Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Is it legal for an employer to use our SSNs for passwords on their computer system?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
Ilsa Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 07:44 PM
Original message
Is it legal for an employer to use our SSNs for passwords on their computer system?
Edited on Mon Sep-13-10 07:45 PM by Ilsa
My new employer does this. I don't like it at all, and there is no option to change out the PW. I think way too many people have access to our SSNs period.

I would appreciate any constructive comments or direction to legal info on this.
Printer Friendly | Permalink |  | Top
Jamastiene Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 07:47 PM
Response to Original message
1. I hate it when they do that.
I always feel uneasy about using my SSN for any more than I absolutely have to use it.

I'm interested in knowing the answer to your question too.

K&R
Printer Friendly | Permalink |  | Top
 
CurtEastPoint Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 07:57 PM
Response to Reply #1
4. I found this on the SS website. I'd tell the employer or HR to let you use a different p/w.
SS says:

Must I provide a Social Security number (SSN) to any business or government agency that asks?

The SSN was originally devised to keep an accurate record of each individual’s earnings, and to subsequently monitor benefits paid under the Social Security program. However, use of the Social Security number as a general identifier has grown to the point where it is the most commonly used and convenient identifier for all types of record-keeping systems in the United States.

Specific laws require a person to provide his or her SSN for certain purposes. While we cannot give you a comprehensive list of all situations where an SSN might be required or requested, an SSN is required or requested by the following organizations:

* Internal Revenue Service for tax returns and federal loans;
* Employers for wage and tax reporting purposes;
* Employers enrolled in E-Verify;
* States for the school lunch program;
* Banks for monetary transactions;
* Veterans Administration as a hospital admission number;
* Department of Labor for workers’ compensation;
* Department of Education for Student Loans;
* States to administer any tax, general public assistance, motor vehicle or drivers license law within its jurisdiction;
* States for child support enforcement;
* States for commercial drivers’ licenses;
* States for Food Stamps;
* States for Medicaid;
* States for Unemployment Compensation;
* States for Temporary Assistance to Needy Families; or
* U.S. Treasury for U.S. Savings Bonds

The Privacy Act regulates the use of SSNs by government agencies. When a federal, state, or local government agency asks an individual to disclose his or her SSN, the Privacy Act requires the agency to inform the person of the following: the statutory or other authority for requesting the information; whether disclosure is mandatory or voluntary; what uses will be made of the information; and the consequences, if any, of failure to provide the information.

If a business or other enterprise asks you for your SSN, you can refuse to give it. However, that may mean doing without the purchase or service for which your number was requested. For example, utility companies and other services ask for an SSN, but do not need it; they can do a credit check or identify the person in their records by alternative means.

Giving your SSN is voluntary, even when you are asked for the number directly. If requested, you should ask why your SSN is needed, how your number will be used, what law requires you to give your number and what the consequences are if you refuse. The answers to these questions can help you decide if you want to give your Social Security number. The decision is yours.

For more detailed information, we recommend the publication Your Social Security Number And Card .
Printer Friendly | Permalink |  | Top
 
Recursion Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 08:51 PM
Response to Reply #4
10. Request for SSNs are supposed to be accompanies by an authorization notice
And they usually say something like "you are not required to share your SSN with us, but if you do not we will be unable to..."
Printer Friendly | Permalink |  | Top
 
elleng Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 07:50 PM
Response to Original message
2. Don't think its 'illegal,' but surely unwise.
Printer Friendly | Permalink |  | Top
 
Zing Zing Zingbah Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 07:51 PM
Response to Original message
3. I don't know... but it seems like you should have the option
to change your password.
Printer Friendly | Permalink |  | Top
 
WolverineDG Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 08:00 PM
Response to Original message
5. My former employer did the same
hated it with a passion, especially at first because the IT "geniuses" didn't understand why we'd want the screen to show asterisks instead of our SSNs. :eyes:

These same IT "geniuses" couldn't understand why I'd want them to FAX instead of emailing the instructions for getting onto the new server, with its new IP address, even when I told them at least 5 times that we had no internet access at the office. Convo went something like this "We can't get on the internet because you guys sua sponte decided we needed a new server & IP address. Please fax us the new instructions." "Okay, I'll email them to you." "What part of 'we have no internet access' do you not understand?" "Oh, well, you can't get on the internet because we have a new server & IP address." (my internal dialogue: no shit sherlock) "Great, so you'll fax us the new instructions?" "Well, I don't have time for that, can't I just send you an email?" "DO.YOU.SPEAK.ENGLISH? I can't get to my email because we have no internet access because you decided to change servers & IPs today WITHOUT TELLING ANYONE AHEAD OF TIME." "OK, I'll send you an email."

:banghead: :nuke: :banghead:

Sounds like some of our IP "geniuses" now work for your employer. Good luck trying to reason with them.

dg

Printer Friendly | Permalink |  | Top
 
liberal N proud Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 08:19 PM
Response to Original message
6. I have seen it used as account user names
But never as a password.
Printer Friendly | Permalink |  | Top
 
Cleita Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 08:27 PM
Response to Original message
7. The last time I worked on a large system, and it was in a
university, we made up our own passwords and no supervisors or other co-workers were privy to them except one co-worker, which we were allowed to choose. We also held another co-worker's password, who chose us, just in case something happened to any of us workers. When we left the job we turned our files over to the supervisor and were allowed to delete the password ourselves. I wouldn't want them to use any numbers or names associated with me, whether SS, Passport, bank information or whatever is exclusively mine.
Printer Friendly | Permalink |  | Top
 
Ruby the Liberal Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 08:43 PM
Response to Original message
8. They have your SSN on your W9 for your W2 and
depending on encryption policies, may not be accessible by staff with network/database access.
Printer Friendly | Permalink |  | Top
 
Ilsa Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Sep-14-10 08:09 AM
Response to Reply #8
11. I would expect Personnel to have it along with Payroll...
Those departments normally have big security roadblocks.

But passwords in the IT dept? Almost anyone in that dept could access it, and I'm concerned about hackers grabbing that information like they did at the Pentagon a few years ago.
Printer Friendly | Permalink |  | Top
 
Recursion Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-13-10 08:50 PM
Response to Original message
9. I don't know about illegal but that's horrible systems administration policy
I've run very large networks in which I've never known any user's password. I shouldn't be able to know it (I can change it if need be, but I don't have to know it to do that).
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Dec 27th 2024, 02:36 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC