They are like "pre-shared key" based authentication (actually much worse). It is well understood that pre-shared keys are fine for small scale use like your home wireless network and even then it is recommended that they be changed periodically. The case with SSNs is much worse: the same key is used as an authenticator over a person's whole lifetime and everywhere the person needs to authenticate himself: banks, rental leases, loans, employers... And it cannot be changed!


Add to Technorati Favorites
1 comment:
http://aspe.hhs.gov/datacncl/1977privacy/c16.htm
This is what the government thinks...it doesn't know the difference between identification and authentication. If the writer of this chapter finds this page:
identification = who are you?
authentication = prove that you are who you claim to be.
Post a Comment