 The government-issued numbers may not be that secure. Two researchers say they've figured out the code, and identity thieves might not be far behind.
 The government-issued numbers may not be that secure. Two researchers say they've figured out the code, and identity thieves might not be far behind.By The Associated Press
For all the concern about identity theft, researchers say there's a surprisingly easy way for the technology-savvy to figure out the precious nine digits of Americans' Social Security numbers.
"It's good that we found it before the bad guys," Alessandro Acquisti of Carnegie-Mellon University in Pittsburgh said of the method for predicting the numbers.
Acquisti and Ralph Gross report in Tuesday's edition of Proceedings of the National Academy of Sciences that they were able to make the predictions using data available in public records as well as information such as birth dates cheerfully provided on social networks such as Facebook.
For people born after 1988, when the government began issuing numbers at birth, the researchers were able to identify, in a single attempt, the first five Social Security digits for 44% of individuals. And they got all nine digits for 8.5% of those people in fewer than 1,000 attempts.
For smaller states, their accuracy was considerably higher than in larger ones.
Acquisti said in a telephone interview that he has sent the findings to the Social Security Administration and other government agencies with a suggestion they adopt a more random system for assigning numbers.
"It's good that we found it before the bad guys," Alessandro Acquisti of Carnegie-Mellon University in Pittsburgh said of the method for predicting the numbers.
Acquisti and Ralph Gross report in Tuesday's edition of Proceedings of the National Academy of Sciences that they were able to make the predictions using data available in public records as well as information such as birth dates cheerfully provided on social networks such as Facebook.
For people born after 1988, when the government began issuing numbers at birth, the researchers were able to identify, in a single attempt, the first five Social Security digits for 44% of individuals. And they got all nine digits for 8.5% of those people in fewer than 1,000 attempts.
For smaller states, their accuracy was considerably higher than in larger ones.
Acquisti said in a telephone interview that he has sent the findings to the Social Security Administration and other government agencies with a suggestion they adopt a more random system for assigning numbers.
Social Security spokesman Mark Lassiter said the public should not be alarmed by the report "because there is no foolproof method for predicting a person's Social Security number."
"The suggestion that Mr. Acquisti has cracked a code for predicting an SSN is a dramatic exaggeration," Lassiter said via e-mail.
However, he added: "For reasons unrelated to this report, the agency has been developing a system to randomly assign SSNs. This system will be in place next year."
The researchers say their report omits some details to make sure they aren't providing criminals a blueprint for obtaining the numbers.
The predictability of the numbers increases the risk of identity theft, which cost Americans almost $50 billion in 2007 alone, Acquisti said.
"The suggestion that Mr. Acquisti has cracked a code for predicting an SSN is a dramatic exaggeration," Lassiter said via e-mail.
However, he added: "For reasons unrelated to this report, the agency has been developing a system to randomly assign SSNs. This system will be in place next year."
The researchers say their report omits some details to make sure they aren't providing criminals a blueprint for obtaining the numbers.
The predictability of the numbers increases the risk of identity theft, which cost Americans almost $50 billion in 2007 alone, Acquisti said.
A problem in the battle against identity thieves is that many businesses use Social Security numbers as passwords or for other forms of authentication, something that was not anticipated when Social Security was devised in the 1930s. The Social Security Administration has long cautioned educational, financial and health care institutions against using the numbers as personal identifiers.
"In a world of wired consumers, it is possible to combine information from multiple sources to infer data that is more personal and sensitive than any single piece of original information alone," Acquisti said, warning against providing too much data on social-networking sites.
Acquisti, who researches the economics of privacy, said he got interested in what could be learned from easily available sources by looking at social networks, which he termed "a great experiment in self-revelation."
People were willing to include their birth dates and hometowns, he said, and he already knew that was part of the information used in issuing Social Security numbers.
So the researchers turned to the Social Security Administration's "Death Master File," which lists the numbers of people who have died. The purpose of making that file public is to prevent impostors from assuming the Social Security numbers of deceased people.
But by plotting the data for people listed on the file between 1973 and 2003, the researchers were able to develop patterns for number issuance.
"In a world of wired consumers, it is possible to combine information from multiple sources to infer data that is more personal and sensitive than any single piece of original information alone," Acquisti said, warning against providing too much data on social-networking sites.
Acquisti, who researches the economics of privacy, said he got interested in what could be learned from easily available sources by looking at social networks, which he termed "a great experiment in self-revelation."
People were willing to include their birth dates and hometowns, he said, and he already knew that was part of the information used in issuing Social Security numbers.
So the researchers turned to the Social Security Administration's "Death Master File," which lists the numbers of people who have died. The purpose of making that file public is to prevent impostors from assuming the Social Security numbers of deceased people.
But by plotting the data for people listed on the file between 1973 and 2003, the researchers were able to develop patterns for number issuance.
 
 
No comments:
Post a Comment