Acquisti and Gross 2009 — Predicting Social Security Numbers from Public Data

SSNprivacyidentity-theftDeath-Master-FileEABSSAstatistical-reidentificationinformation-economicsdata-combinationpublic-records

Summary

Using the Social Security Administration (SSA)'s publicly available Death Master File (DMF) as a training set, Acquisti and Gross show that an individual's full 9-digit Social Security number (SSN) can be predicted with high accuracy from only their birth date and state of birth. The Enumeration at Birth (EAB) program (launched nationally in 1989) dramatically increased the correlation between birth timing and SSN assignment, making post-1989 cohorts especially vulnerable. The vulnerability is structural and universal — unlike data breaches, it applies in principle to any SSN issued under the old scheme.

Key Claims

Concepts Introduced or Extended

Entities Mentioned

Quotes

"Unlike data breaches, which are local threats (that is, specific to the records contained within a certain database, however large that may be), the predictability we observed is universal, in that applies, in principle, to any current and future SSNs—unless their assignment scheme is modified."

"SSNs were designed as identifiers at a time when personal computers and identity theft were unthinkable; today, abused as authentication devices, they enable an 'architecture of vulnerability.'"

My Take

The paper is a clean proof-of-concept for the general principle that aggregating individually innocuous public data sources can expose private information at scale. The key insight is that an antifraud policy (EAB) inadvertently created the vulnerability by increasing the informativeness of birth metadata about SSN assignment — a canonical example of unintended privacy consequences of well-intentioned policy. The paper directly prompted SSA to fully randomize SSN assignment in June 2011 (SSA 2011 Federal Register). Limitations: prediction is probabilistic (not deterministic), accuracy falls sharply in large states and pre-1989 cohorts, and real-world identity theft requires the attacker to also access a verification oracle (a credit reporting agency or the SSN Verification Service [SSNVS]). The botnet attack scenario is illustrative but optimistic about adversary coordination.