2 ms·
Or, just a thought, design an identifier where compromising one system doesn't immediately compromise all the individual data contained within it. SSN breaches
by UseStrict 5y ago
Or, just a thought, design an identifier where compromising one system doesn't immediately compromise all the individual data contained within it. SSN breaches only really hurt because its exposure means instant compromise of identity, whereas a system with some sort of partial key, signature, etc, where the user retains a portion means they have to compromise the database and the user, and if a "central" system (i.e. government, private key issuer, etc) is compromised you can re-issue the user identifier portions.
If anything it might encourage companies to smarten up if there was a law on the books that required companies that get compromised to pay for the re-issuing of the user tokens to every impacted individual.