5 ms·
I live in Denmark so also Europe. Our social security number (which can be guessed with enough information and a few tries) has been incorrectly used as a passw
by liversage 6y ago
I live in Denmark so also Europe. Our social security number (which can be guessed with enough information and a few tries) has been incorrectly used as a password instead of a key just like you describe. You make a call, provide this number and the clerk on the phone believes that you are who you claim to be.
Nowadays things are better because computers are used everywhere We have a national ID system using 2FA which is pretty safe. Unfortunately, identify theft is still a thing.
Recently someone installed keyloggers on public computers. The second factor in the 2FA is a cardboard card with a list of one time password codes. You use a code on each sign in.
The criminals were able to determine when there were only a few codes left on the card. You then get a new cardboard card sent to your home address. They would stalk their victim's mail box and steal the new card as soon as it arrived.
With user name (your social security number) and password from the key logger together with the 2FA codes they were able to perform identity theft.
It's not easy to guard against attacks like this.
- bonzini 6y agoAbsolutely, but it's more effort than knowing an SSN and being immediately able to get a loan in the name of that person. That would be ridiculous in Europe.
- kortilla 6y agoThat’s pretty ridiculous in the US as well. An SSN is never enough. Usually they will need some copy of a state ID and proof of access to a mailing address on your credit history.
- bonzini 6y agoI didn't say that, the US government does: > Identity thieves can use your number and your good credit to apply for more credit in your name. Then, they use the credit cards and don’t pay the bills, it damages your credit. You may not find out that someone is using your number until you’re turned down for credit, or you begin to get calls from unknown creditors demanding payment for items you never bought. https://www.ssa.gov/pubs/EN-05-10064.pdf https://www.ssa.gov/pubs/EN-05-10064.pdf
- kortilla 6y agoThat’s not how it works though in the vast majority of US financial institutions though. They won’t just send a credit card to a random address. That document is written to scare people into protecting their SSN. It’s discussing what is now an edge case that may have been easier 20 years ago.
- Svip 6y agoWhile all that is accurate, it should be noted that they have already mitigated some of the problems mentioned above (no more displaying number of keys left), but also that the entire system is being replaced this year with one that does not rely on a physical cardboard key card, but can use something like a Yubikey instead. You can also change your username to something other than your CPR-number. Indeed, the problem lies more with other services that has used it as a password rather than 'username'. But those are rarer to come by these days.
- fogihujy 6y agoDitto in Finland. Just like in Denmark, the social security number is being used for authentication by some actors, even though it's inherently insecure to do so. The Swedish way of handling those numbers seems more reasonable; they're just used as unique identifiers and you still need to show some other kind of ID. When I lived in Denmark, airlines occasionally did identity spot checks on domestic flights. I was always horrified to notice that everyone just pulled up (picture-less) social security cards and used them as identification.