Live data from Hacker News

FBI Probes Service Selling 153M+ Drivers Licenses

krebsonsecurity.com

91–100 of 307 posts

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#91
post #90

The main question to government is: 1. You already know who everyone is. By definition identification as an individual is by government. 2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving l…

We can't do any of that because it is forward-thinking and doesn't involve clear-cutting a rainforest to make the stacks of paperwork that are otherwise required to fill out forms in triplicate, run everything through 17 different departments, and ensure an army of bereaucrats have something to do with their day.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#92
post #65

Earlier quoted context omitted.

The ID scans in the article weren't submitted by people from their phones. They include IR and UV scans, too. The database might contain multiple sources but at least the big one appears to have a lot of IDs from physical locations where you hand your ID over the counter to someone to scan.

I'm now very curious how does a UV/IR scan of an ID card looks like!

https://www.microptik.eu/product/id-card-verification

Basically swaps the LED illum with an UV LED instead. Makes all the security features pop right out.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#93
post #90

The main question to government is: 1. You already know who everyone is. By definition identification as an individual is by government. 2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving l…

This is exactly the way its being implemented in EU (Yes, this person is over 18").

European Digital Identity Wallet (EUDI Wallet) framework established under the eIDAS 2.0 regulation (Regulation (EU) 2024/1183)

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#94

Earlier quoted context omitted.

Estonia has it's ID cards which can sign things.... That suddenly means a data leak doesn't matter - nobody can make new signatures. Verifying someone's ID would be as simple as asking them to sign your company name and today's date.

The problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about "mark of the beast", the Democrats and the ACLU fear them being used as part of a surveillance state. [1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...

Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver's license, and whatever else.

If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed).

We'll get there eventually, but not before we try everything else first.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#95
post #90

The main question to government is: 1. You already know who everyone is. By definition identification as an individual is by government. 2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving l…

This is already present today in California Driver's licenses in your Apple Wallet (mDL).

When you scan your driver's license at a compatible reader, you're given a notice of what information is being requested and the ability to share it (or not).

It can also request some derived attribute (is this person above the age of 21?) instead of the actual data field itself.

Most of this is from ISO/IEC 18013-5

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#96

Earlier quoted context omitted.

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure. So most businesses are not permitted to just delete the data.

Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234" Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.

Unfortunately letting random companies photocopy your passport leads to identify fraud.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#97
post #54

If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold. Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in…

I'm in Europe and got ~$350 because of three data leaks. The amount per instance was vastly different though - $255, $80 and $15.

I'd be very interested in which ones, since I've never received anything despite being in several big breaches (and have received the boatload of spam to prove it). I'm pretty sure this is very country specific.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#98

Earlier quoted context omitted.

Estonia has it's ID cards which can sign things.... That suddenly means a data leak doesn't matter - nobody can make new signatures. Verifying someone's ID would be as simple as asking them to sign your company name and today's date.

The problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about "mark of the beast", the Democrats and the ACLU fear them being used as part of a surveillance state. [1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...

I grew up in that tradition, so I can shed some light: The fear of a national ID isn’t just about tracking and privacy, but that an individual cannot participate in society or survive if the government decides to revoke the id.

Meaning, I can’t buy food; rent or buy a home; or hold any sort of job and earn and save.

What we have today isn’t better, but until recently I was hard pressed to see how such fears were even warranted.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#99
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

I believe we need to criminalize possession of the data, with statutory damages per violation.

It would be fun if the GDPR naysayers end up coming up to the same conclusion

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#100
post #68

Earlier quoted context omitted.

And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.

Maybe the bureaucracy is there for a reason some times? Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses? Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model? Hm.

In case it wasn't obvious: I do not at all agree with these complaints about the GDPR or EU.
Post reply on HN