<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A Modest Proposal &#8211; Eliminate the SSN Facade</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=635" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=635</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Saar Drimer</title>
		<link>http://spiresecurity.com/?p=635&#038;cpage=1#comment-896</link>
		<dc:creator>Saar Drimer</dc:creator>
		<pubDate>Sat, 26 Feb 2005 20:35:53 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=635#comment-896</guid>
		<description><![CDATA[False sense of security is dangerous! SSNs give the impression of security while, as you say, provide none. People should come to realize that SSNs (and Mother&#039;s maiden name) are pretty much public record and we should move on to a better authentication system.

]]></description>
		<content:encoded><![CDATA[<p>False sense of security is dangerous! SSNs give the impression of security while, as you say, provide none. People should come to realize that SSNs (and Mother&#8217;s maiden name) are pretty much public record and we should move on to a better authentication system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stuart Berman</title>
		<link>http://spiresecurity.com/?p=635&#038;cpage=1#comment-895</link>
		<dc:creator>Stuart Berman</dc:creator>
		<pubDate>Sat, 26 Feb 2005 07:37:13 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=635#comment-895</guid>
		<description><![CDATA[Great series of posts on ChoicePoint and the issues around identity theft.

I have a tough time with all the cries for more patchworks of regulations that seem like bandaids while the patient is hemorrhaging internally.

SSN was never meant to be identification or authentication... You hit the nail on the head - in the US we don&#039;t have any consistent and robust identity standard. Most security pros seem to shy away from advocating them. Well, how about a voluntary system? You could request a federal identity card which some institutions might honor and grant additional privileges (not unlike the idea of pre-screened frequent flyers). Then piggy back that onto digital certificates as an optional field for stronger authentication. Let consumers pick any certificate issuer that they choose (as well as company supplied certs for employee use).

Don&#039;t want the &#039;mark of the beast&#039;? Fine, there will be that market in demand also - just more expensive mechanisms like tokens, more risk, etc.
]]></description>
		<content:encoded><![CDATA[<p>Great series of posts on ChoicePoint and the issues around identity theft.</p>
<p>I have a tough time with all the cries for more patchworks of regulations that seem like bandaids while the patient is hemorrhaging internally.</p>
<p>SSN was never meant to be identification or authentication&#8230; You hit the nail on the head &#8211; in the US we don&#8217;t have any consistent and robust identity standard. Most security pros seem to shy away from advocating them. Well, how about a voluntary system? You could request a federal identity card which some institutions might honor and grant additional privileges (not unlike the idea of pre-screened frequent flyers). Then piggy back that onto digital certificates as an optional field for stronger authentication. Let consumers pick any certificate issuer that they choose (as well as company supplied certs for employee use).</p>
<p>Don&#8217;t want the &#8216;mark of the beast&#8217;? Fine, there will be that market in demand also &#8211; just more expensive mechanisms like tokens, more risk, etc.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
