Slashdot Mirror


South Carolina Department of Revenue Hacked, 3.6 Million SSNs Taken

New submitter Escape From NY writes "3.6 million Social Security numbers and 387,000 credit and debit card numbers were stolen from the SC Department of Revenue. Most of the credit and debit card numbers were encrypted — all but about 16,000. There were several different attacks, all of which originated outside the country. The first they're aware of happened on August 27, and four more happened in September. Officials first learned of the breach on October 10, and the security holes were closed on October 20. This is still a developing story, but anyone who filed a SC state tax return since 1998 my be at risk. Governor Nikki Haley today signed an executive order (PDF) to beef up the state's IT security."

77 of 112 comments (clear)

  1. Love their response by Anonymous Coward · · Score: 2, Informative

    No worries, every single citizen of South Carolina--just call this skeevy company that offered us free credit protection and give THEM your personal info too.

    And also, the phone lines are busy. And the website doesn't actually work. And the offer is just a scam to try to try to get you on the hook for their "upgraded" service, which you'll never be able to cancel.

    Sorry, you didn't expect the state to actually PAY to fix this mess did you?

    Also, the Governor forgot to mention that one of her first acts in office was to order her agencies to cut their IT staff as much as possible (in hopes of creating a statewide Department of Administration that would answer only to her). What could possibly go wrong, huh?

    1. Re:Love their response by Anonymous Coward · · Score: 2, Funny

      That's OK. Security's fixed now; the governor signed an executive order that made it so.

    2. Re:Love their response by Anonymous Coward · · Score: 1

      With the GOVERNATOR, the criminal would already be dead ;)

      I'll be back!

    3. Re:Love their response by jhoegl · · Score: 1

      I dont see South Carolina reversing anything since they dont believe in Evolution they can never evolve.

  2. why bother by Rivalz · · Score: 3, Insightful

    obviously there is no repercussions to the vendors, administration and IT staff.

    1. Re:why bother by AmiMoJo · · Score: 1

      You assume they are at fault, but it is possible a zero-day vulnerability was used and there was absolutely nothing they could reasonably have done.

      Disclaimer: I didn't read TFA.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  3. So when is someone going to swing? by Tastecicles · · Score: 4, Insightful

    This is yet another fine example of Government security doing its usual - leaking like a sieve, in clear violation of Statutory data security requirements. I'll make a prediction right here: some anonymous H1B or lowly DEC will catch it and be fired, notwithstanding the fact that the buck should stop not there, but at the feet of the DCM or the Executive who will continue to collect seven digit salaries.

    --
    Operation Guillotine is in effect.
    1. Re:So when is someone going to swing? by penix1 · · Score: 4, Insightful

      I'll play devil's advocate here...

      The true fault lies with the lazy citizens. They demand every government agency put their stuff online so they don't have to get off their fat asses and actually do something in person. The fault lies in the citizens always screaming "no taxes to pay for the services I demand". The fault lies with the citizens screaming for "less government" yet expecting government to do everything for them. The fault lies with the citizens who demand lowest bids be accepted for contracts allowing inferior products and services.

      Two things come to mind...

      Be careful what you wish for. You just may get it!
      and
      You get what you pay for.

      --
      This is a sig. This is only a sig. Had this been an actual sig you would have been informed where to tune for more sigs.
    2. Re:So when is someone going to swing? by Obfuscant · · Score: 4, Insightful

      The fault lies with the citizens screaming for "less government" yet expecting government to do everything for them.

      Sorry, mate, but I'm one of the ones who says "less government", and I also say "stop doing things for me that I can do better myself." Trying to paint all people who call for less government with the same brush as those who feel the government should be a nanny state is a mistake, and leads to a sloppy and fatally flawed argument.

    3. Re:So when is someone going to swing? by penix1 · · Score: 1, Insightful

      So when the crime rate goes up because of your less government you will remain silent right? When your house burns down because they closed the fire department that was closest to you you won't complain right? When the hurricane hits the east coast next week you won't have a single comment on how the government handles the response right?

      Right....

