The US needs to just scorch the earth re: social security numbers. Set a date when all liability for fraud enabled by improper use of SSN's for "authentication" is the responsibility of the party misusing SSNs and publish the entire list.
The list has, arguably, already been published (thanks, Equifax!). We just need to close the loop.
As I’ve mentioned elsewhere, SSN is not the only fact used for authentication. We need to move away from all pure fact-knowledge proofs of ID and to MfA preferably with one factor based on a government issued ID and asymmetric encryption.
I concentrated on SSN because it's the government-issued fact-based "authentication" factor. The other fact-based factors are just as bad.
I wish we could have a government-sponsored PKI but between concerns from citizens about "freedom" (either freedom for business to "innovate" in the space, or freedom from individuals to be "tracked" by the government) and from surveillance advocates who will want to include key escrow/recovery provision I don't see it flying.
In some other comments on this post I mentioned the USPS would be a great "trust" provider. They already serve in that capacity to some extent evidenced by the various government entities who accept an addressed piece of mail as proof of residency. I don't think there'd be enough bipartisan support to make it happen, but I think it'd work great.
But yes, this could have all been headed off if the social security act had prohibited private organizations from requesting, using, or storing these identifiers in the first place, for anything but immediately passing them on to tax authorities. A Customer ID is good enough for all non-credit uses, and credit should require actual in-person verification to issue. But this is the general shape of totalitarianism in the US. The government mandates the barest minimum of systems, companies lobby against any restrictions that would prevent their abusing it, and we end up with a legally-mandated freedom-destroying system invading most aspects of our lives.
PS I've got to wonder about a blockchain solution for keeping a public catalog of leaked PII that gets abused for verification. Make the "exploit" plain as day and companies will have to change. Right now the carding community keep this to themselves, and out of sight is out of mind for the companies that continue to abuse it.
That requires collecting social security numbers.
Citation?
There was a huge problem a few friends and I caused our first year there when we got bored in the computer lab. Every student account on a school computer had a folder named PUBLIC. Out of curiosity we dug down a few folders and found the txt file that was referenced by the simple visual basic program the IT guy wrote for class scheduling. That program used your name and SSN as login credentials. So there was a txt file that was simply a list of everyone's name and SSN for it to reference.
We being the idiots we are copied the file because it was a public folder anyone could access. The only reason we didn't get expelled was because one of the kids had a lawyer father who threatened to go public about them being that irresponsible with our data.
If you had a mag stripe writer you could grab a random person's grades, encode their SSN on a student ID, and then use the card to buy stuff on campus.
EDIT: It’s been a long time since I was in school, and, frankly, I was expecting someone with fresher knowledge to come up with a counter-example. So, see the comment above about an IRS form 1098-T.
They also need it for the 1098-T (Tuition Statement). That's not to say they couldn't design better systems and not use SSN as an identifier, but there is a legitimate need for it.
It's possible they were doing something similar.
I've also had to give my SSN to verify my identity to my insurance carrier at my dentist.
It’s sad for lots of reasons, but understandable considering that it is useful. for whatever reason there isn’t much political will to make an honest effort at a federal government ID (even though we de facto have multiple)