US Reviewing Better Tech Identifiers After Hacks

Discussion in 'other security issues & news' started by ronjor, Oct 3, 2017.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,838
    Location:
    Texas
    By AFP on October 03, 2017
     
  2. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,838
    Location:
    Texas
    Replacing Social Security Numbers Is Harder Than You Think

     
  3. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    OMG. This is a straightforward simple thing to fix. I swear they have to be putting something in the water.
    The problem is not the social security number, the problem is random business entities storing them in their databases!
    They don't need to replace SS numbers, they need to make it illegal for businesses to database them.
    Businesses should be forced to use a standardised cryptographic hash function to store them like the new sha-3. Then when business needs to look you up, you give them your SS number they enter it in the system which creates the same sha-3 hash, the hash is then used to look you up on the database.
    What is so difficult about that. A mediocre programmer could write an app, in just a few minutes to convert each SS record in a database to the sha-3 hash and the app on the customer service side to create the hash from your SS number is Freeware!!
     
    Last edited: Oct 6, 2017
  4. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Indeed, because they have now proven they are sorely inadequate of protecting any of it.

    In fact I agree they should make it illegal for businesses to store what they are incapable of securing but this is now a genie well out of the bottle.
     
  5. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    Even more secure, hash the name and social security number together, then no database record would be identifiable on the database until that individual needs a credit check.
    Credit check person enters your name and SS number into their application on their terminal, it creates the hash and the hash is the key used to pull up your record on their database.
     
    Last edited: Oct 6, 2017
  6. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    Its not, they are just retarded.
    Equifax should be ordered to notify everyone that was affected, and they should be generated a new SS number and Equifax should have to pay for it.
    Then do what I said in my other posts
    If I was president there would not be any of this, "well its harder than we thought" BS. I would be getting it fixed already.
     
  7. Reality

    Reality Registered Member

    Joined:
    Aug 25, 2013
    Posts:
    1,198
    Some lids are just not designed to be put back on. I don't think what they should do and what they want to do are one and the same.
     
  8. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,838
    Location:
    Texas
  9. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,838
    Location:
    Texas
    SSN for authentication is all wrong

     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.