As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the pl…
Proposed alternative - you get your own private-key as an identifier. Nobody ever can ask for the private key, they can only ask for a signed message that proves identity. Thus a lot of categories of fraud are no longer possible because there is no shared reusable number in the event of a leak.
Who issues the private key? "get" implies it comes from somewhere, i.e. a CA system.
If the government is the CA system, and your private key is your identity, how do you establish your identity in the event that you lost your key?
The nice thing about SSNs being immutable is that none of these are concerns. (It's also the bad thing about SSNs being immutable.)