Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

To steal a SSN (It's easier than you think!)
LinkedIn Timothy Martens ^ | May 20, 2015 | Timothy Martens

Posted on 05/27/2015 5:39:48 AM PDT by the_boy_who_got_lost

What would you say if I told you I could get your Social Security Number if you gave me your name and birth date? And sometimes I don't even need your birth day.

How easy is it? How many people know your name and birth date? I imagine quite a few. And if you have your birth date available on Facebook, LinkedIn or any number of other services online which ask for and publicly display your birth date then A LOT more people have your birth date.

The second half of the equation is finding an online service which you have used which is also vulnerable to the exploit.

(Excerpt) Read more at linkedin.com ...


TOPICS: Computers/Internet; Society
KEYWORDS: ssn
Navigation: use the links below to view more comments.
first 1-2021-38 next last
Disclaimer: I am the author of this article.

I have been contracted by several private companies to secure their web applications after I revealed that I could steel their customers SSN's.

I have been in contact with two government agencies trying to get them to listen.

The first told me to write a letter to a P.O. box with my concerns telling me I was crazy.

The other listened and told me they would take the concerns to their security team.

I've found the private sector very responsive and the government agentcies very lack luster (and frankly offensive.)

1 posted on 05/27/2015 5:39:48 AM PDT by the_boy_who_got_lost
[ Post Reply | Private Reply | View Replies]

To: the_boy_who_got_lost

Momentarily I thought the title meant a submarine.


2 posted on 05/27/2015 5:44:30 AM PDT by exnavy (BLOAT: buy lots of ammo train.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the_boy_who_got_lost

I believe all government, federal, state, and local have decided that if citezens have problems of any type, those citizens turn to government. Many do. Most do not, at least in the United States. Self sufficiency is indedependance, is freedom. Thus, the lack of interest in any true solution to all problems from gubmint.


3 posted on 05/27/2015 5:53:19 AM PDT by exnavy (BLOAT: buy lots of ammo train.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the_boy_who_got_lost

If you want to get the bureaucrats’ attention, steal their SSNs and include in your correspondence with them.


4 posted on 05/27/2015 5:54:03 AM PDT by Paine in the Neck (Socialism consumes EVERYTHING)
[ Post Reply | Private Reply | To 1 | View Replies]

To: exnavy

I also thought the title meant a submarine at first.


5 posted on 05/27/2015 5:57:16 AM PDT by T-Bone Texan (B.L.O.A.T. : Buy Lots Of Ammo Today)
[ Post Reply | Private Reply | To 2 | View Replies]

To: T-Bone Texan

Same here. Title looked like a submarine. I always thought the correct abbreviation for Social Security number was SSAN, as in “social security account number”.


6 posted on 05/27/2015 6:00:22 AM PDT by captain_dave
[ Post Reply | Private Reply | To 5 | View Replies]

To: Paine in the Neck

I’ve thought about that...I also don’t want to go to jail for any length of time....or have to fight anything in court. I am broke enough as it is.

I recently discovered a mortgage company who was leaking the:
Full SSN, first and last name, home address, mailing address, bank and routing number if they has signed up for automatic ACH payments each month.

I could have made millions selling that data on the black market.

I did the honerable thing and reported it...and made a measly $5,000 in comparison. Now I’m glad for the money and a clear conscience.

I read about this hack today: http://apnews.myway.com/article/20150527/us-irs-breach-a05ef24734.html

I could have done that easy sneezy...it doesn’t take a whole lot of sophistication do run a scheme like that. There are plenty of smart programmers out there.


7 posted on 05/27/2015 6:02:16 AM PDT by the_boy_who_got_lost (Real men scare liberals)
[ Post Reply | Private Reply | To 4 | View Replies]

To: captain_dave; exnavy; T-Bone Texan

Sorry I had no idea that SSN might mean a nuclear sub.


