Security Breach at US Universities
dorper.me
dorper.me
It should be clear by now that as long as the data is stored somewhere it is at risk of being leaked. It doesn't matter how secure you think your tech stack is. Improving tech is not the solution. Here's the solution:
1. Don't collect information in the first place, unless absolutely needed. Some schools collect DOB, address and so on just to register for a webinar.
2. Don't permanently store information. If you collect SSN for employability verification then do the verification, store a flag, then delete the SSN. Similarly, after verifying DOB, store a flag then delete DOB.
3. Assume information is already public. This is the most important part. Despite all of the leaks happening, many financial and other sites will let you use your DOB, SSN etc. to prove that you are who you say you are. This is absurd. It appears American businesses prioritize convenience over security. Americans need to demand better.
I think we need something like drivers licenses with public-key crypto. Lost your ID? Go to the police, prove your identity to them and get a new driver's license. If people are worried the masses are too dumb for PKI, then make it opt-in and leave it to advocacy groups to expand utilization.
The problem isn’t specific to SSNs. Most authentication of users in the public sector in the USA is done by knowledge of facts, whereas it should require proof of government ID card (preferably with digital certificate, not just knowledge of the ID number)
It is rapidly approaching that point by virtue of all these breaches. SSNs are like gold or fiat currency: they only hold value because they are relatively scarce. If too many are in circulation, then no institution will trust them, which makes them useless.
> If people are worried the masses are too dumb for PKI
Use OAuth to communicate with a central service that uses FIDO2 for authentication. Easy to use, easy to revoke, almost impossible to pwn.
Costs born by the victim are not the only problem. It is that the brittleness of SSN makes it impossible to lay the costs at the feet of the proper "company which got hoodwinked".
You must share your SSN 100 times for: work, home, credit, school, health. All of them have been popped 5 times each. 20 years later, you are victimized. Who pays?
SSN should be deprecated. You can pretty quickly reason to public/private-key SSN alternatives. The US government would actually do it for the consumer (this term) but the US probably doesn't want to pay it's share of the replacement cost to do so.
Still, we should demand it.
Since all those companies can plausibly point to someone else, the victim pays! Which is just how they like it — privatize the profits and socialize the losses.
What would actually get creditors to stop using social security numbers is if the SSN's utility as a proxy for creditworthiness drops. But that won't happen, even with many more breaches, because individual consumers need to do everything they can to keep their credit scores up.
> Still, we should demand it.
Yep. The market will not drive this. It will have to be consumers, speaking collectively through the government, imposing regulations.
Culturally, I think we need to move away from the idea of "identity theft", which places most of the burden of "restoring their good name" on the individual whose "identity" was "stolen". We need to treat it like what it is-- fraud. We should hold the parties who are negligent in their duty to authenticate liable for the fraud committed.
Insurance companies and banks would act quickly if the liability were theirs. We'd have "chip and PIN" in the United States if fraud liability rested with banks, instead of mainly with merchants, for example.
I'd like to see the US Postal Service get into the identity/authentication "game", personally, but efforts at a state level would be better than nothing.
The only reason that SSNs remain convenient is because there is no viable alternative when your authorization hits government or financial institutions.
Maybe financial institutions will get wise (I doubt it, unless they have to pay $1,000,000 to every user whose SSN gets leaked from their systems) but the government will probably never change in our lifetimes.
It's not like universal government issued IDs haven't been suggested, but the SSN is used because it's the thing resembling one that hasn't died in committee or debate. There's no political will to create a single identification system for US Citizens and it will be fought tooth and nail by liberals and conservatives.
Then don't replace SSN, augment it. Once you opt-in, your government-issued FIDO2 will be required alongside your SSN.
Here's the ACLU's stance: https://www.aclu.org/other/5-problems-national-id-cards
Ideally, the identifier they give you would be not be the one that they use to government either, but one tired to it
I learned a valuable lesson, no matter how “secure” you think your servers are, at some point all the data on them will be compromised.
So...
* Backup - often in many places
* secure it as much as you can
* Encrypt we much as you can
* Airgap sensitive stuff
And even with all of that you will still be compromised. Eventually.
Protect your data so you can spin up on a new server if you need to.
Sigh.
It is, just not enough.
Of course, many many students in undergraduate life are also employees of the school part time, so presumably they need to provide this information.
Given the construction of SSNs (first five digits are a key for state-and-date), and our large population of students from different states, reconciling SSN to human was trivial.
Ironically, the foreign students were in better shape because the registrar issued them an ID number which was not their SSN.
Source: I work for a software company in the higher ed market.
X:Q = V->generatepair(Qpub) // Generate a unique ID stri g for interacting with the university. Not confidential, because not verifiable by anyone.
Tok = V->encode(Xpriv, X:Q, Qpub, property:FullName, Vpriv) // Generate a token string unique to the pairing of X:Q, for a specified property like FullName, signed by the verifier.
FullName = decode(Tok, Xpub, Qpriv) // The query entity (university) can decide this blob, but no one else can.
If the Q looses confidentiality of Qpriv and all the Tok, then that data is lost. But having that doesn't let the attacker prove they are X to a different entity.
I'm sure more rigorous schemes have been thought out, but there is so much inertia in changing anything.
Many attacks go from an initial point of compromise to find and attack target information. If you can detect this activity early, it might be possible to reduce the severity of the breach.
Signed, someone who watched a company learn the hard way that restoring from tape backup is not an easy or 100% perfect process.
It's possible they were doing something similar.
I've also had to give my SSN to verify my identity to my insurance carrier at my dentist.
It’s sad for lots of reasons, but understandable considering that it is useful. for whatever reason there isn’t much political will to make an honest effort at a federal government ID (even though we de facto have multiple)
There was a huge problem a few friends and I caused our first year there when we got bored in the computer lab. Every student account on a school computer had a folder named PUBLIC. Out of curiosity we dug down a few folders and found the txt file that was referenced by the simple visual basic program the IT guy wrote for class scheduling. That program used your name and SSN as login credentials. So there was a txt file that was simply a list of everyone's name and SSN for it to reference.
We being the idiots we are copied the file because it was a public folder anyone could access. The only reason we didn't get expelled was because one of the kids had a lawyer father who threatened to go public about them being that irresponsible with our data.
If you had a mag stripe writer you could grab a random person's grades, encode their SSN on a student ID, and then use the card to buy stuff on campus.
EDIT: It’s been a long time since I was in school, and, frankly, I was expecting someone with fresher knowledge to come up with a counter-example. So, see the comment above about an IRS form 1098-T.
They also need it for the 1098-T (Tuition Statement). That's not to say they couldn't design better systems and not use SSN as an identifier, but there is a legitimate need for it.
Citation?
But yes, this could have all been headed off if the social security act had prohibited private organizations from requesting, using, or storing these identifiers in the first place, for anything but immediately passing them on to tax authorities. A Customer ID is good enough for all non-credit uses, and credit should require actual in-person verification to issue. But this is the general shape of totalitarianism in the US. The government mandates the barest minimum of systems, companies lobby against any restrictions that would prevent their abusing it, and we end up with a legally-mandated freedom-destroying system invading most aspects of our lives.
PS I've got to wonder about a blockchain solution for keeping a public catalog of leaked PII that gets abused for verification. Make the "exploit" plain as day and companies will have to change. Right now the carding community keep this to themselves, and out of sight is out of mind for the companies that continue to abuse it.
The US needs to just scorch the earth re: social security numbers. Set a date when all liability for fraud enabled by improper use of SSN's for "authentication" is the responsibility of the party misusing SSNs and publish the entire list.
The list has, arguably, already been published (thanks, Equifax!). We just need to close the loop.
As I’ve mentioned elsewhere, SSN is not the only fact used for authentication. We need to move away from all pure fact-knowledge proofs of ID and to MfA preferably with one factor based on a government issued ID and asymmetric encryption.
I concentrated on SSN because it's the government-issued fact-based "authentication" factor. The other fact-based factors are just as bad.
