Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Right, but surely they could run your credit and then throw away the data, right? What interest do they have in holding on to it?


If you stop paying, they want to make a report to the credit agencies.


I think the solution is simple then: The SSN should be used for read-only. Once the credit report is read/accessed, the credit bureau issues a write-only code. The company then deletes the SSN and only retains the write-only code. If the write-only code is leaked later in a hack, it is useless to criminals trying to open new accounts.


Folks haven’t learned that this data is a liability and not an asset.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: