Hacker News new | ask | show | jobs
by smoody 5066 days ago
four digits are worthless. somebody was able to get the last four digits of my social security number (how many times have we given that info to customer service reps thinking it's "safe?") and used the digits to open a credit account on BillMeLater (yes, they did not require the full social security number to open an account). they then started buying stuff (nike shoes -- why doesn't that surprise me?).

the only reason i discovered this is because they didn't have my real email address and BillMeLater called me to tell me they needed me to update my email address. so, we also know that they don't even require email address authentication. now all of my credit reports are locked. i recommend everyone do the same.

sorry to hijack the discussion, but wanted to provide another "4 digits suck" example.

3 comments

I'd like to know more. How did BillMeLater know your phone #? Did PayPal/BillMeLater absolve you of all charges, considering they basically bill anyone someone else points to?

Many of our financial systems rely on trust alone. For example, anyone you give a personal check to can drain your checking account. All they need is your account # and routing #, that are on the check.

Why doesn't it surprise you?
People go to stupid lengths to get them. They are a luxury good that is just cheap enough that a lot of people can realistically desire them, but just expensive enough that people will do stupid things to get them, instead of just paying for them.
I'm not surprised. Nikes are totally badass sneakers.
Another place four digits is used is paper receipts of credit card payments for example - http://salesreceiptstore.com/fake_store_receipts/fake_credit...