Hacker News new | ask | show | jobs
by gertrunde 32 days ago
The lack of security is one thing, but why have they retained the information at all!

iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger).

Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.

It would be reasonable and fair to retain a photo of the user to verify that the person matches the account, but that's it.

2 comments

10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked.

WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!?

Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager.

Until stupid s**t like this becomes illegal, it will just keep continuing.

I'm not american, but the idea that your SSN, which is effectively a (federal) unique identifier for a person, would be secret, is very foreign.

In most countries, like most databases, our primary keys do not hold an expectation of secrecy.

I would even argue that the expectation of secrecy is what creates it's secret semantics, that is, it's secret because you make it secret. I get that it's a collective action thing, if you just publish your own SSN, a bank in another state might not be aware it's a public thing for YOU, and might open an account for a stranger.

Interestingly enough, for corporations, their identifiers, EIN, are not assumed to be private, in many states these are available through the DoS public records. So it turns out the system works just fine if you make the ID of a person (juristic or legal) public.

So what prevents people applying for loans or doing identity theft, in other countries?
To sign on for a house, marry, claim a child as yours etc you need witnesses where I live. Web of trust I guess?

If someone takes a loan in my name and I don't receive the money it is not an identity theft it is fraud and the victim is the bank not me.

Sure, but what if someone steals your money by impersonating you? Here too, ideally the victim is the bank, but now the onus is on you to convince the bank that they are the victim. They are going to say you're the victim, your identity got stolen, sorry you lost all your savings!

We need to update our laws. This is not "Identity Theft", this is "Negligent Verification Fraud", and it is the bank's fault because they were lax in their verification process.

I meant online. Lower-value types of fraud, like e-commerce, prepaid mobile phone bills.
do you think scammers don't travel in packs?
Key difference might be that most countries have centralized Federal ID document. The Americans never allowed the government such a power, which is a tremendous idea. But they did concede to an ID number through a federal tax entity which de facto served as an id number. Turns out one disadvantage there is that a document is easier to prove ownership of than a number.
Sure but all countries have numbers (tax, SS, ID card) that serve de-facto as IDs. The question is why the number alone (i.e. a username without a password) would ever be considered sufficient to authenticate something.
That seems irrelevant. The most commonly used ID document for many things in the US is a driver's license; it's issued by the states, not federal govt, so what.

Similarly you could argue that addresses and zip codes are assigned by the USPS not directly by the federal govt, so what.

Combine this with date-of-birth and phone no. and you have a very small set of sufficiently near-unique identifiers (even if that wasn't the intent of the SSN).

One big mistake was not to legislate (at any point between the 1930s and 1980s) to criminalize third parties from using the SSN as unique identifier, as is done by other countries.

Imagine if the East German Stasi had merely outsourced surveillance to data brokers and credit bureaux - different regime, same effect.

>The most commonly used ID document for many things in the US is a driver's license; it's issued by the states, not federal govt, so what.

That doesn't uniquely identify a person though does it? You could get a license from Florida, open an account, then get a license from New York and open another account, and if you defaulted on the credit of one, the other bank would be the wiser and issue you a new loan.

>Similarly you could argue that addresses and zip codes are assigned by the USPS not directly by the federal govt, so what.

Similarly, you could trivially open two accounts under different addresses.

>One big mistake was not to legislate (at any point between the 1930s and 1980s) to criminalize third parties from using the SSN as unique identifier, as is done by other countries.

Certainly it has its disadvantages, but it has its advantages, not really by virtue of not having a central document, but by the other benefits that a legal system that doesn't bestow so much power on the federal government has.

While I agree that the relation of between the lack of central document and the secrecy of SSN numbers isn't proven or self-proving, it's certainly worth considering up to the point that it's a reasonable default and the burden on proof is on disproving it. I can't think of any other country where there's no central document or where a citizen ID is considered secret, so that's pretty good evidence in itself.

My original SSN card has "not valid for identification" printed on it. Originally, it was supposed to only be used for filing taxes. The first 3 digits identified the state you applied in, the second 2 digits identified the office (in that state) and 2 of the last 4 digits identified the filing cabinet.

Over the years, it ended up becoming the de facto federal identity number. It has no check digits, so you can make up any you want (I used to use a phone number of a major customer - only dropping 1 digit). I was a rebel/jerk/butthead back then. Now I just yell at clouds.

Long ago, I worked at a place that handled electronic prescriptions, lab results and insurance claims. There were huge numbers of incorrect SSNs which meant there were huge numbers of duplicates. Someone transposed 2 digits? Yep. Someone remembered their number incorrectly? Sure. Someone made one up? Like from a phone number? Oh noes! Before 911, trying to match someone with faulty ID numbers and messed up names was called "patient matching" and after 911 all the academics doing research into this stuff disappeared into large defense contractors or 3-letter-agencies trying to find more terrorists/bad guys.

