Hacker News new | ask | show | jobs
by coldtea 3119 days ago
>- Names: this is public information - Addresses: this is public information - Bank Account Details: this is on every check you've ever written - SSN: this is on so many applications for things and compromised so many times it can't be realistically called private - Account Login Details: not to be pedantic but this is a shared secret and should be treated as such

Those may not be difficult for an adversary that targets someone personally to get. They'll have some trouble getting a few of them (something being on "every check you've ever written" doesn't mean I can see it easily if I'm not a person making business with you. Besides few write checks anymore anyway), but they will be able to gather most.

That's completely different than anybody who doesn't know you at all having all those details for millions of people in a large data dump - that is, any scammer worldwide.

1 comments

That, and linked together, in a nice clean, easily automatically exploitable package.