<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Social Security Numbers are Worthless as Authenticators</title>
	<atom:link href="http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Mon, 15 Mar 2010 15:02:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: ID Thief</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5936</link>
		<dc:creator>ID Thief</dc:creator>
		<pubDate>Sun, 26 Jul 2009 01:56:50 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5936</guid>
		<description>Consider someone pretending to be you - like an Identity Thief.  He/she knows your SSN, Name, Address, Birthdate, and gets your Resume online (all quite simple to obtain).  Now consider this ID Thief applying for Jobs and going to interviews as you, using your information and applying for these jobs in your name, pretending to be you.  The company just wants the SSN in their hiring system (your SSN provided by the ID Thief) to run a background check and &quot;verify&quot; the  information provided by the ID Thief.  The SSN check and background check comes back clean because you are a great person and the employment history and other information from your resume matches the company background check.  Now, the company offers the ID Thief a job and hires the ID Thief now using your name and identity, starts working, earns money in your name.  Now consider after a month this person murders someone in the company or steals something big and simply leaves town to another state and starts all over again.  I would say you are screwed and the SSN failed to provide any authentication at all. And we wonder why ID Theft is a serious problem in America.  Wake up people...  Call and scream at your elected officials Now to prevent employers from using your SSN for autheticataion.  And good luck with cleaning up the mess left behind by the ID Thief...
</description>
		<content:encoded><![CDATA[<p>Consider someone pretending to be you &#8211; like an Identity Thief.  He/she knows your SSN, Name, Address, Birthdate, and gets your Resume online (all quite simple to obtain).  Now consider this ID Thief applying for Jobs and going to interviews as you, using your information and applying for these jobs in your name, pretending to be you.  The company just wants the SSN in their hiring system (your SSN provided by the ID Thief) to run a background check and &#8220;verify&#8221; the  information provided by the ID Thief.  The SSN check and background check comes back clean because you are a great person and the employment history and other information from your resume matches the company background check.  Now, the company offers the ID Thief a job and hires the ID Thief now using your name and identity, starts working, earns money in your name.  Now consider after a month this person murders someone in the company or steals something big and simply leaves town to another state and starts all over again.  I would say you are screwed and the SSN failed to provide any authentication at all. And we wonder why ID Theft is a serious problem in America.  Wake up people&#8230;  Call and scream at your elected officials Now to prevent employers from using your SSN for autheticataion.  And good luck with cleaning up the mess left behind by the ID Thief&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ID Thief</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5935</link>
		<dc:creator>ID Thief</dc:creator>
		<pubDate>Sun, 26 Jul 2009 01:55:07 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5935</guid>
		<description>Consider someone pretending to be you - like an Identity Thief.  He/she knows your SSN, Name, Address, Birthdate, and gets your Resume online (all quite simple to obtain).  Now consider this ID Thief applying for Jobs and going to interviews as you, using your information and applying for these jobs in your name, pretending to be you.  The company just wants the SSN in their hiring system (your SSN provided by the ID Thief) to run a background check and &quot;verify&quot; the  information provided by the ID Thief.  The SSN check and background check comes back clean because you are a great person and the employment history and other information from your resume matches the company background check.  Now, the company offers the ID Thief a job and hires the ID Thief now using your name and identity, starts working, earns money in your name.  Now consider after a month this person murders someone in the company or steals something big and simply leaves town to another state and starts all over again.  I would say you are screwed and the SSN failed to provide any authentication at all. And we wonder why ID Theft is a serious problem in America.  Wake up people...  Call and scream at your elected officials Now to prevent employers from using your SSN for autheticataion.  And good luck with cleaning up the mess left behind by the ID Thief...
</description>
		<content:encoded><![CDATA[<p>Consider someone pretending to be you &#8211; like an Identity Thief.  He/she knows your SSN, Name, Address, Birthdate, and gets your Resume online (all quite simple to obtain).  Now consider this ID Thief applying for Jobs and going to interviews as you, using your information and applying for these jobs in your name, pretending to be you.  The company just wants the SSN in their hiring system (your SSN provided by the ID Thief) to run a background check and &#8220;verify&#8221; the  information provided by the ID Thief.  The SSN check and background check comes back clean because you are a great person and the employment history and other information from your resume matches the company background check.  Now, the company offers the ID Thief a job and hires the ID Thief now using your name and identity, starts working, earns money in your name.  Now consider after a month this person murders someone in the company or steals something big and simply leaves town to another state and starts all over again.  I would say you are screwed and the SSN failed to provide any authentication at all. And we wonder why ID Theft is a serious problem in America.  Wake up people&#8230;  Call and scream at your elected officials Now to prevent employers from using your SSN for autheticataion.  And good luck with cleaning up the mess left behind by the ID Thief&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Brodbeck</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5934</link>
		<dc:creator>David Brodbeck</dc:creator>
		<pubDate>Tue, 07 Jul 2009 18:14:33 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5934</guid>
		<description>The problem, of course, is that a unique identifier is a useful thing to have for tracking things like credit reports; but for political reasons any kind of national ID number is a non-starter.  So we&#039;re stuck with using the SSN as a sort of defacto national ID number.
</description>
		<content:encoded><![CDATA[<p>The problem, of course, is that a unique identifier is a useful thing to have for tracking things like credit reports; but for political reasons any kind of national ID number is a non-starter.  So we&#8217;re stuck with using the SSN as a sort of defacto national ID number.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5933</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Tue, 07 Jul 2009 11:18:40 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5933</guid>
		<description>Student, mckt,
SSNs lack a check digit, and are too short.   If you really want an identifier, you want at least 3, preferably 4 digits for issuing government, then at least 10 digits to encode ten billion people (so China and India are covered for a few generations.
So a &quot;perfect identifier&quot; is probably 15 digits, not 9.
(This of course assumes that such a thing exists or is desirable, which it doesn&#039;t and isn&#039;t.)
</description>
		<content:encoded><![CDATA[<p>Student, mckt,<br />
SSNs lack a check digit, and are too short.   If you really want an identifier, you want at least 3, preferably 4 digits for issuing government, then at least 10 digits to encode ten billion people (so China and India are covered for a few generations.<br />
So a &#8220;perfect identifier&#8221; is probably 15 digits, not 9.<br />
(This of course assumes that such a thing exists or is desirable, which it doesn&#8217;t and isn&#8217;t.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Blakley</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5932</link>
		<dc:creator>Bob Blakley</dc:creator>
		<pubDate>Tue, 07 Jul 2009 11:13:21 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5932</guid>
		<description>I&#039;m surprised at the publicity this has gotten; anyone who didn&#039;t move a lot and had siblings already knew that SSNs had these issues.  Back before the IRS tightened the child deduction rules to essentially require parents to get SSNs for children before their second birthdays, it was pretty common for a family to apply for SSNs for their kids in a batch when the oldest turned 15 or so and applied for a first job.
This resulted in a set of nearly identical SSNs - same first 5 digits with the last 4 increasing in an obvious pattern.  If you were paying even a little bit of attention it was pretty clear how the system worked.
I suppose someone who wants 15 minutes of fame could write the next paper on the not-very-sophisticated algorithms many states used (maybe some still use them; I haven&#039;t checked recently) to derive drivers&#039; license numbers from SSNs.
</description>
		<content:encoded><![CDATA[<p>I&#8217;m surprised at the publicity this has gotten; anyone who didn&#8217;t move a lot and had siblings already knew that SSNs had these issues.  Back before the IRS tightened the child deduction rules to essentially require parents to get SSNs for children before their second birthdays, it was pretty common for a family to apply for SSNs for their kids in a batch when the oldest turned 15 or so and applied for a first job.<br />
This resulted in a set of nearly identical SSNs &#8211; same first 5 digits with the last 4 increasing in an obvious pattern.  If you were paying even a little bit of attention it was pretty clear how the system worked.<br />
I suppose someone who wants 15 minutes of fame could write the next paper on the not-very-sophisticated algorithms many states used (maybe some still use them; I haven&#8217;t checked recently) to derive drivers&#8217; license numbers from SSNs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5931</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Tue, 07 Jul 2009 11:07:27 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5931</guid>
		<description>Nicko,
Lots of people are &quot;protecting&quot; the SSN by showing only the last 4 digits.  I&#039;ve gotten tax documents from states redacted like this.  If an attacker can guess the first 5 44% of the time with my birthday (on the form) and my place of birth (also easily found), then that security measure is pretty poor.
</description>
		<content:encoded><![CDATA[<p>Nicko,<br />
Lots of people are &#8220;protecting&#8221; the SSN by showing only the last 4 digits.  I&#8217;ve gotten tax documents from states redacted like this.  If an attacker can guess the first 5 44% of the time with my birthday (on the form) and my place of birth (also easily found), then that security measure is pretty poor.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mckt</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5930</link>
		<dc:creator>mckt</dc:creator>
		<pubDate>Tue, 07 Jul 2009 09:53:19 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5930</guid>
		<description>SSN is not even good for identification:
1. Duplicate SSNs can be, and have been issued
2. SSNs can be changed
3. Not everybody has an SSN (non-citizens and non-taxpayers aren&#039;t required to do so)
</description>
		<content:encoded><![CDATA[<p>SSN is not even good for identification:<br />
1. Duplicate SSNs can be, and have been issued<br />
2. SSNs can be changed<br />
3. Not everybody has an SSN (non-citizens and non-taxpayers aren&#8217;t required to do so)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gunnar</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5929</link>
		<dc:creator>Gunnar</dc:creator>
		<pubDate>Tue, 07 Jul 2009 08:40:27 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5929</guid>
		<description>authentication: something you have (written on your hide)
</description>
		<content:encoded><![CDATA[<p>authentication: something you have (written on your hide)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Student</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5928</link>
		<dc:creator>Student</dc:creator>
		<pubDate>Tue, 07 Jul 2009 07:42:14 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5928</guid>
		<description>SSN are perfect for Identification. They are a global identifier attached to a person.
The problem is that people use them for Authentication and, even worse Authorization. Given an SSN you need to verify that the person matches the SSN and that he allowed to do what he wants to do. It seems that this is the problem, not the usage of the SSN as an Identifier.
Keeping Identity, Authentication and Authorization apart is too hard for most designers of computer system, which is exactly why security professionals should scream bloody murder everytime something like SSN are used for anything beyond Identification.
</description>
		<content:encoded><![CDATA[<p>SSN are perfect for Identification. They are a global identifier attached to a person.<br />
The problem is that people use them for Authentication and, even worse Authorization. Given an SSN you need to verify that the person matches the SSN and that he allowed to do what he wants to do. It seems that this is the problem, not the usage of the SSN as an Identifier.<br />
Keeping Identity, Authentication and Authorization apart is too hard for most designers of computer system, which is exactly why security professionals should scream bloody murder everytime something like SSN are used for anything beyond Identification.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2009/07/social-security-numbers-are-worthless-as-authenticators.html/comment-page-1#comment-5927</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Mon, 06 Jul 2009 23:35:44 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=3160#comment-5927</guid>
		<description>I guess I&#039;m glad I was born in the NYC metro area.  Take that, Delaware!
I guess what we really need is a proper government issued universal identifier, eh?  (ducks)
</description>
		<content:encoded><![CDATA[<p>I guess I&#8217;m glad I was born in the NYC metro area.  Take that, Delaware!<br />
I guess what we really need is a proper government issued universal identifier, eh?  (ducks)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
