Rich Freeman on 4 Apr 2018 07:08:20 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] Fwd: [FD] Massive Breach in Panera Bread


On Wed, Apr 4, 2018 at 9:01 AM, Ezra Wolfe <ewolfe@ethosce.com> wrote:
>> Many years ago when Commerce bank was around they weren't using POST, so
>> my SSN was being sent via a URL. It was SSL, so maybe that was just me being
>> pedantic.
>
> Even with SSL those SSNs would be in web server logs, almost certainly
> unencryped - not pedantic at all.
>

Sometimes I think the cleanest solution to this problem would be for
the Social Security office to just publish the official list updated
daily of all SSNs and their owner's names and addresses.

It is basically public info already at this point, but maybe people
would actually start to realize that this is the case.

Maybe as a follow up credit card companies should be required to
publish the credit card numbers and names of all their customers.
That is also basically public info at this point.

At some point society needs to realize that shared secrets that you
share with half the planet aren't very useful shared secrets.

--
Rich
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug