
Www.social Security.gov – The US Social Security Administration announced last week that it will now require a mobile phone for all Americans who want to manage their retirement benefits at ssa.gov. Unfortunately, new security measures do little to prevent fraud by identity thieves.
The SSA says that all new and existing “My Social Security” account holders will be required to provide a mobile phone number. According to the agency, mobile numbers will be used to send users an 8-digit code that they must enter along with a username and password to access the website.
The SSA said it is making the changes to comply with an executive order requiring federal agencies to provide more secure authentication for their online services.
“If people don’t have a cell phone or don’t want to provide a cell phone number, they can’t access their personal Social Security account,” the agency said. “The purpose of providing your phone number is to use your username and password every time you sign in to your account. We will send you a unique security code that you must enter to properly start your account. We hope to provide you with more options based on the national guidelines that are currently being developed ».
SSA’s policy change does not appear to grant that person additional credentials, even if the signer first provides additional proof of multi-factor authentication.
The SSA offers other “extra security” options, such as sending users via US mail a special code they must enter on the agency’s site to complete the registration process. If you choose to enable additional security; The SSA will ask you to:
Unfortunately, it is still quite easy for thieves to create an account in the name of an American that was not created for them. All that is required is the name of the target; date of birth Social Security number; Residence and telephone number. These personal data can be purchased from various online cyber crime shops for approximately $3-4.
After that, the SSA issues four multi-pronged tests called “Knowledge-Based Authentication” or KBA by credit bureau Equifax. In practice, the previous address; Many of these KBA questions, such as loan amounts and dates, can be successfully guessed using random guesses. And you can often find the answers to these questions by checking out free online services like Zillow and Facebook.
In September 2013, the SSA and financial institutions warned that identity thieves are on the rise in cases where retirees register an account using their personal information on the SSA portal and divert the recipient’s benefits to prepaid cards controlled by fraudsters. Unfortunately, because the SSA’s new security features are optional, they do little to block crooks from undoing SSA benefit payments to retirees.
Because I can only create one Social Security account for each Social Security number. Registering an account on the portal is a fundamental way for Americans to avoid falling victim to these scams.
To review: Once you’ve set up and verified your account and started receiving login codes, you’ll be more secure from there. If you haven’t signed up yet, these new Security options won’t make it difficult for someone else to sign up as you.
It’s not clear that these optional security measures will be of much benefit, as many seniors still distrust text messages and are unlikely to send or receive them. I would like the SSA to make it mandatory for all new accounts to receive a one-time code to complete new account creation via US Mail, whether users choose “Extra Security” or not. The agency will need it in the future; But why this isn’t done by default is a mystery to me.
In addition to SSA’s optional security measures; Americans can further block ID thieves by placing a security block on their credit files with the major credit bureaus. Readers who have taken my ongoing credit freeze advice should temporarily remove the freeze to complete the process of creating an account at ssa.gov. Look at it another way. Having a suspension prevents ID thieves from fraudulently creating an account in your name and siphoning off government benefits.
SSA’s new messaging system is experiencing some technical difficulties, at least for Verizon Wireless customers. The SSA posted this message on its website over the weekend: “We are working to resolve an issue that is preventing Verizon wireless customers from receiving a mobile phone security code. Verizon wireless customers are currently unable to access their personal My Social Security account.”
Update 1:00 PM ET: For the record; I am going to the US to check their credentials. We asked the SSA for comment on why it did not contact all consumers by mail. I got this reply:
“The Social Security Administration has strengthened the online registration process, protecting the information provided to us and making identity verification and authentication more stringent. I can’t give more details publicly because I don’t want to make a road map for criminals.”
As one reader has already pointed out in the comments below. As the National Institute of Standards and Technology (NIST) released new draft guidance on authentication, the SSA appears to have decreased its use of 2-factor SMS authentication. SMS-based two-factor authentication.
Update August 11, 2016: A source who helped test things for this story by registering on the SSA’s portal said he received a snail mail the other day saying someone had opened an online account in his name. So while the SSA is sending letters if you register online, it doesn’t take advantage of that opportunity to send you a special code to securely complete your registration. Go image It provides estimates of the future Social Security benefits you and your family may receive each month, along with a basic overview of the Social Security program. It also provides a record of your income history and other valuable information. Your future benefits are based on your earnings record, so it’s important to tell us when you see an error; That way you can review it and make sure you get all the benefits you deserve. yours
Easy to read; Written in easy to use and understand language. We’ve divided the information into sections like different benefits so you can easily find what you need. the new
Here’s a bar chart of your personal retirement benefit estimates for nine different ages, based on when you want your benefits to start. This key information can help you make decisions about your financial future.
. Technical sheets of social security programs; We can help you better understand the benefits and how they apply to your situation. For example, for young workers, we give you information that you can save for your future. We explain how benefits for older workers are taxed and how to avoid the Medicare penalty. Information pages contain links for easy reference and additional information.
In addition, new sheets (in English and Spanish). Share these resources with your friends and family.
Social
Security Account. If you don’t have an account Be sure to create one today! Your account allows you to access other services online, such as applying for a replacement Social Security card and obtaining a letter verifying that you are no longer receiving Social Security benefits. for example, you can easily request a replacement Social Security card; Track the progress of your applications. Estimate future benefits or manage your current benefits effectively.
With two trusted identity partners, Login.gov or ID.me, creating my new Social Security account in the US is easier than ever.
The previous government provided a single account, simple, secure and private access to US government agencies.
ID.me, on the other hand, serves as a trusted login provider that meets the US government’s online identification and authentication requirements. username in your credentials; It includes password and two-factor authentication, ensuring a high level of security in the online authentication process.
Get started Visit www.ssa.gov/myaccount. There, you have the option to create an account using our preferred identity partner.
You must be at least 18 years old; Please remember that you must have a Social Security Number (SSN) and a valid US mailing address.
When you select “Sign in with Login.gov” or “Sign in with ID.me” you will be redirected to the partner’s website.
After successfully creating your identity, you will be returned to the My Social Security website for additional steps.
“For your protection, only you can create your own Social Security account for your personal use,” warns the official Social Security website.
“We may not create or use an account on your behalf without your written or verbal consent.
“Official use of this service misleads your evidence to the Union Government and may lead to an offence.
Social security us gov, social security gov application, social security card gov, social security benefits gov, social security gov online, social security gov medicare, social security .gov disability, social security gov onlineservices, social security gov appeal, social security gov applyforbenefits, social security ssa gov, social security administration gov