Nine Easy Numbers Away From ID Theft
The Social Security code is a cinch for hackers to crack.
Carnegie Mellon professor Alessandro Acquisti and graduate student Ralph Gross discovered that Social Security numbers are easily predicted using public data. Below, Acquisti tells how.
Please describe your findings.
We found that Social Security numbers, which are supposed to be confidential, are predictable from publicly available data. We can start with someone's birthday, add the state where they were born and, based on these two pieces of information, infer their Social Security number.
Sign up for Kiplinger’s Free E-Newsletters
Profit and prosper with the best of expert advice on investing, taxes, retirement, personal finance and more - straight to your e-mail.
Profit and prosper with the best of expert advice - straight to your e-mail.
How?
The assignment scheme for Social Security numbers has been publicly available for many years. Take that scheme, combine data from other sources, apply statistics and data-mining tools, and you can end up with information that is significantly more sensitive than what you started with.
Who is most at risk?
It's easiest to predict the Social Security numbers of people from less-populous states and those born after 1988, when a number of policy initiatives made it more likely that parents would apply for a newborn's Social Security number right away. On average, we can identify the entire nine-digit number in fewer than 1,000 attempts for 9% of people born after 1988. That makes those numbers no more secure than a three-digit PIN.
How do you go from there to identity theft?
To make the algorithm work, you need only information that's public or semi-public for most of us. An attacker has to find a way to exploit the information, and unfortunately, there are many ways. For example, attackers can use botnets -- networks of compromised computers controlled by someone, somewhere. Botnets can be used to run automated queries on an online system, such as an online credit-card application, to verify a Social Security number.
How can we prevent such exploitation?
We need to stop using Social Security numbers as both identifiers and authenticators. The numbers were created to identify earnings in the Social Security program. Your phone number is another example of an identifier. But the password for your voicemail is an authenticator, a secret fact that proves you are who you claim to be. No sane person would use the same digits as identifier and authenticator, but that's exactly the way we use Social Security numbers.
Anne Kates Smith brings Wall Street to Main Street, with decades of experience covering investments and personal finance for real people trying to navigate fast-changing markets, preserve financial security or plan for the future. She oversees the magazine's investing coverage, authors Kiplinger’s biannual stock-market outlooks and writes the "Your Mind and Your Money" column, a take on behavioral finance and how investors can get out of their own way. Smith began her journalism career as a writer and columnist for USA Today. Prior to joining Kiplinger, she was a senior editor at U.S. News & World Report and a contributing columnist for TheStreet. Smith is a graduate of St. John's College in Annapolis, Md., the third-oldest college in America.
-
Strategies to Optimize Your Social Security Benefits
To maximize what you can collect, it’s crucial to know when you can file, how delaying filing affects your checks and the income limit if you’re still working.
By Jason “JB” Beckett Published
-
Don’t Forget to Update Beneficiaries After a Gray Divorce
Some states automatically revoke a former spouse as a beneficiary on some accounts. Waivers can be used, too. Best not to leave it up to your state, though.
By Andrew Hatherley, CDFA®, CRPC® Published
-
403(b) Contribution Limits for 2024
retirement plans Teachers and nonprofit workers can contribute more to a 403(b) retirement plan in 2024 than they could in 2023.
By Jackie Stewart Published
-
Roth IRA Contribution Limits for 2024
Roth IRAs Roth IRA contribution limits have gone up for 2024. Here's what you need to know.
By Jackie Stewart Published
-
Four Tips for Renting Out Your Home on Airbnb
real estate Here's what you should know before listing your home on Airbnb.
By Miriam Cross Published
-
Five Ways to a Cheap Last-Minute Vacation
Travel Procrastinator? No matter. You can pull off a fun and memorable getaway on a moment's notice — without breaking the bank.
By Vaishali Varu Last updated
-
Social Media Scams Cost Consumers $2.7B, Study Shows
Scams related to online shopping, investment schemes and romance top the FTC's social media list this year.
By Joey Solitro Published
-
How Much Life Insurance Do You Need?
insurance Instead of relying on rules of thumb, you’re better off taking a systematic approach to figuring your life-insurance needs.
By Kimberly Lankford Published
-
When Is Amazon Prime Day?
Amazon Prime In 2023 Amazon had two Prime Day events — one in July and another, called Big Deal Days, in October. We expect 2024 to follow the same schedule.
By Bob Niedt Last updated
-
How to Shop for Life Insurance in 3 Easy Steps
insurance Shopping for life insurance? You may be able to estimate how much you need online, but that's just the start of your search.
By Kaitlin Pitsker Published