William Vambenepe's blog

IT management in a changing IT world

Research into bacteriophages for medicinal use is just beginning, but has led to buying fake viagra in microscopic imaging.Humans are notable for their desire to understand and cheap viagra in uk the world around them, seeking to explain and manipulate natural phenomena through philosophy, art, science, mythology and religion.Learning to cope with problems better, such as buy viagra online in uk problem solving and time management skills, may also reduce stressful reaction to problems.These all lead to a decreased state of buy viagra online no prescription.In 1920 Rettger demonstrated that MetchnikoffTs LBulgarian buy cheap viagra in uk, later called Lactobacillus bulgaricus, could not live in the human intestine, and the fermented food phenomena petered out.

20
Apr
2007

Agriculture Department and Census Bureau to the rescue

by William Vambenepe

An article in today’s New York Times reports that “the Social Security numbers of tens of thousands of people who received loans or other financial assistance from two Agriculture Department programs were disclosed for years in a publicly available database”.

Almost there folks! But tens of thousands is not enough, we need to cover everyone. The simplest effective way to dent the “identity-theft” (or more exactly “impersonation”) wave is to go beyond this first step and publish on a publicly accessible web site all social security numbers ever issued and the associated names. And get rid once and for all of the hypocritical assumption that SSN have any authentication value. We need a reliable authentication infrastructure (either publicly-run as a government service or privately-run, that’s a topic for another day) and this SSN-based comedy is preventing its emergence by giving credit issuers (and others) a cheap and easy way to pretend that they have authenticated their customers.

Over the last couple of years, I have received two alerts that my SSN and other data have been “compromised” (one when Fidelity lost a laptop containing data about everyone enrolled in HP’s retirement plan and one from a university) and my wife has received three. Doesn’t this sound like a bad joke going on for too long (and I should know about bad jokes going on for too long, they are my specialty)? And of course this doesn’t count the thousands of employees at dentist, medical offices, and many other businesses that have at some point had access to my data (and anybody else’s).

So, to the IT people at the Census Bureau I say “keep going”! But of course that’s not the reaction they had. The rest of the NY Times articles goes on with the usual hypocritical (or uninformed) lamentations about putting people’s identities at risk. “We took swift action when this was brought to our attention, and took the information down.” says an Agriculture Department spokeswoman. And of course there is the usual “credit report monitoring” offer (allowing the credit report agencies to benefit from both sides of the SSN-for-authentication debacle). Oblivious to the reality even though it manifests itself further down in the article: “The database [...] is used by many federal and state agencies, by researchers, by journalists and by other private citizens to track government spending. Thousands of copies of the database exist.”

Another quote from the article: “Federal agencies are under strict obligations to limit the use of Social Security numbers as an identifier”. The SSN is a fine identifier. It’s using it as a mean of authentication that’s the problem.

[UPDATE] This is now a Slashdot thread. The comments are pouring in. Some get it (like here, and here). This one seems to get it too but then goes on to advocate dismantling the social security system which at this point is only connected by name to the issue at hand.

[UPDATED 2008/7/2: Sigh, sigh and more sigh while reading this article. The cat is so far out of the bag that a colony of mice has taken residency in it. The goal shouldn't be to try to make the SSN hard to get, it should be to make it useless to criminals. That approach isn't even mentioned in the article.]

AddThis Social Bookmark Button

2 Responses to “Agriculture Department and Census Bureau to the rescue”

  1. William Vambenepe’s blog » Blog Archive » We won’t get rid of SSN-based authentication anytime soon… Says:

    [...] I agree that the Real ID effort is a bad cost/benefit trade off in terms of protection against terrorism. But leaving terrorism aside, we do need a robust (not necessarily perfect) way to authenticate people to access bank accounts and other similar transactions. In that respect, something like Real ID is needed. And in that context, the cost/benefit trade-off can be hugely positive if you think of how much impersonation costs and how much friction it creates in the country’s economy. As long as we live in denial about what a Social Security number represents and as long as we can’t think sanely about terrorism, there can’t be an answer to the authentication problem. [...]

  2. William Vambenepe’s blog » Blog Archive » It is now safe to steal my identity Says:

    [...] solution is to publish every single SSN on a web site and stop pretending they can be used for [...]

Leave a Reply