3 ms·
That is basically a 'super SSN'. With the same sort of issues that SSN has. It is a decent idea but even that you should be able to change if needed. Remembe
by sumtechguy 6y ago
That is basically a 'super SSN'. With the same sort of issues that SSN has. It is a decent idea but even that you should be able to change if needed. Remember there are nefarious players out there.
- deleted 6y ago[deleted]
- jsty 6y ago> With the same sort of issues that SSN has Only if knowledge of one's "GUID" was regarded as sufficient to authenticate as them surely?
- shadowfox 6y agoI mean it can also be used as a universal, semi-permenant activity tracking id with almost no work, which may not be desirable depending on your feelings wrt privacy. Maybe an ability to generate virtual IDs based on a permanent id (like with virtual credit cards) might help though this is sometimes tricky to use correctly in a privacy-preserving way.
- nojokes 6y agoSSN has only issues when it is used as password. Many other national id's are not used like that and do not have any issues.
- sumtechguy 6y agoThat assumes all players will use the number correctly. SSN is an example where that did not happen and is used as an authentication and authorization token at the same time.
- nojokes 6y agoThat is true and it requires some educating by the state. Not possible when the state is using it wrong.
- sumtechguy 6y agoEducation would not work that well either unfortunately. On the card it says 'not for identification' (in most cases now). Once the number was disassociated from the advice people did whatever with it. It is a thing where identity theft usually starts. It is one thing companies like to do is get whatever info they can and keep it forever and do random things with it.
- sagarm 6y agoIdentity theft itself is an example of regulatory failure. How is it my problem that you gave someone a loan based on practically public information? They should have to prove, beyond simply an SSN, that an individual is responsible for the debt before being able to send it to collections or report it to credit agencies.
- josefx 6y agoI thought you can at least derive location and date of birth with quite a bit of accuracy from them. Also if a data set containing the SSN is leaked anyone can cross reference it with any other leaked data set. Ideally you would need a unique and completely random SSN per service.
- nojokes 6y agoYes, this is true. I do not know about SSN but the two national identifiers I have (from two different countries) do have this problem (both leak birth date and one also place and gender). But when an real random GUID is used then this is not a problem.
- hundchenkatze 6y ago> I thought you can at least derive location and date of birth with quite a bit of accuracy from them. You can for numbers issued before 2011, they're random now. The first three numbers are tied to the zip code of the application and the month/year of the application can be determined by the group numbers (the two in the middle). https://www.ssa.gov/employer/stateweb.htm https://www.ssa.gov/employer/stateweb.htm
- WorldMaker 6y agoWhich is why it remains hilarious that when sites block/mask out the first five digits and show only the last four, the last four are the only real "secret" parts for most SSNs before 2011. That's often the case with Bank Account and Credit Card numbers too that the parts commonly masked are the least significant from a security entropy standpoint (are often built algorithmicly and tend to cluster; CC numbers often encode processor and bank in the first bunch of numbers). The parts left unmasked to make them easy to recognize are easy to recognize precisely because they have the most security "entropy" and are the most sensitive parts. SSNs adapted in 2011 and CC Numbers are in the process of adapting (and I suppose Bank Numbers are adapting at a per-Bank rate), but it's almost funny how universally this "best practice" of masking these security identifiers started from the "wrong end" and have forced their own generation algorithms to move a lot more entropy into their prefixes and middles.