TL;DR If you're a parent, monitor your child's SSN for activity. Especially considering this is a healthcare breach, nobody is immune.
TL;DR If you're a parent, monitor your child's SSN for activity. Especially considering this is a healthcare breach, nobody is immune.
Also, for clarification, the breach involved all of the information required to establish identity - which was my main point in the protection and monitoring of the SSN, with special regard to children/minors.
But realistically, the cat is out of the bag with regards to SSNs. Legally you can obtain someone's SSN for very little money. If you go the illegal route, I'd be willing to bet that there is black-market identity data on over half of Americans. We really need to treat SSNs as about as secret as your e-mail address, because for all intents and purposes they are already. I wouldn't be surprised if online ad networks were using your SSN as a primary key in the background - the information is so easy to get and it would solve a lot of problems.
I guess I'm saying that sticking your head in the sand and pretending that SSNs are secure won't make them any more so. I'd doubt that a whole lot of SSNs were gathered in this hack that weren't already effectively disseminated widely in black market circles or marketing databases already.
The difference is simply data dispersion. If a breach dump ends up on the public Internet everyone has access to that data, worst case scenario, infinitely. Individual targeting has a similar risk but the overall impact is smaller.
Not sure what your point is with the "head in the sand" comment - I happen to work for a security company in an engineering role. I'm not, in any way, defending security through obscurity or the way SSNs are used or (mis)handled. Reading through these comments it is apparent credit agencies don't even get it - and that is disturbing in itself.
But stating that you "doubt a whole lot of SSNs were gathered in this hack that weren't already effectively disseminated widely" is, in fact, a head-in-sand approach compared to doing everything you can to preserve and prevent in the mean time. I, personally, don't agree.
edit: added "compared" to second to last sentence for clarification
Not legally. You certainly can go onto a website and buy them, if you misrepresent your purposes, and you won't be caught... but it's still illegal.
However, there would be less harm from these kinds of breaches if consumers were not obliged to prove their own innocence whenever someone loaned money in their name without rigorously verifying their identity. If someone claims to have loaned a bunch of money to me without ever interacting with me, the recovery of that foolish loan should really not be my problem. It would still be bad for an insurance company to expose private information, but there wouldn't be such a tremendous incentive to steal, agregate, and distribute this kind of data if there wasn't so much easy money in it.
Stolen credentials of the kind described in this breach are valuable largely because there is an asymmetry of effort favoring thieves: it's so much easier to borrow money in my name than it is for me prove my innocence that the process of borrowing money with other peoples' identity can be done in bulk, and to some extent automated. This situation is only sustainable because the lenders have shifted the responsibility of authentication onto their customers, retroactive to the issueance of credit. Identity verification prior to extending credit to a debtor is trivial and automated, while retroactively proving fraud has a large cost to the debtor in actual human labor.
It seems like payment systems and consumer creditors have colluded to force a Faustian bargain on us: to gain access to utilities and payment systems you have use credit, even if you don't want it. Therefore, if you want to be able to have municipal water, a place to live, or a phone, all of which are practically contingent on credit rating even if you pay with cash, you have to protect your credit rating.
It would be nice to decouple payment systems from consumer credit, but we won't. Nobody, whether they are a buissiness or the state, can afford to cross the credit card companies or the ratings agencies. They are buisiness titans with big lobbying clout. If you get taken by theives, it doesn't mattter if you're a consumer, a big corporation like Target, or a government agency like the VA, you're going under the bus because the status quo is too profitible to fix, and security is your problem. Nothing can be allowed to slow down the issuance of easy credit, or to create the slightest friction in CC transactions. Look what just happened with chip and pin? We can't even _opt into_ a pin for CC transactions because it might confuse us. While we're on the subject, go read about what happens to people who to try to build alternative payment systems that cut out MCVISA...
How many data breaches would there be if bad actors had to take the trouble to personally hassle each of the millions of people they had data on before they could take our money?
Probably some, but how much would we care who knew our SSN's or addresses if they couldn't easily be monetized?
Some, but less, I think.
SSN should not be worth anything because it's really not different from a name. Instead of saying "hi my name is exelius", you're saying "hi my name is 302-45-9522". You wouldn't trust me if I said the former, so why the latter?
I don't know any solution to this problem that would realistically be any better. Crypto isn't a good long-term solution -- any crypto we use today will be trivially cracked by a cell phone 20 years from now. Trust mechanisms seem better, but even then they can be simulated (see: twitter bots, facebook bots, click fraud, etc.)
Identity theft is far too easy today, but even if we had an effective system that could prove identity... I'm not sure we would want that societally. It basically guarantees big brother and wraps it in the guise of security.
Tldr: this is a tricky problem where the situation caused by the solution may actually be worse than the original situation.
This is completely false for correctly implemented crypto unless mobile phones of the future are made of something other than matter and occupy something other than space. It could also be that fundamental understandings of math and physics are incorrect. But the idea that just because of improved technology we'll be able to crack today's crypto is ludicrous
I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.
Combine this with a smartcard. I guess a lot of European countries already do something like this?
The problem is that everyone working on crypto products focuses on just developing technology, often attempting to make existing crypto systems easier to use for ordinary people. This is fine, but it's only a partial solution. We need to educate people who don't know and don't care about proper security. Nobody is going to use the most secure and easy to use crypto system if they don't see the benefit and think that a SSN or a driver's license is a good way to show their identity.
There is a lot of hand wringing about how hard it is to get ordinary people to take security seriously, but honestly this is a problem that will solve itself given enough time and enough breaches such as this. Until people understand that only secret information--which they and only they know--can be used to authenticate them and protect their information, this will just keep happening.
Their main purpose is to serve as a primary key - many people have the same name, but SSN is unique. It should never be used for establishing identity - it's about as effective as asking someone for their middle name.
What about not doing that at all? Hear me out. Not relying on "identity" would cost many orders of magnitude less. And besides, why should I care who you are-- what does your identity matter to me? And why should anyone else care?
Can you save us a long and stupid discussion and simply explain your plan to practically deploy a better authorization system that will cost many orders of magnitude less?
Let's not pretend there aren't valid reasons for identity to be established.
In most states it will cost in the neighborhood of $10 for each of the three bureaus, unless you're already the documented victim of identity theft (ask me how I know this).
You can also apply to put a security freeze on your child's SSN. State by state laws and application process here: http://consumersunion.org/research/security-freeze/
And then there's the myriad of companies who can give you protection for a monthly fee:
AllClearID: https://www.allclearid.com/
LifeLock Junior: http://www.safety4yourkids.com
Also, Experian has a monitoring service as well specifically for kids: http://www.familysecure.com/
Hope this helps.