Hacker News new | ask | show | jobs
by dannyw 2517 days ago
Name, DOB, and address is available via the Electoral Roll. While I don't think NAB is blameless, at some point the blame lies with companies that accept insufficient forms of authentication.

For example, to transfer funds with my bank, I get texted a 2FA code and this is a mandatory requirement for online banking at CBA.

1 comments

Name and address is in the roll. DOB absolutely is not.

Further, suggesting the blame lies with companies accepting "insufficient forms" of authentication obviously does not bear up in light of this. 2FA texts, for example, are easily worked around by SIM-swapping. Performing a SIM-swap in Australia generally does not require 2FA, and the details leaked herein would get you well on your way.

Ack. Still, the DOB is not difficult to access: just apply to work for the AEC and your copy of the roll certainly includes DOB.