TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Stripe Atlas Vendor Leaked SSNs

136 pointsby sunils34over 5 years ago

12 comments

mjevansover 5 years ago
I agree with <a href="https:&#x2F;&#x2F;twitter.com&#x2F;constmontague&#x2F;status&#x2F;1213309357204688899" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;constmontague&#x2F;status&#x2F;1213309357204688899</a><p>&quot;... we need a new personal identifier, SSNs are all stolen at this point&quot;<p>Though identity and authentication should be different things, as an identifier the only real problem with SSNs is that we should be using UUIDs instead.<p>The hard part is authentication, which should have a far more secure process than merely knowing 9 digits everyone (re)uses.
评论 #21953274 未加载
评论 #21955060 未加载
评论 #21954952 未加载
评论 #21953625 未加载
评论 #21954258 未加载
评论 #21957755 未加载
评论 #21959192 未加载
nedwinover 5 years ago
Why are they notifying folks via mail instead of good old fashioned email?<p>Haven&#x27;t got a letter yet but would be super easy for me to check my inbox...
评论 #21953195 未加载
numchkover 5 years ago
As more Social Security Numbers are leaked from security breaches like Equifax et al - I have done a deep dive into all things publicly known about SSNs and published the results on a hobby site (with limited ad revenue to cover the server cost) to both educate myself on the historic data contained in a social security number, how its usage has changed throughout the years (enumeration at birth in the 80&#x27;s for example) and then how finally the state and date information was removed around 2009 so that numbers are now randomly assigned. For those born before the 2010 - there is a real information encoded (or deduced) from your number beyond what most are aware. If you are curious what types of information a hacker could deduce, or additional ways your SSN could be mis-used if disclosed (or guessed) take a gander at<p><a href="https:&#x2F;&#x2F;numchk.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;numchk.com&#x2F;</a>
评论 #21956307 未加载
etaioinshrdluover 5 years ago
Is this relevant to LLC formation only or also c corps?
评论 #21958850 未加载
throwGuardianover 5 years ago
Why was Stripe sharing something as critical as [SSN+Name] with a third party? If Atlas is simply a white labeled service of another service, then I hope it was prominent in Stripe&#x27;s communication with customers&#x2F;potential-customers. I say this because the market has many competitive offerings in the space, and among the primary reasons to pick Stripe is the assumption of better security, given it&#x27;s multi billion dollar venture funding and valuation
zellyover 5 years ago
The problem with SSNs is how short they are. 9 digits.<p>Even if you hash them, it&#x27;s not that hard to make a 10^10 - 1 rainbow table.<p>It&#x27;s the same problem with IPs (v4). You simply cannot store them at all if you care about your customers&#x27; privacy.
mobileexpertover 5 years ago
Strange to not see an official statement and post Mortem from Stripe mentioned anywhere. Can someone who got a letter post a (redacted as necessary) scan of it?
评论 #21954788 未加载
评论 #21954753 未加载
miki123211over 5 years ago
How could Stripe Atlas even require SSNs? Wasn&#x27;t the whole point of that service giving access to the U.S. market for people from other countries?
评论 #21957019 未加载
revielover 5 years ago
If anyone needs a Stripe Atlas alternative that doesn&#x27;t require SSN and also less expensive ($350 vs Stripes $500 + $400&#x2F;yr) check out <a href="https:&#x2F;&#x2F;www.blook.io&#x2F;stripe-atlas-alternative" rel="nofollow">https:&#x2F;&#x2F;www.blook.io&#x2F;stripe-atlas-alternative</a>
评论 #21960076 未加载
ryanlolover 5 years ago
Odds are that all these SSNs had been leaked from a bunch of other sources anyways. Why the “fuuuuuuuck”? This doesn’t seem like a big deal at all.
评论 #21954763 未加载
duxupover 5 years ago
Is there any verification &#x2F; info other than a tweet?
评论 #21953249 未加载
rolltiideover 5 years ago
getting your identity stolen in any way that’ll effect you is all random<p>they’re all leaked now and people borrow them for things that would never show up on your credit report<p>hope you don’t get framed! Good luck
评论 #21953254 未加载