Sunday, February 27, 2005

First Choicepoint, now Bank of America?

Few people haven't heard of the
ChoicePoint
theft but now MSNBC is reporting yet another large incident that could affect us: Bank of America had it's back-up tapes stolen and says they are presumed lost and if they were stolen it would be virtually impossible to recover any data from them... Of course when asked if the data was encrypted they had no comment.

Isn't the point of making a back-up tape to be able to recover the data from it in case of an emergency? Hmmm.... That's a tough one so take your time.

To me personally, and I know MANY large companies have my data, I feel its impossible for them to keep that data secure. How can they say my information is safe unless noone is allowed to access it. This seems like the tip of the iceberg. Having a number which uniquely identifies you and is near impossible to change is going to cause a whirlwind of headaches for many people. It does not prove it's you. If you've had your wallet stolen or someone improperly disposed of a job application your number could be compromised... Once compromised your in for a lifetime of checking your bank statements, worrying about who owns your house and cars, whose going to make your benefit changes at work.

Hypothetically, when someone steals your SSN the first thing they do is get your Drivers license (Usually with their picture) Change your address to a PO BOX, Change your phone number to Vonage (almost Instantly) and use your credit card numbers to pay a bank outside of the states whatever your accounts will bear. Then they declare bankruptcy. (Why? Well if you've ever declared bankruptcy you can't change your SSN... Hence they own you for life. Check it out: Protect your SSN.

We need a biometric security measure in addition to a SSN. Fingerprint.. Retinal or something. Coupled with a PIN this would provide more security and perhaps the PIN could be a private 4 digit extension to your SSN. They only way to set or change your PIN is to appear in person at a police station or Social Security office and be authenticated via a biometric signature. Your pin could NEVER be written down or recorded by law. Employers would have to have you present to input your pin into a secure system in order to run a background check. Should your pin ever be recorded there would be a $50,000 dollar fine and a mandatory 1 year in jail. Should a company record multiple pins then the fine would be imposed for each incident and the people who inputted or recorded the pin would be forced to serve a minimum of 1 year in jail each. The CIO of the company would also be fined and held accountable for such a gross breach of security protocol.

Having this stringent measure installed would mean you would HAVE to be notified at any attempt to read your records as you would have to provide the pin. As a proposed solution lets say a company needs my social security pin for some reason, they would fill out a form with a centralized intelligence agency charged with the security and protection of consumer affairs. You could then goto to this centralized site which would be verified by you and input your pin to authorize the request. Should you not have access to a computer you could visit the Police Station or the Social Security office to authorize the request. This centralized agency is the only govermental branch allowed to store your pin. This may seem big brotherish but really it puts more power into the hands of the people and allows you to keep a close watch on your financial transactions and allows you a way to change a portion of your social security number should it ever become compromised. (That is the 4 digit extension pin)

1 comment:

Shawn said...

Add: LexisNexis:

http://www.wired.com/news/privacy/0,1848,66842,00.html