Slashdot Mirror


US Studying Ways To End Use of Social Security Numbers For ID (securityweek.com)

wiredmikey quotes a report from Security Week: U.S. officials are studying ways to end the use of social security numbers for identification following a series of data breaches compromising the data for millions of Americans, Rob Joyce, the White House cybersecurity coordinator, said Tuesday. Joyce told a forum at the Washington Post that officials were studying ways to use "modern cryptographic identifiers" to replace social security numbers. "I feel very strongly that the social security number has outlived its usefulness," Joyce said. "It's a flawed system." For years, social security numbers have been used by Americans to open bank accounts or establish their identity when applying for credit. But stolen social security numbers can be used by criminals to open bogus accounts or for other types of identity theft. Joyce said the administration has asked officials from several agencies to come up with ideas for "a better system" which may involve cryptography. This may involve "a public and private key" including "something that could be revoked if it has been compromised," Joyce added.

197 of 311 comments (clear)

  1. Step one and two. by msauve · · Score: 3, Interesting

    Unlink SSN from TID (Taxpayer ID). Banks need TID, they have no business with SSN. Unlink SSN from healthcare (it wasn't legallay required until Obamacaare, although healthcare providers used it).

    --
    "National Security is the chief cause of national insecurity." - Celine's First Law
    1. Re:Step one and two. by aaarrrgggh · · Score: 4, Insightful

      Doesn't solve the problem though. You still have high-value information linked to the TID, which ultimately is the root of the problem.

      Ultimately you need the TID to be unique to each taxpayer, and a subset/hash of the TID plus additional information to be linked for other (financial) purposes. The IRS should be the only ones able to re-associate you to a unique qualifier.

      But, until you eliminate the profit motive for credit bureaus everything will end up being re-assembled. Back to square one.

    2. Re:Step one and two. by arglebargle_xiv · · Score: 3, Informative

      US Studying Ways To End Use of Social Security Numbers For ID

      Am I the only one who's immediate reaction to that is "Well, no shit, Sherlock".

    3. Re:Step one and two. by hcs_$reboot · · Score: 1

      Unlink SSN from healthcare

      If a SSN is not linked to healthcare, what is its use really??

      --
      Slashdot, fix the reply notifications... You won't get away with it...
    4. Re:Step one and two. by msauve · · Score: 3, Informative

      "If a SSN is not linked to healthcare, what is its use really??"

      Uh, Social Security (AKA OASDI). Duh.

      --
      "National Security is the chief cause of national insecurity." - Celine's First Law
    5. Re:Step one and two. by msauve · · Score: 1

      "Ultimately you need the TID to be unique to each taxpayer"

      Uh, it is.

      --
      "National Security is the chief cause of national insecurity." - Celine's First Law
    6. Re:Step one and two. by alvinrod · · Score: 1

      But, until you eliminate the profit motive for credit bureaus everything will end up being re-assembled. Back to square one.

      Then you need to come up with a better solution for how borrowers can extend credit and assess risk. Credit bureaus don't collect and maintain this information for no reason, they do so because lenders can make better decisions with that information and they only care about that because people want credit for all manner of things. The information isn't profitable in and of itself, merely as a byproduct of helping lenders make better decisions. It can be used for all kinds of bad things, but that's true of most things.

      At best I think you can only impose regulations to protect that data and to use a lot of techniques to make it more difficult for these kinds of breeches to occur, but it will never be completely secure. Personally I think the NSA would be better put to use if it stopped spying on our own citizens an instead worked as white hats that would do penetration testing against the kinds of organizations that need to have valuable data secured, whether its credit bureaus or medical providers.

      The only alternative is that you ban the collection of this kind of data, but that just means interest rates go up across the board because lenders will naturally make less intelligent decisions due to having less information and that cost is going to be borne by someone.

    7. Re:Step one and two. by Anonymous Coward · · Score: 1

      Unlink SSN from TID (Taxpayer ID). Banks need TID, they have no business with SSN. Unlink SSN from healthcare (it wasn't legallay required until Obamacaare, although healthcare providers used it).

      One good thing: Unlinking SSN from Medicare is being done. Everyone that has Medicare will get a new non-SSN Medicare account number. The new cards will be mailed in 2018. https://www.cms.gov/Medicare/N...

    8. Re:Step one and two. by Z00L00K · · Score: 1

      The problem isn't the SSN, the problem is that it's not used in a proper way to assert identity.

      Use the SSN to look up additional infornation to validate the identity of the person like biometric data and full name and match that to the person that's trying to get some service.

      Then also use capital punishment for ID theft, that would make offenders to think twice before they mess up things.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    9. Re:Step one and two. by ShanghaiBill · · Score: 1

      "Ultimately you need the TID to be unique to each taxpayer"

      Uh, it is.

      Nope. SSNs are not unique. SSN+DOB is unique.

    10. Re:Step one and two. by Qzukk · · Score: 1

      > relatively hard to forge

      We have 50+ relatively hard to forge ID cards, but there's millions of kids in college with tons of disposable income that want to get beer with one of those ID cards, so they're pretty regularly forged. Replacing the 50+ cards with one card solves the problem of a guy at Washington State trying to pass off his Arkansaw driver's license as valid, at the cost of having 50 times the resources going into cracking it. Meanwhile, I have to hand out my Social Security Number to every bank, every employer, every credit card, every phone company, the water company, the doctor, and so on. Once I have my new Super Secure Number and provide that number to my bank, employer, credit card, phone company, water company, my doctor, etc... is it still secure?

      I like the other idea posted of having a single-purpose Virtual SSN. Just like foo+slashdot@yahoo,com, I can tell who leaked the SSN since only one person had it.

      --
      If I have been able to see further than others, it is because I bought a pair of binoculars.
    11. Re: Step one and two. by Anonymous Coward · · Score: 1

      Dude you are wrong, I fact checked that. Social security numbers ARE unique by themselves. The Social Security Administration has issued over 450 million numbers out of a pool of 1 billion. It has never recycled a number. Presumably at some point 9 digits wonâ(TM)t be enough. But we havenâ(TM)t reached that point yet.

    12. Re:Step one and two. by thegarbz · · Score: 1

      Why? Simply eliminate the TID. The government doesn't need more than one key to use in a database. The issue here isn't the fact that these numbers are used, it's the fact that any single identifier is used for identification and authentication.

      Any system built on this basis is too easy to abuse.

    13. Re:Step one and two. by Kjella · · Score: 1

      Doesn't solve the problem though. You still have high-value information linked to the TID, which ultimately is the root of the problem.

      Truth is that most places would also need other information like name, address, phone number etc. that's pretty good for linking up information. The issue is thinking that a SSN or any other ID number is a good secret when you constantly need to share it with people. It's the 21st century, you're issued an electronic ID and make digital signatures. That's what Estonia does through e-identity, it's what we do here in Norway through BankID. I can show you my driver's license, but having my national ID number (DOB in ddmmyy format + 5 digits for sequence number + century/sex/control digit) doesn't really count as proof for much of anything.

      --
      Live today, because you never know what tomorrow brings
    14. Re:Step one and two. by Boutzev · · Score: 1

      This is how most countries do it - in Europe at least. You have a personnal Id card, which serves the purpose of physically identifying you. You want a bank account - you go personnaly to the bank, then show your nationnal Id card, which has your photo, birth date, name, etc. They verify it's not fake, then you can open an account and you eventually get separate bank credentials (for phone or online banking). That's just one example, but everything works on the same principle. Some EU governments have unified authentification, usually based on a digital certificate or at least some kind of OTP. To get it you have to be identified physically in person and it is usually valid for accessing all government based services and sometimes even for other purposes (ie. banking authentification). However, that's not really an issue when strong authentication is used, as there is no easy feasible way to leak all identities, as in the case of SSN numbers.

      I've never really understood why the social security number is used for almost anything in the US. There is no inherent security behind an SSN and it was not meant to be used for authentication, it is just a number after all - it provides less security than an alphanumeric password.

      I understand that in the past there was resistance against having a nationnal Id system in the US - for privacy reasons, but nowdays this doesn't really make sense, as people are identified and tracked by thousands of other means.

    15. Re:Step one and two. by Hognoxious · · Score: 1

      SSN's were intended to be unique to a person, but they aren't. A duplicate can occurs due to error. Adding DOB will certainly reduce the likelihood but it can't eliminate it.

      Oh, it doesn't work the other way round either - some people have been assigned more than one.

      https://www.computerworld.com/...

      https://www.aol.com/2010/08/12...

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    16. Re: Step one and two. by Hognoxious · · Score: 2

      Not recycling them doesn't prove that there are no dupes. Errors can happen, and they have.

      https://www.nbcnews.com/techno...

      https://www.pcworld.com/articl...

      Here's a fact - you suck at fact checking.

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    17. Re:Step one and two. by Hognoxious · · Score: 1

      Then you need to come up with a better solution for how borrowers can extend credit and assess risk.

      With a compass, watch, and sextant - like they used to do before. Oops, sorry, wrong story.

      I mean by doing it themselves, like they used to before.

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    18. Re:Step one and two. by pjt33 · · Score: 1

      Meanwhile, I have to hand out my Social Security Number to every bank, every employer, every credit card, every phone company, the water company, the doctor, and so on.

      That is the problem which needs to be fixed. Why should a phone company need your social security number? They don't have anything to do with social security. An employer might need it to pay their contributions, a doctor might need it if your medical care is paid for by social security, and bureaucrats who deal with social security obviously need it. No-one else ought to.

    19. Re:Step one and two. by dwillden · · Score: 4, Insightful

      Well by law it's supposed to only be used for Tax identification purposes. Not healthcare, not insurance, not anything else. But everybody just ignores the Privacy Act of 1974 because it's never been enforced.

      --
      I'm too lazy to compose a creative sig.
    20. Re: Step one and two. by Anonymous Coward · · Score: 1

      You are right regarding the pool size of numbers, but not exactly right concerning reuse. For many in the older generation it wasn't uncommon for a wife to not have her own SSN number so she would use her husband's.

      Then there was a period of time when if you purchased a wallet or purse there was a fake SSN card in it with a number from a block of numbers. Quite a few people thought that was their real SSN number and used it.

