Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Tweaking Social Security to Combat Fraud
Tim Mullen, 2008-02-13

Americans lost over 45 billion dollars in identity-related fraud in 2007. Reports are so commonplace that we've actually become de-sensitized to them. "200,000 victims reported..." "500,000 victims reported..." Even figures into the millions don't seem to faze us anymore. And that is a Bad Thing.

Comments Mode:
Tweaking Social Security to Combat Fraud 2008-02-13
Bob
The problem is not the permanance of SSN.
The problem is that SSN is a loginid and
password, all rolled into one. Of course,
a loginid must be public, and a password must
be secret, so SSN necessarily fails in some way.

The solution, IMHO, is to publish ALL SSNs
and names on a public web p...

[ more ]  [ reply ]
Tweaking Social Security to Combat Fraud 2008-02-14
Pete
There is a much easier answer - publish all SSNs and eliminate the charade of trying to use an SSN as an authenticator. See http://spiresecurity.typepad.com/spire_security_viewpoint/20
07/03/ssns_rerererevi.html for details....

[ more ]  [ reply ]
Tweaking Social Security to Combat Fraud 2008-02-15
Anonymous
Very good article and I agree with most points. However I do disagree with the idea that "If a non-government entity requires the use of one?s SSN to be used or validated as part of its process model, the first step is for the validation bodies (both of them) to authenticate the status of the suppl...

[ more ]  [ reply ]
Tweaking Social Security to Combat Fraud 2008-02-15
h3h
Interesting article, and interesting comments. Arguments similar to this have been going around for quite some time, and I highly expect that will remain the case. I honestly don't expect anyone to ever do anything about this.

The main thing that makes a SSN dangerous to share is its link to obt...

[ more ]  [ reply ]
Tweaking Social Security to Combat Fraud 2008-02-18
Anonymous
The problem is that your SSN is allowed to be used for _anything_ other than Social Security and Taxes.

The author spends too much time trying to maintain the credit history linkage through the SSN. If there is a clear path from old SSN to new SSN it won't help anything.

Identity fraud occurs...

[ more ]  [ reply ]
Tweaking Social Security to Combat Fraud 2008-02-20
Scott
My issue with the SSA is why don't they contact a "customer" ,the true SSN holder, when something doesn't match up in their records. Case in point: A lady in Ohio goes to apply for a job at Target only to be turned down because "she" already works at Target in another state. Well she has never worke...

[ more ]  [ reply ]
wrong - just go back to the original intent 2008-02-21
Anonymous
I'm old enough to have a social security card that says
FOR SOCIAL SECURITY AND TAX PURPOSES - NOT FOR IDENTIFICATION
on the front. Instead of trying to secure SSNs or creating a whole new bureaucracy for maintaining and tracking who had what number when, just go back to where the SSN was used O...

[ more ]  [ reply ]
Tweaking Social Security to Combat Fraud 2008-02-22
JustAThought
IMHO, the problem is because their using an ID that was meant for a social service and the credit companies got a cheap way to ID people. The use of SSN for credit use is outdated. Its really the credit companies who don't want to come up with their own form of ID system that can protect consumers. ...

[ more ]  [ reply ]
Tweaking Social Security to Combat Fraud 2008-03-03
Tampa Dude
According to your idea, when an SSN changes the old on eis voided. What about the hundreds of systems surrounding the customer that bases their accounting on the SSN of the customer. For example, electric bills, water, credit cards, mortgages, health information, insurance, etc... are comprised of...

[ more ]  [ reply ]
Tweaking Social Security to Combat Fraud 2008-03-04
Anonymous
After visiting many government sites in regards of fraud against the program or law, it is very difficult to make a report. There seems to be no facility to report them. After all they are all talking about combating them. Almost none of them have any email address to report only hotline (phone numb...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus