Death Master File: Researchers Find Social Security Number Hack

by Jordan Yerman | July 7, 2009 at 10:11 am
748 views | 3 Recommendations | 0 comments

Alessandro Acquisti and Ralph Gross, researchers at Carnegie Mellon University, have found a way to guess social security numbers based on the structure of those numbers based on examing the publicly-available SSDI, or the Death Master file. The Social Security Death Index is a publicly-available database listing the names, birthdates and registry locations of deceased Social Secuity cardholders.

Social Security numbers have three parts: are number, group number, and serial number, all of which correspond to when and where the number was applied for, typically at birth for American citizens.

Photos

bandit (Skype emoticon)

bandit (Skype emoticon)

see larger image

uploaded by Jordan Yerman

What does this mean for you? You may want to keep your birth city off of any public social networking pages, for starters. There are other measures you can take as well. This isn't meant as a scare story: just understand that identity info is like toxic waste: once it's out on the web, it's very, very hard to remove. This applies to other data besides Social Security. If you use your pet's name for your banking password, your Facebook or MySpace page can end up betraying you.

Carnegie Mellon researchers Alessandro Acquisti and Ralph Gross say the Social Security numbering system combined with the widespread use of S.S.N's as an identifying number has created an "architecture of vulnerability," and is an unexpected consequence of the availability of basic personal information and modern computing power. The study will be presented on July 29 at this year's Black Hat security conference in Las Vegas.

While the success rate is low (.08%), it's still better odds than Vegas. Social Security numbers generated in smaller states were easier to deduce:
The reason is that as of 1989, Social Security numbers were assigned according to the Enumeration at Birth initiative, where people received their Social Security number at birth.

Comments (0)

This story was created over 3 months ago, the comment thread is now closed.

What is NowPublic?

NowPublic lets people work together to cover news events around the world.

Find out more

Crowd Power

Spydermonkey
First Flagged at 10:49 AM, Jul 7, 2009 by Spydermonkey
These members have powered this story:

Related Stories

Recommendations (3)

Most recently recommended by:
 

closeSign in to NowPublic

is reporting from