Bank: Here is $100 from your account, Joe.
Joe: Hi bank, where's my $100?
Bank: Already gave it to you.
Joe: Wasn't me.
Bank: Well, Joe, you screwed up big time. You let someone steal your identity. Sucks to be (the real) you!
Bank: Here is $100 from your account, Joe.
Joe: Hi bank, where's my $100?
Bank: Already gave it to you.
Joe: Wasn't me.
Bank: Well, Joe, you screwed up big time. You let someone steal your identity. Sucks to be (the real) you!
I would think that each new account or transcation should generate a notification to Joe and he should be able to reverse them within a certain amount of time.
Joe could make it so that his device ignores notifications about transactions made by his own device, and only hear about other ones.
That would be the same crime as someone using Joe's stolen credit card info - fraud.
Therefore the bank can't establish that it was you, who leaked the secret. (Because it's easy to leak SSN, it could have been any random company you did business with. Or the SocSecAdmin.)
And even if your shared secret was used to withdraw, there's still a chance of the bank leaking it.
So usually the shared secret's hash is stored.
This works pretty well.
Around here banks ask you to give your PIN for identification, or you have to present your ID, and they compare it with what they have on file. (So trust on first use is still important.) Sure, it's probably not hard to fake these plastic cards, but that's a rather serious crime, and then the bank can pull the security cam footage, etc...
Of course, requiring confirmation on an SMS even when you do in person banking might make sense.
I have one given to me at birth, which is a sequence of 13 numbers that gets calculated with a formula and has a control number at the end (kind of like credit card). This one is random enough for nobody be able to guess anyone else's (for example, how many babies were born before you on your birth day in that region is a relevant factor in the formula) and is used with government entities and government entities only (it is illegal for the businesses to require from you to provide that number to them to give you a service).
And I have the second one, which is the national ID number. This one was given to me when I was 18, and it serves as a proof of identity with the businesses.
And there you have it. Two distinct numbers. One for your government, and the second one for you dealing with businesses. Someone can't fake anything important (as in, government-related) with your ID, and businesses have a second number that is usually proven on the spot with the photo of you in your national ID.
Problem is solved.
Not all countries have or want that.
Why do they want a NUMBER? Because names are too... human. They're messy, and they can change, and they don't fit standard forms. It's an impulse to purge the humanity from social identity that motivates establishment of national ID numbers.
Then we got income taxes and federally guaranteed pensions (Social Security) and medical assistance (Medicare/Medicaid) and a few other, smaller safety net programs. Furthermore, while there's plenty of fighting around the margins, the overwhelming majority of Americans are broadly in favor of keeping at least some of the Great Society programs, and that means we have to have a national registry of some sort.
It turns out that when the population is broadly distrustful of the idea of a national registry but broadly in support of a tax regime and social programs that require a national registry to function the stable equilibrium is a really really shitty national registry that everyone hates but nobody feels they can improve without getting shouted out of office. American politics is dumb.
Voter suppression in the United States has had a long, sordid history. Blacks were given the right to vote after the civil war, prompting southern states to implement literacy tests, poll taxes, basically any legitimate-seeming test to de-facto turn away black people at the polls. This got so bad that we literally wrote an Amendment (24th) to state "yeah you can't do this either".
What's fucked up is that this sort of thing STILL happens. This past Tuesday, a number of voters in Virginia received calls telling them to go to a different polling station from the one they were assigned. See https://theintercept.com/2017/11/07/virginia-voters-get-myst...
Stuff You Should Know did a really good episode on voter suppression in the US that I'd recommend.
The only thing everyone has is a person number, and the difference is that it is explicitly considered public information and you can get anyone's person number by just asking the Tax Agency. It's just a convenient way to keep track of people, not a way to actually identify yourself.
Absolutely not. I mean, I don't know which jurisdiction we are talking about, but I don't know of any that bases identity on a number.
The numbers don't serve as proof. They are just a number to help refer to you in databases.
The proof of identity is provided by the plastic cards and other items/papers. (Such as a birth certificate. And usually if you lose that to get a new copy you need some ID, and if you lose your ID cards, then a written statement from the police that you lost your ID card.)
This is only an issue because of tracked non-anonymous accounts. The key for money laundering in high profit / service retail businesses is using dirty anonymous cash. Often the customers literally do not exist, imaginary entries are made at the register and cash is stuffed in.
The last suggestion is easily worked around, merely trade device IDs along with account IDs. In fact the easiest way to steal money would be simply to clone your device outright complete with saved passwords etc. Joe certainly doesn't control his own device, not the firmware, OS, or apps, not to mention MITM attacks.
...
Joe: Hi bank, where's my $100?
FTFY
Bank: Here is $100 from thin air, Joe.
..
Joe: Hi bank, why is there an IOU for $100?