Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

51–60 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#51
post #17
post #15

Earlier quoted context omitted.

Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?

The DMV sells the data you give to the DMV. The DMV does not sell the data you give to the DMV to the DMV.

In guessing you can't choose to opt out ?

Re: Hackers had a live feed of every ID verification company scanned for over a year

#53

Earlier quoted context omitted.

It also dropped off the front page, pretty quickly, despite getting a lot of upvotes and comments. I was surprised by that, as this is exactly the type of story that tends to spend a couple of days on the front page. But it’s also the kind of story that won’t stay down, and will definitely be back. It appears as if there are folks here that don’t want to talk about this.

Was on the front page for ~12 hours. https://hnrankings.com/49529621

OK. That's how it got all the upvotes. I am here fairly often, and in my neck of the woods, it was only high up for about three of them. I note that it starts its drop (quickly) at about 9AM, East Coast time. I should note that front page is 30 or less, and, according to that graph, it was only there, for about ten hours; most of which wasn't daytime, in the US. I only noticed it, the first time, because I woke up in the middle of the night, and checked the site.

But it's still the type of story that should have had a much longer tenure, especially as it was Krebs.

I am now thinking that the access may have been through a backdoor. It certainly seems to have operated like a direct intravenous link.

BTW: Thanks for this link: https://securitywall.co/tools/ipa-analyzer

Looks interesting.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#54
post #29

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…

Passkey?

Re: Hackers had a live feed of every ID verification company scanned for over a year

#55
I’ve been following the development of the drivers license sharing system from Apple where different fields can be selected; are there any implementations of PKI based identification systems where multiple certificates can be generated and revoked when compromised?

I’ve often thought that replacing the US social security number with a more robust root key makes for a fun thought experiment. Hard to imagine how such a system could securely serve so many people but passports with embedded chips seem to be doing okay.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#56
How exactly does that work? How can you sneak a live feed past detection systems? It is incomprehensible to me, considering this is highly regulated and sensitive data. It is just open ports sending what they shouldn't be sending all the way out or what?

Re: Hackers had a live feed of every ID verification company scanned for over a year

#57
post #50

Earlier quoted context omitted.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.

Your digital identity would then be under the jurisdiction of the US government, who (despite talking a big game) are arguably worse for that same sort of behaviour.

If anyone has to have this type of control, better it be a local national government that you can in at least some small way influence.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#58
post #29

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…

Passkey?

I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)

Re: Hackers had a live feed of every ID verification company scanned for over a year

#59

Earlier quoted context omitted.

All the kids will be safe now they're logging into porn sites as Pete Hegseth.

Only after they've had their mandatory scrotum inspection and testosterone check to join the military at age 18.

You guy don't have to show cock and balls to the military commission? It's a standard practice in post-Communist countries, including NATO ones.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#60
post #19
post #5

This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet

This is precisely why the authority doing these checks needs to be the government that already issues the IDs . Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place . I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue…

Government systems leak information all the time. The type of institution managing the data makes little difference. Its how the institution manages the data that matters.
Post reply on HN