Saving the World with User-centric Identity.

Publish all SSN eliminate the 'secret'

A radical identity solution - publish all SSN eliminate the 'secret':

It’s time to eliminate the SSN façade. The solution to the problem of identity theft is a “cold turkey” one: publish all SSNs to ensure that no organization has the opportunity to suggest that their secrecy can be maintained. The Social Security Administration should pick a date 2-3 years in the future and announce that on that day it will publish the SSNs to the world.

The most obvious objection here is also the point: What about all the companies, and perhaps most importantly the Social Security Administration, that rely on the SSN as a secret? Won’t that really change the way they do business today? I sincerely hope not (because they should have stronger controls today), but I suspect so (because they don’t). There is a big difference (in controls) between the initial use of the SSN as validation of identity for a financial transaction (say, to get a credit card or purchase a car) and the ongoing relationship between an individual and an organization that retains the SSN.

The organizations currently using SSNs have other information available to them from their existing customer base – mutually-agreed upon “secrets” and transaction histories among others – and methods of “out-of-band” verification like sending verifying mail to the address-of-record. These techniques are more useful with the history of a relationship; often, setting up an account relies on information being provided by the consumer (or prospective fraudster).

A government mandate is the only way to build out a much stronger program for identity protection - one built on mathematics rather than on 150 thousand people keeping a secret. Otherwise, the laws for protecting the SSN will continue to grow in volume and complexity, organizations will continue to build in more controls, and we will continue to have our identities compromised.

Perilocity is also writing about this:

What's your social?" How many times have you heard that question, from credit card companies, doctors' offices, and just about every other type of organization? Perhaps you were confident that all these organizations are keeping your "social" completely confidential.

Security experts held a contest this month to show just how quick and effective Google hacking can be. During a technology security-industry meeting in Seattle, contestants using only Google for less than an hour turned up sensitive information -- potentially useful for financial fraud -- on about 25 million people. They dug up various combinations of people's names, dates of birth, Social Security numbers, and credit-card information, including some card numbers apparently left exposed by the U.S. Department of Justice.

The big problem is that so many organizations collect too much such information and then don't bother to secure it.

I think it would be most useful if some organization were to organize a reputation system that made it its business to discover which entities had the most such information visible via the Internet and findable via google or Yahoo! Such an organization could report first to the affected entities, with a time limit before it would make the information public. I don't know how potential liability would be handled in such a case, but once over that little hurdle, such an organization would be doing a great public service and could probably make a bundle advising organizations on what not to publish.

And of course the biggest identity leaks don't come through web search engines, anyway. They come through companies mailing unencrypted tapes or keeping back data on disks that are then stolen.

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
  • Share/Bookmark

Related posts:

  1. Open a Credit card in anybody's name. . .
  2. Identity related issues at the bank...
  3. The insecure keys to our castles SSNs
  4. Your 'dead' but you are not really dead.
  5. Phone troubles - Is Grand Central the Answer?

Printed from: http://www.identitywoman.net/publish-all-ssn-eliminate-the-secret .
© Kaliya Young Hamlin 2010.

Leave a Reply

  • Latest Tweets


    • She's Geeky NYC registration is LIVE!!! super early bird only lasts for a week http://bit.ly/bKOUxl 2 days ago

    • @pamelarosiedee has a post inspired by the lastest women in technology kerfullful. http://bit.ly/dCwFrL 2 days ago

    • I just posted more information about or DC venue for IIW - http://bit.ly/cja7SP 3 days ago

    • "Help" I am saving illustrator images as Jpg. that start out white then turn grey-black. what to do? 5 days ago

    • hi @RobBonta thanks for the follow cause I live in Alameda. Bad news is I can't vote I am Canadian (for now). 5 days ago

    • I went to your site @redjotter and like what I see there. I think focus on service design will be key for "identity" & #vrm services 5 days ago

    • @jayhori you mean the one in NYC? we are still trying to find a venue that doesn't cost the moon. 7 days ago

  • Archives

    • 2010 (16)
    • 2009 (82)
    • 2008 (112)
    • 2007 (167)
    • 2006 (300)
    • 2005 (189)
  • Categories

    • Active Clients (1)
    • Art (1)
    • Articles in other Publications (1)
    • Biometric (2)
    • Books/Papers on ID (7)
    • Business Cases (2)
    • Canada (5)
    • Community (1)
    • Community Dinner (2)
    • Community Management (2)
    • Digital Death (1)
    • Electronic Beacons (1)
    • Enterprise ID (1)
    • Environment (2)
    • Event Annoucements (11)
    • Event Review (7)
    • Facebook (4)
    • Facilitation (1)
    • Freedom (1)
    • Future (11)
    • Government (7)
    • ID Protocol (10)
    • Identitification (6)
    • Identity Commons (5)
    • Identity Gang (9)
    • Identity Layer (4)
    • Identity Rights (7)
    • IIW (14)
    • Industry Commentary (9)
    • Industry Developments (16)
    • Innovation (5)
    • Interesting (7)
    • interop (3)
    • Kids (1)
    • Legal Cases (4)
    • Legislation-Regulation (2)
    • me (6)
    • Media Commentary (5)
    • Media Coverage (2)
    • Mobile (1)
    • National ID (7)
    • Non-US (2)
    • NPTech (2)
    • Open Source (3)
    • Past Lessons (5)
    • Physical Devices (2)
    • Presos/Podcasts/Videos (19)
    • Privacy (14)
    • Representational Systems (1)
    • reputation (3)
    • Reputation Currents (2)
    • She’s Geeky (2)
    • Social Implications (2)
    • Social Network (7)
    • Tool Usage (9)
    • Uncategorized (771)
    • unconferences (2)
    • User Centrism (3)
    • Virtual World (1)
    • visionary (1)
    • What is Identity? (6)
    • Women (3)