Live data from Hacker News

FBI Probes Service Selling 153M+ Drivers Licenses

krebsonsecurity.com

61–70 of 303 posts

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#61

> vendors who collect this sensitive data need to be held to a higher standard. They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news). One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local leve…

> They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there

Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is.

And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We're talking a $5 billion company handing 15 million people's credit reports to hackers, and getting fined $15 million.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#63
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Yeah, this is the part I don't get either. Verification should produce a yes/no result, not a permanent archive of everyone's identity documents

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#64
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure. So most businesses are not permitted to just delete the data.

Regulatory retention is a valid reason for some of this data to exist. It isn't a blanket justification for every intermediary in the verification chain to retain its own permanent copy. If anything, that makes minimizing the number of copies even more important.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#65

One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera. They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are…

The ID scans in the article weren't submitted by people from their phones. They include IR and UV scans, too. The database might contain multiple sources but at least the big one appears to have a lot of IDs from physical locations where you hand your ID over the counter to someone to scan.

I'm now very curious how does a UV/IR scan of an ID card looks like!

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#66

One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera. They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are…

Yeah, the irony is that every extra signal added to make verification "safer" also becomes another extremely valuable thing to steal when the verifier gets breached

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#67

If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold. Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in…

Data minimization becomes a lot less abstract once every unnecessary record on disk has an actual dollar value attached to the risk

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#68
post #44

Earlier quoted context omitted.

Not quite the same, but the GDPR gives you a right to erasure.

And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.

Maybe the bureaucracy is there for a reason some times?

Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses?

Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model?

Hm.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#69
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Storing personal data should require insurance that increases per data point.
Post reply on HN