As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem.
As an aside: When it comes to an authentication source to take the place of silly shared public "secrets" I think it would be great if the United States Postal Service "pivoted" into issuing digital certificates to individuals. They already have infrastructure and procedures in place for identity verification and physical delivery. I suppose that's too much like a federally-issued ID to ever fly, though our "REAL ID" drivers licenses are, in effect, a federal ID anyway. I'd rather have a digital certificate out of the deal too.