Ban SSNs and birthdays as passwords

I got a class action settlement postcard today — a payroll company got hacked, my SSN was “exposed,” and now I’m entitled to maybe $30, a year or two from now.

After the lawyers take their $866,000 cut from the $2.6 million fund.

The postcard may have cost more to send than my claim is worth. Counting my time filling it out, for sure.

This system is not free. Lots of expensive people’s time goes into it. And it doesn’t protect anybody from actual security risk – quite the contrary. Congress should ban this insanity.

SSNs and birthdays were never secret – there are lots of laws that require us to give them out on request. They’re on every W-2, every 1099, every insurance form, every medical form.

The entire financial system treats knowledge of a static, lifetime-assigned, widely known number and date as proof of identity, and every time it predictably fails, we get more lawsuits, settlements, and $30 checks.

The GAO estimates that identity fraud costs the federal government alone $233 to $521 billion per year. The COVID unemployment fraud ($100+ billion stolen, mostly through identity compromise) should have been the most recent wake-up call.

This is astroundingly stupid. It costs average Americans money every year. Yet nobody seems to care. There is no serious effort in Congress to fix it, or lobby groups pushing for that.

2 thoughts on “Ban SSNs and birthdays as passwords

Leave a Reply

Your email address will not be published. Required fields are marked *