kaj wrote:I don't know that we know that it's Social Security Numbers in clear text, do we? We only know that the name of the column is SSN, I think. It could theoretically contain anything. 🙂  Including a properly scrambled Social Security Number.
But, sure, it would be a very bad design if it does indeed use clear-text SSN information as primary and foreign key!
 We actually do know.  The information comes from a previous post on this very subject.  The justification was that it was only being used for an "in-house" application.