The Way We Use Social Security Numbers Is Absurd
fivethirtyeight.com
fivethirtyeight.com
As you mention, it's easily determinable, and it has the fortune of being an existing ID number system already connected to everyone.
Allowing everyone the ability to tell people apart based on a number is infinitely better than matching names.
In my country we use our ID numbers for everything, dentist appointments, vehicle inspections.. if you call any business at all it will likely be one of the first things you're asked for.
The number should be an identifier for a person, not a security measure. If you just accepted the fact that SSNs are insecure and that by knowing someone's SSN does not necessarily mean you are that person, then the US could use them more effectively, cut down on a significant number of errors in every industry, and actually reduce identity theft.
I can see a point in having an identification system that spans the country and is easy to use, but SSNs are not (and should not be) it. It's also something unlikely to properly happen in the US due to the state/federal powers separation. (Which is why we have the kludge of so many businesses using SSN for the purpose in the first place...)
Prior to the IRS requiring a SSN for claiming dependents, many people did not get a SSN until they started working; parents did not apply for them at birth. Most of the people I went to high school with, got them in high school.
The simplest solution would be a disassociated ID card with a 2 or 3 factor identification (eye scan, fingerprint, etc.). Except this requires everyone to register and isn't going to gain widespread support in the U.S. for privacy reasons.
Info security just needs multiple factors, so require SSN and then an RSA-type second-factor to authenticate. This would make it about as secure as GMail, except for when you lose your PIN generator. I have backup codes for my GMail... How do we handle lost PINs when it's personal ID at stake?
Identification could be as simple as a personal e-mail address... Except we have all kinds of things tied to SSN as ID, including credit history, bank loans, etc. that require proof of individual identity, not just "unique identification".
Is this a solved problem?
Almost all of the "identifying" objects about a person (names, emails, even fingerprints can change over time/accidents) change with time and circumstance. That's hard to encode in a database or program against, so identity is a harder problem to solve than people would like it to be.
People like 1:1 mappings because it is easy to map and report, but those are rare in the real world. There is more than one John Smith. John Smith may have more than one email address (at the same time even).
Credit Reporting Agencies are essentially tasked with doing an ad hoc mapping of the vast fuzzy cloud of identifying statistics about a person to a 1:1 report ID. It should be no great shock to anyone that the Credit Reporting Agencies will get this wrong sometimes. Sometimes I wonder if its the Credit Reporting Agencies that should just hand out identification numbers (here's your Equifax Report #, use it apply for credit from here on out; we will no longer provide results without that specific ID #) and stop trying to corral data that will always be wild and untamable.
How do they validate you, though? You give them the unique ID, but what's to keep you from reporting someone else's with a FICO score of 800 (top of the chart, for those outside the US).
Turn the SSN into a (not secret) username/uid and add a 2-factor seed that's a shared secret between the SSA and the individual. Provide an API for 3rd parties to validate (SSN, 2FA code) pairs. If things go wrong, 2FA seeds are lost, etc, there's the same fallback that exists for lost SSN cards or stolen SSNs: go to a SSA office and get it fixed in person.
The SSA could provide an online SSL-protected client-side webapp to generate 2-factor codes for those who don't have a smartphone. They could offer it as a telephone service too.
A good solution to identification would be a central state operated database. But it would have to be backed by strong laws defining what it can be used for with no loopholes, not even for police of "national security", and a default deny policy. It would help secure taxes, welfare benefits, health care, voting, and background checks. The database information cannot be sold, data mined, or used in a criminal investigation without a non-rubberstamped warrant. The database can be used to confirm identity but the ID number cannot be stored anywhere else. Other agencies, both government and non-governmental, will be required to generate their own internal IDs without recording the national ID so if one database is compromised it doesn't collapse the whole house of cards.
