aka3fullname, StartDat, alt1DOB, alt2DOB, and alt3DOB. There are no emails at all. There is no "@" in the files anywhere. Phone numbers are very rare. I don't know what the ID number at the head of each line represents. I presume it is an internal index used by the organization that compiled the data. The SSN is at the end of each line. The files have U.S. addresses only as far as I can tell. Nothing from Mexico, Canada, or other foreign countries. Many of the lines (records) concern the same person at various addresses. Of 7 random people who I personally know that I checked on, all had entries. There were between 3 and 20 lines (records) for these 7 persons, averaging about 10. They usually differed only in the address field. Going by an estimate of 10 records per person, the 2.6 billion lines represents about 2695681513/10 = 269,568,151 distinct persons in the U.S. The U.S. population is about 337M where 78% is over 18 years of age. In other words, 337000000*0.78 = 262,860,000 Americans are adults. This is pretty close to my estimate of 269,568,151 distinct individuals in the NPD data files. Of the 7 persons I checked on, the names were spelled correctly, although the middle name was sometimes just an initial. I searched each person by multiple methods (address, last name, birth date) so I believe I would have detected names that were spelled slightly wrong. The addresses appeared correct but there was no way to tell which was the current address and the order in which they lived at each address. There is a StartDat field but it was almost never filled in. The latest entry was not always the most current address. In a couple cases, the current address, where the person has been living for several years, was absent. The birth dates were correct in a couple cases, were abbreviated in three cases (that is, instead of showing 19800704, meaning July 4 1980, it showed 19800700, meaning July 1980 without an exact day), and was wrong for one person by a wide margin. All 7 persons I checked had SSN numbers. It was correct for 1 person but I don't know for the other 6. The SSN numbers were consistent for each of the 7 persons I checked on. By this I mean that a person did not have more than 1 SSN number, at least among the 7 persons I checked on.
- peterbecich 2y agoi.m.o. "National Public Data" in title should be capitalized; it is a proper noun https://en.wikipedia.org/wiki/National_Public_Data https://en.wikipedia.org/wiki/National_Public_Data
- zephyra334 2y ago[dead]
- USDoD 2y agoDoes anyone know the correct password?
- dimgl 2y agoI used Robokiller to remove myself from data broker lists. I'm extremely impressed with it. I pay yearly. My only annoyance with Robokiller is that A) It's necessary. When is the government going to start creating laws to help us and prosecute this? B) It's expensive. Most people cannot afford this. I can barely afford it but my information has been leaked online. C) It's inconvenient. A majority of calls are spam, but I'll often miss important calls from unknown numbers because Robokiller acts as a proxy and for some reason the call is routed through the Internet. Anyhow, my wife and I are not on this list. I'm wondering if using Robokiller saved us from a lot of pain here.
- esmeraldametteo 2y agoI recently hired the experts of {hacker11tech (@) gmail com} to help me track my spouse's GPS location, as I suspected infidelity. They provided me with accurate and timely information, revealing that my spouse was frequently visiting another person's location instead of going to work as claimed. Their expertise and professionalism were very impressive, and their ethical approach ensured a discreet and confidential process. The evidence gathered was comprehensible and reliable, giving me clarity that I needed to address the situation. I highly appreciate the {hacker11tech (@) gmail com} dedication helping to uncover the truth while maintaining ethical standards, their services was valuable in helping me make decisions about my relationship. I highly recommend this team {hacker11tech (@) gmail com} for anyone seeking reliable ethical practices and their commitment is reassuring.
- itamblyn 2y agoIs there a straightforward way to download this file for research purposes?