A better rule is that PII data should never be used as a basis for auth/auth except by government agencies in the process of delivering legally mandated government services.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments