Page Content | Main Menu | Section Menu | Support Us | Contact Us
Center for Democracy and Technology
Working for Democratic Values in a Digital Age
Support CDT
Contact Us
PolicyBeta - Digital Policy in Process
This Section

CRS Weekly Report: The Social Security Number

July 9th, 2009 by Jennifer J. Chen

The Congressional Research Service is a $100 million a year think tank that researches and writes informative and non-partisan reports on topics suggested by members of Congress. The catch–and the reason you might not have read their work–is that CRS reports are only made easily available to members of Congress. Citizens can request these reports from lawmakers, but without a public index, they can’t request something they don’t know exists. The CRS Reports currently rank first on CDT’s Most Wanted Government Documents. In an ongoing effort liberate these documents, CDT runs Open CRS, an online repository of public CRS Reports. To spotlight these reports, I will be writing “CRS Report of the Week” posts and feature a relevant report each week. These reports are informative in both that they serve as excellent primers to political issues and that they offer a degree of insight into what information is circulating around Congress.

The Social Security Number: Legal Developments Affecting Its Collection, Disclosure, and Confidentiality
#RL30318
October 2nd, 2008

It is well known that Social Security Numbers (SSNs) should not be used as authenticators. A new study demonstrating the ease with which SSNs can be predicted serves as further evidence to this fact.  Simply put, SSNs weren’t designed to be authenticators. The problem with SSNs is that they have become both the de facto national identifier and authenticator for private industry.  This is analogous to using your name (an identifier) as your password (an authenticator). Identifiers are simply a reference to who you are and, thus, are often public.  Authenticators, on the other hand, are used to prove identity, and should not be known publicly.  These dual uses of SSNs as identifiers and authenticators has worried identity experts for some time because of this difference in security levels.  The new research steps over those concerns and suggest that SSNs should never be used as authenticators not just because of the risk an individual’s SSN might be disclosed, but because SSNs are predictable based upon publicly available information.  Ultimately, it does not matter how vigilant one is in protecting his or her SSN.  It can easily be discovered.

This CRS report provides an overview of several laws regulating SSN use by the federal government.  The two major statutes are the Privacy Act of 1974 and the Tax Reform Act of 1976.  The Privacy Act discouraged government agencies’ use of SSNs as identifiers by requiring that government services not be denied simply because an individual chooses not to disclose their SSN.  However, agencies may require the collection of SSNs if a Federal statute requires it, or if the agency already had record systems based upon SSNs.  The Tax Reform Act, two years later, only solidified the use of SSNs by requiring the use of SSNs on federal tax forms.

SSN use as an identifier is entrenched the government, despite numerous examples of the widespread use and abuse this practice. Current law focuses primarily on SSN disclosure by the federal government in public records.  However, given this research, disclosure does not seem to be the greatest concern if SSNs are predictable from public information.  The main problem is the widespread use of SSNs as authenticators in the private sector for activities like credit approval or background checks.  There are no federal laws that prevent private entities from requiring SSN disclosure, in which the SSN is likely used as an authenticator, as a condition to their providing goods and services.  Given the entrenchment of SSNs as authenticators, it is unlikely that their use in the private sector will change any time soon.


This entry was posted on Thursday, July 9th, 2009 at 1:10 pm and is filed under CDT, Consumer Privacy, Open Government. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

2 Responses to “CRS Weekly Report: The Social Security Number”

  1. CDT Blog Posts « The Wibble Says:

    [...] The Social Security Number [July 9th, 2009] [...]

  2. Kendal Says:

    My ssn was stolen in 2005..i was 14. I did not realized this had happened until i was trying to get a job with a big company and
    they paid a third party company to do background checks.
    Now i have worked many places and have gotten many tax returns since then. I have never lost my ssn card or gave it to anyone but i still got stolen and is still currently being used by this woman in California. I can’t find her because her address is fake. Now how is she able to take loans out in my name, get a house, get a job, under an 14 year old girls name. Didn’t anyone think it looked a little suspicious whenever they had a 14 year old girl applying for a loan? Trying to get a job? Getting credit cards? The fact is no one bothered to even do a in depth background check for many years. I have a huge problem with this. Ssn’s are not safe. No matter who you are or how your protect yourself.

Leave a Reply

About the Blog

    PolicyBeta is a forum for CDT experts to discuss news and developments in the technology policy arena. Visitors are encouraged to comment on the blog or email the authors.

    Our goal with PolicyBeta is to foster thoughtful discussion regarding technology policy as it relates to civil liberties and democratic values. While we encourage comments, we must insist that they be focused, relevant and written in a tone that is respectful of other posters. For more information, please feel free to contact PolicyBeta editor Brock Meeks.

    Check the main CDT site for complete, up-to-date information on CDT initiatives and activities.

Search Blog
       Top
Privacy Policy | Feedback