Live data from Hacker News

FBI Probes Service Selling 153M+ Drivers Licenses

krebsonsecurity.com

51–60 of 306 posts

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#51
post #16

Earlier quoted context omitted.

Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.

It's obvious they are keeping them all. 150 million didn't get all re-scanned at once.

It's actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker's claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned.

Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#54

If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold. Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in…

I'm in Europe and got ~$350 because of three data leaks. The amount per instance was vastly different though - $255, $80 and $15.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#55

Bankrupt this company to serve as a warning to others that hang on to way too much data.

In addition, actual federal prison time for the C-levels would help as a deterrent to future fuckery.

This is the actual answer. Things like this need to be a criminal offense.

Monetary fines have a tendency to simply be modeled in as a cost of doing business. Going to prison is far more effective when the goal is to concentrate minds.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#56
post #44

Earlier quoted context omitted.

I believe we need to criminalize possession of the data, with statutory damages per violation.

Not quite the same, but the GDPR gives you a right to erasure.

And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#57
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure. So most businesses are not permitted to just delete the data.

Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234"

Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#58
post #22

Earlier quoted context omitted.

I believe we need to criminalize possession of the data, with statutory damages per violation.

Negligence is already illegal. Just locate a prosecutor.

I'll sleep so much better at night when the company that'll leak my Social Security Number on the internet due to hosting a backup of a database that's assessible publicly gets fined $0.30 per SSN leaked.

Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#59

Earlier quoted context omitted.

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure. So most businesses are not permitted to just delete the data.

Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234" Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.

A system abandoned decades ago? https://en.wikipedia.org/wiki/Gold_standard
Post reply on HN