Slashdot Mirror


Is The US Social Security Site Still Vulnerable To Identity Theft? (krebsonsecurity.com)

Slashdot reader DERoss writes: Effective 1 August, the U.S. Social Security Administration (SSA) requires users who want to access their SSA accounts to use two-factor authentication. This involves receiving a "security" code via a cell phone text message. This creates two problems. First of all, many seniors who depend on the Social Security benefits to pay their living costs do not have cell phones [or] are not knowledgeable about texting.

More important, cell phone texting is NOT secure. Text messages can be hacked, intercepted, and spoofed. Seniors' accounts might easily be less secure now than they were before 1 August... This is not because of any law passed by Congress. This is a regulatory decision made by top administrators at SSA.

In addition, Krebs on Security reports that the new system "does not appear to provide any additional proof that the person creating an account at ssa.gov is who they say they are" and "does little to prevent identity thieves from fraudulently creating online accounts to siphon benefits from Americans who haven't yet created accounts for themselves." Users are only more secure after they create an account on the social security site -- and Krebs also notes that ironically, the National Institute for Standards and Technology already appears to be deprecating the use of SMS-based two-factor authentication.

1 of 46 comments (clear)

  1. Google Voice by duckintheface · · Score: 4, Informative

    I don't have text messaging on my cell phone (I specifically had it disabled by the carrier). But I can still receive text messages on my computer by using a Google Voice number. The text message appears in my Gmail inbox and I can reply to it as I would to an email.

    Ok, maybe folks who don't have a cell phone also don't have a computer. So there needs to be an option of letting SS that you want online services to be blocked for security purposes.

    --
    "He took a duck in the face at 250 knots." -- William Gibson, Pattern Recognition