      --
      This is a sig. This is only a sig. Had this been an actual sig you would have been informed where to tune for more sigs.
    4. Re:So when is someone going to swing? by Havokmon · · Score: 4, Interesting

      I'll play devil's advocate here...

      The true fault lies with the lazy citizens. They demand every government agency put their stuff online so they don't have to get off their fat asses and actually do something in person. The fault lies in the citizens always screaming "no taxes to pay for the services I demand". The fault lies with the citizens screaming for "less government" yet expecting government to do everything for them. The fault lies with the citizens who demand lowest bids be accepted for contracts allowing inferior products and services.

      Two things come to mind...

      Be careful what you wish for. You just may get it! and You get what you pay for.

      Nope. SC is accepting credit cards. They are under the same requirements (PCI) as all other MERCHANTS who wish to accept credit card payments. They weren't PCI compliant (I'll go out on a limb and 'guess' that's the case), and they got hacked.

      They need pay the fine to Visa. That'll be interesting to see how that happens.

      I walked out of a company, where I built the IT and PCI Compliance, because exactly what the parent says will happen - does happen. I just got out before the morons in charge let us get hacked and I got fired for their idiocy. I can only imagine what happened to the IT guys at CardSystems.

      --
      "I can't give you a brain, so I'll give you a diploma" - The Great Oz (blatently stolen sig)
    5. Re:So when is someone going to swing? by penix1 · · Score: 1

      Nope. SC is accepting credit cards.

      Because their citizens demanded it.

      --
      This is a sig. This is only a sig. Had this been an actual sig you would have been informed where to tune for more sigs.
    6. Re:So when is someone going to swing? by Vellmont · · Score: 1


      This is yet another fine example of Government security doing its usual - leaking like a sieve, in clear violation of Statutory data security requirements. I

      Have you SERIOUSLY not paid any attention to the massive, massive amount of data security breaches that have occurred over the last 10+ years? MOST of them are from private industry. How many times did Sony get 0wn3d in 2011.. like 10?

      The problem really has nothing to do with "Government security doing its usual", it's a problem across the board. Your reply is complete and utter bullshit for singing out the Government for having shitty security. That's a problem for the entire industry.

      --
      AccountKiller
    7. Re:So when is someone going to swing? by Obfuscant · · Score: 4, Insightful

      So when the crime rate goes up because of your less government you will remain silent right?

      Unfortunately for your rant, the things you want to claim I've been calling for less of aren't. You don't know, so please stop making a fool of yourself.

      When the hurricane hits the east coast next week you won't have a single comment on how the government handles the response right?

      Yes, I will. I will say "those idiots who build houses on a coast that both erodes on a regular basis and is innundated by storms should not get taxpayer support in rebuilding. They chose to live there despite the dangers, they should assume the risk.

    8. Re:So when is someone going to swing? by lgw · · Score: 3, Insightful

      So when the crime rate goes up because of your less government you will remain silent right? When your house burns down because they closed the fire department that was closest to you you won't complain right?

      Texas has no income tax yet has fire departments, police departments, schools, roads, and so on. California has the highest income tax, yet far crappier roads (seriously, the don't even light the freeways in town, and they're full of potholes), though the schools might be better (that tends to vary more between neighborhoods than between states, though).

      Here's a clue: the "infrastructure" part of government only takes a very small government to do. Mostly, government takes your money to give it to supporters

      When the hurricane hits the east coast next week you won't have a single comment on how the government handles the response right?

      Florida has no income tax, and had great government support when 4 hurricanes hit that one year (I was living there at the time). They even had a Republican governer that stood up against insurance companies and forced the to continue offering insurance that covered hurricane damage.

      You don't need a government that vacuums all possible cash form its citizens to do the good stuff government does - you only need that only to hand over vast sums of money to governments friends.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    9. Re:So when is someone going to swing? by Tastecicles · · Score: 1

      um...yes, actually I have. Those were just a few out of my bookmarks. OK, some of them were subcontractors to Government departments, but there are more than an insignificant number of breaches there that were quietly swept under the carpet that were entirely down to Government agents being either totally stupid or deliberately making sure that that data got out. Who knows how many breaches of remarkable severity go unreported?

