![]() |
|
|
|
Registered
|
Last 4 of your social
So, we have been going round and round on this at work. HR and one other department setup user names for staff and it uses the first initial and last name for the user name and then the initials and last for of the SS# for the password.
Being in IT I said that is a lousy policy and we should never use the SS# for anything identifying our staff. They said going forward they will use the employee number instead of SS# but it is too much work to change existing accounts. How do I convey how this is so not a good idea to them, or am I just paranoid?
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Control Group
|
Impress upon them the potential financial downside, to them, not just their employees
__________________
She was the kindest person I ever met |
||
![]() |
|
Driver, not Mechanic
Join Date: May 2013
Location: SF Bay Area
Posts: 3,002
|
Someone in HR is being creative. They might have tried to use the username for something else.
Are there too many John Smiths in the company and they weren't willing to do any manual work? Most other companies go with: firstname.lastname@company.domain First letter of first, than full last name First letter of first, then max 7 characters of last name But somebody had to manually fix the duplicates. |
||
![]() |
|
Registered
Join Date: Jan 2002
Location: west michigan
Posts: 26,464
|
I wouldn't be too concerned if all they were wanting was the last four numbers.
Not much could happen bad with just those. But, that's just my opinion...I think the security thing is overblown in most cases.
__________________
78 SC Targa Black....gone 84 Carrera Targa White 98 Honda Prelude 22 Honda Civic SI |
||
![]() |
|
Fleabit peanut monkey
|
On a side note when I started with Sohio back in 84, my employee number was my social. Probably common back then.
__________________
1981 911SC Targa |
||
![]() |
|
Registered
|
Quote:
Our email is first initial last name @ domain.com and they choose their own password.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Registered
|
The last four are the only unique parts. The first three are the locale/area you were born, the next two are the year you were born and the last for are the unique identifiers. If I know those four and your name I have your whole identity.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Registered
|
Tried that. I also asked if it would be more work to fix it now or after one of those sites was hacked and the hackers now have the SS# and name to go with it.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
non-whiner
Join Date: Aug 2012
Location: Slightly right of center
Posts: 5,235
|
Um...no. You cannot uniquely identify someone as you describe.
There are state laws in most states that prohibit employers from using your ssn as a company ID number. However, even though it’s not a good idea there is no law prohibiting them from using a portion.
__________________
"Too much is just enough." |
||
![]() |
|
A Man of Wealth and Taste
Join Date: Dec 2002
Location: Out there somewhere beyond the doors of perception
Posts: 51,063
|
6666...of course what did youse think it would be?
__________________
Copyright "Some Observer" |
||
![]() |
|
The Unsettler
|
That is incorrect.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
![]() |
|
Registered
Join Date: Apr 2001
Location: Linn County, Oregon
Posts: 48,506
|
Please allow Tabby to introduce himself. He's a man of wealth and taste..
__________________
"Now, to put a water-cooled engine in the rear and to have a radiator in the front, that's not very intelligent." -Ferry Porsche (PANO, Oct. '73) (I, Paul D. have loved this quote since 1973. It will remain as long as I post here.) |
||
![]() |
|
![]() |
G'day!
|
Quote:
![]()
__________________
Old dog....new tricks..... |
||
![]() |
|
Registered
Join Date: Jan 2002
Location: west michigan
Posts: 26,464
|
nope
__________________
78 SC Targa Black....gone 84 Carrera Targa White 98 Honda Prelude 22 Honda Civic SI |
||
![]() |
|
Registered
|
Yeah, sorry. locale/state then group number. My bad.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Registered
Join Date: Feb 2000
Location: Dallas, TX
Posts: 4,612
|
No way... How many credit card companies etc validate your identity by asking the last 4 digits of your SSN? I would not want those digits used anywhere it could be avoided.
__________________
Neil '73 911S targa |
||
![]() |
|
Cars & Coffee Killer
Join Date: Sep 2004
Location: State of Failure
Posts: 32,246
|
Really, really, really bad idea.
Look at it this way. I can spearfish someone in your HR department for their password. From their, even If I can only get a list of everyone's social security numbers with no other data attached, I can reasonably pick out that one person's whole SSN based on the last 4. Don't think it will happen, this is exactly how hackers operate. They use what they know to get at something they don't, once they have that, they now know more and have even more to use. Most hacking is a combination of security flaws, social engineering (fooling people into giving up info), and using stupid security procedures like this to your advantage. Did I mention that I'm getting a boat? I just need to know the first name of your HR's departments newest hire....
__________________
Some Porsches long ago...then a wankle... 5 liters of VVT fury now -Chris "There is freedom in risk, just as there is oppression in security." |
||
![]() |
|
Registered
|
Funny thing is they all have failed phishing tests and I have just had personal one on one training to explain how this stuff happens. They say it is too much hassle. I have thought about having our lawyer send them a note.
Mreid, in our state there is no law but other states prohibit using it for an employee ID or any part of identification including part of a password or PIN. I just can't see any good coming of using it when they have an employee number that is 4 digits also and nothing lost when the hacking occurs. Legion, their first name is
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Registered
Join Date: Mar 2003
Posts: 10,318
|
Nope. Only place your SSN should be is with payroll info. Which if I could dream a perfect world, would run on a entirely secondary setup and be totally separated from any other data storage. Everything else should reference employee number - which shouldn't be based on the SSN, and should definitely have a larger keyspace than 4 digits gives you.
|
||
![]() |
|
Get off my lawn!
|
Quote:
Your bank will REQUIRE it as well. No other option. Even if if is a business account registered under a federal I’d number. They will tie it to an person with a SSN unless it it a publicly traded business.
__________________
Glen 49 Year member of the Porsche Club of America 1985 911 Carrera; 2017 Macan 1986 El Camino with Fuel Injected 350 Crate Engine My Motto: I will never be too old to have a happy childhood! |
||
![]() |
|