By Ray Birch
SAN DIEGO—One security expert is hoping that the massive Equifax data breach serves as a catalyst to markedly change how people identify themselves for financial and other purposes.
“Essentially half of all Americans’ personal data was compromised from this breach,” said Jim Stickley, CEO of Stickley on Security. “That means that every bit of your personal info, the things that make you who you are, someone has it. If, and I believe when, this information gets dumped onto the dark web or released, the ability to become someone else then becomes ridiculously simple. All you need is a fake driver’s license, which you can get on the dark web, and become any one of the people affected by this breach. This is nuts.”
Stickley contends that with so much stolen personal data now available for crooks to use, it’s time the U.S. reevaluates the concept of personal identification.
“It comes down to reevaluating what makes you who you are,” he said. “I think the idea of using Social Security numbers—this is the straw that broke that camel’s back. We need a new system.”
Stickley said that a potential “silver lining” from the Equifax breach is that it could serve as a catalyst for the country to move in a new direction.
“This system we use, using Social Security numbers, has been broken for so long,” he said. “I hate using the words national identification, as that rings of Big Brother, but we need a system in which you have an ID of some sort that can be changed quickly and easily—not much different than getting a replacement credit card.”
Simple Fix
When someone’s credit card data is stolen, Stickley noted that people don’t panic anymore. They simply call their issuer, stop the old card, ask for a new card and move on.
“That’s a pretty simple process,” said Stickley. “But when your Social Security number gets stolen, it’s not a simple fix. In fact, it’s about impossible to get it changed. Pretty much the answer is ‘it’s tough to be you.’”
Stickley said that if a new system of identification were in place that allowed that primary ID to be easily changed, if a breach like Equifax occurred again it would not become the major concern facing many Americans today.
“We need a way to quickly change things,” said Stickley. “Everyone has a mobile device today, you could tie your ID back to an app and then easily manage it. We have got to get into the 20th century. That is what we have to get to—a system like that and one that is also tied back to better ways to authenticate, such as multifactor, maybe biometrics, especially with the new iPhone facial recognition if that proves to work well.”
To illustrate how antiquated and ineffective Social Security numbers are for ID purposes, Stickley pointed out that the numbers were never intended to be used for identification.
“I remember my old paper Social Security Card,” he said. “It used to say not to be used for identification right on the card. Now all of us use it for identification. Social Security numbers clearly can’t be used for identification now because so many Social Security numbers are now out there, so they are no longer private and it’s time to change.”
A Place In History?
Looking back, the Target breach signaled a new era of more sophisticated and widespread cybercrime had begun. Stickley said the Equifax breach might grab its own place in history.
“The Target breach started the cry for EMV in the U.S. So that breach had a big effect on us. Maybe the Equifax breach will have that same moment in time,” Stickley said.
Hopefully, he said, the Equifax breach won’t simply become “just another breach, and people will just toss up their hands, there will be some lawsuits and tomorrow will be another day.”
The real matter to pay attention to, he said, is that the fraud situation in the U.S. is not getting any better.
“No one is becoming more secure, no one is resolving the problem, if (Washington) keeps kicking the can down the road, hopefully soon they will run out of road and have to do something,” Stickley said.