      So in both of these cases the numbers are being reused, though not the fault of re-issuance by the social security administration. The SSA had to recognize these issue however and not allocate any numbers from the wallet block and accept multiple people on one number like for the spouse situation.

    21. Re:Step one and two. by Headw1nd · · Score: 1

      This. SSNs were never intended to be secret, in fact the first SSNs were easily guessable because they used a location ad grouping structure that could be easily guessed if you knew the birth location and date of the individual. Companies have used them, pretty much in defiance of the law, simply out of convenience. If private industry needs a secure identifier, private industry should make one.

    22. Re:Step one and two. by ishamael69 · · Score: 1

      Can you perhaps provide a cite from the Privacy Act of 1974 saying that private companies (such as healthcare companies and insurance companies) are not supposed to be using the SSN? I can't.

    23. Re:Step one and two. by ishamael69 · · Score: 1

      Can you perhaps back up your claim that companies using SSNs are in defiance of the Privacy Act of 1974? I can't see any where they are breaking the law.

    24. Re:Step one and two. by Cro+Magnon · · Score: 1

      That's one of my peeves. How could anyone consider the SSN as secret? The damn thing was on my drivers license for years! I don't put my password on my drivers license.

      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
    25. Re:Step one and two. by jbengt · · Score: 1

      Actually, that is not the problem that needs to be fixed. The problem is thinking that having a Social Security Number is the same as knowing who the person is that claims that number is theirs. SSNs were never intended to be secret, and were never intended to serve as identification. They were meant to be unique keys into the SSA's "database" (likely paper folders in steel filing cabinets at the time they started using the numbers).

    26. Re: Step one and two. by aaarrrgggh · · Score: 1

      The more common issue is the way the number blocks are assigned often led to duplicates. The first three indicated issuing region/office, next two were alphabetical, and the next four were consecutive. (Now the numbers are issued centrally, so it is less of an issue.) Because of this setup, numbers were periodically duplicated. It is likely well under 0.1%, but it happens/d. In about 60 years any duplicates would likely filter out of the system.

    27. Re: Step one and two. by cayenne8 · · Score: 1

      And, we cannot dismiss the problem with so many illegal aliens in the US, that either make up, or steal a real US citizen's SS number for their jobs while here.

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    28. Re:Step one and two. by ctilsie242 · · Score: 5, Interesting

      You can have a national ID system, but the way it likely will be designed will be a jackpot for all well-heeled attackers.

      Instead, why not a national ID system based on certificates? For example:

      When someone turns 21 here in the US, the country they were born in signs a certificate stating that the owner is over 21. This way, a bar owner has 100% cryptographic proof that someone is of legal age to drink... but doesn't need to know their name or any other info about the person.

      If a degree from an accredited school is required, the school signs the ID with a cert showing the degree. That way, it doesn't matter who the person is... but the cert is valid.

      Going into short-lived certs, one can have a cert signed by the FBI stating that there are no priors on the RAP sheet. This cert can be valid for a few days. Again, it solves the purpose and gives no data out.

      Even credit records, Equifax or whatnot can sign a certificate stating someone's FICO score is over 700, ensuring they have an easy track for qualifying for a house. Since all this requires is a HSM to do the signing, it can be made well secured, with the actual scores being on an air-gapped database.

      If we go with certificates, it means that one's privacy is kept, but the legal needs for stuff (age, no criminal history) are met. Add an option for the ID card holder to only show certs that are relevant, and this makes for an extremely private ecosystem.

      Secure as well, since the only real points of attack are the cryptosystem (good luck), endpoint cards (which would only compromise users singly), and a signing cert holder (which only affects them). The only real single point of failure would be the physical ID card itself.

    29. Re: Step one and two. by budgenator · · Score: 1

      I don't think the pool is 1 billion or even 1 billion -1 because not all area numbers are in use and several sequences of number are not allowed.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
    30. Re: Step one and two. by rickb928 · · Score: 1

      I doubt the 'next two' were alphabetical. My wife and I were born more than 2 years apart, in the same state, and our SSNs differ only by the last four digits. Our last names were not close at all, the difference between a 'C' and a 'T'.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    31. Re: Step one and two. by azadrozny · · Score: 1

      SSNs are now issued more randomly, but prior to 2011, the middle two digits were issued in the following sequence: 1) odd numbers from 01 through 09, 2) even numbers from 10 through 98, 3) even numbers from 02 through 08, 4) odd numbers from 11 through 99. If your SSNs are the same except for the last 4 digits your parents applied for the numbers at almost the same time, and lived in the same geographic region of the country.

    32. Re: Step one and two. by lgw · · Score: 2

      Credit agencies can suck air. They have no business extending easy credit to anybody who knows my SSN at the cash register of a clothing store.

      Credit agencies don't extend credit to anyone - they just keep a DB of creditworthiness. It's the banks that are the eternal villains in this story, and they should never escape blame.

      I believe there's a very simple fix here: any time a bank issues fraudulent credit, they're fined 3x the amount of credit issued. If that turns out to not produce sufficient ID checking, up it to 10x or 30x, or keep going until it does.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    33. Re:Step one and two. by networkBoy · · Score: 1

      I have two SSNs, three names (though one is obviously a placeholder 'Baby Boy <lastname>'), one birthday, two sets of parents listed as my "real" parents on two different original birth certificates.
      The joys of a cross military to civilian adoption.

      As to the SSN issue, there is simply no issue using the SSN as an identifier, the issue is it started being used as an authentication token.
      All we need to do is implement a national PIN register for the SSN holder. They provide the PIN to authenticate that they are the actual person represented by the SSN.

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    34. Re:Step one and two. by suutar · · Score: 1

      I'm afraid I'm not understanding one thing. Sure, the bartender knows that _somebody_ is over 21, but how do they know that the somebody is the person standing in front of them asking for a vodka shot, unless the certificate is attached to something hard to counterfeit that also (hopefully) uniquely identifies the human (photos, under most current systems)?

    35. Re: Step one and two. by rgbatduke · · Score: 1

      Sorry, used my mod points yesterday. Otherwise I'd mod you way up.

      Even now, if somebody did steal my information from Equifax and uses it to borrow a zillion dollars, I have zero liability for that, as I did not do it and there is simply no way that they can prove that I did. So the loaning company will eat the debt, not me. It will be at most an annoyance to me, and probably not much of that.

      Most responsible loaning agents already make it enormously difficult to borrow large amounts of money "anonymously", that is, without face time, notarized documents, and due diligence. The big exception is credit card companies, and all one can say to them is fuck them if they issue cards to an anonymous stranger just because they have my SSN and address in hand.

      Yes, there have been people that have been royally screwed by all of this in the past, but it is not OUR RESPONSIBILITY to protect all of this. It is and always has been the responsibility of the loaner to verify that the loan is indeed a good risk, and hey, verifying that the loanee is who they claim to be is simply part of their due diligence, and accepting a single token like SSN as de facto evidence of this is just plain stupid, on THEIR part.

      It would, of course, be lovely to implement a 3x penalty rule, but the top article is dead on the money -- SSN is a dated, stupid way of verifying identity. Ultimately, we're probably going to have to tie identity to something like DNA, so taking out a loan involves processing a cheek swab PLUS the usual due diligence. That would really put a stop to a lot of this even now -- if the loaning agency has a cheek swab, taken in front of witnesses, in a vault indexed by your loan, it is at the very least going to make prosecuting for fraud very, very easy.

      --
      Even when the experts all agree, they may well be mistaken. --- Bertrand Russell.
    36. Re:Step one and two. by ctilsie242 · · Score: 1

      It is nice to see someone who "gets" this. The card or token is mainly a cert holder. This could even be someone's smartphone, but there are times when one doesn't want a device that does 24/7/365 geolocation with them, so having a simple device that is presented, has some means of showing that the person claiming to be the person who the certificates apply to is truly that person, and maybe a few other features like showing/hiding certificates, as a barkeep doesn't need to know that you are a gold medal winner in last week's chainsaw fencing contest.

      This is not perfect... but this model is a hell of a lot better than the current one. A compromised key can be revoked. A database chock full of people's info can't be "un-copied" once it its pastebin or torrent sites.

      Perhaps this could be used similar to a MFA device in Duo. You have a hardware card, but you can also use your phone to show that you are whom you claim you are, provided the phone has some security mechanism so this is a relatively trustworthy way to do things.

    37. Re:Step one and two. by Baleet · · Score: 1

      This is correct. In fact, there are lots of old codgers (some of whom are the kind that insist the IRS was created illegally and who may or may not be crackpots) who refuse to give their SSN to anyone for identification purposes.

    38. Re:Step one and two. by Baleet · · Score: 1

      I recall seeing the notice on my first SS card. Looked at https://www.ssa.gov/history/hf... and found the following: "Q21: When did Social Security cards bear the legend "NOT FOR IDENTIFICATION"? A: The first Social Security cards were issued starting in 1936, they did not have this legend. Beginning with the sixth design version of the card, issued starting in 1946, SSA added a legend to the bottom of the card reading "FOR SOCIAL SECURITY PURPOSES -- NOT FOR IDENTIFICATION." This legend was removed as part of the design changes for the 18th version of the card, issued beginning in 1972. The legend has not been on any new cards issued since 1972."

    39. Re:Step one and two. by Scarletdown · · Score: 1

      This. SSNs were never intended to be secret.

      That would explain why back in the late 70s, there were "Go Into Business for Yourself" ads in the comics for door to door selling of metal name plates to go on peoples' front doors with their SSN engraved on them. They also sold metal SSN wallet cards as well.

      Yes, as a kid, I tried all of those schemes, from Sales Leadership Club to Grit; since we did not get an allowance in our family and otherwise just had to rely on finding and redeeming pop bottles and cans for the deposits (or going door to door in a fake bottle drive.)

      --
      This space unintentionally left blank.
    40. Re: Step one and two. by rickb928 · · Score: 1

      We were living about 50 miles apart, mostly rural area. But our SSNs are 4827 serial numbers apart. My sister's is consecutive. My two brothers not so much, and my other sister's further apart.

      4827 SSNs could have been issued over to years in that region back then.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    41. Re: Step one and two. by ChrisMaple · · Score: 1

      You're blaming the victim.

      --
      Contribute to civilization: ari.aynrand.org/donate
  2. National ID? by borcharc · · Score: 5, Insightful

    Sounds like another attempt at a national ID. I am sure it will go as well as all the past efforts.

    1. Re:National ID? by 93+Escort+Wagon · · Score: 5, Insightful

      We already have a national ID - it's called Social Security - so what's the objection to another one?

      --
      #DeleteChrome
    2. Re:National ID? by Anonymous Coward · · Score: 1

      The thing is, we already have a "National ID", and it's the SSN. The problem is that this particular national ID can, in the wrong hands, wreak havoc on one's financial health, because it doubles as form of authorization.

      The choices aren't between "National ID" and "no National ID". The choices are between "National ID that doubles as authorization" and "separate National ID and National Financial Authorization Number".

    3. Re:National ID? by Known+Nutter · · Score: 2

      Government!! Reasons!!!

      --
      Beware of the Leopard.
    4. Re:National ID? by Nethemas+the+Great · · Score: 4, Insightful

      At some point the "States Rights," "Big Brother," "Don't Tread on Me" folks are going to have to concede the fact that they're US citizens and need to have a unique identifier as such. With rare exception, US citizens have already been assigned a unique identifier by default with their SSN. By their perpetual protests against a nation ID they've forced governments and NGOs to this lowest common denominator to everyone's detriment.

      --
      Two of my imaginary friends reproduced once ... with negative results.
    5. Re:National ID? by hord · · Score: 1

      The first one leaked out onto the internet.

    6. Re:National ID? by clovis · · Score: 1

      Sounds like another attempt at a national ID. I am sure it will go as well as all the past efforts.

      One problem isn't that the details of your identity are not a secret and actually can't be a secret or it would be pointless to maintain. The problem is that the institutions that ask for your identification, SSN, phone number etc, are getting that information from whoever is making the application and the institution really has no way to verify that the you are the person you claim to be holding the documents for.

      What I want to do is indeed have something like a national ID, and in an accessible database that has a series of photos taken during your lifetime such as your driver's license photo, State ID, Student ID and so on. When you show your identification documents to the bank, or other major entity that matters, and that has an ID to be doing that, they go to the governments database using their ID. your name and SSN, and can see from the photo history that "Clovis" looks like a meth head from a South Ga trailer park (this is almost true, btw) and the person applying for credit as "Clovis" looks like Michael Moore. So, they say no.
      And access to your identity on the national database can be frozen and unlocked in the same way that your credit bureau data can be frozen to prevent snooping.
      Various government agencies already have your photo and other identity data, so it's not like you'll be giving them anything.

      So, what about setting up an account at online-only banks, or initial Social Security on-line account, or IRS web site?
      I don't know.
      My first thought is that physical banks, social security offices, post office, or such can offer identification services to people. You go to the bank/office, pay a fee, they verify it's you and give you a one-time code that you use for whatever online account you are trying to setup.
      It's not every day, or even every year that you need a mortgage or new bank account.

      My second thought was to use skype or webcam for the initial account setup and the inevitable lost password reset requests.
      If you don't have internet access, then you won't often be setting up online accounts anyway.

      And it should be voluntary for banks or financial institutions to participate, but mandatory for government agencies.

    7. Re:National ID? by JoeCommodore · · Score: 1

      Well technically a SSN has been used because, for many developers, it's the only well documented, truly unique identification that each US citizen has that is universally used throughout the US.

      SSNs weren't really a problem until the banks tied the numbers to individual's credit or debt that is causing the problem.

      --
      "Enjoy what you're doing! If it becomes drudgery, you're doing it wrong!" - Jim Butterfield
    8. Re:National ID? by Dutch+Gun · · Score: 1

      From TFA:

      This may involved "a public and private key" including "something that could be revoked if it has been compromised," Joyce added.

      This problem has already been solved many times already. A randomly generated private key, and an associated public key for validation. That's all that's needed. The private key stays secret from *everyone*. The number never leaves the enclave in your card, and can't be extracted. A simple USB-based reader can perform authentication via a computer or smartphone. There's no need for anyone to EVER have access to that number, since all they need is the public key for validation. Thus, the risk of compromise is limited to physical theft of your ID card - a much higher bar than simply stealing a SSN number.

      Initial validation of identity doesn't have to involve anything new. Local SSN offices set up all over the country do this every day. They could also handle revocation and re-issue of new cards as well.

      The technology is there to do all this. It's just a matter of political will and moving a massive bureaucracy, which are tough enough challenges. Look at some posters' comments just above, claiming that a national ID will destroy our freedoms and are inherently racist, or something, and you get an idea of the political fight ahead to implement this.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    9. Re:National ID? by DarkOx · · Score: 2

      No the problem is really simple, the problem is using the SSN both as identification and authentication. You should think of your SSN the same way you think of your name. The only difference is SSN is more uniq.

      If anything the government should issue cards with private keys associated with your existing SSN. The proof of your identity would be your ability to cipher (nonce + SSN + timestamp) or something similar and the bank, SSA, IRS, etc would determine its really you by deciphering with the public key and getting the same value back out.

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
    10. Re:National ID? by mark_reh · · Score: 1

      If your card is stolen and you need a replacement, how do the authorities know that you are the legitimate card holder and not the guy who stole a card and then, pretending to be you, requested a replacement?

      It seems to me the only way to absolutely identify a specific individual is to use some hopefully unalterable biomarker, if there is such a thing, such as a DNA sequence. Imagine the protests that would ensue when everyone is ordered to hand over DNA samples to the authorities so they can issue new govt ID cards.

      Once you have this new ID system worked out, it should eliminate the need for passports, assuming you can get the rest of the world to go along with it. The fundamentalist Xtains will be literally up in arms over trying to do something like that.

    11. Re:National ID? by chill · · Score: 5, Interesting

      So, use the driver's license as the identifier. You have to physically go into the DMV and prove your identity to get one -- just like now. Nothing's perfect for this step, but this is one of the more workable and accurate systems so far.

      Change the cards to be PIV/CAC/HSPD-12-style smart cards, so they can store a private key unique to the individual. These can be used for legally binding digital signatures.

      You end up with 56 or so "certificate authorities" -- the 50 States, the various U.S. possessions and territories, and the Federal Gov't themselves. States already can validate each other's DL numbers and records in real time.

      This deals with the concerns of having the big, bad central government in charge of everything yet still provides for a workable, federated system.

      --
      Learning HOW to think is more important than learning WHAT to think.
    12. Re:National ID? by Cro+Magnon · · Score: 1

      I have no problem with my ID getting leaked onto the internet. I have a big problem with my damn password getting leaked onto the internet!

      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
    13. Re:National ID? by jbengt · · Score: 1

      The thing is, we already have a "National ID", and it's the SSN.

      The thing is, the SSN is not a national ID in the sense of authenticating a person's identity, and it never has been, yet, that's what it is commonly used for. The SSN is essentially a publicly known identifier for getting records from the SSA's database, so authentication of a person's identity needs to be done by another means.

    14. Re:National ID? by NicknameUnavailable · · Score: 1

      The thing is, we already have a "National ID", and it's the SSN. The problem is that this particular national ID can, in the wrong hands, wreak havoc on one's financial health, because it doubles as form of authorization.

      The choices aren't between "National ID" and "no National ID". The choices are between "National ID that doubles as authorization" and "separate National ID and National Financial Authorization Number".

      Realistically we should keep SSNs as the id and just add a password component which changes every 6 months, has a minimum length of 8 characters, minimum of 2 upper case, 2 lower case, 2 special characters, and two numbers, and has a password history to prevent reuse of old passwords. Maybe even make the requirements change slightly from use-to-use (e.g. if you're logging into a bank you can't use the character %. if you log into a credit card company you can't use *, if you log into the IRS you can't use $, if you log into some other government system you can't use #, etc - that way it gets people to pick unique passwords.)

      Ah fuck it, let's just give everyone implanted RFID chips, who cares if they cause cancer, this is MONEY we're talking about - the most tangible thing in all of existence.

    15. Re: National ID? by chill · · Score: 2

      Uh, what? Did you reply to the wrong message?

      --
      Learning HOW to think is more important than learning WHAT to think.
    16. Re:National ID? by painandgreed · · Score: 1

      So, use the driver's license as the identifier.

      Drivers licenses are issued by the state and each one does it differently, so it changes every time you move from state to state, and sometimes from license to license. A national ID would have to start at the national side of things. In addition, you'll need your national ID long before you need a driver's license just like you usually have to get a SSN pretty soon after birth these days. Plus, in my experience, since most people get their DL during school trip to the DMV as part of Driver's Ed class, they really don't check that hard and just assume you are who you say you are. They didn't even look at my birth certificate when I went. Another friend of mine mistakenly gave them the wrong birth year and spent his senior year as 20 years old. If there was a national ID, it would probalby be a passport, but those can be revoked or at least taken away.

    17. Re:National ID? by painandgreed · · Score: 1

      Democrats won't even allow driver's licenses to be used for proving who you are to vote. But I assume there's an ulterior motive there.

      You mean the constitution won't even allow a driver's license for proving who you are to vote. If the states wanted to provide IDs for free and made sure everybody got them, they could do it, but they don't want to have to pay the price and the point of IDs to vote is not to prove who people are but to prohbit people from voting through an effective poll tax and higher and higher hurdles to jump through.

    18. Re:National ID? by Dutch+Gun · · Score: 1

      If your card is stolen and you need a replacement, how do the authorities know that you are the legitimate card holder and not the guy who stole a card and then, pretending to be you, requested a replacement?

      It's not complicated. You have to go in IN PERSON to a government office and get a card re-issued, using several alternate sources as proof of identity. This is already what I had to do when got a replacement Social Security card or a passport.

      Also, there's no need to actually use this new system to replace anything else immediately. It can just be used as a stand-alone authentication. That is, your SSN can still uniquely identify you as a person, but in order to prove who you are when requesting credit, you'd need to perform a one-time validation using your private and public keys. Same as with the passport - initially, this would only be used to acquire the passport, which can be used normally afterwards.

