As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…
Also why are these phone companies persisting SSNs in database ? Why can't they run the credit check initially and discard the SSN. There should be laws around this and enforced. It is time to hold these companies accountable. We are so tired of being worried that our ID may get stolen.