> Unless the universities pay the ransom, the hackers will continue publishing student information.
That is an incredibly irresponsible thing to say. The data is out now, you'll be able to buy it from a broker soon enough. Any money paid is money lost. I think paying would also contravene US law.
What these victims do need is new SSNs, and the Gov't needs to find a way to identify people without the ID also being the password.
SSN were never really secret. For the most part the first 5 digits are a derivative of when and where you were born (public record) and you’ve given out the last 4 to every financial institution and employer.
You last part is spot on. Basically people should setup a password at the DMV or something.
The United States Postal Service would be a great "trust provider" (managed PKI, signing personal certificates for individuals and busnesses, etc). They already do it inasmuch as many government agencies (the BMV in my state, for example) accept addressed official correspondence as proof of residency.
I can just imagine the panic of having to increase the field size by a single digit, it'd be a billion dollar, decade long problem that never gets fixed.
Nothing about SSNs is ideal. The uniqueness and permanence assumption is part of why identity theft is so calamitous. So sharing an SSN with someone who's been dead 20 years seems preferable to sharing one with someone who is reusing yours.
Utter bullshit. How could you even come up with something like this? We've got a long record of thousands of ransom payments by US companies, don't you think someone might have already said something if this was illegal? There's a whole industry of companies that facilitates these ransom payments, and insurers who will cover the ransom amounts.
That is an incredibly irresponsible thing to say. The data is out now, you'll be able to buy it from a broker soon enough. Any money paid is money lost. I think paying would also contravene US law.
What these victims do need is new SSNs, and the Gov't needs to find a way to identify people without the ID also being the password.