Skip to main content

Social Security Administration Now Requires Two-Factor Authentication

  • August 2, 2016
  • 5 replies
  • 11 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
1st August 2016
 
The U.S. Social Security Administration announced last week that it will now require a cell phone number from all Americans who wish to manage their retirement benefits at ssa.gov. Unfortunately, the new security measure does little to prevent identity thieves from fraudulently creating online accounts to siphon benefits from Americans who haven’t yet created accounts for themselves.
 
http://krebsonsecurity.com/wp-content/uploads/2016/08/ssasite-580x339.png
 
The SSA said all new and existing ‘my Social Security’ account holders will need to provide a cell phone number. The agency said it will use the mobile numbers to send users an 8-digit code via text message that needs to be entered along with a username and password to log in to the site.
 
Full Article

5 replies

Baldrick
Gold VIP
  • Gold VIP
  • August 2, 2016
Well, 2FA is already yesterday's technology amd has already been hacked but I suppose that it is better than nothing or relying on 1FA...LOL

ProTruckDriver
Moderator
This news really makes me feel safe now. :S Our Government at work, they never screw anything up ~ look at Health Care and that website.:@

ProTruckDriver
Moderator
The Social Security Administration is back to the old way of logging in. I just received this email today:
 
On July 30, 2016, we began requiring you to sign into your my Social Security account using a one-time code sent via text message. We implemented this new layer of security, known as “multifactor authentication,” in compliance with a Presidential executive order to improve the security of consumer financial transactions.  SSA implemented the improvements aggressively because we have a fundamental responsibility to protect the public’s personal information.
However, multifactor authentication inconvenienced or restricted access to some of our account holders. We’re listening to your concerns and are responding by temporarily rolling back this mandate.
As before July 30, you can now access your secure account using only your username and password. We highly recommend the extra security text message option, but it is not required. We’re developing an alternative authentication option, besides text messaging, that we’ll begin implementing within the next six months.
We strive to balance security and customer service options, and we want to ensure that our online services are both easy to use and secure. The my Social Security service has always featured a robust verification and authentication process, and it remains safe and secure.
We regret any inconvenience you may have experienced.
There is no requirement that you access your personal my Social Security account as a result of the steps we are taking.  However, when you do access your account, we encourage you to sign up for the extra security text message option. 

Baldrick
Gold VIP
  • Gold VIP
  • August 24, 2016
Robust...don't make me laugh...have they employed an ethical hacker to try some of the nefarious real life techniques that are practiced out there or did they just go...Security tested...check...LOL

ProTruckDriver
Moderator
Well it's been almost 8 years since some people were issued Obama Phones. Maybe their phones are worn out. Obama needs to issue more new Free Obama Phones (on the tax payers dime) so these people that are complaining could receive text messages. ROFL