this post was submitted on 07 Aug 2024
517 points (98.7% liked)
Technology
59143 readers
2600 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
There are only 1 billion SSNs possible with 9 digits, and at most around 350M living people who have them (the US population). This breach is international but SSN is a US thing.
And not all 9-digit numbers are used, so there are fewer than a billion. It sucks when organizations store them because the search space is so small it's relatively easy to unhash them in a stolen database.
A lot of businesses use the last 4 digits separately for some purposes, which means that even if it's salted, you are only getting 110,000 total options, which is trivial to run through.
9 digit social security number specifically might be, but a unique number tied to you that is often used as identification when it really shouldn't isn't, it's a shitshow that has been implemented in many countries around the world.
The Finnish version was called an SSN originally for example, though now its a "henkilötunnus", personal identity code.
https://en.wikipedia.org/wiki/National_identification_number
Do TINs overlap with SSNs? Because businesses and non-citizen taxpayers have TINs instead of SSNs, but they're used just the same.
This I don't know. I remember reading that around 70%(?) of SSNs have been allocated, and there are enough left for a few decades. No idea whether corporation TINs come from that. I believe non-citizen taxpayers get similar SSNs to citizens. IDK if they pay into social security and collect benefits the same way.