Password-protecting PDF pay statements with Social Insurance Number (Canada).

I’m in a dispute with a friend about the safety of an employer’s method for distributing pay statements: they email each employee a password-protected PDF file, and the password is the employee’s Social Insurance Number (SIN) which is among the most sensitive pieces of information that a Canadian has. A SIN is a 9-digit number; there may be other constraints but the pool already seems so small that it doesn’t matter.

Am I right that it is a trivial matter for an attacker to test all one-billion 9-digit numbers to see which one unlocks the PDF, thereby deducing the SIN of the person who the PDF belongs to? Since email isn’t exactly a secure channel of communication, this employer’s practice seems extremely vulnerable to attack.

submitted by /u/SmickDibbly
[link] [comments]

May 1, 2023
Read More >>