Insurance systems rely on knowing who has provided the information.
If you lodge a claim online with an insurance company an account will be setup.
Often the user-name will be your email address.
While this is not good practice so long the email address is linked to a person and not public this is done so that the person can be emailed etc.
The same reason applies to filing out an information sheet on a renewal.
However, If the email address has a typo or has to be changed it is easy to fix if the email address is NOT used as the username and changes can be made to the email address without affecting the use of the username and password.
There are other reasons why user-names can be set to a generated user name including:
- email addresses can be 'harvested' and sold making it easier to try to hack the account.
- Using email addresses as a username in turn creates an incentive to automate hacking overloading system and causing service levels to drop of the service to cease operation.
- Having a unique user name not only reduces those risk but makes it more certain that the person logging in is the person identified to complete the task – this is a key way that promotes better identity management
- if the user changes their email address, then password resets can be sorted by updating the user ‘credentials’ with a new email address without having to create a new user.
- Using generic
email addresses creates 3 further issues:
(a) password resets can then go to a group - the user identity is no longer knowable
(b) there is no way to establish who did what on the password reset
(c) as each password is unique to whoever reset the password a group email can result in the real user being locked out of the account.
Rotary’s identity management may need to improve further with other measures such as 2 Factor Authentication – e.g. txt messages to confirm who is logging in and the gold standard is now using stored encrypted ‘keys’, usually called pass-codes. At present we are using unique user-names and unique passwords is better identity management than using an email address as the user name because an email address is not unique.