Post #2833211
2026-02-17 03:08 UTC
SSNs are generally considered public information but how the SSN is linked to other information is usually the more difficult bit to find and it's generally pay-walled. (Any jackass with a business license and a credit card can usually buy background check information for 'hiring'.)
But no, it shouldn't be solely used for authentication. That is just dumb. However, it can be used as part of a larger verification and validation scheme while building authentication/authorization profiles. In most systems that I have seen that use full or partial SSNs, it is always linked to several other identifiers that need to match.
Replies (1)
-
@Archer@lemmy.world 2026-02-17 03:21
They are definitely not. People consider it increased risk for identity theft if they hear their SSN was stolen and you just cited how people are still using them in part for authentication. They need to be completely useless for authentication