Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Social Security Administration Now Requires Two-Factor Authentication
Krebs on Security ^ | 8/16/2016 | Brian Krebs

Posted on 08/04/2016 8:11:41 AM PDT by snarkpup

The U.S. Social Security Administration announced last week that it will now require a cell phone number from all Americans who wish to manage their retirement benefits at ssa.gov. Unfortunately, the new security measure does little to prevent identity thieves from fraudulently creating online accounts to siphon benefits from Americans who haven’t yet created accounts for themselves.

...

“People will not be able to access their personal my Social Security account if they do not have a cell phone or do not wish to provide the cell phone number,” the agency said.

...

Also, as one reader already pointed out in the comments below, the SSA’s adoption of 2-factor SMS authentication comes as the National Institute for Standards and Technology (NIST) released a draft of new authentication guidelines that appear to be phasing out the use of SMS-based two-factor authentication.

(Excerpt) Read more at krebsonsecurity.com ...


TOPICS: Government; News/Current Events; Technical
KEYWORDS: accessibility; cellphone; cybersecurity; identitytheft; smartphone; socialsecurity; ssa
Navigation: use the links below to view more comments.
first 1-2021-4041-54 next last
After I read this article, I tried to access my account. Sure enough, I am now locked out because my cell phone is voice-only.

The first problem here is that people old enough to be on social security are less likely to have the kind of phone required—partly because we can't see well enough to use smart phones and partly because we don't need it for business purposes and aren't on the road as much.

The second problem is that it looks like the authentication method they just started using is in the process of being banned by the National Institute of Standards and Technology because it isn't secure anyway. If someone steals your phone, they've got the keys to your kingdom.

I contacted someone in the agency responsible for policing the accessibility of federal websites; and he says he is attending a meeting later today about this problem. I got the impression that the online account access system may have been done by a subcontractor who didn't know what they were doing.

1 posted on 08/04/2016 8:11:42 AM PDT by snarkpup
[ Post Reply | Private Reply | View Replies]

To: snarkpup

We have the same problem. Only use voice for phone. Funny. Google has a fix for this. If you don’t text, they will call your phone and leave a voice message.

And if you ever saw the movie “Cinder House Rules” - the main message is - Those that make the rules don’t live here!


2 posted on 08/04/2016 8:16:23 AM PDT by NEWwoman (God Bless America)
[ Post Reply | Private Reply | To 1 | View Replies]

To: snarkpup

You don’t ID to vote

Why do you need ID to collect social security?


3 posted on 08/04/2016 8:16:38 AM PDT by 2banana (My common ground with terrorists - they want to die for islam and we want to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: snarkpup

I don’t have a cell phone of ANY KIND.........................


4 posted on 08/04/2016 8:18:14 AM PDT by Red Badger (Make America AMERICA again!.........................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: NEWwoman

CIDER.................although CINDER may be more appropriate now...............


5 posted on 08/04/2016 8:18:48 AM PDT by Red Badger (Make America AMERICA again!.........................)
[ Post Reply | Private Reply | To 2 | View Replies]

To: snarkpup

so they can monitor your calls and if you say “Gun” they can cut off your benefits


6 posted on 08/04/2016 8:19:07 AM PDT by butlerweave
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

D@mn that spell checker! ;)


7 posted on 08/04/2016 8:19:32 AM PDT by NEWwoman (God Bless America)
[ Post Reply | Private Reply | To 5 | View Replies]

To: snarkpup
“People will not be able to access their personal my Social Security account if they do not have a cell phone or do not wish to provide the cell phone number,” the agency said.

What the...? And people can't even get a picture ID so they can vote....? This is sooo disciriminatory to minorities. </sarc>


8 posted on 08/04/2016 8:19:55 AM PDT by Perseverando (For Progressives, Islamonazis & other Totalitarians: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: snarkpup

This is why I use a lockout code for my phone. Nothing’s 100% but it beats having a phone people can just swipe and get to everything in it or that it has access to.

Having an unsecured smart phone today is the equivalent of having an open wi-fi at your home.


9 posted on 08/04/2016 8:20:15 AM PDT by Mr. Douglas (Today is your life. What are you going to do with it?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: NEWwoman

Your spellchecker may be a profit...............(sic).............


