Its Time to Randomize Social Security Numbers

By Wayne Rash  |  Posted 2011-10-15 Print this article Print


However, data breaches aren't the only way criminals get SSNs. A network of cyber-criminals has figured out how the Social Security Administration generates its numbers and is using that to come up with valid Social Security numbers around the time that a child is born. Because the first three digits of a Social Security number reference the region where the number is issued, it's only the last six numbers that are really tied to identity, and those are issued in a predictable sequence.

This means that a child's SSN can be stolen without any sort of data breach and that a fresh SSN can be tied to someone else's name and address. That person can then use the new SSN to get credit or a new identity. The Social Security Administration is working on a plan to randomize Social Security numbers, and in the meantime is offering some guidelines to dealing with identity theft, including getting a new number.

There's not a lot you can do about criminals who have cracked the SSN code, but you can prevent data breaches to some extent by not providing your SSN (or your child's) when it's not required. This means that even if your T-ball league asks for your child's number, you don't need to provide it. If someone or some organization needs the number, or claims to, ask why they need it, how they will secure it, how they will destroy the information when it's no longer needed and what they will do to prevent a data breach.

But what happens if someone does steal your child's identity-or yours? In the case of your child, this discovery can happen at tax time when the IRS doesn't issue the refund you expect or notifies you that your child has already filed his or her own return. Or sometimes you might hear from creditors.

But the best way to find out is by getting an annual credit report for everyone in your family, every year. It's free. It's worth noting that your minor children shouldn't have a report to request because they won't have a credit file. If they do, it's a red flag.

In the enterprise, the new effort by organized crime to steal the numbers belonging to children can have serious consequences. Your company depends on Social Security numbers in hiring, in extending credit and other financial transactions, and in reporting wage information to the IRS. A surge in stolen numbers can have its own security implications for your company no matter how they're used. 

Wayne Rash Wayne Rash is a Senior Analyst for eWEEK Labs and runs the magazineÔÇÖs Washington Bureau. Prior to joining eWEEK as a Senior Writer on wireless technology, he was a Senior Contributing Editor and previously a Senior Analyst in the InfoWorld Test Center. He was also a reviewer for Federal Computer Week and Information Security Magazine. Previously, he ran the reviews and events departments at CMP's InternetWeek.

He is a retired naval officer, a former principal at American Management Systems and a long-time columnist for Byte Magazine. He is a regular contributor to Plane & Pilot Magazine and The Washington Post.

Submit a Comment

Loading Comments...
Manage your Newsletters: Login   Register My Newsletters

Rocket Fuel