      --
      Operation Guillotine is in effect.
    10. Re:So when is someone going to swing? by penix1 · · Score: 2

      Florida has no income tax, and had great government support when 4 hurricanes hit that one year (I was living there at the time). They even had a Republican governer that stood up against insurance companies and forced the to continue offering insurance that covered hurricane damage.

      I couldn't let this one slide since I was in FEMA during that time...

      Florida gets far, far, far more federal dollars than it contributes especially in disaster response. Hell, there are still about 2,500 federal employees still deployed there for those hurricanes. Just because the Florida governor can push the cost of the disaster to the federal government instead of passing it off to you directly doesn't mean we all aren't still paying for it.

      --
      This is a sig. This is only a sig. Had this been an actual sig you would have been informed where to tune for more sigs.
    11. Re:So when is someone going to swing? by KingMotley · · Score: 2

      You are totally right penix1!

      Instead of reducing government waste, we should actually increase it. Just think! Almost no crime, or fires if we had 10x the government we do now. And in order to pay for it, instead of them taking 18% of you paycheck, they will only have to take 180% of it! What a utopia that would be!

    12. Re:So when is someone going to swing? by lgw · · Score: 1

      And collective that's a trivial part of the federal government. The "non-military, non-mailing-checks-to-supporters" part of the federal goverment -pretty much everything all active, non-military federal employees do, is about 20% of the federal budget. Probably couldn't make that work with no income tax, but it's still cheap. The federal government is a pension plan with a military -the actual productive work it does is almost an afterthought, budget-wise.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    13. Re:So when is someone going to swing? by pixelpusher220 · · Score: 1

      Truth Troll at your service

      --
      People in cars cause accidents....accidents in cars cause people :-D
    14. Re:So when is someone going to swing? by Obfuscant · · Score: 1

      Florida gets far, far, far more federal dollars than it contributes especially in disaster response.

      So? You seem to think that anyone who wants smaller government must accept no federal money under any circumstances. You can have a smaller government and still have federal aid in times of disaster. Maybe not aid to people who build in known-hazard areas, but when a hurricane rips all the way across a state, not everyone is in a known-hazard area. Or when the levies break. People who build right on the shore, and build on stilts because they know floods happen on a regular basis, however, are a different sort.

      It seems this is not an unusual twist to how things should work. Biden seemed to make quite a point of it in his debate with Paul, pointing out that Paul had written letters supporting his consitutuents' access to federal handouts. Why shouldn't he? If the Democrats are going to freely hand out billions of taxpayer dollars, why shouldn't the taxpayers in Paul's district get their share -- no matter how Paul voted on the handouts?

    15. Re:So when is someone going to swing? by AmiMoJo · · Score: 1

      Did you ever consider that they might not have had a choice? Perhaps they were born in that area, got a job there and needed to live within commuting distance. Couldn't just up-sticks and move inland.

      I think most people would prefer not to have to be building engineering and geological experts and instead just have the government figure out what is safe and set some rules for building houses.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    16. Re:So when is someone going to swing? by firex726 · · Score: 1

      Also the Governor of SC already cut funding and personnel to the state IT depts.
      So Yea, I would agree that it's not likely to have been an honest mistake and the eventual consequence pf government action.

      You can cut corners all you like but at the end of the day, security and redundancy do cost money.

    17. Re:So when is someone going to swing? by Obfuscant · · Score: 1

      Did you ever consider that they might not have had a choice? Perhaps they were born in that area, got a job there and needed to live within commuting distance. Couldn't just up-sticks and move inland.

      The people who build or buy $2 million homes on the beachfront were neither born there, got a job there, nor are they so poor that they cannot afford to move somewhere else. In fact, many of those million dollar homes built on stilts are VACATION properties that they are busy renting out for big bucks whenever they aren't using them. Their jobs are in DC or New York or someplace else, they aren't commuting from the Outer Banks of North Carolina.

      I think most people would prefer not to have to be building engineering and geological experts and instead just have the government figure out what is safe and set some rules for building houses.

      Yes, most people would rather have a nanny state where some civil servant tells them what is safe and what isn't and prohibits them from doing anything that might be bad for them.

      I'm sorry, but it doesn't take a degree in rocket science to see a bunch of other houses on the beach all built on stilts, and to see some stilts often just sticking up out of the surf (that look just like the kinds of stilts that a house might be built on), and to hear the stories from the locals about "the big one of oh-2" to know that the place they want their million dollar vacation home might not be a good risk. But since the guvmint will help them rebuild, why hesitate?

      Let's put it this way. I was in a rental house where the beach was eroded so far back that the high tide was actually UNDER the house. I mean, waves all the way up under the garage. And yet, these houses were for sale, and people were actually coming to look at the property as potential buyers. There's somethig wrong in a system that rewards that kind of audacity.

    18. Re:So when is someone going to swing? by ai4px · · Score: 1

      Oh my, are you crazy???? we have to take the federal money.... if you leave the money on the table, someone else will get it and we'll just end up paying for it anyway. Well, at least that seems to be the prevailing mentality. I'm convinced that between federal grant programs used to permanently fund certain departments (mating habits of indigenous gray squirrels anyone??), and unconstitutional government alphabet soup agencies, we are doomed. The last governor of SC refused to get $700M federal stimulus money and our wonderful legislature voted to make him take it. No politician has the political courage to say no to money with purse strings.

  4. The horses have run by starfishsystems · · Score: 3, Funny

    The horses have run. Hurry up and close that barn door!

    --
    Parity: What to do when the weekend comes.
    1. Re:The horses have run by dmdavis · · Score: 1

      Obviously for those 16,000, closing the leak doesn't do much good. But, assuming more than 16,000 people live in South Carolina :), there are certainly some horses still in the barn to be protected.

    2. Re:The horses have run by Anonymous Coward · · Score: 1

      Forget the credit and debit card numbers. TFA "none of the Social Security numbers were encrypted". Amusing the summary cherry picked the most useless info.

  5. breached on October 10 by Anonymous Coward · · Score: 1

    The first they're aware of happened on August 27, and four more happened in September [...] breached on October 10, and the security holes were closed on October 20.

    What's wrong with this picture?

    1. Re:breached on October 10 by pixelpusher220 · · Score: 1

      If you're implying they learned of the attacks on 8/27 and didn't act until 10/20, you're not reading that correctly...

      --
      People in cars cause accidents....accidents in cars cause people :-D
  6. "Only" 16,000 credit/debit numbers at risk by Andy+Prough · · Score: 4, Insightful

    Well - that's reassuring! So, "only" 16,000 people potentially have their life savings at risk, or are about to have their lives turned upside down? Sure is convenient that government agencies have immunity from civil liability...

    1. Re:"Only" 16,000 credit/debit numbers at risk by Tastecicles · · Score: 1

      oh, they have that in the US as well? Here it's covered by section 71 of the Serious Organised Crime and Police Act 2005, where blanket immunity is given for any public agency which turns evidence in *any* *other* *proceeding*.

      --
      Operation Guillotine is in effect.
    2. Re:"Only" 16,000 credit/debit numbers at risk by Tastecicles · · Score: 1

      addendum: what I don't get is this: they broke the Law, why should they get to hide behind it?

      --
      Operation Guillotine is in effect.
    3. Re:"Only" 16,000 credit/debit numbers at risk by RobertLTux · · Score: 1

      some folks may decide to pay the tax bill on a CC and or they used it to pay for the tax prep (plus they may also have actual bank account numbers for DD of a refund).

      --
      Any person using FTFY or editing my postings agrees to a US$50.00 charge
    4. Re:"Only" 16,000 credit/debit numbers at risk by LateArthurDent · · Score: 1

      Why do they even need credit card numbers to process tax returns? I am not American, so maybe I'm missing something in how you handle things, but seriously, why?

      They don't need them, and I've never given them mine. You may, however, elect to pay your taxes with a credit card.

    5. Re:"Only" 16,000 credit/debit numbers at risk by Obfuscant · · Score: 1

      Well - that's reassuring! So, "only" 16,000 people potentially have their life savings at risk,

      Uhhh, what? None of the data was encrypted, according to the actual article. Why the summary says most of it was is a mystery. So all of the millions have their credit/debit info exposed.

      Why you are claiming they have their "life savings" at risk, I don't know that, either. A public statement of this kind pretty much puts the credit card companies on notice that their reports of fraud are going to go up, and you don't lose your life savings just because someone steals your credit card data.

      Similarly, your debit account is also protected with appropriate notice -- you lose access to the money until the problem is resolved. If you keep your "life savings" in your debit account, you're asking for trouble.

    6. Re:"Only" 16,000 credit/debit numbers at risk by Obfuscant · · Score: 1

      addendum: what I don't get is this: they broke the Law,

      Which law? Is there a law that says government agencies must encrypt certain information when they store it? Is there one that makes the government the criminal when a real criminal breaks in and steals data?

    7. Re:"Only" 16,000 credit/debit numbers at risk by Obfuscant · · Score: 1

      Oops, none of the SSN were encrypted. All but 16,000 cc/debit were. My bad. Rest of points stand.

    8. Re:"Only" 16,000 credit/debit numbers at risk by Fnord666 · · Score: 1

      some folks may decide to pay the tax bill on a CC and or they used it to pay for the tax prep (plus they may also have actual bank account numbers for DD of a refund).

      Don't forget people who may have elected a direct deposit of any tax refund. They may have had their bank account details compromised as well.

      --
      'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
    9. Re:"Only" 16,000 credit/debit numbers at risk by Tastecicles · · Score: 2

      In answer to your first question: Data Protection Act 1998. In answer to your second question: the same Act, under the heading "Offences by Bodies Corporate", which includes actionable negligence.

      --
      Operation Guillotine is in effect.
    10. Re:"Only" 16,000 credit/debit numbers at risk by Obfuscant · · Score: 1

      In answer to your first question: Data Protection Act 1998.

      Nice try. Last time I checked, South Carolina wasn't in the UK, so the UK Data Protection Act of 1998 wouldn't apply. I think the odd spelling of "Offences" might have been a give-away. We'd have called it "Offenses".

    11. Re:"Only" 16,000 credit/debit numbers at risk by Smallpond · · Score: 1

      I wonder where the decryption key to the rest of the numbers where stored ...

      This could explain the break-in and theft of over 200 Post-it notes.

  7. Re:Icing on the cake by PolygamousRanchKid+ · · Score: 1

    Cybersecurity consultants

    Who do think broke in in the first place . . . ? It's called market making . . .

    --
    Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
  8. Re:TWO MONTHS to close the security hole? by Andy+Prough · · Score: 2

    Can we fire the government?

    Apparently early voting has already started if you want to fire the current group. Not that that will make a big differenced for this kind of activity.

  9. Re:TWO MONTHS to close the security hole? by fustakrakich · · Score: 1

    Yes, you can

    --
    “He’s not deformed, he’s just drunk!”
  10. South Carolina by Spy+Handler · · Score: 1

    First in Flight, last in computer interwebs

    1. Re:South Carolina by 0racle · · Score: 3, Interesting

      South Carolina - First in Flight, last in computer interwebs

      Ah the wonders of the American Education System

      --
      "I use a Mac because I'm just better than you are."
    2. Re:South Carolina by SleazyRidr · · Score: 1

      I'm sure if you tried you could squeeze "fuck" in there a few more times.

    3. Re:South Carolina by Pete+Venkman · · Score: 1

      I don't know what came over me.

    4. Re:South Carolina by crazyjj · · Score: 2

      NC was first in flight.

      SC was first in fight.

      --
      What political party do you join when you don't like Bible-thumpers *or* hippies?
    5. Re:South Carolina by LateArthurDent · · Score: 1

      I'm sure if you tried you could squeeze "fuck" in there a few more times.

      Hell, it's not even challenging. He could have gone, "Except the fucking plane fucking flew first in fucking North fucking Carolina. Fuck yourself you fucking fuck. Fuck!"

    6. Re:South Carolina by tombeard · · Score: 1

      "First in Flight" is a bit north of here. Try "Smiling Faces. Beautiful Places."

      --
      The reason we subjugate ourselves to law is to better procure justice. If law does not accomplish this purpose then it m
    7. Re:South Carolina by Nyder · · Score: 1

      South Carolina - First in Flight, last in computer interwebs

      Ah the wonders of the American Education System

      Oh, the system we don't put money in?

      --
      Be seeing you...
    8. Re:South Carolina by Obfuscant · · Score: 1

      Oh, the system we don't put money in?

      No, the system we keep throwing money at as if simply throwing money at the system would fix it.

      You can hire a thousand teachers so the class sizes are all less than one student per teacher, and as long as the teachers are hamstrung by federal requirements (and local requirements implemented to deal with federal and state requirements), you'll not get good results.

    9. Re:South Carolina by JimBobJoe · · Score: 1

      Dayton was at its time a mini-Silicon Valley: a hotspot for innovation, bringing us people like the Wrights, Charles Kettering and John Patterson.

      North Carolina is just windy.

    10. Re:South Carolina by lightknight · · Score: 1

      Wait, are you serious? Last I checked, most teachers were earning well over the US median wage, with a few of them earning much more than that. Only a handful are earning anything near a below standard salary -> we've heard it in the press, how they're earning $10-30,000 more than the median wage of the people of their surrounding community.

      On top of that, I don't know of a teacher alive who wouldn't testify against the corruption of the administrators / supervisors of their school districts. Not one.

      You see, there is a lot, and I mean a lot, of money flowing into the school system; that it is not getting to where it is intended is a different matter from whether there is enough flowing into it. And yes, hypothetically speaking, if we increase the amount going in by 10%, the teachers at the bottom might see a 0.01% increase in their pay-checks, but it would be an insult to the common gentlemen's intelligence to pursue this course.

      --
      I am John Hurt.
    11. Re:South Carolina by Smallpond · · Score: 1

      The classes with less than one student per teacher don't do well.

    12. Re:South Carolina by SleazyRidr · · Score: 1

      Meow meow meow meow meow meow meow meow meow meow

      In a sentence, no, but you didn't ask for that.

    13. Re:South Carolina by Obfuscant · · Score: 1
      How well they do depends on how good the teachers are, not the class size. You'd expect a class with more than one teacher per student to do very well, wouldn't you? Personalized instruction.

      But I'll just point out that the statement was a bit of hyperbole in a reductio ad absurdum manner. If reducing class sizes is good, then reducing them even more must be gooder, and the lower limit is somewhere below one student per teacher. That's "throwing money at the system" for a result that is absurd.

  11. Re:Spy Handler by Sparticus789 · · Score: 1

    First to run his mouth, last in 20th century American History

    --
    sudo make me a sandwich
  12. COBOL on IBM-360 emulation by peter303 · · Score: 1

    I heard our state still runs its unemployment system this way. I would think something like that would be practically self-encrypting.

    1. Re:COBOL on IBM-360 emulation by MBGMorden · · Score: 1

      Don't know about the state, but the county level agencies still run a ton of OS/400 stuff written in COBOL. Suggestions to replace the aging codebase with something newer are quickly reigned in when they hear about the cost involved.

      --
      "People who think they know everything are very annoying to those of us who do."-Mark Twain
  13. Re:3.6 million submarines?? by Anonymous Coward · · Score: 2, Funny

    Uh, for those who missed it, "SSN" is the Navy term for a nuclear submarine.

    (SSN = "ship, submersible, nuclear")

    So the headline saying "3.6 million SSNs taken" is a bit disconcerting, if you're reading the wrong acronyms.

  14. Re:3.6 million submarines?? by K.+S.+Kyosuke · · Score: 1

    Haha, that was my first thought as well. :-) Where would they put them? That would be one heck of a naval port. Also, it would solve the energy problem - just plug their power plants into the grid and voila, and any potential energy crisis would be instantly prevented!

    --
    Ezekiel 23:20
  15. Re:TWO MONTHS to close the security hole? by AwesomeMcgee · · Score: 1

    Show's what you know.

  16. Why are SSNs secret? by bigwheel · · Score: 2

    A social security number is just a hash code to numerically identify a person. Kind of like a full name, except a little more precise. It was my student ID for both undergrad and grad school. It has since turned int a closely guarded secret, although it is included on the paperwork of pretty much anything you sign. There's got to be a better way.

    1. Re:Why are SSNs secret? by icebraining · · Score: 1

      The SSN system is stupid, but the CC system isn't any better.

      You have to give a single set of numbers to a merchant (or other) and hope that not a single one fucks up, or you have to cancel the whole card and all the stuff (e.g. recurring payments) associated with it. It's fucking braindead, especially nowadays.

      Here we like to complain about our banks, but at least we have decent payment system where the payer and not the payee initiates the transaction, as it should. Not to mention free virtual CCs for when we have to interact with foreign merchants.

    2. Re:Why are SSNs secret? by JimBobJoe · · Score: 1

      I think the Swedish experience is that its national ID number doesn't do anything all that significant (none of the purposes you noted here would be severely inconvenienced or affected if you just used another number.)

      In short, stealing someone's Swedish number doesn't achieve much.

      The US uses the SSN as a gateway to the person's financial history.

  17. Re:TWO MONTHS to close the security hole? by tombeard · · Score: 1

    No early voting in SC. Might cause an increase in Democratic votes.

    --
    The reason we subjugate ourselves to law is to better procure justice. If law does not accomplish this purpose then it m
  18. Get a credit freeze by gumpish · · Score: 2

    Credit freeze

    "A credit freeze, also known as a credit report freeze, a credit report lock down, a credit lock down, a credit lock or a security freeze, allows an individual to control how a U.S. consumer reporting agency (also known as credit bureau: Equifax, Experian, TransUnion) is able to sell his or her data. The credit freeze locks the data at the consumer reporting agency until an individual gives permission for the release of the data."

    You have to pay each of these companies $10 for the privilege, but it's worth it.

    Of course, any time you need to do something that requires a credit check (take out a loan, apply to lease an apartment, apply for a job (sometimes)...), you'll have to temporarily lift the freeze, which is another fee.

    1. Re:Get a credit freeze by Chickan · · Score: 1

      Thanks. I moved to SC for a job (they exist here) and will need to look into this. Its crazy you have to individually call all three credit bureaus though, seems like a good way to waste a few hours.

    2. Re:Get a credit freeze by gumpish · · Score: 1

      Actually they all have web forms available:

      Experian

      Equifax

      TransUnion

  19. Re:TWO MONTHS to close the security hole? by pixelpusher220 · · Score: 1

    Not 2 months to fix a hole. Read that again.

    --
    People in cars cause accidents....accidents in cars cause people :-D
  20. So that's where that account came from... by HeathenSkwerl · · Score: 1

    Count me as someone who got directly affected by this. Some jackass opened a fraudulent PayPal Mastercard in my name last month and promptly maxed it out. I had no idea how they could have gotten my information as I'm fairly careful with it and I didn't know of anyone I did business with that had been hacked. Now I find out a month later after the damage has been done that they almost certainly got my information from SC. They have all of my current data as I had to give it to them when I moved to my current address. No proof, of course, but the timeframe matches up perfectly. Thanks, SC, for still screwing me over with crappy service even AFTER I leave. -Skwerl

  21. You are wrong about the type of risk by Andy+Prough · · Score: 1

    The bigger risk is from identity thieves, once they have your personal data, SS#, and account #. New York Times reported on a $66,000 "life savings" loss of an 81-year-old woman just one month ago: http://www.nytimes.com/2012/09/12/business/retirementspecial/old-trusting-and-prime-prey-for-swindlers.html?pagewanted=all&_r=0

  22. Not "stolen", they've been shared by Rogerborg · · Score: 1

    They're just data, right? Copying them doesn't take them away. You can't steal numbers.

    Applies to music and movies, applies to any other data.

    --
    If you were blocking sigs, you wouldn't have to read this.
  23. Wrong slogan by Edgester · · Score: 1

    North Carolina claims "first in flight", and has that phrase on the license plates, and South Carolina does not. Please don't confuse North Carolina with South Carolina.