This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…
> For the public system, assign to every participant a true unique identifier, rather than the SSN which explicitly states should not be used as such.
This will work for a time, but what happens when the next breach occurs? How do people renew their UUID's? Expire compromised ones?
> For those citizens that do not want to register in this way, allow for physical authentication at physical locations.
Physical authentication probably means fingerprints, face data, correct? These are already compromised. Worse yet, they cannot be changed.
CCTV cameras are everywhere, and getting better resolution each day. Face authentication can be easily duplicated - some of the early versions of FaceID (by Apple) were broken by 3-D printing a mask [2]. Furthermore, some organizations are already compiling a list of "face data" that can be used to fool sensors and other biometric tools. By the time "face readers" are widespread, hackers will already have large pools of face data to use to hack into these systems.
There are other cases where fingerprints have been printed using a 3-D printer and have broken security of mobile smartphones [1]. What's to say whatever government issued terminal won't be broken in a similar way? Furthermore, it's not easy to expect people to guard their fingerprints: every glass they drink at a restaurant will have their fingerprints. I don't expect to shed my SSN whenever I order a pint at my favorite pub.
[1]: https://www.theverge.com/2019/4/7/18299366/samsung-galaxy-s1...
[2]: https://www.wired.co.uk/article/hackers-trick-apple-iphone-x...