      I think with this sort of thing, it's important not to let perfect be the enemy of good. There's probably no such thing as a 100% foolproof system, but I don't think it needs to be. It just needs to be significantly better than what we have right now, which is pretty much broken beyond belief.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    19. Re:National ID? by sydbarrett74 · · Score: 1

      At some point the "States Rights," "Big Brother," "Don't Tread on Me" folks are going to have to concede the fact that they're US citizens

      These folks have no problem acknowledging that they're US citizens -- when it benefits them personally. They just don't want anyone else to accrue those same benefits. In other words, they don't mind having other tax-payers provide them with benefits, they just don't want to pay taxes themselves. Try withholding Medicare and SS from a Tea Partier and you'll be facing the business end of an AR-15.

      --
      'He who has to break a thing to find out what it is, has left the path of wisdom.' -- Gandalf to Saruman
    20. Re:National ID? by ebvwfbw · · Score: 1

      How about using this ID to be able to vote? Oh yea, forget that... we can't even get them to use a drivers license yet I can't even get rid of trash at the county dump without my drivers license.

  3. The cool thing is by Maxo-Texas · · Score: 5, Funny

    You'll be able to conveniently use your social security number to get your new id number.

    --
    She was like chocolate when she drank... semi-sweet at first and then increasingly bitter.
    1. Re:The cool thing is by hackwrench · · Score: 1

      Which of course means, so can the bad guys.

    2. Re:The cool thing is by Maxo-Texas · · Score: 1

      Actually, it was just a silly joke. :-)

      --
      She was like chocolate when she drank... semi-sweet at first and then increasingly bitter.
    3. Re:The cool thing is by Wrath0fb0b · · Score: 1

      Which is fine actually if it's a one time thing. Everything is always bootstrapped from something else, you can't generate trust or identity any other way.

  4. My SS Card by Anonymous Coward · · Score: 2

    Clearly says "not to be used for identification purposes" on it. I guess its an oldie.

    1. Re:My SS Card by iTrawl · · Score: 1

      It's probably seen as a historic artefact, similar to the phrase "I promise to pay the bearer on demand the sum of [...]" as seen on paper money, since nobody in authority is actually enforcing it.

      --
      "Everybody's naked underneath" -- The Doctor
  5. String by mentil · · Score: 1

    So, like, you'd go to the SSA website, and they'd give you a string of digits. And you take this string and give it to banks or whatever, and they type it into the SSA website and that brings up who that is associated with. And the owner can revoke their string at any time and replace it with a new one. Better yet, make them all one-time-use, it's not like I REALLY need to use my SSN very often.

    --
    Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
    1. Re: String by freeze128 · · Score: 1

      Retina-scan

  6. Ooooh, I know! by aaarrrgggh · · Score: 5, Funny

    Blockchain. All the cool kids are doing it! Say it with me... Blockchain!

    1. Re:Ooooh, I know! by Tablizer · · Score: 2

      NoSql.Blockchain.node.js is so last year, keep up!

    2. Re:Ooooh, I know! by NicknameUnavailable · · Score: 1

      But node.js+RFID implanted hand chips are the way of the future (the forehead is also acceptable.)

  7. Medicare for all will fix this by Anonymous Coward · · Score: 1

    The new Medicare card will no longer have the primary (usually husband's) SSN as the Medicare number.

    https://www.cms.gov/Medicare/New-Medicare-Card/index.html

  8. About friggin' time! by Ungrounded+Lightning · · Score: 5, Informative

    About friggin' time! I've been doing my best to avoid giving out my SSN where it's not required by law since the '80s.

    One big hole that has been going on for decades is Medicare:

      * Once you're old enough to be on it, you can't get regular health insurance to pay for the portion of your medical work (often all or the bulk of the cost) that Medicare pays for. Regular health plans turn into cover-the-difference supplements. You must sign up for Medicare or pay the charges yourself. (And if you don't have the government imposing price levels or the insurance companies negotiating deep discounts you get to pay the drastically inflated "regular price" that makes up for their discounts.)

      * But if you DO sign up for Medicare, what do you get for an ID? Your SOCIAL SECURITY NUMBER with a single letter appended after it. They won't provide any alternative (though they have "been thinking about it" for years). You have to give this to ALL your medical providers. Get a prescription or an immunization at a pharmacy, hand in your Medicare ID. Go to a doctor, hand in your Medicare ID. Get a lab test, hand in your Medicare ID. Go to a specialist, hand in your Medicare ID.

    Dozens, or even hundreds, of medical billing paperwork operations, with unknown numbers of clerks doing data entry (often offshore) and unknown competency of IT people configuring their databases, get your name and SS#. Some have even been CAUGHT selling them. Oops!

    * So then we get stories about how people over 65 have a much higher rate of identity theft - typically trying to imply that these oldsters are lax in guarding their SS numbers. Well, DUH!

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
    1. Re:About friggin' time! by msauve · · Score: 2

      People need to fight back. Equifax leaks? That should be a problem for lenders, not individuals. PROVE it was me, and not someone giving you my info to take out a loan or ???. Reporting credit issues to any of the 3? That's libel (deliberate, you should know better) without that proof. It's their own damn fault for building a house of cards because it's cheap and easy.

      --
      "National Security is the chief cause of national insecurity." - Celine's First Law
    2. Re:About friggin' time! by Ungrounded+Lightning · · Score: 1

      Reporting credit issues to any of the 3? That's libel (deliberate, you should know better) without that proof.

      Nice idea.

      But truth is an absolute defence against claims of defamation (libel or slander). Seems to me you have a case if, and only if, the information reported is wrong (and the burden of proof for that would be on you).

      I like it: A raft of libel suits could make the cost of doing business as a credit reporting agency high enough that it might finish off the business model. (And the time to hit them is when they're already weakened.)

      --
      Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
    3. Re:About friggin' time! by Hognoxious · · Score: 2

      Seems to me you have a case if, and only if, the information reported is wrong (and the burden of proof for that would be on you).

      No it wouldn't. That would require proving a negative.

      If a newspaper printed a story about you fucking goats could you prove you don't?

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    4. Re:About friggin' time! by bluefoxlucid · · Score: 1

      Hell it's about time. I put this up as soon as this happened. FIDO is the way to go for validation.

    5. Re:About friggin' time! by ausekilis · · Score: 1

      The funny part: I was never intended to be used for identification. The SOLE purpose of the Social Security Number was to track income and earnings for later disbursement from the Social Security fund.

      IANAL, but I read that as, legally, Financial Institutions and Healthcare providers have no basis for needing your SSN. Unfortunately, it's just become used as a national ID.

  9. Time to implement? by vlueboy · · Score: 3, Interesting

    Practically half of us are already hacked NOW.
    When would something be implemented even if a standard were already agreed upon and mandated? I get the feeling this will be treated like Android security where if you don't invest in X flagship, which is optional and expensive, you're just not covered. 140 million is nearly half of all US citizens. I'm pretty sure we can't just reprint all our forms, reprogram all our websites, rework all our databases and change the mentality towards accepting the new name and (hardest of all) technical requirements of the new setup.

    All in all, we need a solution (whatever it is) Yesterday, but even in 1, 3, 5, 10 or 15 years I can't see it really in place (there is failure inertia of British / Metric conversion proportions here). Reminds me a bit of the stupid job we've done when it comes to the spirit of the law for chip&pin Credit cards, being optional and all and totally backward compatible to the old insecure method when the card gets stolen to pay for something online without you there (which is the point).

    1. Re:Time to implement? by Arzaboa · · Score: 1

      Hey now, everyone isn't "hacked", don't be an alarmist. Everyone, for the 7th time, has had their info released to the masses for their identities to be stolen is all.

    2. Re:Time to implement? by 140Mandak262Jamuna · · Score: 3, Insightful

      Practically half of us are already hacked NOW.

      Let me fix it for you.

      Practically half of us know we are already hacked now. The rest will learn soon.

      --
      sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
  10. ID without Auth is still insecure by Tora · · Score: 1

    Changing the ID doesn't help. The problem is we are not authenticating. We need authentication, then the ID does not matter. Sovrin.org as a start?

    --
    tora
    1. Re:ID without Auth is still insecure by Anonymous Coward · · Score: 1

      Sovrin.org as a start?

      Yes, lets put all our identity information in the hands of a private company. That's always had good results before.

  11. Someone doesn't understand the problem by Anonymous Coward · · Score: 5, Insightful

    There's nothing wrong with using SSNs for ID. A unique number for each person in the country? Perfect.

    The problem is when it gets treated as a secret, and abused for "authentication". It's not a secret, any more than your date of birth is a secret. It should be treated as publicly available information. Merely "knowing an SSN" should not be sufficient information to do much of anything, except possibly "give someone money".

    1. Re:Someone doesn't understand the problem by Hognoxious · · Score: 1

      I've seen too many inexperienced devs, for example, create a unique index over an SSN field.

      Because they're too stupid to know what a surrogate key is and/or too lazy to create one.

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    2. Re:Someone doesn't understand the problem by MrLogic17 · · Score: 2

      This.

      A Social Security number is a username, not a password.

      Having a mere SSN should not be enough to authenticate a person is who they say they are, it's just a way to tell me from you. Any person or system using a SSN as proof of identity is just plain lazy - especially since SSN is now practically public domain information. (Thanks Equifax!)

    3. Re:Someone doesn't understand the problem by Ghostworks · · Score: 1

      Exactly. The SSN works as intended: it identifies a person. Proving that someone calling in on the phone actually _is_ the person that number identifies is a completely different problem.

    4. Re:Someone doesn't understand the problem by Hognoxious · · Score: 1

      It's exactly the same principle, stop being a cunt.

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
  12. Lemme see... by scdeimos · · Score: 1

    Banks and businesses require customers to hand over their SSN, despite it being tagged "Not for use as identification", and then subsequently lose them in breaches. Government says let's replace SSN with something else - let's call it SSN2. What do you think will happen next?

    1. Re:Lemme see... by Dracos · · Score: 1

      Lose Them In Breaches 2, Electric Boogaloo

  13. Virtual SSN - White House Petition ? by perpenso · · Score: 5, Interesting

    I was thinking about a White House petition for Virtual Social Security Numbers:

    Virtual Social Security Numbers
    Single use numbers that are aliases for your real number.

    To protect consumers from fraud and theft many banks now offer Virtual Credit Card Numbers. They are aliases, pseudonyms, for a real credit card number. They “lock” to the first merchant to use them. If a merchant’s database is compromised and a virtual credit card number is exposed, it is unusable. All charges not originating from the first merchant are declined.

