Of course, you could let the site specify the password, which would work if they're long and random. But social security numbers are neither of those.
Except for the US government, and most banks, medical providers, and cell phone companies.
I've noticed some sites using identification only (like the days of IRC), so you can have a consistent identifier to interact with people but a username isn't actually secure or owned. The converse should also be possible, in the same sense that a bank PIN is used to authenticate with no public identifier involved.
That said, for many offerings we should consider "a company employee" to be a third party. There are already employees with access to my data, but the outsourced call center employee who answers the customer service number probably isn't one of them, and I want them to be able to look up my account details without being able to impersonate me.