3 ms·
There are legitimate use cases where collecting and storing (in some manner at least) is necessary. You cannot just stop companies from collecting information,
by scient 9y ago
There are legitimate use cases where collecting and storing (in some manner at least) is necessary. You cannot just stop companies from collecting information, and furthermore stop them from storing any of it. Thats just naive.
- thanksgiving 9y agoThe private university I went to used to issue student emails that were first three letters of last name followed by last four digits of social security number. It always seemed odd to me. Years later, they've switched and we don't have that problem any more. Companies can generate a unique identifier without using SSN. Of course, the main problem is that they can't do authentication based on that identifier. So why can they do authentication based on SSN?
- kevin_thibedeau 9y agoSSN is the only reliable way to disambiguate duplicate names. Differentiating all the John Smiths by mailing address is too intractable, especially when you have JS Jr. and JS III living together. It is used to construct a primary key for the database.
- ihattendorf 9y agoOr just assign duplicates/everyone a generated unique/sequential number?
- WorldMaker 9y agoExcept that's not always been the case, either. SSNs have always been a terrible way to disambiguate people. There are weird, crazy edge cases in SSN history. Cases exactly such as JS Jr getting the same SSN as JS III in a podunk town because the local SSA administrator was feeling lazy that day and JS III was already deceased. The federal SSA website claims that that never happened, but if you have a big enough database (say, Equifax) you can spot all kinds of simple dumb human errors like that. For many, many years the SSA left local administrators in charge: the first 5 digits and the weird way they are hyphenated were local district numbers. For people born before 2011 (!), when the new randomization scheme was switched to, there is a 90% chance you can guess their first five numbers if you know their birth date and birth city (which is why it is so ridiculous that PII rules to keep SSNs safe ever considered it fine to show only the last four, those are only meaningful digits for still the majority of SSNs in the wild). SSNs were never designed for what the credit bureaus and banks and insurance companies (and everybody else) use them for, and there are too many cracks and failure cases. Companies need to admit their failures and come up with a real solution; but companies have so much sunk cost in SSN-keyed databases they aren't likely to ever actually do that. (Maybe this Equifax breach pushes more companies to try. Cynicism says companies remain cheap and invested in their sunk costs.)
- bsder 9y agoReally? I don't buy it. A corporation needs my name, address, and probably email to do business with me. They need a credit card number when I purchase something and never else. That's IT. My phone number is not necessary (and everybody using it for 2 factor just makes everything less secure). What I buy is not necessary to record past fulfillment. When I buy is not necessary to record. Where I am is not necessary to record. etc. If a company stores this stuff and it gets leaked, they should be liable. A couple of egregiously expensive fines will stop companies from collecting this information quite nicely, thank you.