Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

61–70 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#61
post #56

How exactly does that work? How can you sneak a live feed past detection systems? It is incomprehensible to me, considering this is highly regulated and sensitive data. It is just open ports sending what they shouldn't be sending all the way out or what?

Brian Krebs' article makes a good case for the ID source being a harvester on the internal Hertz Car Rental network, and likely other similar consumer services that log ID for asset security and recovery.

These are hardly military grade networks, as long as the driver licence scans make it to the database and can be used to identify and recover damages from accident or theft it's unlikely anybody has cared much past that functionality.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#62
post #55

I’ve been following the development of the drivers license sharing system from Apple where different fields can be selected; are there any implementations of PKI based identification systems where multiple certificates can be generated and revoked when compromised? I’ve often thought that replacing the US social security number with a more robust root key makes for a fun thought experiment. Hard to imagine how such a…

[deleted]

Re: Hackers had a live feed of every ID verification company scanned for over a year

#63

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’

That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain.

The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know.

I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"?

Re: Hackers had a live feed of every ID verification company scanned for over a year

#64

Earlier quoted context omitted.

Passkey?

I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)

I don´t think I've ever come across a service that only used passkeys. Username/email + password + 2FA is usually the primary form of verification. There's usually a way to recover your account through email.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#65
post #40

Earlier quoted context omitted.

You know, it always bugged me that the NSA (and more directly Google, and my phone company, and so on) know where I was at exactly this time a year ago, but that I do not.

In Google Maps Timeline you can definitely see it (if you set it up and you brought your phone)

This is news to me. Never knew you could do that... too late now.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#66

Earlier quoted context omitted.

Only after they've had their mandatory scrotum inspection and testosterone check to join the military at age 18.

You guy don't have to show cock and balls to the military commission? It's a standard practice in post-Communist countries, including NATO ones.

There's a guy in the US military intake processing facility (MEPS) whose job is, among other things, to inspect your bunghole

https://www.google.com/search?client=firefox-b-d&q=MEPS+assh...

But more serious and non joking answer, the new thing from the "department of war" is testosterone level lab exams for existing servicemembers.

https://news.google.com/search?q=US%20military%20testosteron...

Re: Hackers had a live feed of every ID verification company scanned for over a year

#67
post #50

Earlier quoted context omitted.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.

I understand the sentiment, but your government you can actually fix by voting.

If Apple (or another large international company) suffers from decreasing margins, gets a new CEO and decides to turn the data it sits on into money there is absolutely nothing you can do, and you might in fact still stay a "forced" customer because of network effects (=> just consider whatsapp being an important communication channel in many places worldwide).

I think this attitude in general is often harmful; if your government sucks, fix the government instead of making yourself dependent on some quasi-monopolist private company.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#68
post #33

Earlier quoted context omitted.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

On the end of the day, it is the state that issues these ID documents. So if you let the government go bad, IMHO the form of the documents does not matter that much. During the totalitarian communist rule in Czechoslovakia, the state would regularly interfere with passports of people considered not loyal enough - withholding them outright or inventing extra paperwork that was necessary for the border police to let yo…

[deleted]

Re: Hackers had a live feed of every ID verification company scanned for over a year

#69

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’

They do not care about 'secure' part at all.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#70
post #29

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…

That sounds like this prediction from 2003

https://www.fourmilab.ch/documents/digital-imprimatur/#SI_an...

Post reply on HN