[Cryptography] After Equifax pwning, what is the best means for replacing the SSN?

Benjamin Kreuter brk7bx at virginia.edu
Wed Sep 13 22:25:10 EDT 2017


On Wed, 2017-09-13 at 20:44 -0400, Tony Patti wrote:
> Hi Ben,
> 
> With respect to your statement "I doubt MOST [my emphasis] banks
> would have difficulty dealing with customers not having one." [SSN]
> This article from the NY Times dated March 2013 says that 20 of the
> top 25 banks REQUIRED SSN to open a bank account.

I suspect that has more to do with legal requirements (KYC laws etc.)
and the convenience of SSNs than with an actual need.  I suppose I
should clarify my statement: if banks were unable to use SSNs, I doubt
most would really have difficulty identifying their customers.  In
fact, I see this statement:

> The article starts with a prescient statement: "Despite the risk of
> fraud associated with the theft of Social Security numbers..."

as saying that banks have enough other ways to identify their customers
that SSN fraud is not a big problem.

-- Ben



More information about the cryptography mailing list