Showing posts with label SSN. Show all posts
Showing posts with label SSN. Show all posts

Monday, January 28, 2008

Top Five Ways to Protect Yourself From Identity Theft

Identity theft is big business these days. Between 10 and 15 million Americans were victims of fraud that stemmed from identity theft between mid-2005 and mid-2006. The average loss more than doubled as well, from $1408 to $3257. With numbers like that, more and more people are wondering how to keep their credit and their identity safe.

Fortunately, there are a number of simple things you can do to help protect both.

1. Review: Get a free Credit Report

Your credit report shows what credit you have - a who, what, and where of your financial standing. Simply reviewing your credit report three times a year using the free credit reports available through www.annualcreditreport.com and checking for things that you don't recognize can help save you. Be careful, and use the official site.

When you receive your report, you will not receive your credit score. You don't need it to help protect your identity, so don't worry. Look for accounts that aren't familiar, addresses you don't recognize, and anything that you are not familiar with.

Since each of the credit agencies will give you at least one free credit report a year (and in some states, or other certain circumstances, more), you can check your credit report every four months. Think of this as preventative maintenance like changing the oil in your car, and
set a reminder for yourself.

The credit agencies are:

2. Guard: Protect Your SSN

Your Social Security Number or SSN is used for many identification purposes. Everything from taxes to credit applications to health insurance relies on Social Security numbers, and that makes them one of the most frequently targeted pieces of personal information. You can help protect yours by only giving it when required - many forms request it, but do not require it.

A few tips:
  • Never write your social security number on a check
  • Don't provide your SSN over the phone unless you have dialed the company yourself, and you trust the company.
  • Don't carry your Social Security card unless you need it - most people can keep their Social Security card at home in a safe place, rather than in their wallet where it can be stolen along with credit cards and a driver's license or other personal data.
3. Dispose: Properly dispose of records, receipts, and credit applications.

Shred statements, receipts, credit card applications and checks, and any other records that you throw away. A diamond or crosscut shredder is always preferable to a strip cut shredder, but any shredding is better than throwing them away intact.

4. Monitor: Check your financial statements, and keep accounts up to date.

Monitor bills and other financial statements such as bank statements regularly. Check for charges you didn't make, or locations that are unfamiliar. In addition, make sure that all of your accounts are up to date, and that addresses and other contact information are current. This ensures that you receive your bills, replacement credit cards, and that the companies can contact you in the event of a problem.

5. Cleanup: Cancel old accounts, and remove yourself from mailing lists.

You can remove your name from the Direct Mail Association's Mail Preference Service at https://www.dmachoice.org/MPS/, which will help cut down on junk mail and credit offers. You can also opt to not receive pre-screened credit offers at http://www.optoutprescreen.com/.

Canceling old accounts helps to ensure that credit cards aren't sent to old addresses, and keeps your unused cards from being abused without your knowledge. Not carrying extra cards can also help to make you safer if you do lose your wallet - you'll be less exposed, and you'll still have a card that you can use while you wait for replacements.

Simple maintenance can really help to protect your personal information and your credit. Make these steps a part of your everyday habits, and you can feel confidence that you're taking the right steps to protect your identity!

Creative Commons licensed photo credit Flickr user shawnzlea

Tuesday, October 9, 2007

SSN: when a unique ID isn't.

As regular readers know, I work in higher education. I switched employers earlier this year, and recently discovered that the switch led to some interesting issues with insurance. The description below is the best fit to what appears to have happened, however it is written with no inside technical confirmation.

The sequence appears to be:

  1. End employment at former employer A, with insurance provided by insurance company X.
  2. Start employment with new employer B, employer B also uses insurance company X.
  3. Employer B insurance starts, and is identified by SSN to company X.
  4. Employer A carries my insurance through for a few weeks, then sends notice to the same insurer to terminate insurance for my SSN.
This led to my insurance being invalid, despite my current employer - B, believing that it was active. It also points to some interesting flaws behind the scenes.
  • A trusted entity can end insurance for a given SSN.
  • A trusted entity can declare themselves authoritative or is by default authoritative for a given SSN.
  • Crossovers are not flagged for activity - if employer A makes a change, then employer B makes a change, then A makes a change, this is not caught and investigated.
  • There is no regular feed that updates this information.
  • SSNs are used as unique IDs for the insurance - and even if you select a non-SSN ID (which the insurer offers) they appear to still be the primary key for your account.

Thursday, June 21, 2007

What if everybody used your SSN?

The story starts like this:

"In 1938, wallet manufacturer the E. H. Ferree company in Lockport, New York decided to promote its product by showing how a Social Security card would fit into its wallets. A sample card, used for display purposes, was inserted in each wallet. Company Vice President and Treasurer Douglas Patterson thought it would be a clever idea to use the actual SSN of his secretary, Mrs. Hilda Schrader Whitcher."
Read the rest on the Social Security Administration's website. If you deal with user IDs, or Social Security numbers, this one will make you wince...and smile.

Tuesday, April 10, 2007

Hard drive encryption and breach notification

I've had a number of conversations about SSN disclosure laws recently, and they're a major topic in the higher education security space. If you're an Indiana resident, last year's SSN release law and the breach disclosure laws for both private and public institutions made life more interesting. The usual disclaimer applies - I am not a lawyer, and you should talk to yours definitely applies here. With that said, the Indiana laws and others include a possible out for organizations - for example, the state agency version reads:

"Sec. 5. (a) Any state agency that owns or licenses computerized data that includes personal information shall disclose a breach of the security of the system following discovery or notification of the breach to any state resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person."
The key here is the "unencrypted" - if you can reasonably state that the data was encrypted, and could not be accessed, then your reporting requirements typically are lessened, if not largely removed. It is worth noting that in general, the laws do not specify an encryption technology - presumably ROT13 would be considered a less than good faith effort.

Does it now behoove you to encrypt everything? Possibly, if you deal with covered data everywhere, but few organizations do. At the least highly sensitive systems, or systems that are likely to be exposed should be considered in your remediation plan. Most organizations are considering laptops and PDA/smartphone devices as part of their first round of targets. Both of these are likely to be exposed or stolen, and often contain local copies of sensitive data. The past 12 months have shown a number of cases of stolen or missing laptops.

From a technical perspective, you have a few options:
  1. Full drive encryption software. Utimaco's product is a good example of this. The best part about software of this nature is that it can be installed on existing systems. Pay particular attention to backups, key escrow, and OS and hardware compatibility. You're sure to find some systems that your encryption scheme just won't work on - many products are Windows-centric. There are some real benefits to full drive encryption, including temporary space and virtual memory being encrypted. There is also typically a real performance hit, particularly for disk intensive activities such as using a virtual machine.
  2. User directory encryption - things like Bitlocker and FileVault can easily encrypt user directories. The caveat here is that you have to make sure that data isn't stored elsewhere - a single application that stores data elsewhere, or a user who stores to the unencrypted root directory of the hard drive can make your encryption useless. In the case of FileVault, you'll also need to make sure you figure out a method for managing the master password. There is still a performance penalty, but general non-user directory software should run at normal speeds - the performance hit is constrained within the bounds of files in the user's encrypted directories.
  3. File or volume encryption. Security professionals will probably point you to software like TrueCrypt for this. You must encrypt the file or volume and unlock it when you use it. This does not account for memory resident data, nor does it handle temporary files, thus making it far more difficult to claim that data would not have been potentially exposed.
Should your organization use an encryption product? If you deal with sensitive data, and want to safeguard it, you should definitely take a look at the products on the market. If your organization is subject to a disclosure law, encryption products may also provide a needed protection in the form of both a reputation and a data disclosure control.

What about cost? In most cases, encryption products can be had in a variety of price ranges - Bitlocker and FileVault are free with Vista and OS X, while commercial solutions range in price up to a few hundred dollars per machine. As with any security control, you'll need to gauge the cost and benefit to determine where and when you should deploy the technology.