Replacing Social Security Numbers Is Harder Than You Think
motherboard.vice.com
motherboard.vice.com
> Why don't they do [stronger authentication] for credit card requests? At a guess, it's because these stronger schemes are too inconvenient, and will drive away consumers who are trying to apply for credit.
> If that guess is correct, it suggests that the real solution is regulatory: make credit providers liable for the full damages, including ongoing inconvenience, suffered by victims of identity theft. SSNs are not the problem; authentication commensurate with the risk to all parties, including especially individuals, is.
Doesn't sound that hard to me...
An article with the same title, but written by, say, a marketing specialist would probably get a more sceptical reading.
Deferring to a subject matter expert is logical.
They could also do things like send paper mail to the last long-term address, to confirm it. Why don't they do that for credit card requests? At a guess, it's because these stronger schemes are too inconvenient, and will drive away consumers who are trying to apply for credit. If that guess is correct, it suggests that the real solution is regulatory: make credit providers liable for the full damages, including ongoing inconvenience, suffered by victims of identity theft. SSNs are not the problem; authentication commensurate with the risk to all parties, including especially individuals, is.
That’s a loooooot of guesses for my taste.
[0]: https://www.opensecrets.org/pacs/lookup2.php?strID=C00139519
What's the now?!
[0] https://www.metrotimes.com/detroit/how-dan-gilbert-just-scor...
If you just show up and dump $300k on some politicians laps, the effect isn't likely to be particularly overwhelming. You need to cultivate relationships, wait for a good moment (when the money is disproportionately valuable to said politician), at least sell the perception that you're able and willing to dish up more in the future, etc.
So the actual cost is a lot higher than the amount the politician actually receives.
It's hardly a secret yet identity theft is not a major problem here.
In Finland we do have check code. Valid check byte is '0123456789ABCDEFHJKLMNPRSTUVWXY'. Format is DDMMYY then separator (if CC==19 then - elif + CC==20 then +)NNNC where NNN is sequence number and C is check byte. NNN contains also sex in format of parity, and even sequence numbers are used for females. -> Creates a limit of 500 identities / day / sex. Full example: 0123456-7890
To login to secure services like all government services, our banks, our digital post box etc we mostly use BankID.
With BankID you enter your SSN, your personal password and a code from your 2FA key fob/phone app. https://www.bankid.no/en/
I wonder if I or, more likely, someone else could write a GreaseMonkey script that would turn all these obscure abbreviations into explanatory tooltips.
https://news.ycombinator.com/item?id=15210634
The "secrecy" of the SSN is seemingly an US only problem, that all the rest of the word has already solved, one way or the other, so, no it it is not "harder than you think", it is "not hard at all" ...
It would be dead in the water before you could draft the bill.
When I obtain a drivers license or passport (or some other process to confirm my identity at a government facility) that I should be able specify my 2FA medium (email address or phone number [text or call]).
Any organization that wants to prevent identity theft should be able to do a 2FA challenge. As an individual I would receive a phone call or text or email "Acme Co. is processing a request to open up a new line of credit under your SSN. Did you initiate this action?"
There should then be regulatory requirements on banks, insurance, etc that require 2FA confirmations before associating an SSN to your account.
1. Who will be the CA and RA?
2. How do you prove your identity to RA?
If I were implementing a replacement for SSNs, I'd send out certs rendered as QR codes by physical mail. That's not perfect, but it's at least as secure as the current practice of sending out UIDs by physical mail. At least the is the possibility of getting the key safely inside a secure device and destroying the original. With the current protocol, in which the only way to prove you know a secret is to reveal the secret, it's completely hopeless.
For someone to issue you a certificate, you have to prove your identity to them. How would you do that?
1) No check digits--every number is valid. Adding a couple of extra digits would help tremendously
2) No ability to retire/change the number--this is the big one. Once the criminals get your SSN--game over. You can't change it and shut the old one down. If you simply changed this, a lot of the issues with SSNs would go away.
Then there are the usage issues:
SSNs have two tasks which need to be separated:
1) Identification for "blocking" or "association" tasks. SSNs are fine for identity on a blocking task--ie. trying to shut something down, taxation identification, etc.
2) Identification for "allowing" tasks. SSNs are BAD for allowing tasks--new credit card, new bank account, etc. These kinds of tasks should always require SSN plus something else. This is where the primary failure modes are.
You can change your SSN in certain situations [1].
[1] https://faq.ssa.gov/link/portal/34011/34019/article/3789/can...
[1] https://www.newyorker.com/magazine/2010/10/04/the-scholar-je...
(as for whether this case was actually a case of fraud, well, "the heart of Yould’s defense was that she thought she was allowed, under the hale program, to use the new Social Security number to apply for the loans above the lifetime cap and to use one name as a co-signer for loans to the other" pretty much sums it up for me... who would think that?!)
We don’t have a problem with people providing technically invalid (I.e. never issued) social security numbers, only reusing ones that aren’t theirs.