8 posted on 05/27/2015 6:06:48 AM PDT by the_boy_who_got_lost (Real men scare liberals)
[ Post Reply | Private Reply | To 6 | View Replies]

To: the_boy_who_got_lost
I read the book and saw the movie. It was easy, but it was an SSBN, not an SSN.


9 posted on 05/27/2015 6:07:06 AM PDT by Pollster1 ("Shall not be infringed" is unambiguous.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: exnavy

Me too!
Was wondering how they get past all the security to get inside!
Then figure out how to operate the controls; then make it out to sea!


10 posted on 05/27/2015 6:07:37 AM PDT by HereInTheHeartland
[ Post Reply | Private Reply | To 2 | View Replies]

To: the_boy_who_got_lost

I always fake my birth date but I’ll tell you guys. I was born on May 29, 1976.
Or did I graduate high school on that date? Man, I hate getting old.


11 posted on 05/27/2015 6:10:06 AM PDT by AppyPappy
[ Post Reply | Private Reply | To 1 | View Replies]

To: exnavy

Me too. I thought, “Well, that would be interesting.”


12 posted on 05/27/2015 6:12:08 AM PDT by LS ('Castles made of sand, fall in the sea . . . eventually.' Hendrix)
[ Post Reply | Private Reply | To 2 | View Replies]

To: the_boy_who_got_lost

If you have a federal student loan I CAN steal your SSN.

Here is one website that is vulnerable to the attack.
https://fafsa.ed.gov/index.htm

Before telling me to shut up that it wasn’t possible they told me to write a report up and mail it to:
FSAIC
Application Processing Concern
P.O 84
Washington D.C. 20044

This is one of several BIG sites that are vulnerable.


13 posted on 05/27/2015 6:13:27 AM PDT by the_boy_who_got_lost (Real men scare liberals)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the_boy_who_got_lost

My birth day on facebook is not my real birth day. My daughter pinged me one day and said, “Today isn’t your birthday”.

i.e. the downside is that everyone is wishing me a happy birthday when it’s not my birthday. I don’t care.


14 posted on 05/27/2015 6:15:14 AM PDT by cuban leaf (The US will not survive the obama presidency. The world may not either.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: AppyPappy

Does your mortgage company know your real birth date?
Does your bank know your real birth date?
Do you have student loans?

Typically if you give your SSN you give your real birth date.

You might not use a bank, have a mortgage or ever has a student loan. But millions of people do or have had one or more. And millions of SSN’s are potentially vulnerable.

Mortgage companies, banks and loan companies/government entities are prime targets for hackers.

I have helped a few in this industry secure their sites after proving that I could steal their customers Social Security Numbers.

However many sites are still vulnerable. Including government sites.


15 posted on 05/27/2015 6:19:01 AM PDT by the_boy_who_got_lost (Real men scare liberals)
[ Post Reply | Private Reply | To 11 | View Replies]

To: exnavy

LOL. Me, too. When I visited the Stennis, in port of course, they had removed the steering wheel. Navy tradition, I was told.


16 posted on 05/27/2015 6:23:53 AM PDT by Attention Surplus Disorder
[ Post Reply | Private Reply | To 2 | View Replies]

To: the_boy_who_got_lost

I just checked outside in the pool, and my submarine is still there. Whew!


17 posted on 05/27/2015 6:26:24 AM PDT by Cementjungle
[ Post Reply | Private Reply | To 1 | View Replies]

To: cuban leaf

Ditto.


18 posted on 05/27/2015 6:26:44 AM PDT by logi_cal869 (-cynicus-)
[ Post Reply | Private Reply | To 14 | View Replies]

To: exnavy
Momentarily I thought the title meant a submarine.

So did I!

19 posted on 05/27/2015 6:31:48 AM PDT by AlaskaErik (I served and protected my country for 31 years. Progressives spent that time trying to destroy it.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: the_boy_who_got_lost

The Mexicans are such a trashy bunch, along my property I have picked up litter and twice picked up SS cards they had discarded.


20 posted on 05/27/2015 6:33:26 AM PDT by vetvetdoug
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-38 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson