this post was submitted on 15 Aug 2024
255 points (98.9% liked)

Privacy

31799 readers
348 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

You may have heard about a lawsuit filed regarding a data breach concerning social security numbers. I encourage you to read at least the first few pages of the linked class action complaint to see how massive a violation of privacy this is.

The data breach concerns National Public Data, a company which offers background checks. They collect personally identifiable information (PII) as a part of their business. The defendant claims that NPD scraped PII from non-public sources (¶11). NPD then stored the data in an insecure manner and did not adequately protect this personal information (¶25). Consequently, a hacking group by the name of "USDoD" stole records of 2.9 billion individuals from NPD. According to the document, the data was independently reviewed by VX-underground, the cybersecurity company. They confirmed the breach included full names, address and address history, and social security numbers. They were also able to identify familial connections, both living and deceased (¶ 22-24).

Based on this class action complaint, NPD's conduct was grossly negligent, leading to potential identity theft for almost anyone in the United States. It was also a massive privacy violation by scraping data from non-public sources. Even after they took millions of Americans personal information, they failed to secure the data from hackers.

Criminals can ruin your life if they target you with this information. They can open lines of credit without you knowing. You might only find out until creditors call you, demanding that you pay them back (¶60).

So, yeah. I am very concerned. I'll have to figure out how to defend against this identity theft. Overall, I'm new to the privacy community, but I'm feeling like "privacy" in the United States is an absolute mess. If your data wasn't somewhere on the dark web, it might be now. Protect your data. Stay safe.

you are viewing a single comment's thread
view the rest of the comments
[–] astrsk@fedia.io 59 points 2 months ago (2 children)

There’s no longer any restrictions on feeezing and thawing your credit from the big 3 agencies. All of them also offer temporary thawing that automatically freeze after a designated time. Do not under any circumstance permanently thaw them again. If you need new credit cards, credit checks from apartments or mortgaging / car loans, just work with your lender / seller to figure out which agency they will query and when. Set a temporary thaw for as small amount of time as you can, and all will be peachy. What’s more, after a temporary thaw, get a credit report in a couple months after that to verify nothing snuck in during that time.

[–] Chozo@fedia.io 12 points 2 months ago (2 children)

What does freezing your credit do, exactly? Is this still something someone should do if they don't even have any credit cards?

I've generally been pretty ignorant toward how credit reporting works.

[–] MajorHavoc@programming.dev 24 points 2 months ago* (last edited 2 months ago) (2 children)

What does freezing your credit do, exactly?

It prevents opening new credit cards or other lines of credit in your name.

The reason this matters is lots of fraudsters are using names and SSNs they bought on the dark web, to open credit cards they have no intention of paying back.

If you're an American, your name and SSN combination is almost certainly for sale for about 25 cents, on the dark web, today.

Freezing your credit at all three agencies is the only effective prevention, today.

The credit agencies will attempt to charge you a monthly fee for the privilege, but don't fall for it. They're legally required to provide the service for free.

If I'm ever a juror on a murder trial where the "victim" worked in leadership at one of the big three credit agencies, I'll have to admit that I couldn't possibly convict someone for that.

Is this still something someone should do if they don't even have any credit cards?

Yes. Absolutely. Being a victim of credit fraud can make it impossible to get a home mortgage, or even get certain jobs or apartments. It can be incredibly difficult and expensive to clean up, and the burden is largely left entirely on the victim.

[–] brbposting@sh.itjust.works 13 points 2 months ago (1 children)

Thanks, Major. How hard is it for fraudsters to unfreeze credit?

[–] MajorHavoc@programming.dev 6 points 2 months ago* (last edited 2 months ago) (1 children)

Generally they need all of your personal information (Full Name, Date of Birth and SSN - which costs them 25 cents or less on the dark web), plus your username and password that you create when you first visit each site. (Which hopefully isn't on the dark web, because it's new and unique.)

The new username and password that you create are what give some security.

And a warning, only because someone reading along will need it:

don't re-use a password used elsewhere.

Re-used passwords, from past data breaches, paired nicely with email addresses and full names, also cost about 25 cents on the dark web.

[–] brbposting@sh.itjust.works 3 points 2 months ago (1 children)

Oh nice

Bitwarden FTW! (If they get hacked it’ll only take, oh, an entire day to change all my passwords 😉 you’re probably a KeePass person?)

[–] MajorHavoc@programming.dev 3 points 2 months ago (1 children)

you’re probably a KeePass person?

Yeah. I feel seen. Naturally I try to only use the finest artisinal open source from F-Droid.

Though, honestly, I'm impressed by BitWarden and I'm happy enough to recommend it.

[–] brbposting@sh.itjust.works 1 points 2 months ago

Ahaha good then my lazybones aren’t doing too bad!

[–] ampersandcastles@lemmy.ml 4 points 2 months ago (1 children)

How can anyone genuinely write that and still support any country that imposes it.

Laughable. Fuck this country.

[–] MajorHavoc@programming.dev 7 points 2 months ago* (last edited 2 months ago) (1 children)

Uh... I'm a patriot.

I fully support my country in every meaningful way, especially those ways that might otherwise make my billionaire overlords feel threatened enough to put a hit out on me.

More seriously, my neighbors are, on average, fantastic people, that deserve my support.

Edit: To be clear, I fully agree that this should piss us all off.

[–] ampersandcastles@lemmy.ml 3 points 2 months ago (2 children)

Your neighbors are probably ones being mistreated by this country.

Support the people, not the country.

The US is a cesspool.

[–] refalo@programming.dev 2 points 2 months ago

Have you seen people?

[–] MajorHavoc@programming.dev 1 points 2 months ago

Support the people, not the country.

I agree wholeheartedly.

[–] ChaosCoati@midwest.social 11 points 2 months ago (1 children)

Freezing your credits means you (or anyone else) cannot access your credit report to open new lines of credit. No credit cards, mortgages, car loans, nothing.

[–] izstranger@freeradical.zone 7 points 2 months ago (2 children)

@ChaosCoati @Chozo

Exactly.

But it's very easy and fast to temporarily thaw it when you want to apply for credit.

I've been doing it for years.

[–] refalo@programming.dev 2 points 2 months ago (1 children)

And just as easy for crooks with this same data to thaw it for you.

[–] izstranger@freeradical.zone 1 points 2 months ago (1 children)

@refalo

Not really. Online they'll need my user/pass, 2fa for starters.

If they try to do it by phone they'll need to first answer a bunch of questions (which yes they can probably get), but then upload a photo of my license....

[–] refalo@programming.dev 2 points 2 months ago* (last edited 2 months ago)

There have been several leaks with driver license and passport photos of people from all over the world, usually from sites or services that need to verify identity like for stock trading or porn.

[–] delirious_owl@discuss.online 2 points 2 months ago

What are the chances that my attempt to thaw gets denied "for my protection"?

Because I've gotten locked out if every bank account I've ever owned at some point "for my protection" just because I tried to login. The only thing stopping me from freezing my credit is fear that I'll never be able to thaw it because of these terrible anti-fraud systems that lock me out.

[–] refalo@programming.dev 5 points 2 months ago* (last edited 2 months ago) (1 children)

Can't someone who has your SSN just thaw it themselves?

[–] IphtashuFitz@lemmy.world 4 points 2 months ago

Not easily. The scammer likely has your current address & contact info, but knows nothing about your history.

To confirm your identity when you contact these reporting agencies they will use details from your credit history by asking detailed questions the scammer likely won’t know. For example it might be questions like these:

  • What kind of car did you purchase in 2005?
  1. Honda
  2. Ford
  3. Saab
  4. Jeep
  5. None of the above
  • Which one of these companies did you work for previously?
  1. IBM
  2. Pizza Hut
  3. Macy’s
  4. Jiffy Lube
  5. None of the above

They’ll throw 3 or 4 questions like these at you that you’ll have to answer correctly. They might involve places you used to live, banks you have had accounts with, etc. The chances of a scammer with your SSN knowing all these details about you is pretty tiny.