The Republic of Estonia uses such a system to identify members of its e-Residency program, even with no physical presence. Each e-resident has a public numerical key that serves as a unique identifier, and a corresponding private key that is never revealed.
So an example to emulate then!
Except: Estonia suffered an embarrassing blow to its much-vaunted ID cards that underpin everything from electronic voting to online banking [...] a security risk that affects almost 750,000 ID cards and that would enable a hacker to steal a person’s identity.
I'm very worried about this. I've done a lot to try and build my credit and protect my identity by restricting the information I give out. Now I can do nothing to protect it now besides hope someone doesn't target me. Anyone have ideas on how to ensure an identity is not stolen?
You can use a credit freeze: https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq... > Also known as a security freeze, this tool lets you restrict access to your credit report, which in turn makes it more difficult for identity thieves to open new accounts in your name. That’s because most creditors need to see your credit report before they approve a new account. If they can’t see your file, they may not ex…
You also have to pay Equifax $10 to do this. Insane, right?
It is, and is related to some of the discussion in the main Equifax hack threads. The idea is that this information shouldn't be so sensitive because it isn't really secret in the first place. It also cannot be changed, so it doesn't really meet any reasonable criteria for authenticating information. To quote the relevant top-level comment I had in mind: >mikeash 2 hours ago [-] >If we're lucky, this will be the best…
Also note that other countries don't have this insanity.
You can use a credit freeze: https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq... > Also known as a security freeze, this tool lets you restrict access to your credit report, which in turn makes it more difficult for identity thieves to open new accounts in your name. That’s because most creditors need to see your credit report before they approve a new account. If they can’t see your file, they may not ex…
You also have to pay Equifax $10 to do this. Insane, right?
That sounds like extortion to me. Equifax are running a protection racket.
Also note that other countries don't have this insanity.
Which countries do you mean? How do they manage their credit scores?
Using much more nebulous and unreliable forms of PII as identifiers, in my experience, which leads to situations where you could query someone's report if you know their name and street address.
The Republic of Estonia uses such a system to identify members of its e-Residency program, even with no physical presence. Each e-resident has a public numerical key that serves as a unique identifier, and a corresponding private key that is never revealed. So an example to emulate then! Except: Estonia suffered an embarrassing blow to its much-vaunted ID cards that underpin everything from electronic voting to onlin…
Is there a link to this that's not behind a paywall. Very interested in understanding the flaws of such a system, as a 2 key system seems like the most viable and secure way to establish identity.
The Republic of Estonia uses such a system to identify members of its e-Residency program, even with no physical presence. Each e-resident has a public numerical key that serves as a unique identifier, and a corresponding private key that is never revealed. So an example to emulate then! Except: Estonia suffered an embarrassing blow to its much-vaunted ID cards that underpin everything from electronic voting to onlin…
Is there a link to this that's not behind a paywall. Very interested in understanding the flaws of such a system, as a 2 key system seems like the most viable and secure way to establish identity.
It is, and is related to some of the discussion in the main Equifax hack threads. The idea is that this information shouldn't be so sensitive because it isn't really secret in the first place. It also cannot be changed, so it doesn't really meet any reasonable criteria for authenticating information. To quote the relevant top-level comment I had in mind: >mikeash 2 hours ago [-] >If we're lucky, this will be the best…
I recently encountered an advertisement advising people to keep their Medicare card number secret. So if the SSN stops being considered as a combination identifier/authenticator, other government agencies stand eager and ready to plunge headlong into the same mistake. The way around it is to pass a law that requires government agents and agencies to consider identifiers to be public, and authenticators to be secret,…
Is the problem really government agencies or the many companies which tried to cut costs by misusing an identifier as an authentication secret? The law you propose seems like it would have no effect whatsoever unless it applied to the private companies which created and perpetuate this problem.
The hack isn't just SSNs - it includes address history, date of birth, drivers license number - everything reasonably necessary to establish identity. Not sure why the focus is SSNs, any solution needs to be even higher. This is about companies stockpiling our personal information and us having little say in the matter.
The reason the focus is on the SSN is because it enables credit. Privacy is important, but so is protecting your finances.
When applying for credit, especially online, have you not been asked to verify some current loans from a list, or to pick out a past address from a list of addresses? I know I have. That data also enables credit.