Oh, and the password is almost impossible to change, and you're required to use it to sign in on a host of other sites.
Amtrak’s solution? I could set a PIN, right then and there, verbally with the agent over the phone. No logging into my account. No email or text message confirmation. They didn’t even ask to confirm my DoB or address. Nothing. I had only given him my reservation number.
And not 30 seconds after creating my new PIN the same agent was then able to “verify” my identity/account by asking me... for my PIN.
https://krebsonsecurity.com/2015/10/whats-in-a-boarding-pass...
https://web.archive.org/web/20120324074139/https://www.iata....
Historically, something like that might well have been handled by snail-mailing a default pin to the address on record for the account and telling you to call back after you received it.
Of course, the problem is that a lot of people these days would think that was really poor customer service.
Of course, you could let the site specify the password, which would work if they're long and random. But social security numbers are neither of those.
Except for the US government, and most banks, medical providers, and cell phone companies.
I've noticed some sites using identification only (like the days of IRC), so you can have a consistent identifier to interact with people but a username isn't actually secure or owned. The converse should also be possible, in the same sense that a bank PIN is used to authenticate with no public identifier involved.
That said, for many offerings we should consider "a company employee" to be a third party. There are already employees with access to my data, but the outsourced call center employee who answers the customer service number probably isn't one of them, and I want them to be able to look up my account details without being able to impersonate me.
The solutions Sweden has to proving identity despite this are not exactly radical: photo ID documents, and secure ID apps (encrypted certificates) on phones or smartcards.
SSN and NIN could reasonably be used for identification of the form of "this person's data is different from that person's data". (identification as in primary/unique key)
They can't/shouldn't be used for authentication that this person is who they claim to be. (identification as in password)
SSN's were only ever meant to be used for identification (as in a username). In the beginning the worst that could happen is that someone else would file their payroll taxes with your SSN, and make you eligible for more Social Security benefits when you retired. It was never meant to be a password.
For employment, the I-9 form is what we fill out as authorized US workers and to document same.
https://www.uscis.gov/i-9 (the "paper version" link works best)
You'll note that Social Security card is in List C "documents that establish employment authorization" and not in List B "documents that establish identity" nor in List A "documents that establish both identity and employment authorization"
I guess you can look at it as a form of off-line multi-factor authentication. You are using the Social Security card as proof of eligibility for the person whose identity you have already established using another factor. In that case, it's the card that acts as the factor, not the number (which if you've ever seen a social security card, it's ridiculous to think that it's in any way secure or even durable).
100% agreed, perhaps I should have worded my comment better. My point was that this seems to be common practice in the US but not over here.
Well, TIL. I guess no one ever asked me for it.
One can still ask a Canadian for their SIN for reasons not on that list, but it is illegal to refuse service for not providing a SIN [2].
[1] https://www.canada.ca/en/employment-social-development/servi...
[2] https://www.canada.ca/en/employment-social-development/progr...
The closer equivalent in Germany is probably the Personalausweisnummer (ID card number). Basically everyone has an ID card, and sometimes the number of the ID card is used as age verification or is written down as part of identity verification at a bank or similar. Assuming you verified that the ID card is genuine it's a good unique identifier that survives name changes; however its usefulness doesn't come from secrecy but the forgery-proof piece of plastic it's printed on. Also you can change it at any time within a few weeks by just getting a new ID card, and it naturally expires every ten years or so.
I think a fundamental problem in the US is the requirement to verify identity via phone. In Germany that's just assumed to be impossible without a prearranged passphrase; when opening a bank account you verify identity by showing ID at the bank or a postal station or by waving your ID in front of a webcam during a live call.
- If you want to pay bills you just do a bank transfer (they are free and fast within the EU), transferring the money to a published bank account with my invoice id or similar in the subject. If somebody else wants to pay my invoice neither I nor the company will have any objections, so no need for authentication.
- If I want to check a bank account or a credit account or something similar I have a password that was set up when the account was created
- If I want to set up an account I can authenticate either via webcam (showing off the security features of my ID card) or via PostIdent (where I have to go to a post office)
- When talking on the phone you have an authentication problem (unless a "phone passphrase" is prearranged, but for anything with lasting consequences you usually have to send them a written version per email or snail mail for papertrail reasons anyways, or alternatively they send you a confirmation per snail mail that you can object to in a reasonable time frame.
The new ID card has online features that in theory solve the problem completely for online systems, but few places implement that so far.