If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold. Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in…
FBI Probes Service Selling 153M+ Drivers Licenses
141–150 of 307 posts
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#142Earlier quoted context omitted.
Deleting the data after verification is a good practice. But if you're actively compromised, it probably doesn't matter how long you keep the data because it's already been immediately "backed up" by the intruders the second it is collected. Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in realit…
Ideally it’s not even stored…
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#143I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#144I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…
Which “normal, modern countries” have done variations of this?
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#145Earlier quoted context omitted.
I believe we need to criminalize possession of the data, with statutory damages per violation.
Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.
The GDPR in a nutshell......
Unnecessary personal data is a liability.
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#146I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…
Which “normal, modern countries” have done variations of this?
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#147Earlier quoted context omitted.
I believe we need to criminalize possession of the data, with statutory damages per violation.
It would be fun if the GDPR naysayers end up coming up to the same conclusion
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#148> vendors who collect this sensitive data need to be held to a higher standard. They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news). One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local leve…
As an EU citizen and resident I strongly recommend you not take EU privacy controls seriously. The GDPR functions well as a means of tax collection, but it really doesn't work all that well as something that actually protects people's privacy.
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#149Earlier quoted context omitted.
Which “normal, modern countries” have done variations of this?
European passports are NFC tags and you can prove your identity using your phone.
Recently I added my passport to my Apple wallet but I’m not sure if that’s used anywhere.
Re: FBI Probes Service Selling 153M+ Drivers Licenses
#150I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…
Which “normal, modern countries” have done variations of this?
The private key itself is locked into the Emirates ID, and need my biometrics to unlock.
Example: When I get delivery that needs my ID, the delivery man just put my Emirates into a card reader, and they need my biometrics to digitally sign the receipt.
It’s often used for important delivery (banks/gov documents), and any related gov services (including telecom, if i want to reload my sim card but forgot my pin, i can just insert my Emirates ID and scan my fingerprint and it retrives my SIM card by magic!)
You can try to read how they are doing the Emirates ID and the UAE Pass app, it’s super interesting to see this so well intergrated and at scale.