Identity Guard

Bottom line: All 3 credit scores free; most comprehensive & best overall service; 25% discount & free 30-day trial
PrivacyGuard

Bottom line: All 3 credit scores for $1; monthly credit score & report updates plus other benefits; 30-day trial for $1
Trusted ID

Bottom line: All 3 credit scores free; great value, especially for families; free 14-day trial
Equifax Complete Advantage

Bottom line: All 3 scores plus excellent 3-bureau monitoring and ongoing Equifax score updates; no free trial
ProtectMyID.com

Bottom line: Cheapest monthly price to monitor all 3 credit reports, but no scores
LifeLock Credit Score Manager

Bottom line: 3-bureau credit monitoring & one-time 3-bureau credit scores; updates TransUnion score monthly
ID Protect Premium from American Express

Bottom line: 3 bureau monitoring and one-time 3-bureau credit reports available upon enrollment but doesn't include credit scores
CreditCheck Total

Bottom line: Monthly 3-bureau credit score updates; $1 7-day trial; a bit expensive
Equifax Score Watch

Bottom line: Only monitors Equifax report; two Equifax FICO® Score reports annually plus updated score whenever it changes; no free trial
CreditReport.com

Bottom line: 3-bureau monitoring; bi-monthly Experian score updates; free 7-day trial
True Credit 3-Bureau

Bottom line: Only monitors TransUnion credit report; unlimited TransUnion scores; free 7-day trial
FreeCreditScore.com

Bottom line: Only monitors Experian report; two updates/mo to your Experian Score; free 7-day trial

Enter your email address to receive NextAdvisor.com Daily Blog updates:

Categories


Blog Archives


Social Security numbers can be cracked, creating a greater risk for identity theft

July 7th, 2009 - Posted by Robert Siciliano

Robert Siciliano is a NextAdvisor.com Expert Guest Blogger

SearchSecurity.com reports that researchers at Carnegie Mellon University have developed a reliable method to predict Social Security numbers using information from social networking sites, data brokers, voter registration lists, online white pages and the publicly available Social Security Administration's Death Master File.

Originally, the first three numbers on a Social Security card represented the state in which a person had initially applied for their card. Numbers started in the northeast and moved westward. This meant that people on the east coast had the lowest numbers and those on the west coast had the highest. Before 1986, people were rarely assigned a Social Security number until age 14 or so, since the numbers were used for income tracking purposes.

The Carnegie Mellon researchers were able to guess the first five digits of a Social Security number on their first attempt for 44% of people born after 1988. For those in less populated states, the researches had a 90% success rate. In fewer than 1,000 attempts, the researchers could identify a complete Social Security number, "making SSNs akin to 3-digit financial PINs." "Unless mitigating strategies are implemented, the predictability of SSNs exposes them to risks of identify theft on mass scales," the researchers wrote.

While the researchers work is certainly an accomplishment, the potential to predict Social Security numbers is the least of our problems. Social Security numbers can be found in unprotected file cabinets and databases in thousands of government offices, corporations and educational institutions. Networks are like candy bars – Social Security numbers can be hacked from outside the hard chocolate shell or from the soft and chewy inside.

The problem stems from that fact that our existing system of identification is seriously outdated and needs to be significantly updated. We rely on nine digits as a single identifier, the key to the kingdom, despite the fact that our Social Security numbers have no physical relationship to who we actually are. We will only begin to solve this problem when we incorporate multiple levels of authentication into our identification process.

The process of true and thorough authentication begins with "identity proofing." Identity proofing is a solution that begins to identify, authenticate and authorize. Consumers, merchants, government don't just need authentication. We need a solution that ties all three of these components together.

Jeff Maynard, President and CEO of Biometric Signature ID, provides a simple answer to a complicated issue in four parts:

Identify – A user must be identified when compared to others in a database. We refer to this as a reference identity. A unique PIN, password or username is created and associated with your credential or profile.

Authenticate – Authentication is different than verification of identity. Authentication is the ability to verify the identity of an individual based specifically on their unique characteristics. This is known as a positive ID and is only possible when using a biometric. A biometric can be either static or dynamic (behavioral). A static biometric is anatomical or physiological, such as a face, a fingerprint or DNA. A dynamic biometric is behavioral, such as a signature gesture, voice, or possibly gait. This explains why, when authentication solutions incorporate multiple factors, at least two of the following identifiers are required: something you have, such as a token or card, something you are, meaning a biometric identifier, and something you know, meaning a pin or password.

Verify – Verification is used when the identity of a person cannot be definitely established. These technologies provide real time assessment of the validity of an asserted identity. When we can't know who the individual is, we get as close as we can in order to verify their asserted identity. PINs, passwords, tokens, cards, IP addresses, behavioral based trend data and credit cards are often used for verification. These usually fall into the realm of something you have or something you know.

Authorize – Once the user has passed the identification test and authenticated their identity, they can make a purchase or have some other action approved. Merchants would love to have a customer's authenticated signature to indicate his or her approval of a credit card charge. This is authorization.

Effective identification results in accountability. It is being achieved in small segments of government and in the corporate world, but not systematically. Unfortunately, we are years away from full authentication.

In the meantime, we must make the data useless to the thief. If a Social Security number can't be used to open a new credit account, we have solved one part of the identity theft problem. This can be done by investing in identity theft protection or setting a credit freeze.

Robert Siciliano, identity theft speaker, discusses identity theft.

[youtube]http://www.youtube.com/watch?v=PIFkQfI-SOg[/youtube]

Robert Siciliano is CEO of IDTheftSecurity.com , an identity theft expert, professional speaker, security analyst, published author and television news correspondent. Siciliano works with Fortune 1000 companies and startups as an advisor on product launches, branding, messaging, representation, SEO and media. Siciliano's thoughts and advice on all these matters appear often in both the televised and print news media including CNN, MSNBC, CNBC, FOX, Forbes and USA Today. He has 25 years of security training as a member of the American Society of Industrial Security. He is the author of 2 books, including The Safety Minute: Living on High Alert; How to take control of your personal security and prevent fraud. He's also partnered with Uni-Ball to help raise awareness about the growing threat of identity theft and to provide tips on how you can protect yourself.

Leave a Reply

Recent Comments

  • university of phoenix review: I've read some just right stuff here. Definitely worth bookm...
  • Kincaid: Iunderstand what you are saying and I agree with you...
  • Nathaniel: Thank you for this article, and wait for more on this subjec...
  • here: Hi there awesome web site!! Person .. Stunning .. Superb .. ...
  • Tona Durante: Hmm it seems like your website ate my first comment (it was ...


Disclosure: NextAdvisor.com is a consumer information site that offers free, independent reviews and ratings of online services. We receive advertising revenue from most of the services we review. Our editors thoroughly research and whenever possible test each service we review and offer their honest opinions about each one. We are independently owned and operated and all opinions expressed on this site are our own.