    The Social Security Administration could use a similar scheme to protect employees and consumers. A Virtual Social Security Number could be given to an employer or financial institution and the number “locked” to that organization when they verify the number with the government, submit information to the government, etc. If a different organization then tries to verify or use the number the government will fail to verify, reject the submission, etc. This would help impede identity theft and financial fraud as employers and financial institutions inadvertently expose employee and consumer information.

    Virtual Credit Card Numbers are generated as needed using a credit card issuer’s online services. Virtual Social Security Numbers could similarly be generated as needed by the Administration through its online services.

    The Internal Revenue Service could employ a similar scheme for their various taxpayer identification numbers.

    1. Re: Virtual SSN - White House Petition ? by Anonymous Coward · · Score: 1

      I had a gas utility that would not provide me service without giving them a SSN. They said I could use Two forms of government photo ID. I used my drivers license and my college ID. They got mad when they couldnâ(TM)t find my SSN number on any of my IDâ(TM)s. The underlying reason: they wanted a unique identifier in their database.

    2. Re: Virtual SSN - White House Petition ? by magarity · · Score: 3, Funny

      The underlying reason: they wanted a unique identifier in their database.

      Dear gas utility, my SSN is: select sys_guid() from dual;

    3. Re: Virtual SSN - White House Petition ? by Anonymous Coward · · Score: 2, Funny

      Little Bobby Tables is always up to something.

    4. Re: Virtual SSN - White House Petition ? by Hognoxious · · Score: 1

      a subpeana

      Hey look, a DeVry grad!

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    5. Re:Virtual SSN - White House Petition ? by chill · · Score: 1

      SSNs aren't used as authorization, they're used as identification. You have no grasp of the issue.

      --
      Learning HOW to think is more important than learning WHAT to think.
    6. Re:Virtual SSN - White House Petition ? by jbengt · · Score: 2

      When I first got my SS card (a long, long time ago), it said right on it that it should not be used for identification.
      SS number should be treated like a publicly known database key for the Social Security Administration's use. It should not be treated as an ID nor for authorization. Those should be independent of the SSN.

    7. Re: Virtual SSN - White House Petition ? by TheCastro1689 · · Score: 1

      That's so they could find you if you didn't pay your last bill and to run a credit check, I assume you had to give them a deposit?

    8. Re:Virtual SSN - White House Petition ? by perpenso · · Score: 1

      Think of the stupidest person you know. He/she has to understand this, along with everyone else in the USA. He/she will not understand this, and neither will grandma.

      From a followup: "To avoid disruption of existing users of the real social security number the real number would remain valid for all users prior to the use of the first virtual number. After the use of the first virtual number existing users of the real number are “grandfathered” but any new organization using it will be disallowed. A consumer may have the option to disallow all use of the real number, requiring legitimate organizations to update their accounts with a virtual number."

      So the real SSN is useable and everything works as it does now until that first virtual SSN is used.

    9. Re:Virtual SSN - White House Petition ? by lgw · · Score: 2

      Wat?

      There's no problem with using SSNs as your username in a system. The problem is using them as a password. They're fine to use as an identifier, but not as a proof of identity.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    10. Re: Virtual SSN - White House Petition ? by darthsilun · · Score: 1

      When someone who doesn't (and shouldn't) need my SSN but insists on having one, I give them my number but with the middle two digits replaced with zeros, i.e. xxx-00-yyyy. The zeros guarantee it's not a valid SSN number, or IOW nobody else's legit number and it gets the ignoramus who's telling me that the computer requires it off my back. Problem solved.

    11. Re: Virtual SSN - White House Petition ? by Scarletdown · · Score: 1

      I remember back in the days of Blockbuster and other video stores, when I wanted a membership, I would write in PRIVACY ACT in the area for SSN. No one ever denied me a membership because of that.

      --
      This space unintentionally left blank.
  14. Guessing works by OFnow · · Score: 1

    Since the SSN only has 10 digits and there are 300 million citizens it means (ignoring any restrictions on numbers) that
    one-third of the possible values [and possibly effectively many more] are used up. All you need do if you need an SSN and expect it
    will not be checked by the Social Security Admin is... guess. And someone will get tagged with that data. With a high probability. That's not good.

    1. Re:Guessing works by Actually,+I+do+RTFA · · Score: 2

      Well, except that with the checksums eliminate half the valid numbers off the bat. So, you're looking at 60% off the bat. Except there are 337M citizens, so 67.2% gone . Then, you get into dead people who had SSNs (with imperfect recycling). And there may be other restrictions, but even without those the odds that any well-formatted SSN was ever issued has to be at least 70%.

      --
      Your ad here. Ask me how!
    2. Re:Guessing works by MrLogic17 · · Score: 1

      Checksum? I think you're confusing credit card numbers with SSN's. SSN has no checksum.

      The first 3 digits are the geographical location of where the number was issued, never above 740.
      The middle 2 digits are Group Numbers, which was roughly chronologically issued batches.
      The last 4 digits are Serial Numbers - issued strictly chronology in sequence.
      (more info: http://www.usrecordsearch.com/... )

      No checkums. You have no way to tell if a given number is used or valid, short of validating the geographic portion.

      Even then, the geographic field isn't reliable. My SSN, for example, is from a state I lived in about a year of my life as an infant. Ask me where I'm from and where I've lived, and that state won't come up.

    3. Re:Guessing works by Actually,+I+do+RTFA · · Score: 1

      Hmm.. okay, checksum isn't really correct. But of the last 4 digits, there are only 500 combinations. Specifically the last two digits have something where there are only 50 combinations. I forgot exactly how it works, but somehow the tens digit determines if the ones digit is odd or even

      --
      Your ad here. Ask me how!
    4. Re:Guessing works by MrLogic17 · · Score: 1

      Are you thinking of Canadian Social Insurance Numbers? There is nothing special about the last 4 of a US Social Security number - short of "0000" and "9999" being invalid.

      The credit card checksum uses the Luhn Alogrithm:
      https://en.wikipedia.org/wiki/...

      Even the wikipedia article states there is no checksum.
      https://en.wikipedia.org/wiki/...

      Got a source for your statement that only 500 combinations of the 10,000 possible are valid?

    5. Re:Guessing works by VisceralLogic · · Score: 1

      Got a source for your statement that only 500 combinations of the 10,000 possible are valid?

      How about, everyone post the last four of their SSN here, and let's see how many combinations show up? :)

      --
      Stop! Dremel time!
  15. Get people to show different ID's by AHuxley · · Score: 1

    Start with a US birth certificate.
    The start to request banks, building societies show the same person exists. Driver licence? Education institution?
    Got a mortgage? Credit card? Utility bill? Who is renting a home?
    The best way to work out who is illegal, using fake ID or just treaded a social security number is to request layers of other photo ID.
    City, state, federal and private sector documents have to start to match going back years.
    Does the life story go back to a lot of other valid US id? Does the trail stop with a fictional number?
    Using another persons social security number or creating a fictional social security number should start to show over different federal, city and state databases.
    The problem with a reused or fictional social security number is that it should not safe from in depth city and federal level scrutiny.
    What worked in the past to get a resume in and cover an illegal persons US university education will not stand to deeper investigation.
    Fictional numbers should not be accepted. Reused numbers should be detected.
    Start to match birth dates with names, education, work and other ID. Most illegals would have expected their one number to carry them.
    Trying to use a social security number as few times as possible with ID built on a cover story should be different from average citizens.

    --
    Domestic spying is now "Benign Information Gathering"
    1. Re:Get people to show different ID's by AHuxley · · Score: 1

      AC the US has issues with reused and fictional social security number use. That takes a lot more care to discover as people have built entire educational and work related life stories around stolen or created social security numbers.
      Other nations would not allow fictional numbers to stay and get used over many years in their systems.

      --
      Domestic spying is now "Benign Information Gathering"
    2. Re:Get people to show different ID's by marka63 · · Score: 1

      Which is a real pain to re-bootstrap after a house fire.

    3. Re:Get people to show different ID's by MrLogic17 · · Score: 1

      >The best way to work out who is illegal, using fake ID or just treaded a social security number is to request layers of other photo ID.

      That used to be true. Now there are 12 states that do or have issued drivers license (photo ID) to illegal aliens.A drivers license from these states is unreliable to establish legal residency.

      California, Colorado, Connecticut, Delaware, Hawaii, Illinois, Maryland, Nevada, New Mexico, Utah, Vermont, Washington, Oregon , and DC

  16. Re:How about by hackwrench · · Score: 1

    Trivia: 6 is the number of man because in the Bible man was made on the 6th day. 6 three times is man exalted.

  17. Start by breaking systems that shouldn't use it by thogard · · Score: 1

    A simple solution for now would be just to add 4 or 5 digits to the new SSNs that are issued. That would break so many systems that others would have to address the real problem.

    Decades ago AT&T had a payroll system that couldn't cope with two employees having the same SSN. It turns out that the SSA has stated that the numbers aren't unique, only unique combined with a last name. If Mary marries Mr Smith and there is a Mary Smith with her SSN, they will reissue her a new SSN. There are millions of people who have been issued replacement SSN so far.

    1. Re:Start by breaking systems that shouldn't use it by Anonymous Coward · · Score: 1

      Here is CGP Grey on the topic.

    2. Re:Start by breaking systems that shouldn't use it by zeugma-amp · · Score: 1

      A simple solution for now would be just to add 4 or 5 digits to the new SSNs that are issued. That would break so many systems that others would have to address the real problem.

      Or simply change it to a HEX value. Instantly you get an expansion of possible 'numbers'. Personally, I'd like to see them go to a 10-digit hex number with a checksum as the last char. The main reason I'd not go beyond 10 digits is because the larger the number, the more difficult it is to remember.

      Unfortunately, changing that particular field is a non-trivial exercise given how widely it is used.

      There are also numerous other issues with them using the SSN as an authentication token as well. Much of this was discussed further upthread. It simply is not the authentication token that people think it is and misuse it as.

      --
      This is an ex-parrot!
  18. User name equivelant by burtosis · · Score: 5, Interesting

    Your social security number should really be viewed as a unique user name and not for purposes of authentication. You could then have one or more passwords for authentication purposes. Say one for taxes, one for mecdical, one for credit - you could change your password easily in the case of a data breach and it's less important if your user name only is leaked.