For a good start in this area of research, I recommend this dissertation:

> Adaptive detection of approximately duplicate database records and the database integration approach to information discovery

> AE Monge - 1997

https://scholar.google.com/citations?view_op=view_citation&h...

> The most misused SSN of all time was [see link]. In 1938, wallet manufacturer the E. H. Ferree company in Lockport, New York decided to promote its product by showing how a Social Security card would fit into its wallets. A sample card, used for display purposes, was inserted in each wallet. Company Vice President and Treasurer Douglas Patterson thought it would be a clever idea to use the actual SSN of his secretary, Mrs. Hilda Schrader Whitcher.

> The wallet was sold by Woolworth stores and other department stores all over the country. Even though the card was only half the size of a real card, was printed all in red, and had the word "specimen" written across the face, many purchasers of the wallet adopted the SSN as their own. In the peak year of 1943, 5,755 people were using Hilda's number.

https://www.ssa.gov/history/ssn/misused.html

Most state agencies redact the SSN from public records. I want to say that they all do, but I work for a state and I see too many in all the wrong places.

Don't be so hard on 17-ish-year-old you. What exactly were you supposed to do? Not take the ACT (and probably not get into your desired college)?
Ask if it’s required, instead of assuming it is, is the point.

Modern equivalent “move over here for your picture ‘for the doctor’.”

No thanks, I’d like to opt-out!

This is a real problem.

I was appalled when renewing my car this year that I now need a Texas by Texas account (https://www.texas.gov/texas-by-texas/), which wants... a social security number because why?!?!

Anyway, yet another data breach incoming.

> which wants... a social security number because why?

Because of federal child support legislation. If you are $2500 (or more) in arrears, your passport gets cancelled. Most states will also suspend/revoke your professional licenses and possibly driving license when you cross that state's threshold.

https://travel.state.gov/en/passports/contact-support/legal-...

https://en.wikipedia.org/wiki/Child_support_in_the_United_St...

> In 1996, Congress passed and President Bill Clinton signed the Personal Responsibility and Work Opportunity Act (42 U.S.C. § 666), which required that states adopt UIFSA by January 1, 1998 or face loss of federal funding for child support enforcement. Every U.S. state has adopted either the 1996 or a later version of UIFSA.

https://en.wikipedia.org/wiki/Uniform_Interstate_Family_Supp...

When I worked for my state's motor vehicle bureau, one of the verification apis that the driving license/ID folks got to use was a verification of citizenship/lawful residence service. Which used SSNs.

I'd hope that there's an in-person option for renewal. Maybe people without a data plan don't exist anymore?
My first university, back in the 1970s, used my SSN as my student ID and was embossed into the ID card (who is that stranger in the photo?). Nowadays, no university uses SSN for student IDs. There's a saying that applies: the past is a foreign country.
The real answer?

In case you want to retrieve your test scores 10 years after you took it. They need some way to uniquely identify you. Sure, they could have given you a specific test taker ID, but what if you lost that? They could have created a way for you to log in with an e-mail address, but what if you changed e-mail addresses?

You might think "Why would I need my test scores from 10+ years ago?", but my wife just started a job and they demanded her college transcripts to prove she went there...over 20 years ago.

I think the issue here is that it was the university, not ACT. ACT has a valid reason for holding it. A university he never went to does not.
Identify the student by full name, dob, date of admission, career, etc. It takes 5 minutes instead of one.

The problem here is using a username (the ID) as a password (security check)

And make them call the registrar during regular hours. That’s what I had to do to get a transcript from 15 years ago once. The registrar holds the records and should be able to provide them.
I think every SSN is already leaked and government is doing nothing. I tried to change SSN and they told me it is not possible.
100s of millions have definitely been exposed already. The best defence is probably to be a baby so your risk window is minimal. I haven't been able to pull that off personally, so I follow the other recommended piece of advice which is to keep your credit checks permanently frozen with the agencies and only temporarily thaw it for specific usages.

https://www.upguard.com/breaches/social-insecurity-billions-...

Which is a shame, as there are only hundreds of millions possible… and they still have to include room in that 9-digit namespace for non-social-security-involved ITINs and employer ID numbers!
They’ll definitely issue loans to a child. You have to actually put a special freeze on your child’s credit account, which is insane but welcome to the US, where any obstruction to the wheels of commerce is an affront to our national dignity.
I've had stuff like this happen too, and always wondered if they really leaked my data or were just notifying everyone whose data they possibly leaked.
I think the argument is "if they didn't retain your data, it couldn't have possibly leaked"
Yeah I meant it's possible they didn't retain your passport, they just know you took the test at some point.

  > Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.
Might KYC laws and general CYA policies prefer to keep the proof of age? For instance to protect e.g. against a minor altering the date on their passport. Especially in such a regulated industry.
The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept".

^1: https://www.edpb.europa.eu/system/files/documents/2025-04/ed..., number 36.

Thank you.