Live data from Hacker News

FBI Probes Service Selling 153M+ Drivers Licenses

krebsonsecurity.com

81–90 of 308 posts

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#81
post #69
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Storing personal data should require insurance that increases per data point.

Legislating insurance prices is illegal for good reason. Either it's too high and the government has just siphoned a lot of money to insurance company shareholders, or it's too low and the government has effectively made it illegal to provide that insurance.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#82

Earlier quoted context omitted.

I believe we need to criminalize possession of the data, with statutory damages per violation.

Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.

Estonia has it's ID cards which can sign things....

That suddenly means a data leak doesn't matter - nobody can make new signatures.

Verifying someone's ID would be as simple as asking them to sign your company name and today's date.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#83
post #10

Earlier quoted context omitted.

153 million puts them at roughly 1/2 of all Americans. Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.

I had two active Clear subscriptions at the same time. How did an identity verification company not know both accounts were the same person? They were both using the same credit card! What does an "identity verification" company even do?

> What does an "identity verification" company even do?

Handles the multitude of ID document standards around the world while providing a simple Boolean flag to websites that are required to check if you're an adult.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#84

> vendors who collect this sensitive data need to be held to a higher standard. They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news). One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local leve…

> They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is. And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial…

Germany has Schufa and it keeps getting sued for the whole concept of it being illegal I believe.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#85
post #5

I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

Because the word "simply" isn't. Every time a programmer says "just" or "simply" about someone else's system, it's a lie.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#86
post #70

Now I feel justified that I started boycotting my neighborhood bar when they started scanning IDs at the door with some unknown app.

Those apps are internet ID checks brought to the real world. You're right to be suspicious. They do keep leaking data or getting found out to be storing everything forever or forming profiles of a person's movements.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#87
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

I believe we need to criminalize possession of the data, with statutory damages per violation.

But that would be like GDPR and that is EU which is communist which is satanic. QED.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#88

Earlier quoted context omitted.

Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.

Estonia has it's ID cards which can sign things.... That suddenly means a data leak doesn't matter - nobody can make new signatures. Verifying someone's ID would be as simple as asking them to sign your company name and today's date.

The problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about "mark of the beast", the Democrats and the ACLU fear them being used as part of a surveillance state.

[1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#89
post #5

I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

> They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

Because then that website would get compromised and lose the data on 350 million people instead of 153.

Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.

People throw around terms like "zero trust" like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you'll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.

Using government ID on the internet should simply be banned. 99% of things shouldn't require government ID to begin with and the 1% that do should always be done in person.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#90
The main question to government is:

1. You already know who everyone is. By definition identification as an individual is by government.

2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?

3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")?

Governments need to protect the public, not allow businesses open slather on collecting PII.

Post reply on HN