Names and Identities Change – You Should Design for That
spin.atomicobject.com
spin.atomicobject.com
So supporting names is not only an issue with changing them, but preserving the actual spelling through all systems you call. I actually spent 4 years in college (long ago) with no vowels in my name, and never could get them to fix it (even my diploma had it spelled wrong).
(And they don't support 2FA. Better keep the old email around indefinitely...)
However adding it as a option, raises the problem of people trolling the site, and then quickly changing their username to dodge the fallout - some sites have icons to show that a user has recently changed their name, some have a username history on the profile - it's not a trivial problem to solve.
Names are for friends, not companies.
It would also be a privacy nightmare.
Many other national id's are not used like that and do not have any issues.
They should have to prove, beyond simply an SSN, that an individual is responsible for the debt before being able to send it to collections or report it to credit agencies.
You can for numbers issued before 2011, they're random now. The first three numbers are tied to the zip code of the application and the month/year of the application can be determined by the group numbers (the two in the middle).
That's often the case with Bank Account and Credit Card numbers too that the parts commonly masked are the least significant from a security entropy standpoint (are often built algorithmicly and tend to cluster; CC numbers often encode processor and bank in the first bunch of numbers). The parts left unmasked to make them easy to recognize are easy to recognize precisely because they have the most security "entropy" and are the most sensitive parts.
SSNs adapted in 2011 and CC Numbers are in the process of adapting (and I suppose Bank Numbers are adapting at a per-Bank rate), but it's almost funny how universally this "best practice" of masking these security identifiers started from the "wrong end" and have forced their own generation algorithms to move a lot more entropy into their prefixes and middles.
But when an real random GUID is used then this is not a problem.
Only if knowledge of one's "GUID" was regarded as sufficient to authenticate as them surely?
Maybe an ability to generate virtual IDs based on a permanent id (like with virtual credit cards) might help though this is sometimes tricky to use correctly in a privacy-preserving way.
I have two national ids (from two different countries).
Both of them leak my birth date and the second one also leaks my gender and even birth place.
The main question is - who should be such authority that would actually provide such identifiers that are guaranteed to be globally unique without collisions.
A secure place where you put information about yourself that you want to share.
Then, you won’t have to fill in any more forms, you just put an identity link pointer that fills in the rest.