All U.S. Social Security numbers may need to be changed following a massive breach that is already being investigated as a national threat

https://infosec.pub/post/42113550

All U.S. Social Security numbers may need to be changed following a massive breach that is already being investigated as a national threat - Infosec.Pub

cross-posted from: https://lemmy.ca/post/60478981 [https://lemmy.ca/post/60478981] > Borges alleges that a little-known federal tech team called the Department of Government Efficiency, or DOGE, copied the government’s master Social Security database into a cloud system that lacked normal oversight. > > If his account is correct, the mishandling of this information could expose hundreds of millions of people to fraud and abuse for the rest of their lives.

Spoiler: They won’t change them.
The entire concept of a single number that you share with every employer and can be used to impersonate you and steal your identity is already mind-bogglingly stupid.
The system was never designed to be used for anything beyond Social Security, and from the beginning using it as an identifier has been discouraged. That doesn’t stop companies from using it like that though.
Well, they probably wouldn’t if there was a viable alternative.
Using it as an identifier isn’t really a problem. Using at as credentials, being somehow able to impersonate someone just by reciting a not very secret identifier, that is mind-bogglingly stupid.