TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

900 social insurance numbers stolen from Revenue Canada via Heartbleed

119 pointsby rpledgeabout 11 years ago

10 comments

personZabout 11 years ago
How would they know this? Presumably they would have to log the entirety of IP communications with their services.
评论 #7586239 未加载
评论 #7586195 未加载
评论 #7586291 未加载
评论 #7586774 未加载
评论 #7586178 未加载
评论 #7589951 未加载
评论 #7586606 未加载
stygiansonicabout 11 years ago
Oops, I submitted a duplicate of this. (Upvoted yours)<p>Vulnerability was disclosed on Monday, April 7th. CRA website was shutdown on Wednesday, April 9th. Didn&#x27;t take long for the baddies to take PoCs and point them at vulnerable sites.<p>Any other high-value sites that took more than a day to patch should take this as a warning.
scrabbleabout 11 years ago
I wonder if the data was stolen after or before the vulnerability was disclosed.<p>On the other side of it, I think it&#x27;s really great that they&#x27;ve been able to determine exactly what was stolen from this so that they can attempt to repair any damages.
scosmanabout 11 years ago
For those who don&#x27;t know, SIN = social insurance number. Similar to US SSN.
评论 #7587465 未加载
评论 #7588311 未加载
increment_iabout 11 years ago
Considering the significance of the vulnerability, the only thing I can say is the government is extremely lucky that the number is only 900. For Canadians, SIN numbers are about as critical as it gets.
PeterWhittakerabout 11 years ago
tl;dr: &quot;We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed.&quot; The agency says those affected will be contacted via registered letters, and that any attempts to contact a taxpayer via email or telephone are fraudulent.
评论 #7586586 未加载
neil_sabout 11 years ago
Is this the only reported case of malicious use of Heartbleed so far? (Besides US government agencies allegedly)<p>If so, is it safe to say that this crisis was dealt with rather well? Or is it just too early to know how many sites were actually attacked?
评论 #7587065 未加载
Pxtlabout 11 years ago
Wonderful timing that this vulnerability popped up smack in the middle of tax time, eh?
JoeAltmaierabout 11 years ago
Presumably the numbers were stolen along with associated identity information. The numbers can be easily guessed; they are created with a simple algorithm.
jwrabout 11 years ago
How can you steal a number?<p>Here&#x27;s a number: 147334572. Have I stolen it?<p>This is yet another alarming signal that the whole idea that your SSN&#x2F;SIN or credit card number is somehow secret and can be used for authentication is flawed. We need to work on fixing this. At the very least, we should stop talking about &quot;stolen numbers&quot;. And even if the breach in question resulted in attackers gaining access to names + numbers (unclear from the article), it should not cause any serious consequences.
评论 #7586708 未加载
评论 #7586501 未加载
评论 #7586550 未加载
评论 #7586533 未加载
评论 #7588919 未加载
评论 #7586572 未加载
评论 #7587103 未加载
评论 #7586722 未加载
评论 #7587541 未加载