    1. Re:User name equivelant by Orgasmatron · · Score: 1

      Your social security number should really be viewed as a unique user name

      > social security number
      > unique

      Pick one. Even if you ignore the millions of illegals aliens sharing a few thousand stolen SSNs, they still aren't unique.

      --
      See that "Preview" button?
    2. Re:User name equivelant by burtosis · · Score: 1

      Well when they don't have the password they will get kicked off. Social security numbers shouldn't be used like an hbo go account.

  19. Re:Not understanding the problem... by Waffle+Iron · · Score: 1

    Many organizations have already addressed this problem by not using the SSN as an authenticator, but instead using only the last four digits of the SSN as the authenticator.

    They also use these same four digits as a stand-in for the full SSN in a lower-security context, thereby killing two birds with one stone.

    It's brilliant.

  20. One's Birthday by Trax3001BBS · · Score: 1

    Works for the Medical field.

  21. About damned time... by rnturn · · Score: 1

    The card I received from them decades ago says it's not to be used for identification. Right there plain as day. But... some time between when I got my card and my daughters got theirs, the SS cards stopped saying that. How long before this new ID will get commandeered for use by businesses and we start the whole game over again?

    --
    CUR ALLOC 20195.....5804M
    1. Re:About damned time... by Nethemas+the+Great · · Score: 1

      The point of this new ID is such that it CAN be used by businesses, securely. A common idea tossed out by the tech community would be to use something similar to public key cryptography wherein you have revocable certificates. Your certificate (ID) becomes compromised, revoke and reissue.

      --
      Two of my imaginary friends reproduced once ... with negative results.
  22. and to effectively voluntarily change your SSN by perpenso · · Score: 1

    and to effectively voluntarily change your SSN, rendering the original number completely unusable:

    To avoid disruption of existing users of the real social security number the real number would remain valid for all users prior to the use of the first virtual number. After the use of the first virtual number existing users of the real number are “grandfathered” but any new organization using it will be disallowed. A consumer may have the option to disallow all use of the real number, requiring legitimate organizations to update their accounts with a virtual number.

  23. Maybe I'm wrong... by Streetlight · · Score: 1

    It seems to me there may not be any absolutely secure way of attaching a number, code, text string, retina photo, or whatever used for an identity authentication system. As soon as the system is established, someone will figure a way of compromising it. Even some kind of quickly changing, encrypted algorithmic solution one might come up with might last awhile, but it won't last. Tell me I'm wrong.

    --
    In a time of universal deceit, telling the truth is a revolutionary act. George Orwell
    1. Re:Maybe I'm wrong... by AHuxley · · Score: 1

      It just has to be more expensive than its worth to create an entire city, state and federal ID collection.
      That a life story has to match from birth, to school, to education, to renting, to home ownership, driving a car and full time work. In the same name and with dates that seem real with real sounding decades.
      Lots of retroactive digital database alterations get messy and expensive decades later. Depending on the decade some locations still have actual paperwork for the past generation too. Once one or two generations back don't fit the later alterations then the digital fake ID starts to fail.
      Good enough for an illegal to get schooling? To keep good grades at university? To get a good paying job?
      Their fake or created ID numbers have to pass more in depth requests.
      To get that kind of city, town, state and federal digital cover starts to get more expensive than 1970's -1980's ID creation efforts.
      Was the illegal given an offer years ago? To use an existing number with some risk if caught? Did they create numbers thinking fiction was safer than been found as a 2nd person on one ID?
      At some point it becomes nation state expensive to fake an ID. Possible to forge for a price but the systems is good enough to keep out illegal migrants just creating some random ID numbers and enjoying full citizenship with no risk of detection over decades.

      --
      Domestic spying is now "Benign Information Gathering"
  24. Note to DB developers: by jcr · · Score: 1

    If you use the SSN as a primary key, you're incompetent and you should resign.

    -jcr

    --
    The only title of honor that a tyrant can grant is "Enemy of the State."
  25. Define the problem, then fix the problem by QuietLagoon · · Score: 2

    What is the problem that needs to be solved? Is SSN the problem, or is the over use of SSN the problem? Will any replacement for SSN have the same overuse problem?

    1. Re:Define the problem, then fix the problem by Anonymous Coward · · Score: 2, Insightful

      Good start.
      Just stop at asking the question: what do other countries do. Presumably, Sweden, Great Britain, Japan, France, Germany, Kenya, Brazil, Canada, and may others have been in the same situation. Let's not find out how they did it. Presumably, the solution is separate numbers for a Financial/Tax ID, Social Security Number, Medicare Number, and the like.

      I know what we can do! We can give a $10 million contract to Equifax for them to find the solution for us! No-bid contract, of course.

    2. Re:Define the problem, then fix the problem by Cro+Magnon · · Score: 1

      The problem is, SSN is an ID. It's not a fricking password! If they use the hypothetical replacement as a password, it will have the same problem.

      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
  26. No, we don't. by HBI · · Score: 1

    It's painfully obvious why a national id is a bad thing. There are people on both left and right who think it is a bad idea.

    Another document you have to carry - "papers, please"
    Instantly used for voting and other government services to filter those who can get them. That's racist!
    YA form of ID to renew
    Simple way to make noncompulsory things compulsory - census responses, selective service, jury duty

    Just another step toward totalitarianism and the utter devaluation of human liberty. Fuck that. No one wants your efficiency, or your supposed protection from cybercriminals. This reminds me of the old email idea response sheet.

    --
    HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
    1. Re:No, we don't. by Anonymous Coward · · Score: 1

      Umm, Selective Service and jury duty are already compulsory. Assuming that the appropriate agencies know where you are, at least. And between tax records, voter registration records, and driver license/state id records, it's not hard for them to find you.

    2. Re:No, we don't. by Anonymous Coward · · Score: 1

      "Liberty?" Have you seen the dossiers Acxiom, the credit bureaus, and the like of Google and Facebook already have on us? The only practical consequence of arguing about a national ID is to distract attention from the fact that unless someone doesn't have a cell phone, bank account, credit card, or online account; never files taxes; doesn't own property like a house or car; they are already numbered and cataloged. We can make laws about what the government and private entities should do with this information. Not having a national ID only helps people pretend that such information doesn't exist (and makes it more likely one will have to deal with inaccurate information about oneself).
      As for "papers, please?" Have you tried flying, entering a Federal building, or picking up a package at the post office lately? What does that have to do with how the serial number on the ID card is linked to other accounts?
      The information you object to still there the database uses a set of composite keys instead of a primary key. Why put so much effort into pretending such data isn't out there? Is playing cartoon ostrich that much fun (it will only get sand in your eyes and ears; it will not protect your privacy)?

    3. Re:No, we don't. by OneAhead · · Score: 4, Insightful

      All theories that sound reasonable on paper but are utterly divorced from reality. Only useful for keeping people dumb, just like in the totalitarian dystopias you so decry.

      If you ever step out of your mom's basement (real or allegorical) into the scary, scary world, you'll notice that the US de facto already has this. In most of the country, you can't get anywhere without a car and you can't drive without a driver's license. And folks without one readily get a state ID because in most of the US, you literally can't even do as much as buy a beer without either. Also note that a lot of western European nations have national IDd, and are politically further away from totalitarianism than Ameristan, with (among other things) protection of personal privacy that still has some semblance of meaning. Do you really honestly believe the fact that there's formally no national ID is much of a hindrance to US government services intent on tracking their citizes?

      On a more anecdotal note, I subjectively felt/feel far freer in Western European countries with state ID than in the USA; among many other things, I got ID-ed almost an order of magnitude more often in the latter country. Sure, I could in theory have refused and suffer the consequences, but that "in theory" is exactly why the US is so backward - you conservatives/libertarians/whatever should really get your feet on the ground and start talking in real life terms instead of lofty theoretical concepts that are hollow and being circumvented right under your firmly airborne noses.

      And don't even get me started on SSNs; when I read this story, I rolled my eyes so hard that it was almost audible. Assuming you don't dedicate your life to paranoidly protecting your SSN, its security is an illusion. You know as well as I that your SSN is pretty much everywhere, and identity theft rates are only as "low" as they are because most criminals find it easier to rob people at gunpoint than to jump through a few loops in order to steal the ID of someone who more often than not will turn out to have more liabilities than assets.

      I guess you grew up with it and you'll never understand how utterly bizarre it is to foreigners that there exists a simple 9-digit number that has such huge power over a lot of aspects of your life that it may be your biggest secret, YET YOU HAVE TO FILL IT INTO SOME FORM OR SPEAK IT OUT ON THE PHONE ON A MONTHLY BASIS. Hello? Is this thing on?

    4. Re:No, we don't. by OneAhead · · Score: 1

      OMG, us americans are the dumbest people on earth.

      No, only the conservatives/libertarians are. Most of my American friends would soundly agree with me, using less flattering language than mine (at least in private).

      I feel sad for you if your feeling of national identity is tied to the braindead way in which SSNs are used in the US. There are things to be proud of about the country, but the ID/SSN situation surely isn't one of them.

    5. Re:No, we don't. by OneAhead · · Score: 1

      You must be new here.

  27. Money by sit1963nz · · Score: 1

    What ever they decide, someone will make lots of money

    oh, and it won't work

    Which means someone else will also need to make a lot of money, and they will get to blame the last President of the USA.

  28. Re:Considering Trump is in charge of this by sit1963nz · · Score: 1

    You have NOTHING to worry about.... calm down.... there is a plan.

    Trump will have started a Nuclear war and you will be dead long before they implement another system.

    But the GOOD news is, all the dead people will make the problem much much smaller, saving the (remaining) tax payers billions.
    AND the world will be back to the Stone Age anyways so who needs and ID, you will all looking for something to eat, making fires, and sharpening sticks.

  29. finally, unquestionably really actually "identify" by charliemerritt03 · · Score: 1

    Its about time. Finally. So many years too late we begin the beginning of what had really better be "OPEN SOURCE" dialog on how "WE" are identified as real. Or something like that. Just how do you finally, unquestionably really actually have the real me identified (in court criminally or in ordinary commerce)? I would suppose some combination of "Iris Scan" and a DNA sample would do in an extreme case, like a prison sentence, or even a 30 year mortgage- at what age would somebody be assigned an IDENTIFICATION? I'm sure Apple already has "i dentification"

  30. I am fighting by no-body · · Score: 1

    for years to avoid using my SS# for identification purpose - tuff luck.

