Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

41–50 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#41
post #14

Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

> increasingly fascist chauvinist nationalist drifting in the geopolitical landscape

What's going on in France?

Re: Hackers had a live feed of every ID verification company scanned for over a year

#42
post #17
post #15

Earlier quoted context omitted.

Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?

The DMV sells the data you give to the DMV. The DMV does not sell the data you give to the DMV to the DMV.

Haha, damn not enough caffeine this morning to parse correctly

Re: Hackers had a live feed of every ID verification company scanned for over a year

#43
post #40

I wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!

You know, it always bugged me that the NSA (and more directly Google, and my phone company, and so on) know where I was at exactly this time a year ago, but that I do not.

In Google Maps Timeline you can definitely see it (if you set it up and you brought your phone)

Re: Hackers had a live feed of every ID verification company scanned for over a year

#44
post #10
post #5

This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet

Except this helps no child.

Isn't that the one that was left behind in 2002?

Re: Hackers had a live feed of every ID verification company scanned for over a year

#45
post #31

> There is no safe age verification. There is no age verification that doesn’t put people at risk. There are zero knowledge proofs

Concrete ZKP age verification schemes are hardly zero knowledge.

Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy.

Now little Johnny borrows my ID, and uses it to setup some oracle that provides ID validation for every kid and bot in the country. Woops.

To stop that you must compromise the idealized zero knowledge properties of the scheme, and in doing so you create the potential for harm/risk for everyone.

Sure, it's better than sending an ID card live feed to the dark web, but the risks of ID card theft are at least somewhat easy to understand.

Some of the threats to human rights don't even require the departure from the 'idealized' model-- as even the idealized model requires an ID issuer to issue the of-age person an ID. And so if the ID ZKP is widely required then the issuer can unperson you by simply declining to issue you an ID.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#46
post #31

> There is no safe age verification. There is no age verification that doesn’t put people at risk. There are zero knowledge proofs

True. I built a ZK age verification based on Polish digital identity https://x.com/maciejlotkowski/status/1899896737688436844, but I didn't find a business case for it at the time.

There's a EU initiative https://digital-strategy.ec.europa.eu/en/news/commission-mak.... The direction is generally good, but I'm not very positive about the implementation (as with everything comes from the govs).

Re: Hackers had a live feed of every ID verification company scanned for over a year

#47
post #45
post #31

> There is no safe age verification. There is no age verification that doesn’t put people at risk. There are zero knowledge proofs

Concrete ZKP age verification schemes are hardly zero knowledge. Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy. Now little Johnny borrows my ID, and uses it to setup some oracle that provide…

add MFA to the check

Re: Hackers had a live feed of every ID verification company scanned for over a year

#49

Earlier quoted context omitted.

(2 days ago, 276 comments) https://news.ycombinator.com/item?id=49529621

It also dropped off the front page, pretty quickly, despite getting a lot of upvotes and comments. I was surprised by that, as this is exactly the type of story that tends to spend a couple of days on the front page. But it’s also the kind of story that won’t stay down, and will definitely be back. It appears as if there are folks here that don’t want to talk about this.

Was on the front page for ~12 hours.

https://hnrankings.com/49529621

Re: Hackers had a live feed of every ID verification company scanned for over a year

#50
post #14

Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.
Post reply on HN