Live data from Hacker News

FBI Probes Service Selling 153M+ Drivers Licenses

krebsonsecurity.com

131–140 of 307 posts

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#131

Earlier quoted context omitted.

> Exactly. You do not want to hand the US government the ability to “turn off” someone’s daily life at the press of a button. If you're within the borders of the US, this ability already exists, they have a monopoly on violence in the country, something the government is very eager to demonstrate this year.

There’s a lot of room between violence and financial isolation. The government has shown multiple times that it is willing to go after otherwise law-abiding citizens who take up disfavored careers, whether it’s gun dealers and payday lenders in Operation Choke Point, cannabis dispensaries in states where it was legal, or online cam girls. In all of these cases, going to cash or using alternatives to the banking syste…

And none of those examples you use, involve SSNs, these are all 100% paperless people/companies? Makes me wonder how they got bank accounts in the first place if they're so disconnected from society.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#132
post #90

The main question to government is: 1. You already know who everyone is. By definition identification as an individual is by government. 2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving l…

One can argue, this would be an unintentional tracking of the population by government

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#133
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Deleting the data after verification is a good practice. But if you're actively compromised, it probably doesn't matter how long you keep the data because it's already been immediately "backed up" by the intruders the second it is collected.

Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in reality the attackers had card-sniffing malware installed on every single cash register at every single store across the country.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#134

Earlier quoted context omitted.

I believe we need to criminalize possession of the data, with statutory damages per violation.

Isn't that the case already? Here in many European countries it already is. They're always warning about that when there's a big breach and people download it to see what's in it about them. Not that they're going to prosecute half the country of course but still.

There are also very very strict rules for companies that use or process this kinda of data and how they need to save and handle it. Hence why it's basically illegal to use US based services for anything with real data these days.

I wish it would be more enforced and controlled tho.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#135

Earlier quoted context omitted.

There’s a lot of room between violence and financial isolation. The government has shown multiple times that it is willing to go after otherwise law-abiding citizens who take up disfavored careers, whether it’s gun dealers and payday lenders in Operation Choke Point, cannabis dispensaries in states where it was legal, or online cam girls. In all of these cases, going to cash or using alternatives to the banking syste…

And none of those examples you use, involve SSNs, these are all 100% paperless people/companies? Makes me wonder how they got bank accounts in the first place if they're so disconnected from society.

The individuals had SSNs, but did not have a hypothetical national ID connected to systems that could have been used to fully isolate them. As long as backchannels exist in the system to accommodate those without SSNs/DLs, it is possible to get by even if the system tries to cut you off.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#136
What even would be the fix for this? 153m people need new license asap and id verification systems need to block the stolen ones? Also what are some of the bad things this could cause: a risk malicious actors open verified accounts in their name, ability to vote and travel under stolen id, what else?

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#137
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Deleting the data after verification is a good practice. But if you're actively compromised, it probably doesn't matter how long you keep the data because it's already been immediately "backed up" by the intruders the second it is collected. Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in realit…

Ideally it’s not even stored…

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#138

I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…

Which “normal, modern countries” have done variations of this?

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#139

I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…

Which “normal, modern countries” have done variations of this?

Italy doesn't have crypto keys (as the average person would just lose/leak them) but they offer SSO login with the ID card. Basically whenever you need to verify your identity you pick "sign in with CIEid", you get redirected to a goverment website where you can authenticate (typically by scanning a qr code + scanning your physical id card on your phone) and then you approve/deny the authentication request (you can also clearly see which data is shared (name, last name, dob, etc)).

it's stupid easy to setup, the app is not overly bloated and it has different options to authenticate.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#140

I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…

Which “normal, modern countries” have done variations of this?

[deleted]
Post reply on HN