Earlier quoted context omitted.
> Another concept that I don't understand is that USA's social security number has to be kept secret or otherwise your identity can be stolen. How that is even possible? Doesn't your employer needs it? I think adopting this framing is what makes it really bad. Your identity cannot be stolen. The whole concept of "identity theft" is bullshit intented to shift blame. It only so happens that some entities are incompeten…
> some entities are incompetent at verifying people's identity Some entities are incompetent at verifying identity because some people are very loud about making sure a a modern ID verification system doesn't get built, because the ability to commit fraud is a civil right or something. We need .gov smartcards. Or at least a .gov OAuth provider. Instead we are in the dark ages of shared-secret numbers (SSN, credit car…
That's not really a good solution either, though, because that requires trust in an essentially unverifiable system and the entity producing it.
> banks should be shipping hardware tokens, for example.
No, they absolutely should not. That's like saying banks should send out staff to take care of signing stuff for their customers, and then insisting that the government should enforce whatever their staff signed against the customer. That's a completely broken security model.