Comment on Data Leak at the Pentagon Affects Over 3 Million Military and Civilian Employees
sylver_dragon@lemmy.world 23 hours ago
The Pentagon stated that it currently has no evidence that the stolen data has been used for criminal purposes. Those affected are being offered identity protection and credit monitoring services.
On the upshot, this was probably just China updating the SF-86 database they took from OPM back in 2015; so, they aren’t likely to use it to issue credit cards. The downside is that organizations are still treating identity protection and credit monitoring services as anything other than complete and utter bullshit. We really need to overhaul the SSN system to something more modern to be able to deal with the fact that everyone’s SSN has long since been leaked. Especially when we have the idiots like the DOGE employees dumping this sort of thing on publicly accessible servers.
ScoffingLizard@lemmy.dbzer0.com 17 hours ago
We need a whole admin for sensitive IDs and stop using SSN for it completely.
hoshikarakitaridia@lemmy.world 14 hours ago
Wouldn’t it even help to just do the basics like MFA or maybe OTP?
The issue is not that they’re not meeting special authentication requirements, they aren’t even meeting basic safety standards for any web app.
ScoffingLizard@lemmy.dbzer0.com 4 minutes ago
Social security identities will never be uncompromised. That’s what happens when you give teenage cybercriminal fascist access to everyone’s senaitive info. They were not following any standards at all.