Shocking Poor Security at the Social Security Administration
plus.google.com
Shocking Poor Security at the Social Security Administration
1–10 of 18 posts
Re: Shocking Poor Security at the Social Security Administration
#2Re: Shocking Poor Security at the Social Security Administration
#3Sunset these ###-##-#### format numbers and deprecate their use. (especially forbidding private sector credit report usage, and the like)
Migrate everyone to a stronger ID system, that's secured according to modern standards, and retire each old number as it's converted. Put measures in place so that the new numbers cannot and must not be used for purposes other than government benefit transactions.
I am so sick of being asked by fantastically stupid HR and Data Security goons to do pathetically inadequate tasks, such as:
Please download this SSN_HumanResources.exe
file and double click to run it on your
local machine. This program requires you
to install the .NET runtime, version 3.0 or
higher. Your "C:\" drive will be subjected
to a full text scan of all files, to ensure
that you are not retaining SSN information
provided by fellow employees. When finished,
please download, print out, sign and fax a
copy of the affirmation form to Bob in HR at
(555) 555-5555.
Thank you,
Data Security
This sort of thing actually happens.Re: Shocking Poor Security at the Social Security Administration
#4Based on the password requirements, they have something like 2.6 trillion possible passwords. If your account is locked out after 3 failed login attempts, if they limit to one attempt per second, or if they have a forced password change every month, etc. there are a number of ways to tighten this up.
Their password policy is anachronistic, and this /could/ be a symptom of other issues. However by itself, it seems more like a usability issue than a security issue.
In fact, they could be attempting to discourage password reuse with other sites. That would be a security bonus if it worked (I doubt it works).
Re: Shocking Poor Security at the Social Security Administration
#5What login rate-limiting, account lock-out, and password expiry policies do they have though? Based on the password requirements, they have something like 2.6 trillion possible passwords. If your account is locked out after 3 failed login attempts, if they limit to one attempt per second, or if they have a forced password change every month, etc. there are a number of ways to tighten this up. Their password policy is…
Re: Shocking Poor Security at the Social Security Administration
#6If you're mad about 8 char mandatory case insensitive password rules maybe leaking data, you'll probably be super mad when they just lose the whole db on their end to hacks. Perhaps they should code a 2fa option through one of the many useful api's, as so many other companies have.
Re: Shocking Poor Security at the Social Security Administration
#7This is why the government desperately needs to keep 18F/US Digital Service so they can keep modernizing these sites.
Re: Shocking Poor Security at the Social Security Administration
#8This is why the government desperately needs to keep 18F/US Digital Service so they can keep modernizing these sites.
You misunderstand. The current party in power wants this dysfunction so they can justify further cuts. See the with-holding funds from Obamacare and forcing the post office to save for healthcare decades before those who would use it could require it.
Re: Shocking Poor Security at the Social Security Administration
#9That obviously means that the whole password is rarely sent over the network. It also means that they can use the same validation system over the phone for telephone banking.
The system is however far from ideal of course.
Re: Shocking Poor Security at the Social Security Administration
#10Cite: http://oig.ssa.gov/sites/default/files/audit/full/pdf/A-14-1...