Oh, and the password is almost impossible to change, and you're required to use it to sign in on a host of other sites.
Oh, and the password is almost impossible to change, and you're required to use it to sign in on a host of other sites.
Amtrak’s solution? I could set a PIN, right then and there, verbally with the agent over the phone. No logging into my account. No email or text message confirmation. They didn’t even ask to confirm my DoB or address. Nothing. I had only given him my reservation number.
And not 30 seconds after creating my new PIN the same agent was then able to “verify” my identity/account by asking me... for my PIN.
https://krebsonsecurity.com/2015/10/whats-in-a-boarding-pass...
https://web.archive.org/web/20120324074139/https://www.iata....
Historically, something like that might well have been handled by snail-mailing a default pin to the address on record for the account and telling you to call back after you received it.
Of course, the problem is that a lot of people these days would think that was really poor customer service.
Of course, you could let the site specify the password, which would work if they're long and random. But social security numbers are neither of those.
Except for the US government, and most banks, medical providers, and cell phone companies.
I've noticed some sites using identification only (like the days of IRC), so you can have a consistent identifier to interact with people but a username isn't actually secure or owned. The converse should also be possible, in the same sense that a bank PIN is used to authenticate with no public identifier involved.
That said, for many offerings we should consider "a company employee" to be a third party. There are already employees with access to my data, but the outsourced call center employee who answers the customer service number probably isn't one of them, and I want them to be able to look up my account details without being able to impersonate me.