Live data from Hacker News

FBI Probes Service Selling 153M+ Drivers Licenses

krebsonsecurity.com

141–150 of 305 posts

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#141

If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold. Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in…

I concur. Liability would go a long way.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#142

Earlier quoted context omitted.

Deleting the data after verification is a good practice. But if you're actively compromised, it probably doesn't matter how long you keep the data because it's already been immediately "backed up" by the intruders the second it is collected. Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in realit…

Ideally it’s not even stored…

Well at least they need it until they get back a success response from the bank/payment processor/whoever.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#143

I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…

And just like the government backpedaled on the Real ID deadline, the federal government is backpedaling on login.gov and is still actively launching agencies on private third-party id.me identity verification.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#144

I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…

Which “normal, modern countries” have done variations of this?

European passports are NFC tags and you can prove your identity using your phone.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#145

Earlier quoted context omitted.

I believe we need to criminalize possession of the data, with statutory damages per violation.

Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.

> Exactly. Personal data should be treated like radioactive material

The GDPR in a nutshell......

Unnecessary personal data is a liability.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#146

I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…

Which “normal, modern countries” have done variations of this?

Denmark, for one: https://lifeindenmark.borger.dk/apps-and-digital-services/mi...

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#147

Earlier quoted context omitted.

I believe we need to criminalize possession of the data, with statutory damages per violation.

It would be fun if the GDPR naysayers end up coming up to the same conclusion

A significant percentage of HN posters and readership are those working in US AdTech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic slants towards opposing decent privacy laws.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#148

> vendors who collect this sensitive data need to be held to a higher standard. They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news). One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local leve…

> They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there

As an EU citizen and resident I strongly recommend you not take EU privacy controls seriously. The GDPR functions well as a means of tax collection, but it really doesn't work all that well as something that actually protects people's privacy.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#149

Earlier quoted context omitted.

Which “normal, modern countries” have done variations of this?

European passports are NFC tags and you can prove your identity using your phone.

I think American passports have those as well because I remember all the hax0rs making videos showing where to smash the NFC chip with a hammer or to buy wallets with special NFC blocking properties to keep folks from “stealing their identity” from the NFC chip. Personally I never cared but your comment jogged a memory.

Recently I added my passport to my Apple wallet but I’m not sure if that’s used anywhere.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#150

I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which g…

Which “normal, modern countries” have done variations of this?

UAE has an app called « UAE Pass », and the Emirates ID itself uses Public Key Infrastructure.

The private key itself is locked into the Emirates ID, and need my biometrics to unlock.

Example: When I get delivery that needs my ID, the delivery man just put my Emirates into a card reader, and they need my biometrics to digitally sign the receipt.

It’s often used for important delivery (banks/gov documents), and any related gov services (including telecom, if i want to reload my sim card but forgot my pin, i can just insert my Emirates ID and scan my fingerprint and it retrives my SIM card by magic!)

You can try to read how they are doing the Emirates ID and the UAE Pass app, it’s super interesting to see this so well intergrated and at scale.

Post reply on HN