10 posted on 08/04/2016 8:20:57 AM PDT by Red Badger (Make America AMERICA again!.........................)
[ Post Reply | Private Reply | To 7 | View Replies]

To: snarkpup
I got the impression that the online account access system may have been done by a subcontractor who didn't know what they were doing.
Alas, too bad SS didn't hire the contractor who did ØbamaCare. Oh wait ...
Nothing but the best for us peons.
11 posted on 08/04/2016 8:21:10 AM PDT by oh8eleven (RVN '67-'68)
[ Post Reply | Private Reply | To 1 | View Replies]

To: NEWwoman

This is the first step to ensure that those who are planning on receiving a social security disbursement will not be able to find out that the fund is depleted. Kind of like showing up for a concert that has been cancelled and not being able to find the promoter.


12 posted on 08/04/2016 8:25:53 AM PDT by Mouton (The insurrection laws maintain the status quo now.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Mouton

I wouldn’t put it past them.


13 posted on 08/04/2016 8:29:54 AM PDT by NEWwoman (God Bless America)
[ Post Reply | Private Reply | To 12 | View Replies]

To: snarkpup
It was bad enough that they make us change passwords every 6 months, now they go and pull this stunt.

For anyone who's curious, following is the text of the email notification that was sent out by the SS people:


Starting in August 2016, Social Security is adding a new step to protect your privacy as a my Social Security user. This new requirement is the result of an executive order for federal agencies to provide more secure authentication for their online services. Any agency that provides online access to a customer’s personal information must use multifactor authentication.

When you sign in at ssa.gov/myaccount with your username and password, we will ask you to add your text-enabled cell phone number. The purpose of providing your cell phone number is that, each time you log in to your account with your username and password, we will send you a one-time security code you must also enter to log in successfully to your account.

Each time you sign into your account, you will complete two steps:

Step 1: Enter your username and password.
Step 2: Enter the security code we text to your cell phone (cell phone provider's text message and data rates may apply).

The process of using a one-time security code in addition to a username and password is one form of “multifactor authentication,” which means we are using more than one method to make sure you are the actual owner of your account.

If you do not have a text-enabled cell phone or you do not wish to provide your cell phone number, you will not be able to access your my Social Security account.



14 posted on 08/04/2016 8:31:19 AM PDT by ken in texas
[ Post Reply | Private Reply | To 1 | View Replies]

To: snarkpup

If a “textable” phone number is required, Google Voice ought to work.


15 posted on 08/04/2016 8:32:45 AM PDT by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: snarkpup

I tried this when I first got the email. They sent the code, but when I entered it the system said it wasn’t working currently and to try again later. Lol....about what I expected.


16 posted on 08/04/2016 8:34:02 AM PDT by RightGeek (FUBO and the donkey you rode in on)
[ Post Reply | Private Reply | To 1 | View Replies]

To: snarkpup

Tying access to a cell phone is absurd.
According to this study:
-
http://www.pewinternet.org/2015/10/29/the-demographics-of-device-ownership/
-
70% of American adults over age 65 DO NOT have a smartphone.


17 posted on 08/04/2016 8:36:15 AM PDT by Repeal The 17th (I was conceived in liberty, how about you?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Repeal The 17th

It’s pure gummit for ya. Hurry up and wait.


18 posted on 08/04/2016 8:37:05 AM PDT by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: snarkpup

Please ping when you get anymore info. I very seldom give my cell phone number out.


19 posted on 08/04/2016 8:41:33 AM PDT by Chgogal (A woman who votes for Hillary is voting with her vagina and not her brain.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: snarkpup
They pushed radio PSAs for years about 'going green' with Direct Deposit for your SS and other checks. Then, they said anyone who USES on such automated banking is senile - so no Guns should be owned by you [read DISARM WHITE PEOPLE, esp SENIORS AND VETS].

Now this new rule -- people [read OLD, WHITE, REPUBLICAN, VETS] need to jump through a special (jammable) hoop to get funds -- while all the illegal Rat voters continue to pour across border, unfettered by forms, fees, requirements for their automatic benefits & Motor-Voter cards. Like we can't SEE that all this is happening...


20 posted on 08/04/2016 8:48:14 AM PDT by 4Liberty (We SEE Trump tossed every contrived hurdle. Hillary given every absurd mulligan.THAT'S WHY-GO TRUMP!)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-54 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson