• Horsey@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    23 hours ago

    Wait until non Americans hear that our national social security ID number is only 4/9 digits worth of “random” numbers. (Fun fact, the entire number was procedurally generated based on where you were born and in what order at the hospital for generations until they changed it recently)

    • Blackmist@feddit.uk
      link
      fedilink
      English
      arrow-up
      0
      ·
      19 hours ago

      Yeah, we know. We just can’t believe that you actually use it for anything important.

      • Horsey@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        18 hours ago

        That stupid ass number is used as one of the identifying factors when financing anything. Yes, a house is bought and mortgaged with that number next to 2 other forms of ID lmao.

    • Hildegard (she/her)@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      20 hours ago

      The numbers aren’t random. They are sequential. The early digits are assigned geographically, but the rest are in sequence. If you know a valid social security number, adding or subtracting 1 will be another valid social security number, most likely someone born in the same hospital on the same day.

      They did change it somewhat recently, but they don’t re-assign the numbers when making that change, so most of the numbers are completely insecure.

  • nanometer1625@thelemmy.club
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    This is yet another reason why virtual ID cards are superior: In the event that the card data is compromised, the old virtual ID can be revoked and a new virtual ID can be issued. Virtual ID cards can also have a much shorter duration, because the cost of rotating it is minimal. For example, California’s virtual driver licenses rotate each 30 days.

    • Blackmist@feddit.uk
      link
      fedilink
      English
      arrow-up
      0
      ·
      19 hours ago

      Welcome to Rent-a-car. Please sign into your vehicle with Facebook, Google or AppleID.

  • sunbytes@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    The only way to fix this is to have us upload our IDs online constantly, perhaps to prove we are adults.

    It is the only way we can we safe.

  • 0x0@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    I bought a domain, configured the webserver in the next 5m.

    As soon as it started taking requests (on a domain that i haven’t even announced yet) it got flooded by bots.

    • 0xDREADBEEF@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      19 hours ago

      Registering SSL is a centralized process with root CAs logging new ones as they come in. Cert transparency logs are a thing, and Google is very involved: https://certificate.transparency.dev/

      Once a bad actor hooks up to that, they just get a realtime stream of places to start port scanning and running WHOIS queries for people who didn’t get WHOIS protection. If you used letsencrypt your domains you registered certs for got sent there and anyone who wanted to know about it knew about it before you could tell anyone.

      You can use something like crt.sh to look up domains

    • Brimstone@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      Yeah I worked for company with publicly exposed server, the logs were amazing.

      Just bots scanning default ports trying default username and password for services like Microsoft SQL server.

      It’s such a waste of energy really

      • edgesmash@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 day ago

        That’s been happening since forever, though. I helped manage proxy servers for my first job in the mid 00’s, and those server logs were mostly automated port scans and failed login attempts, even on the newly commissioned servers.

    • ddplf@szmer.info
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      If your browser is based on chromium, you’re employing an army of bots yourself that gets enabled each time you enter any domain.

  • Newhere@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    I don’t understand what is the point to upload all these IDs to dark web. Everything is traceable! Every transaction ect. If it would not be traceable many would just get another ID for identification on web or similar- like Sim card, because government is tracking everything, so they could track "Indiana Jones " and not me. Later just get another Sim with other iD. So, that data is available, I don’t think it’s possible to buy it without being connected to it.

    • hansolo@lemmy.today
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      I recommend listening to the podcast Darknet Diaries. It’s about sketchy things online, and very often has real accounts from real criminals talking about what they did and how they got caught.

      Very often, people only get caught because 1) they get huge and greedy enough that many governments are actively trying to hunt them down, 2) they make a stupid mistake that tracks back to them personally.

      There is no “the government can trace everything!” In reality, it’s more like “if someone does something egregious, a few people will spend months or years trying to find them. And maybe they’ll catch a lucky break.” Hacker OpSec is typically more than enough to frustrate the FBI for years. If they even care to look for attackers. The FBI can’t just show up in Romania and arrest people, either, so it takes international government cooperation. Which is slooooooow to move.

  • 7101334@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    Most of this seems very serious and concerning, but…

    Nexus also claimed to provide scans of marijuana dispensary cards

    What could anyone possibly do with that? It costs like $50 to get one in California, not sure about other states.

    • ellopete22@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      Nineteen Brazilian Nationals Charged in Nationwide Conspiracy to Open Fraudulent Driver Accounts at Leading Rideshare and Delivery Service Companies

      • 7101334@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        Less taxes in most places if you have a med card. Financially sensible if you buy a certain amount per year.

        • Drusas@fedia.io
          link
          fedilink
          arrow-up
          0
          ·
          2 days ago

          But then there’s a record of you being a cannabis user, which could lead to your second amendment rights being curtailed.

    • hansolo@lemmy.today
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      The data gets sold in blocks usually. Could be for identity theft, or SIM swap attacks or any number of things. A lot of things online want an ID scan now, so this is a huge benefit to scammers.

      • youmaynotknow@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        I still have to see the online service or site asking for my ID. Maybe because I’m mostly off of the bullshit-net for the most part. But the moment any service I use asks for ID, it’s getting cancelled and blocked in my house at the network level. I’m expecting my digital life to be dramatically downsized moving forward.

        Car rentals, well, not many options there when traveling, since I absolutely refuse to use ride-share apps like Uber and such.

    • Talcosis@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      My first thought was “so this is how they got my fake from back in the day to scan”

    • Tiral@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      Yeah, there’s like 150 million IDs and licenses. I guess the company that handles like every major businesses ID verification has online security designed by Grom. Should arrest the top 15 people hands down.

  • Hikermick@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    My elderly father recently fell for a Facebook imposter that pretended to be a family member and asked if their friend could contact him. The friend asked him to take a photo of his driver’s license and text it to them, fortunately he doesn’t know how. I’ve been wondering ever since what can they do if they had it? It doesn’t have his social security number on it. His credit has since been locked and banks notified

    • historicaldocuments@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      I’ve been wondering ever since what can they do if they had it?

      Ask for pictures of all his other paperwork so they can finish onboarding him at his new job.

    • GenosseFlosse@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      They can open bank or crypto accounts in his name, and then either overdraw the account or use it to move money from other scams in and out of this account, so the real scammers name is not attached to this account.

      • aceshigh@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 day ago

        Is there a way to block that? Ie: freezing your credit means no one can take a loan, but that doesn’t remove the scenario you described.

  • Bell@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    Annnd this is why a refuse to verify with IDs online and use services like Plaid. And the web of T&C’s from multiple 3rd party services like this will mean all of them get shielded from blame.

    • Raiderkev@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      The IRS made me since I used a different service to file my takes this year. It was a pain in the ass. Apparently my existing id.me login wasn’t enough, they wanted a video call or a scan of my face. There was no other option. It was a pain.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        they tried that with me. I just told em to fuck off.

        if you make it impossible to identify myself through standard means, you don’t get my tax dollars. 🤷 fuck em.

    • 7101334@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      Did you read the article? They were renting a car. A car rental place isn’t going to let you just not show your ID.

      • youmaynotknow@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        Yeah, it was from renting cars, but they are digital copies of your ID, so any online service is just as “at-risk”, if not more.

      • ikidd@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        So how they did it once upon a time was you showed them your license, they punched the # into the system that would check it. The person at the desk would confirm it was you from the picture. No need to scan the actual ID card, which is where this problem comes from.

  • tigeruppercut@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    Jeez, Daniel Gooooooch must be pretty pissed about this article revealing his name as an example pic.