14
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 30 Aug 2024
14 points (93.8% liked)
Canada
7185 readers
522 users here now
What's going on Canada?
Communities
π Meta
πΊοΈ Provinces / Territories
- Alberta
- British Columbia
- Manitoba
- New Brunswick
- Newfoundland and Labrador
- Northwest Territories
- Nova Scotia
- Nunavut
- Ontario
- Prince Edward Island
- Quebec
- Saskatchewan
- Yukon
ποΈ Cities / Local Communities
- Calgary (AB)
- Edmonton (AB)
- Greater Sudbury (ON)
- Halifax (NS)
- Hamilton (ON)
- Kootenays (BC)
- London (ON)
- Mississauga (ON)
- Montreal (QC)
- Nanaimo (BC)
- Oceanside (BC)
- Ottawa (ON)
- Port Alberni (BC)
- Regina (SK)
- Saskatoon (SK)
- Thunder Bay (ON)
- Toronto (ON)
- Vancouver (BC)
- Vancouver Island (BC)
- Victoria (BC)
- Waterloo (ON)
- Winnipeg (MB)
π Sports
Hockey
- List of All Teams: Post on /c/hockey
- General Community: /c/Hockey
- Calgary Flames
- Edmonton Oilers
- MontrΓ©al Canadiens
- Ottawa Senators
- Toronto Maple Leafs
- Vancouver Canucks
- Winnipeg Jets
Football (NFL)
- List of All Teams:
unknown
Football (CFL)
- List of All Teams:
unknown
Baseball
- List of All Teams:
unknown
- Toronto Blue Jays
Basketball
- List of All Teams:
unknown
- Toronto Raptors
Soccer
- List of All Teams:
unknown
- General Community: /c/CanadaSoccer
- Toronto FC
π» Universities
π΅ Finance / Shopping
- Personal Finance Canada
- BAPCSalesCanada
- Canadian Investor
- Buy Canadian
- Quebec Finance
- Churning Canada
π£οΈ Politics
- Canada Politics
- General:
- By Province:
π Social and Culture
Rules
Reminder that the rules for lemmy.ca also apply here. See the sidebar on the homepage:
founded 3 years ago
MODERATORS
It's amazing our system for identity theft is "discover incident yourself, prove there's damage, get a police report, then we'll think about giving you a new SIN but it restarts your credit history"
In today's day and age the SIN should be morning more than a unique identifier for your identity, and should only be trusted when accompanied by a unique SIN authorization token:
This would not prevent a SIN + token pair from leaking, but they could only be abused within one institution, which is generally the same surface area as however your token leaked in the first place. Plus the source of the leak becomes immediately clear.
If there is a leak, you can report it and reauthorize a new token for whatever you need.
You could go further with this concept to improve it by adding a handshake with org level certificates and keys required to verify a token.
For situations where one company must verify your identity to another (e.g. an employee wants to submit your info for insurance purposes, or a bank wants to work with a partner bank), this is where a business entity level key could come into play. It wouldn't be sufficient for the original auth token to propagate to the partner because that increases exposure during a leak.