this post was submitted on 02 Apr 2024
363 points (99.5% liked)

Privacy

32482 readers
258 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 11 points 8 months ago (3 children)

I keep reading "social security number", but still don't understand why it's possible to steal a person's identity with their SSN. Is that all that's required for identification? Some number?

[–] [email protected] 7 points 8 months ago

Basically. It wasn't meant to act as an identification, but people kept using it that way (probably because every citizen gets one at birth, so it's the easiest proof of citizenship).

[–] [email protected] 4 points 8 months ago (1 children)

Getting names, emails, addresses, etc is pretty available. If you can link those up + an SSN you can open accounts pretty easily

[–] [email protected] 1 points 8 months ago* (last edited 8 months ago)

Damn... that seems like a pretty bad system. Have there not been attempts to remedy that?

CC BY-NC-SA 4.0

[–] [email protected] 6 points 8 months ago (1 children)

It's a key component. You need other information, but the SSN is supposed to be secret.

[–] [email protected] 14 points 8 months ago (1 children)

State-assigned unchangeable passwords that you hand out to 20-100 companies throughout your life (every job, every loan, every credit card, every financial account, every background check, every...)

This was 70 million people in 1 breach.

Keep in mind there are only 340 million people in the US, many of which are under 18.

We need a better system.

https://en.m.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach

The Office of Personnel Management data breach was a 2015 data breach targeting Standard Form 86 (SF-86) U.S. government security clearance records retained by the United States Office of Personnel Management (OPM). One of the largest breaches of government data in U.S. history, the attack was carried out by an advanced persistent threat based in China, widely believed to be the Jiangsu State Security Department, a subsidiary of the Government of China's Ministry of State Security spy agency.

In June 2015, OPM announced that it had been the target of a data breach targeting personnel records.[1] Approximately 22.1 million records were affected, including records related to government employees, other people who had undergone background checks, and their friends and family.[2][3] One of the largest breaches of government data in U.S. history,[1] information that was obtained and exfiltrated in the breach[4] included personally identifiable information such as Social Security numbers,[5] as well as names, dates and places of birth, and addresses.[6] State-sponsored hackers working on behalf of the Chinese government carried out the attack.[4][7]

The data breach consisted of two separate, but linked, attacks.[8] It is unclear when the first attack occurred but the second attack happened on May 7, 2014, when attackers posed as an employee of KeyPoint Government Solutions, a subcontracting company. The first attack was discovered March 20, 2014, but the second attack was not discovered until April 15, 2015.[8] In the aftermath of the event, Katherine Archuleta, the director of OPM, and the CIO, Donna Seymour, resigned.[9]

[–] [email protected] 1 points 8 months ago

Wasn't it India that leaked all of its citizens data?