    Argument against my wish is that the "company" has the right to choose what kind of identification they can demand.

    It is sooo MF convenient, to have a whole population of a country tracked by ONE key!

    Guess who benefits most from it?

  31. PKI for all by u801e · · Score: 1

    Apply for a signed certificate from the government or business like one would get a signed certificate from a CA for their website. If you lose your private key, then you have to repeat the process (and the government or business revokes your old certificate). Make it time consuming such that people aren't willing to go through the process that often, and they won't be so careless with their private keys.

  32. Re:How about by davester666 · · Score: 1

    Only if everyone gets to have the number tattooed their forehead!

    --
    Sleep your way to a whiter smile...date a dentist!
  33. Re:How about by sit1963nz · · Score: 2

    my ex was born on the 5/6/66

    Turned out that she came from the 5th circle of hell.

  34. Key pairs by vossman77 · · Score: 1

    Give everyone a private key on their birth certificate, and publish a public key as the new SSN.

  35. Step three by Solandri · · Score: 5, Insightful

    Make the companies who lost people's identity data in hacks pay for it. All of it. They're the ones who broke SSNs. They should be the ones who pay to fix it.

  36. Anonymity by markdavis · · Score: 2

    Please note that this doesn't solve a equally big problem- you shouldn't HAVE to identify yourself for doing most things. A good example would be if you have to prove your age to do something. Age verification doesn't mean that establishment should be allowed to know WHO you are, and even worse, record that fact somewhere. Such acts erode privacy, freedom, and could be used later to frame, manipulate, or harass people.

    1. Re:Anonymity by EndlessNameless · · Score: 1

      Age verification doesn't mean that establishment should be allowed to know WHO you are

      It kind of does though. Without establishing an identity with a known date of birth, it is impossible to know the age of a person.

      The correlation between "body in front of you" and "current biological age" has to happen somewhere, and you will need a complicated authentication system if the establishment can't use a standard license/passport/chip. This is wildly unrealistic.

      and even worse, record that fact somewhere.

      This can be addressed by privacy laws. We could have a law that requires written consent for the retention of any verification-related data---we just need to make Congress pass one.

      Such acts erode privacy, freedom, and could be used later to frame, manipulate, or harass people.

      Strong identity services make it harder for people to get things they shouldn't have---weapons, money, chemicals, etc. It also makes it easier to guarantee people get things they are entitled to: prescriptions, money, tickets/passes, government services. There is an inherent utility in having comprehensive, reliable identity services.

      The potential for misuse is present with any capability. People use everything unwisely or dangerously---pharmaceuticals, cars, solvents, and even whipped cream. This is where you have to bring in social pressure and laws---keep the good uses, and punish or prevent the bad uses.

      --

      ---
      According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
  37. Re:How about by penandpaper · · Score: 1

    Only if the font is Olde English! We should have standards!

  38. Re: How about by Z00L00K · · Score: 1

    Wrong, you need to read the book The Number of the Beast. It states that the true number is 6^6^6.

    --
    If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
  39. Private key by phrobot · · Score: 1

    Cool, now I can log onto my bank account with my private key, from a local library PC, which I'm totally sure is not infected with malware because, you know, Windows, and I can feel safe because... why exactly?

  40. Burden of proof system by thegarbz · · Score: 1

    Why not adopt a burden of proof system like many other countries have. If you want to identify yourself you need to accumulate a certain number of points. Certain points are required for certain things (e.g. 100 points to open a bank account, 200 to apply for citizen ship etc).

    Different items provide different points e.g. drivers license or government ID document with photo 50 points, bank issued document or card 25 points, internationally identifying document like passport 75 points, letter posted to your address 10 points etc.

    Then the burden of proof also needs to link the systems together, i.e. you should always have a document with your name, your face, your date of birth and your home address. Mix and match documents until you have the required number of points and all the core parts covered, and bam. ID.

  41. Change the laws for me too! by Arzaboa · · Score: 1

    A shame that the laws dictate on the backside that we change our SSN's when it wasn't us that gave them up over, and over, and over, and over. Wouldn't it be nice if every time we screwed up, the government changed the laws for us?

  42. SSN is not unique by mveloso · · Score: 2

    You sound like those idiots that say "MAC addresses are unique, let's use them as an identifier."

    Neither your MAC address nor your SSN is a unique identifier.

    In fact, identity confirmation is quite difficult, and as an AC I can say that you are totally clueless when it comes to the various issues of identity.

    Maybe you should let the adults talk and keep your head down.

  43. Re: How about by Hognoxious · · Score: 2

    Revelations 13, KJV

    "Here is wisdom. Let him that hath understanding count the number of the beast: for it is the number of a man; and his number is Six hundred threescore and six."

    A score is 20. Do the math.

    --
    Confucius say, "Find worm in apple - bad. Find half a worm - worse."
  44. But I thought... by gurneyh · · Score: 1

    Cryptography is Evil[TM]

  45. Government issued ID by bradley13 · · Score: 1

    The SSN was never intended to be an ID number. Any organization that ever said "if you know this number, we accept that as proof of identity" was stupid, and frankly should be legally liable for any fraud that they enabled.

    The simplest form of identity check is to require a physical government-issued ID with a picture. This could be a driver's license, or a passport, or something similar. These are (a) reasonably difficult to fake, and (b) faking them is a crime. Those may be low barriers, but just knowing an SSN is no barrier at all.

    Cryptographic keys? Joe Sixpack and Granny Gina don't have a clue about cryptography, and aren't going to get one. If you want to put a chip into the aforementioned government IDs, to make them harder to fake, sure. But the users don't need to know about this, and shouldn't have to care about it.

    Of course, the drivers licenses in the US all look different, which makes them difficult to verify when used out of state. I really do not understand why USAians are so resistant to having a uniform, federal ID. It's not really going to make you any easier (or harder) to track, but being uniform, it would be a lot easier to check it's validity.

    --
    Enjoy life! This is not a dress rehearsal.
  46. National ID card with residency registration by MoarSauce123 · · Score: 1

    Have it like Germany, give out national ID cards that require registering residency. Makes a lot of things much easier from generating voter lists to sending out information to finding people in emergencies. That will also end the patchwork of abusing driver's licenses as de facto national ID. Then again, knowing the US governments track records they will immediately find a way to abuse that information.

    1. Re:National ID card with residency registration by borcharc · · Score: 1

      Don't even talk about ID and voting in the same sentence in the united states. Both sides will appear and start acting like rabid dogs.

  47. Re:How about by OneAhead · · Score: 1

    Anger management issues?

  48. Won't that be fun? by drinkypoo · · Score: 1

    This may involve "a public and private key" including "something that could be revoked if it has been compromised," Joyce added.

    Or if you piss off the wrong person. Or if the system fails, or malfunctions. Or...

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  49. Blockchain vs. Tangle by freechina · · Score: 1

    While Blockchain may have the marketcap, my vote for SSN replacement would be the Tangle i.e. quicker, free, public/private. IOT fits right in

  50. Good luck. by Chas · · Score: 1

    Even if the country mandates it, employers will still use it.
    Because, at this point, EVERYONE does.

    --


    Chas - The one, the only.
    THANK GOD!!!
  51. SSN Not for ID by bobf0648 · · Score: 1

    When I got my SSN, some 60 years ago, printed right on the then paper card, it said, NOT FOR IDENTIFICATION USE, or sommething like that. Guess they knew better then.

  52. Re: How about by MBGMorden · · Score: 1

    Trivia: while the link to Nero is POSSIBLE, that's speculative. Nero is actually never mentioned directly in the bible, but the number 666 most certainly is.

    King James Version (I reference that as it's one of the older English translations)
    Revelation 13:18
    "Here is wisdom. Let him that hath understanding count the number of the beast: for it is the number of a man; and his number is Six hundred threescore and six."

    As said the "man" being referred to may be Nero, but it doesn't explicitly state that anywhere.

    --
    "People who think they know everything are very annoying to those of us who do."-Mark Twain
  53. Good by MBGMorden · · Score: 1

    While I have no specific suggestions on WHAT they should do, I'll agree that this is most certainly a problem that needs to be resolved. Since the dawn of the computing age standard practice has been if an account is compromised, you immediately change your password, yet out in meat-space we're expected to keep a 9-digit number secret (while simultaneously having to hand it out to countless people to conduct business) for our entire lives?

    The SSN was created in 1936. That's 10 years before the first modern, programmable computer was invented. It's a product of a by-gone time.

    --
    "People who think they know everything are very annoying to those of us who do."-Mark Twain
  54. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  55. I don't care how safe you feel, you're wrong by HBI · · Score: 3, Interesting

    Somehow, I made it out of my parents' basement over the past 48 1/2 years. In the process, I got a clearance and roll with more background checking and additional ID than most people will ever have. None of that makes me feel even slightly safe, because I know it's all bullshit, really. It doesn't protect against espionage, identity theft or anything else, really. Moreover, the aggregation of key information into a single database is what enabled the OPM breach that gave it all away to (presumably) the Chinese. So some guy in China now knows everything about me, including my personal contacts and whatever data the USG gleaned during my background investigation.

    I subjected myself to this, and I really only have myself to blame for being captured in the OPM hack. People shouldn't be forcibly subjected to this for zero gain in any critical way. And the data won't remain secure. That much is obvious, now. Governments cannot secure electronic data.

    There's lots wrong with the system, but an ID card with crypto isn't going to fix anything, just make things worse.

    --
    HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
    1. Re:I don't care how safe you feel, you're wrong by OneAhead · · Score: 1

      People shouldn't be forcibly subjected to this for zero gain in any critical way.

      See, I feel that's a rather otherworldly argument to make in a society where you get nowhere without ID.

      There's lots wrong with the system, but an ID card with crypto isn't going to fix anything, just make things worse.

      What you have now it the equivalent of a very important password that is low-complexity, can't be changed, and is re-used pretty much everywhere . I'm sure there's a logical explanation of how this came into being, but right now, I can't see how a cryptographically sound authentication system (or really anything at all) could be worse.

  56. Re: How about by NicknameUnavailable · · Score: 1

    "and" == "."

    Therefore the number of the beast is 660.6

  57. No problem ... by PPH · · Score: 1

    ... using an SSN as a unique ID. What it should NOT be used for is verification of identity. Just because some third party knows my SSN doesn't mean that they are me. There ought to be a law relieving me of all responsibility for any credit, loans or other contracts entered into without the use of a robust means of identity verification.

    But just watch: This is a foot in the door to hand the verification contract to Equifax. Without a bid.

    --
    Have gnu, will travel.
  58. Re:40 Outrageous Facts Most People Don't Know by thegreatbob · · Score: 1

    Most sensible part: "ÎÏ...ÎÎÏÏfOEÏ, ÎÏ...ÎÎÏÏfÎÏ"

    --
    There is no XUL, only WebExtensions...
  59. Re: How about by rickb928 · · Score: 1

    Revelation 13:18. Is that so hard to know?

    And a reasonable interpretation of the phrase 'for it is the number of a man, and his number is 666' is that while 7 is the number of completion, and the number 3 often found to refer to completion.

    From a reasonably useful site:

    "Interestingly, man was created on the sixth day of creation. In some passages of the Bible, the number 6 is associated with mankind. In Revelation “the number of the beast” is called “the number of a man. That number is 666” (Revelation 13:18). If God’s number is 7, then man’s is 6. Six always falls short of seven, just like “all have sinned and fall short of the glory of God” (Romans 3:23). Man is not God, just as 6 is not 7."

    If you reject the Bible and/or God, then this is merely informative for you - knowing what other people believe and why is rarely a bad thing, and should not be offensive, unless you're offended by the truth, which in this instance is merely the truth of others' beliefs. You're free to believe what you will.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  60. Re: How about by rickb928 · · Score: 1

    Numerology is more Gnosticism than theology.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  61. Re: How about by rickb928 · · Score: 1

    Six Hundred
    Three Score
    Six

    How this is anything but '666' is not obvious. The contemporary language of the KJV requires careful interpretation, not reinterpretation.

    You may want to steer clear of the original "Pilgrim's Progress'.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  62. Re:40 Outrageous Facts Most People Don't Know by rickb928 · · Score: 1

    Thank you for the information. Now please take your pills and get into the car.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  63. Never was suppose to be used for ID by p51d007 · · Score: 1

    My first SS card, said "not to be used for identification". Oh, I'm sure the government will come up with an alternative...CHIP implants. And they won't make it mandatory, but, if you don't they'll make a law that says if you don't have one, you can't access this government service or that government service. Hell, Sweden is doing it, and thinking about making it MANDATORY. When it comes to the USA, I'll be long gone, but, if I'm still around, I'll save them the fight, I'll just shoot myself. No one is putting an ID chip inside of me. It's bad enough your phone, home computer, GPS, car computers and what not know where you are and what you do all day long, but I'll be damn if someone plants one inside of me or puts a tattoo bar code on my skin.

  64. +1 Interesting by mccrew · · Score: 1

    Sigh, replying to undo unintended mod. Meant to mark interesting.

    --
    Hey, Windows users, there is no such thing as "forward" slash, there is only slash and backslash.
  65. Re:A White House Petition ? by perpenso · · Score: 1

    It's a representative republic, not a democracy, without a lobbying presence of your own, your Congressman is the place for this kind of request, not a social media holdover from the 44th presidency. That's so 2008.

    The social media holdover is also a way to get a conversation going amongst the public, which can lead to many people contacting their senators and representatives. :-)

  66. Re:How about by sabri · · Score: 2

    everyone gets to have the number tattooed their forehead!

    This should not even be a problem. The problem is not SSN security. The problem is the way that people think it's some kind of secret password.

    On my foreign passport, my SSN equivalent is printed on the same page as my name and photo. It's not a secret because we expect banks and similar businesses to verify identity using photo ID, not knowledge of a random 9 digit number associated with my person.

    And that is the problem. That somehow, knowledge of a 9 digit number does not prove that you actually are that person.

    --
    I'm not a complete idiot... Some parts are missing.
  67. Wrong turn by thunderclees · · Score: 1

    SSN were never meant to be used for ID purposes and it is illegal to use them as such but this never stopped anyone. What about block-chain? Introducing the Blockstack Identity System
    The problem is that with RFID being practically free, becoming more capable and smaller it will not be long before this is mandated at birth, injected into the feet/hands/forehead. The tags will be tied into every object interaction and used for all sorts of metadata hoarding.

  68. 2 way authentication by vladimir.sakharuk · · Score: 1

    Would it be more secure if we have simple feed back solution using 2 ways authentication through phone or computer? Something like If I apply for something, there is pop-up in my phone asks me to confirm? Such implementation already exist with remote login into your work computer and could be trivially replaced each time there is security bridge.

  69. Re: How about by nomadic · · Score: 2

    I try to avoid late-era Heinlein. His stuff got so bad.

  70. Solution in search of a problem.... by oh_my_080980980 · · Score: 1

    The issue is not with Social Security numbers. The issue is with systems used to STORE SENSITIVE INFORMATION. You are still going to have the problem of theft, if you do not have a secure system, regardless of whatever identification system you use.

    Stop ignoring the problem. Focus on securing your system.

  71. But my SS card says, not "not for identification" by AbrasiveCat · · Score: 1

    Hey, my SS card says it is not for identification. Past that we put to much weight in a social security number, particularly after the Equfax (and other unknown) security leaks. We need to have a way to verify it is us without an external (copy-able, steal-able) component. And not a dang implanted RFID chip. Are we back to passwords?

  72. Re: How about by Darinbob · · Score: 1

    One of the older translations, but definitely not one of the most accurate.

    Although 666 is indeed the number in most texts, the various translations are all going to agree. But there is an old manuscript and a papyrus fragment that list 616. Not all that important, as with hand made copies there were lots of variations, sometimes mistakes, some added text, some missing verses, etc.

  73. Revocation List? by FuegoFuerte · · Score: 1

    Going with the Crypto idea and public/private keys and a revocation list... what happens if your private key gets revoked by mistake?

    People complain about how hard it is to get off the terrorist watch list; how hard will it be to get off the Identity Revocation List? "I'm sorry, you must present your valid identity card to file a complaint." "Your identity can not be found. Please try again." "Your identity has been revoked. Please wait, Identity Removal Services agents will be with you shortly. Please enjoy your time in Guantanamo Bay."

    What are all the ways this could go wrong?

  74. Re:How about by ChrisMaple · · Score: 1

    Part of the problem is that it's only a 9 digit number. We've already burned through about half of them.

    --
    Contribute to civilization: ari.aynrand.org/donate
  75. cows are out of the barn... by inerlogic · · Score: 1

    better close the fucking door.....

  76. Re: How about by MercTech · · Score: 1

    Gad, I need to re-read that bit of self referential entertainment R.A.H. wrote.
    Thanks for reminding me of a book from my younger days.

    --
    NRRPT/RCT
  77. It says NOT for use as ID on my SS CARD! by PlaynBass · · Score: 1

    This whole thing is so absurd, given that it was plainly stated on my first Social Security card: "Not for use as Identification." My original card wore out and had to be replaced sometime back, but by then, its use as an ID had become the norm... We definitely need a more secure system of establishing a hack-proof ID.

    --
    PlaynBass
  78. Re:But my SS card says, not "not for identificatio by ebvwfbw · · Score: 1

    That's right. In fact don't give out your SS# to almost everyone. The ONLY ones that need it are banks and it seems health care due to the ACA, sometimes called Obummer care. Something that wasn't even his idea and he admits it.
    You can give a fake number to those people. Start it with 555. That will instantly identify it to a guy like me that it's fake and we'll understand.

  79. Re: How about by slashdotwannabe · · Score: 1

    It is mentioned in the Bible as six hundred three-score and six.

    Yea, but "642, the number of the beast" isn't nearly as dramatic....

    --
    This comment is my opinion and does not represent an official position of Donald Trump or others I do not work for
  80. Exactly. All of this has taken too long... by bussdriver · · Score: 1

    Lack of security education and the use cases involved is why we continue to have this disaster:

    Account Universally Unique Identifiers are needed and just like your email should be public knowledge and able to be changed (but not without some difficulty.) It is illegal to track people using SSN or verify their identity with SSN but that has been going on since the start because people didn't LEARN enough to separate the use cases. Keep some uses illegal, but address the use cases and allow it as a universal unique identifier everywhere (with legal limits-- you can't force everybody post comments online using their UUID as their account name.)

    SSN is just fine to CONTINUE to use as a citizen number. Let them be published. Children born after X date get a smarter UUID. Something easy to remember, base33 with only 6 characters... 3 for time/place of birth and 3 as a serial number. [A-Z0-9] but remove [OZI] to avoid confusion with [051].

    Identity will require 3rd party verification-- by government and allow for other parties to sign on as well.

    Use Cases:
    Age verification, Endorsements, Tax Id, ownerships, claims, signing, HIDDEN anonymous virtual identities.

    Multiple IDs are possible and SHOULD exist. Drinking Age is fine with a photo ID validated by 2D barcode of a digital photo. No identity required-- anonymous age verification!

    Online age verification, smart chip... difficult to copy -- again, no identity given whatsoever. A pin could be used SOMETIMES... skydiving vs porn depends on how strong a verification step is needed if you need a pin.

    Hidden anonymous identity--- as many as you want but the government with a warrant can discover your true identity. You could blockchain all of your aliases. Corporations, Contracts-- all will NOT know your identity or track you precisely with this info-- but lawsuits and crimes would allow in certain cases your alias chain to be tracked down in court (but not disclosed to corps.) Rent a car, steal it-- get sued and the rental service wins but never knows who you are the whole time; but the cops who arrest you know. Credit cards etc could be done using something like this... bankruptcy or identity protection situations could "reset" you while still maintaining an official secret trail.

    Biometrics:
    Tattoo your SSN on your fingers and use that as your password. Biometrics also fail at 5th amendment protections.
    iPhone X: don't put your password on your forehead, make forehead your password!

  81. Re: How about by ArmoredDragon · · Score: 1

    I've always understood that 616 refers to Nero Caesar when writing his name in Hebrew numerals, but 666 refers to the Greek spelling: Neron Caesar.