I wish we could have a government-sponsored PKI but between concerns from citizens about "freedom" (either freedom for business to "innovate" in the space, or freedom from individuals to be "tracked" by the government) and from surveillance advocates who will want to include key escrow/recovery provision I don't see it flying.
In some other comments on this post I mentioned the USPS would be a great "trust" provider. They already serve in that capacity to some extent evidenced by the various government entities who accept an addressed piece of mail as proof of residency. I don't think there'd be enough bipartisan support to make it happen, but I think it'd work great.
That requires collecting social security numbers.
> Good day!
> If you received this letter, you are a customer, student, partner or employee of University of California. The company has been hacked, data has been stolen and will soon be released as the company refuses to protect its peoples' data.
> We inform you that information about you will be published on the darknet ( [link redacted] ) if the university does not contact us.
> Call or write to this store and ask to protect your privacy!!!!
I'm leafing through the linked site and I can see SSNs, tax forms, enrollment forms - yikes!
But the wording the link was a bit off and I really didn't think much of it and moved on
The problem are the Universities, specifically management and the Board of Directors.
They see IT as a complete waste of time, they won't fund it properly, they refuse to pay market rates. Coupled with the fact that the staff behaves like children, pushing back on EVERYTHING that the security teams want to implement.
The staff doesn't understand why people need passwords, I'm not kidding, they want just open access to everything from anywhere without any controls, and they throw temper tantrums when any controls are put in place. Frankly if it wasn't for the safety and security of the University these people would not be able to function in the real world, and I can't image what it must be like for students dealing with these egotistical, bombastic children.
Basically everything the above poster said. It was pulling teeth to update or upgrade anything.
it doesn't have to be that way. IT people are pretty shit in general at soft skills. sometimes, you need to stand up for yourself in a conflict.
your userbases digs in their heels because you let them.
Then you just get fired. They’ll just replace you with someone else who’ll listen. Some people just don’t learn no matter how hard you try.
The problem was never users/faculty. It was other people doing IT there for longer who would not accept anything they were unfamiliar with, and treated "their" hardware as if it was their own children. It led to a sort of balkanization of infrastructure that was extremely difficult to break, and you often had to spend way more of the budget to come up with convoluted solutions so you didn't touch their ancient setups rather than just making the whole thing homogenous and centrally managed.
As a result, depending on what you were working on, you could have to deal with wildly different AWS/Azure/GCP platforms, or on-prem hardware that could range from independent(!) OpenStack installs to ancient Debian machines that might not even be supported anymore. Sometimes people negotiate licensing completely separately, where you could have unused licenses available but it's not communicated so it's bought again by someone else. Some places even had random servers running inside people's offices connected via Wi-Fi.
There's a reason I got out of that line of work. I'm frankly surprised universities aren't a larger target.
Most of the enterprise sales including Microsofts bears responsibility here for knowingly exploiting these idiots in the management position and the Board of Directors. It's a huge circle jerk culture back and forth.
I full well remember working in Louisiana where they tried to introduce Microsoft Dynamics as an EHR backend for Medicaid. The CTO of the DoH was an ex Microsoft guy. The secretary had some times to Microsoft. And Microsoft knew full well that their shit isn't working when they went on their sales pitch that "Dynamics can do everything".
All the engineers advised them against it, multiple waves of them left. I got fired for telling the middle management that I wouldn't be bullied into doing things I didn't consider ethical.
The CTO of the DHH moved on to the HHS btw. There's never any recourse to this, because what they are doing is not only legal, but also with good intention.
EDIT: Also keep in mind that engineers are rarely allowed to talk to leadership, let alone to inform the board. But after what I learned, I think keeping silent is never a good option. Last time I needed to do that I made one of the German Government healthcare institutions change course on an obvious mistake. And all I did was inform the board of what exactly they are deciding, what the consequences of their decisions are and who would be responsibility for it. The recourse of that was mostly bullying, since there wasn't really anything they could have done, but the lesson here is that most people have a lot more power than they think.
(If nothing weird (bad) happened, in a way there's nothing to write about?)
Sounds like your management structure is weak, and lacks power or willingness to enforce mandates.
Your experience is not universally the case in higher ed or academia.
Actually, moving to a more managed environment (so Azure and SaaS instead of hosting your own stuff) might make it better since MS can and will patch their own servers rapidly.
Basic policies were fought tooth and nail by departments and influential professors / individuals who themselves didn't understand the ramifications of their decisions.
IT budgets would get cut and monies given to departments who would build catastrophes of networks, and when the department was tired of it would get handed to IT to make it work, the entire budget already having already been spent on making a mess.
I worked on several projects where complex microscopes or millions of dollars of equipment were connected to off the shelf consumer networking gear (and then they'd blast it with gigs upon gigs of data in a few milliseconds) because the consumer networking gear is what the folks in that department knew how to use. It was then handed to the IT team and then tickets opened about how 'it doesn't work' / it is described as an IT failure when nothing works.
I work in University IT as a developer in the central IT department, but I started off in one of those "shadow IT" groups. There are little islands of technologists embedded with grad students who continue to make many things run on shoestring budgets and with minimal oversight from IT professionals.
I've seen things change in recent years, though. The central IT department is gradually gaining traction in some of these places.
That isn't a panacea, of course, because we have our own issues. But I do think overall the availability of senior IT staff and programmers is a huge boon for these small teams who are starting from little to no experience in the field.
That is an incredibly irresponsible thing to say. The data is out now, you'll be able to buy it from a broker soon enough. Any money paid is money lost. I think paying would also contravene US law.
What these victims do need is new SSNs, and the Gov't needs to find a way to identify people without the ID also being the password.
You last part is spot on. Basically people should setup a password at the DMV or something.
SSN assigned after 2011 are randomly assigned. The first digits no longer have any special meaning.
Utter bullshit. How could you even come up with something like this? We've got a long record of thousands of ransom payments by US companies, don't you think someone might have already said something if this was illegal? There's a whole industry of companies that facilitates these ransom payments, and insurers who will cover the ransom amounts.
If I said
"can I have a loan, my name is John Smith from 123 Main Street"
And the bank gave me money and stuck it on John Smith's account, people (John Smith) wouldn't stand for it.
In an ideal world SSNs would be published in a global lookup list, getting rid of the entire idea in the average person's head that SSNs are secret information when they aren't.
Could just replace that with "in other countries".
Where I live my personal number is considered public and government will give it to anyone asking. Authentication is done using one time codes, certificates, identification cards and similar. Nothing stops a company from treating the personal number as some authentication factor but it would make no sense.
(A large number of problems in the US are cultural problems, and many "solutions" from SV are solutions for uniquely american problems)
For a few services if you forget the password you get the letters again.
It's mostly used to log into government services, but you can also use it to digitally sign arbitrary PDFs.
Banks have their own system where you need an app from the bank to confirm your identity when logging into your bank account or to authorize payments.
As far as I know, identity theft is really not much of an issue here. The biggest weakness is phishing (eg. people could call and pretending to work for your bank, asking to you to confirm something on your phone app)
Fault isn't the important question. Often the damage is done to the SSN owner, with zero consequences to the person/organization who misuse and/or mishandle the data.
There were three breaches in 2014-15: https://www.networkworld.com/article/3039116/uc-berkeley-mak...
There was a massive one back in 2009: https://www.networkworld.com/article/2254411/160-000-student...
There was a 2006 breach involving the DoE labs managed by UC: https://www.networkworld.com/article/2292688/university-hit-...
And that’s just what I dug up on UC Berkeley in a few minutes. At what point do we start saying “no” to anyone requesting personal information? If a university known for its computer science programs can’t keep this info secure, how can we trust our doctors, insurance companies, landlords, and so on to get security right?
You really do not want to know what passes for IT at universities even as renowned as Stanford or Berkeley.
Arguably, the hundreds of Accellion clients should have separately encrypted their data and used some sort of PKI to exchange public keys. But try getting users to do that properly.
Unfortunately, since Broadcom bought Symantec there hasn't been any good PGP solution for corporate file exchange.
I mean, they assured they'd form a working group with other Universities about remaining concerns regarding privacy issues in Windows 10 and planning to confront Microsoft about them. I guess Microsoft is shivering with fears and busy removing all telemetry right now.
Other great changes form this new deal are that Universities now have to pay a full Windows license for every employee, no matter how many hours they work; before you'd pay by how many full-time jobs all the employees would make up for. That means most Universities pay twice as much now. And did you know the new deal explicitly forbids remote access to any Windows machine under this license? You have to pay extra for that. What a strange coincidence regarding the current epidemic. Universities' legal departments are clueless whether this only applies to RDP, or alternative 3rd party tools as well (or rather whether this would hold up in court).
This is the first time the deal is made nation-wide, you'd think this puts our Universities in a better position, but we got fucked in every way possible.
I realize this is only marginally related with the original post, but 1) sorry, I just had to vent somewhere, this seemed just like the final straw, and 2) am I the weird one for seeing a problem in this trend? Universities were once driving innovation in technology, students were fiddling with emerging and expensive tech, but today we already have some Universities that don't even have their own datacenter anymore, everything is hosted elsewhere and maintained by contractors. Students access SaaS via a Browser. Walled gardens everywhere. This doesn't help.
How about IP KVMs? How about non-IP KVMs? How about a long usb cable?
E.g.:
https://www.urz.uni-heidelberg.de/de/microsoft-landesvertrag
https://www.rz.uni-freiburg.de/services/beschaffung/software...
it also comes with a5 licenses with a special and cheap deal so it's basically ridicolous that all other customers are paying for this.
> but today we already have some Universities that don't even have their own datacenter anymore, everything is hosted elsewhere and maintained by contractors. Students access SaaS via a Browser. Walled gardens everywhere
tons of software was already from external contractors. I'm not sure but some people like you are living in bubbles.
of course it would be possible to have everything open source. BUT with our current governement M365 is the best solution. the cdu sleeped for over 20 years to have a great open source solution. so it would be impossible to have something integrated ready within a short window, it would also blow a huge budget. the only thing you can be mad about is our government, the m365 is the best thing that could happen.
btw. I hate the strange bashing against american companies, as if german companies are any better (they are not).
btw. I'm german and everytime I see something like that I'm mad, we do everything to even have a SaaS vendor, with ridiculous data privacy (only if you are an american company, for german company's the authoritis are looking away or making special rules) and than our governement fucks every citizen by making rules that don't even work together with the privacy rules. time to relocate. everything starts to be stupid and the wrong questions are asked.
True, but no reason to dig an even deeper hole.
> of course it would be possible to have everything open source. BUT with our current governement M365 is the best solution. the cdu sleeped for over 20 years to have a great open source solution. so it would be impossible to have something integrated ready within a short window, it would also blow a huge budget. the only thing you can be mad about is our government, the m365 is the best thing that could happen.
You're completely ignoring that I'm complaining about the move to the cloud, and the restrictiveness of the contract. Even just continuing the old contract and staying with offline-Office would have been better.
> btw. I hate the strange bashing against american companies, as if german companies are any better (they are not).
I never even hinted at this being about Microsoft being American. I don't want my University to upload my PII to "the cloud" so I can use Word in a Browser.
You're basically saying we shouldn't even be trying anymore. Why not shut down the CS departments of universities entirely and just hand out accounts to Skillshare et al., so those still interested in CS can learn from there? There's nothing left a University could offer that you can't access from there. Maybe a couple credits for the Azure cloud if you need to do something computationally intensive. Your University surely doesn't have anything left in-house for this anyways.
a cloud is a necessity. it's basically impossible to have a local solution, for every fucking university and most stuff is basically serices built together with closed and open source software, which is a managemend disaster.
> I never even hinted at this being about Microsoft being American. I don't want my University to upload my PII to "the cloud" so I can use Word in a Browser.
your PII is uploaded to so many companies, besides microsoft. microsoft is probably the lesser evil of all these.
> You're basically saying we shouldn't even be trying anymore. Why not shut down the CS departments of universities entirely and just hand out accounts to Skillshare et al., so those still interested in CS can learn from there? There's nothing left a University could offer that you can't access from there. Maybe a couple credits for the Azure cloud if you need to do something computationally intensive.
we should but as of now we should have a intermediate ms solution. btw. the cs departments most of the time do managed services, they do not develop stuff. often they already manage microsoft solutions, so they already use microsoft active directory and exchange. most of them were also breached by hafnium.
what we should do is built a edu cloud (SaaS/PaaS/IaaS) with services (open source) for students and profs, which has a central mail system and is managed centrally. but until this is built you need a working solution.
> Your University surely doesn't have anything left in-house for this anyways.
I'm not a student anymore, but most universities do not have that much selfbuild code lying around anyways. I mean most people working at universities don't care what they os is, they want to use their ms outlook or ms word. of course some universties are way more science oriented and thus more personal wants to use linux & co or write stuff in latex, but that is a minority.
also as soon as you are leaving your university, there are only a handful of corporations where you won't be using a ms product. after hafnium tons of them are also moving to m365.
For whom? It's a necessity for software vendors, because they finally have an easy and straightforward way to bill per user.
Nobody needs a cloud based solution, running software on a local machine is a perfectly workable solution.
Except people who want to collaborate on the internet?
I am thinking that universities have missed huge opportunity to build their own m365. If they started 20 years ago, by now they would have mature system tailored for their own organisation. But you needed people with vision and able to get others on their side. Something like this would be perfect for CS students, to have a taste of the corporate real world before even starting their professional life. Unfortunately these days I don't see much value in universities when it comes to CS. It may be useful for networking as you get a chance to meet like minded people and spend time with them, but other than that you can learn everything online mostly for free these days. Something like 20 years ago universities had advantage that they had resources you wouldn't otherwise get, but now that advantage is gone. Many people just see it as a fun time outside of parents' home and don't take it seriously.
Some developments from those projects live on today, such as Kerberos. But most of those innovations had crappy user interfaces and never made it outside the university. Commercial companies took their ideas and built products mere mortals could use. Now there is no reason not to use the commercial products that are more stable, more secure, and have more applicability outside the university. Plus you have to serve students who aren’t there for CS with the same network.
The incentive for commercial companies on the other hand is entirely opposite. Their incentive is to build a product that appeals to the widest population faster than their competitors. They optimize for user friendliness and eschew the untested in favor of hacky solutions that work now. From the developers perspective, they are now paid to work so they have more of an incentive to do things that may not be as attractive to them personally such as fixing bugs.
Also, there is a difference between university and apprenticeship. Traditionally university focused on teaching the soft skills, the “liberal arts”, providing a broad base of knowledge from history to widen the mind of those who attend. It’s not meant to be a job training center. Unfortunately these days it seems that most employers are uninterested in mentoring and apprenticeships, looking for the public to subsidize job training for them. Universities in my opinion are poorly set up for this, but alas this is what most expect.
you assume that the administration of these managed services is better. This is an bold assumption.
I too prefer offline Office install for my own use, but they are systemically less secure. Just rampant exploitation.
and ever for a second you don't think that there may be a catch?
It's possible to strongly disagree with a comment without inflammatory language. E.g.: "I really disagree with that comment."
It helps keep the conversation productive.
Since you've continued to do the things we banned you for, I don't see why we would unban you.
I guess software is weird that way: the market forces are almost completely inverted which is how companies like Microsoft,Oracle, and IBM keep going.
(a) isn't really uniquely German, of course. Most people not in tech, though privacy-conscious, won't really bat an eyelid on Windows 10 telemetry, Instagram's excess of data gathered, etc.
With (b), I bet the Universities are satisfied that Microsoft has all clearances/certifications to be GDPR-compatible or whatever else. That pacifies their cynicism. If shit hits the fan, the courts can worry about it. The important thing is they checked all the boxes in the paperwork with sufficient diligence.
Again, just my two cents. I'm not even European but it seems to me Switzerland in real-life is what Germany is in most people's imaginations. But again, that's just more of my opinions.
Contemporary Germany has bureaucratic tendencies.
I decided to check their website and was stunned to learned that it's: an Enterprise Content Firewall that prevent breaches and compliance violations from risky 3rd party communications.
I guess they will need to review some of their core business model because they failed to fulfill their promises to their clients and customers.
Maybe complianceware should be banned.
At least they had the common sense to stop asking me (somebody affected by said breach and a dropout, no less) for alumni donations.
[1] https://www.cnet.com/news/data-breach-at-university-of-maryl...
Yes, we need to move away from SSN as a { unique-ID + secret } combo. But that's a non-trivial task.
I'm starting to think we need something like PCI for SSN: want to use a SSN? Bam! You are now subject to intense audits that will evaluate all your data practices (and for which you will be billed). Orrrr… use a third-party vendor and never touch this data.
That being said, it's still not a perfect option because Credit Card numbers can be rotated whereas SSN seems to be engraved in stone. Still following the Credit Card analogy, having multiple numbers would greatly help. Just the same as you don't go around (anymore) showing everybody your bank routing information and have multiple cards for various purposes, have multiple identity numbers:
- tax ID number
- driver's license number
- passport number
- medical record number (yes, MRNs are a thing, just prefix it with the org ID)
- medicare number
- actual social security number for only social security (and at this point, a new one + rebranding is in order)
- credit-worthiness number
- etc.
Generally, it is actually LESS common to require SSN now than 20 years ago; when I was an undergrad, exam grades would get posted by SSN on a public bulletin board (the idea being you could find your own, but you wouldn't know anyone else's SSN to look up their grade). So SSN was considered less sensitive than your grade on a single ordinary exam.
Hopefully people stop finding it weird when customers don't want their PII in the vendor's database.
SSNs are fine as IDs (with time bound assumptions), the problem is using them for authentication.
A few reasons why SSNs are bad as IDs:
1. There are a number of situations where people will not have a SSN.
2. SSNs are "secrets" that need to be broadly shared to participate in many parts of business and government in the US.
3. SSNs lack many security and authentication mechanisms most forms of ID have (e.g. photo ID)
There are folks in the US who rally against the idea of a national ID, but I've always thought it was a silly argument considering how pervasive and problematic SSNs are as a form of identification.
The video conflates identification and authentication to its detriment.
Social Security Numbers are very good identifiers, that’s literally their purpose.
Social Security Cards are poor authentication tokens because they contain no validation to prove the card holder is the person associated with the number. Or said another way, you cannot prove your identity (authenticate) with a social security card.
I don’t see what built in validation of the number has to do with the security of the identifier.
So again, the problem is using a Social Security Number or card for authentication. It’s fine as an identifier.
[1]: Social Security Numbers can be reissued but this should only happen when the number is no longer in use.
Q20: Are Social Security numbers reused after a person dies?
A: No. We do not reassign a Social Security number (SSN) after the number holder's death. Even though we have issued over 453 million SSNs so far, and we assign about 5 and one-half million new numbers a year, the current numbering system will provide us with enough new numbers for several generations into the future with no changes in the numbering system.
In the absence of such a system, various ad-hoc systems emerge, and that's IMO why identity theft is so staggeringly common in the US - it's easy, and it's easy because very poor systems are routinely used for authentication. If I understand correctly, you can do a lot in the US with one-factor knowledge authentication, where the "something you know" are things like your name, address, DOB or SSN, all of which are exceptionally poor as authentication.
This may seem strange to outsiders but makes more sense when you consider the United States is a federation of sovereign states. The system is built on the idea of limited federal power with states sharing but retaining much of their own sovereignty. This has many of the benefits of any federated system and makes for a robust democracy.
There’s very little of consequence you can do in the United States with single factor knowledge. If identity theft is more common here than elsewhere (citation needed) I would guess it has more to do with a lack of consequences (consumer protection) than a Federal ID.
European government-issued IDs don't work well just because they are accepted, they work well because no other ID is accepted, and that's only possible when 99% or more of the population has such an ID (and the rest can be handled in a somewhat more convoluted but uncommon procedure).
