Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>appear on my credit report

The root of the problem is sharing the private information. Why your credit reports are shared among completely different entities? Nobody want to gives them a consent to share your private information.

> system of universal secure IDs

Actually, it's the opposite. US has universal ID(not secure though). That's the problem. If there exist one idiot who doesn't verify your identity, everything fails in chain reaction, because everybody else believe the idiot.



> US has universal ID(not secure though)

Do we? Our SSN is not a unique number, and not just because the keyspace is too small for our population. (It's worse: some of the prefixes are geographically related.)


SSNs have not been issued with a geographic prefix in a decade. I'm not sure if you're really suggesting two different individuals are issued the same SSN, but no, they never are. SSNs are never reused.

https://www.ssa.gov/employer/randomization.html https://www.ssa.gov/employer/randomizationfaqs.html


> SSNs have not been issued with a geographic prefix in a decade.

Even if what you say were true, handwaving this as unimportant because it only affects people over the age of ten seems a bit silly.


SSNs are entirely insecure as mentioned earlier in this thread. Geographic prefixes are a drop in the bucket on that front.

The post that I replied to is almost entirely incorrect as it relates to available SSN “keyspace” (misnomer), uniqueness, etc.—-for which geographic prefixes and group numbers are relevant.

I supplied direct sources, so no idea what your “even if what you say were true” skepticism is rooted in.


With "ID" I mean "a photographic ID document used for verifying one's identity" - SSN (or, really, any "something you know" factor) is not an insecure ID, it doesn't even attempt to be one.


>Nobody want to gives them a consent to share your private information.

Freeze your credit. Burden shouldn’t fall on the consumer, but it’s easy and easy to lift when needed.


The problem is knowing when to take action. It could be months after the actual event before you find out about it. And you’re liable for everything in between.

Identity Theft is actually just fraud. And the companies that allowed the fraud should be required to shoulder the burden of addressing that matter with the actual people who committed the fraud. No part of that burden should ever be placed on you, just because someone pretended to be you and commit a fraud.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: