Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

RE: storing SSNs, CCNs, password in the DB

Subject: RE: storing SSNs, CCNs, password in the DB
Date: Tue, 1 Mar 2005 11:18:34 -0600
Andrew McAllister wrote...

Some companies like banks will claim that they require SSN's
because of money laundering laws, but I have yet to find the 
actual law that does require it.

The argument (from banks) that I always hear is that they need
your SSN because it's your "taxpayer ID" and they need your
taxpayer ID so that they can create a 1099-DIV for you and report
your interest to the IRS (which they are supposedly required to
do by some federal banking regulation or another).

So perhaps if you can find an interest-free account (there's
not many that offer these--in fact, most banks offer interest
bearing checking accounts nowdays), then you MIGHT be able to
open an account at the bank w/out providing your SSN, but I
sincerely doubt it. Instead, you're likely to get "I'm sorry
sir, but it's just our policy to require that you give your SSN."

Of course, as others on this list have pointed out, I suppose
you could accidentally make a typo when writing down your SSN.
(Note: I'm _not_ recommending this; you probably still could be
reported as engaging in fraudulent activities and who knows
whether the bank will demand that you show your SSN card at
some future date.)

Of course, I'll concede my SSN to a bank who is paying me
interest. OTOH, I'm not going to give it to my veterinarian
who asks for it or various other places. Thanks to HIPAA
at least the HMOs are no longer using our SSNs for the account
number on the medical cards. But I digress...

-kevin
---
Kevin W. Wall           Qwest Information Technology, Inc.
Kevin.Wall@qwest.com    Phone: 614.215.4788
"The reason you have people breaking into your software all 
over the place is because your software sucks..."
 -- Former whitehouse cybersecurity advisor, Richard Clarke,
    at eWeek Security Summit


<Prev in Thread] Current Thread [Next in Thread>