These are common sense policies but they are all human policies. No amount of technical wizardry can stop a human from doing something stupid. That's what laws and regulations are for. However the US has been stuck in a counterproductive attitude of treating regulation as a bad thing. So poorly implemented policies keep screwing up all the best technological intentions of the engineers.
(* Like most Mark Twain quotes there's a good chance this is misquoted or misattributed.)
Good luck with that, in any country, in any regime.
"However the US has been stuck in a counterproductive attitude of treating regulation as a bad thing" Which is why other countries have such air-tight centralized databases that are never abused...right?
Line of questioning is:
How big is the non-driving population?
How many of these need/want access to credit, utilities, other public services?
What is recourse when you don't drive? Seek a state ID card?
Are there any privacy/other problems with requiring that ID be obtained?I found it amazing that the article didn't mention the role that the credit agencies play in this. Almost all the time you are asked for your SSN, certainly in commercial transactions, it's so a credit check can be run. The credit agencies could solve this. They could even some it securely.
When some utility wanted the number to run a credit check I said I could not remember it. They ran the check anyway (using Name and Address), and read my social back to me!
You do see driver's licence and passport numbers being used, but it's far from the de facto standard that the SSN is, and thus far less of a data security nightmare.
We are long overdue for some federal legislation about how ssn can be used and how it cannot along with other basics to protect people from I'd theft. It should be illegal to use it as any kind of identity verification for instance, but its not.
Also yes, IDs are not passwords and should never be used for authentication purposes. This is never "two-factor", it is always a "wish it were two-factor" kludge.
[] I love the mostly clause here, because they can, in fact, change, and it's sad how much software and credit reporting breaks because of that in-built assumption that person will ever have one SSN.
unlike SSNs, driver's licenses in most states don't have
"Please don't use for other identification purposes"
written on them like SSN cards do.
SSN cards haven't had that printed on them since 1972.But a prepaid T-Mobile, recharging via CC over the phone? Asked for SSN and insisted. When I said I was Canadian, they insisted on the Canadian equivalent. Had to hang up and get another rep.
Why do Americans just go along with it and give their SSN out? Just say you don't have one. Canada does it right. Upon getting a SIN, the government is very clear that you are not obligated to give it out and that companies cannot refuse service if you do not provide it.
A while back, in 2007, I think, I tried to get copper-loop telephone service to my house, with AT&T. They wanted a SSN. I wouldn't give it. So they refused to give me dial tone.
And I haven't given AT&T a single penny since, more due to the snotty, imperious, Ernestine-like attitude I got from every single customer service rep I talked to than any great reluctance to hand over some 9-digit number. I actually haven't had any copper-loop phone service at all since. It's been all VoIP and mobile, and I only have the latter by spouse mandate.
I have since given up the fight against misuse of SSNs. It's Sisyphus rolling the boulder uphill--a constant, arduous struggle that ultimately produces no useful results.
It would be nice if the USG would fix this and force it to be optional. Companies might refuse you credit without a check, but not service.
And really, who wants credit? I signed up with Fido (cell) in Canada, and the rep was going on about how since I was new, I'd have only $300 credit, but they'd raise it later. I laughed and said I would like to lower it. He was genuinely confused why I wouldn't want more credit. The fact that my service plan is only $60 a month so anything near $300 is fraud wasn't understood. (Fido charges $6 per kilobyte for US data roaming.)
I already suspected the true reason. It was probably so they could more easily send and receive credit reporting information to the 3 big CRAs. And that's why I offered to pay for a year of service in advance. But they stuck to their "we just need it" and "it's company policy" non-reasons to the end. And when I heard about their data breach in April, I felt so much schadenfreude welling up within me that I just couldn't stop grinning, until I remembered that no one actually cares any more.
I can't wait until mainstream businesses and government offices drop their PSTN numbers and start accepting synchronous audio-stream sessions (or "calls") between endpoints identified by a URN or user address.
I hate, I hate, I hate "the telephone company".
A German-speaking friend helped us solve it (I still don't know exactly what he worked out with them), but it wasn't a pleasant experience. Especially since in France we literally just walked into an Orange shop, and I said, in my bad US-high-school French, "Nous voulons acheter une carte SIM", and they said "OK", quoted a price and that was that.
In this case (~2006) T-Mobile was insisting that American Express would not process my charge if T-Mobile didn't submit my SSN along with the charge. Which is obviously just false (Amex verified this to me).
A funnier thing I've seen in Guatemala is that many places will ask you to write your phone number down on the CC voucher. They say it's for "security", as if someone using a stolen card would provide their real number. They don't verify the number as they just take it along with the signature, they just make a big fuss to get something written down.
I'm currently in Limbo with my healthcare provider because they won't let me pay my bills online (or set up appointments, see results, or email my doctor) until I validate my identity, I've had to do my auto registration through snail mail because the state's website won't recognize my SSN, and have also had to call other places to get set up on their websites because of having no SSN when I started.
You mentioned T-Mobile, who were pretty good in getting me set up without a credit check, but won't auto debit my credit card when I have a bill. I have to go online each month and pay, with that same credit card. And getting to that point took a couple of phone calls.
I'm pretty sure foreign residents get an Individual Tax ID Number (TIN). [1] Not sure why @swalberg doesn't have one...
[1] https://www.irs.gov/Individuals/International-Taxpayers/Taxp...
I applied for a SSN when I got here but it took 4 weeks to process. I now have an SSN card with a statement on it saying that I'm only allowed to work with DHS authorization.
Part of the hassle is because I signed up for services with no SSN but web sites all assume you have an SSN. The other problem is that credit histories don't cross the border. Even with an SSN, I've got no public record or credit history.
What I find funny (or sad) is that when I call to update my records with my SSN (largely so I can build a credit history) people refuse to take the number over the phone, and will not take an email scan. They only want snail mail or fax.
So I have to be a victim already to add security to my SSN? Why can't I just opt-in before I get my identity stolen?
Citizens of Florida, Georgia, or DC can, though. Wonder how we expand this program...
So much for 2FA. So much for strong passwords. All I have to do is obtain your SSN, call up your cell phone provider and hijack your phone number, and initiate a password reset with Google. That gets me into your Gmail, which in turn gets me into all your other accounts.
Ridiculously easy. Google should be ashamed.
physical 2FA always provided less security against people who know you (and thus could easily make that link), because those people have the physical presence to steal your token unlike a hacker in Elbonia.
...
...
..Now tell us what they should use instead of phone 2FA?
[0] http://ece.rocks/alex/2015/02/01/generated-at-birth.html
Yet just last week to sign up for a mobile contract, I had to print a PDF, sign it and scan it. The adoption has been almost nil.
Of course the lack of adoption is another concern.
Unfortunately, they made a bizarre system where US students had their student ID be their SSN with a fixed prefix, and international students got a random number with other prefixes. They refused to give up on using SSN even when they knew it wouldn't work for a good portion of students.
Heaven forbid someone just add an SSN to student ID lookup table to the database.
Why does a school even need this number?
The only groups that need this number are financial institutions of all types (including employment and borrowing) and government agencies.
A school does not need it. If they lend you money then that department might, but no further.
What I do when places that don't need the number ask for it is pretend I don't remember it. So far I've not had any problems, they mange just fine without it.
Let's not also forget that in year 2015, we still use passwords as primary access control guards. That's technology that was invented shortly after the development of speech in humans, circa 100,000 BC.
There's nothing intrinsically wrong with them. There are people who propose we generate key pairs for every newborn. It is, however, delusional to believe that the same governments which struggle with flat documentation will then turn around to properly do PKI.
It outlined how the first 3 numbers are kind of based on your location of application (like a 3 digit code for a county). next 2 are kind of related to your date of birth. The only hard part was the last 4 digits which are random but easy to get as thats the first thing most companies ask for.