Of course I have no good insight into how feasible it is for a US state / federal government to ensure that everyone (for sufficiently large values of everyone) in the state / country has an ID, without disadvantaging anyone.
No, they actually are NOT fine for ID or authentication. They contain no security features and if an attacker knows their victim's birth location can often determine the first set of digits of an SSN.
SSN are not fine as IDs.
I could claim my name is Joe Biden and I live at 1600 Pennsylvania Avenue, just like I could go onto HN and claim my userid is urda, that isn't a problem.
The next step would be to authenticate - and that's where the problem comes -- SSNs and names are no good for authentication. They're a userid.
In rigorous use in security, identification just means unambiguously referring to a specific identity. This is as simple as providing an identifier. Which the social security number roughly does (they can be re-used after death apparently).
Actually proving the provided identity is your identity is authentication. SSNs come with no decent authentication method. Hence, the identifier of an SSN is not very good in situations where authentication is required.
For an example where authentication of identifiers is not required. Consider the following: "Dear business please identify all your employees so we can correctly give them benefits". In this case, having identifiers for people is sufficient.
Heck, any case where you are asked to identify a 3d party cannot require authentication.
Strictly speaking "please identify yourself" means please give me your name. If this is spoken by someone with authority they may want prove of that claim. In that case, it is great if authentication of your given identifier is possible.
They aren’t, I was wrong! https://www.ssa.gov/history/hfaq.html
For the US, that sounds like a perfectly good guid to use in situations where a name isn't good enough (There's more than one John Smith in the US). The company authenticates your identity SSN with you via some means other than you telling them, you authenticate with the government via some means, and job done.
The problem is that the authentication bit doesn't exist. It's basically 0-factor authentication.
Technically there's a trivial solution -- assuming the government can authenticate a person's SSN (which they do when tehy are given out), then at that point the person gives their public key to the government, and this is stored in an open database against the guid. That means anyone needing to authenticate their SSN could simply use their private key to do so.
In reality those private keys would of course not remain private, so it's not a good solution, but it does highlight how an SSN could be used.
Even with a secure SSN, that number should only be collected by a company in limited circumstances -- you shouldn't collect PII unless you have a legitimate need, be that a name, phone number, or SSN, and you shouldn't keep it for longer than you need to. In some countries that's a legal requirement, but it's always the morally right thing to do. If you need to communicate with the government about a person, then sure, collect their SSN. If you need to know where to ship their order, then sure, collect their address.
That doesn't mean the address or SSN should be considered secure.
I've been doing this for over a dozen years. My customers don't need to have a single piece of my PII.
To be honest, the thought of sending even a single piece of my PII to a customer or vendor gives me the heebie-jeebies, given what we know about data breaches. I don't even let my personal services people handle my data in Google Apps until and unless I've shipped them a chromebook and walked them through setting up hardware 2FA and enabling Advanced Protection.
I'm waiting for a national bank chain or AmEx to get popped; thanks to the legally mandated total lack of financial privacy in the United States there's no way to insulate oneself from those vendors.
It is a pitty, that many (most) governments make the life hard (through laws/regulations/...) for companies wanting to offer services like aliases for phone numbers.
Wouldn't it be great if I could give an alias phone number, and if I want I can redirect that number into the void [1]
[1] or instead of redirect into the void possibly other good or less good ideas like "pay $1 to call me"... which would help some cases where I would have liked to delete an alias, but not sure if I didn't give it to someone that I want to keep in contact with
I have had the same mobile phone number for decades and I get maybe one call a year from a business that I haven't specifically allowed or requested calling me and it is always international because local laws actually work.
And I wouldn't derive from your lack of need from a lack of need for others!! Independently from the country. Stealing is allowed in no country, and it still happens in every country. Laws and enforcement is great, but it won't stop 100% cases, and if I like to have a door lock on my door (or two), then let me do... I don't care if some don't feel a need for it (and stealing is just an example... the same for so many illegal things).
The rest belong in public directories, where they have been for decades.