Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

71–80 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#71
post #19

Earlier quoted context omitted.

This is precisely why the authority doing these checks needs to be the government that already issues the IDs . Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place . I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue…

Government systems leak information all the time. The type of institution managing the data makes little difference. Its how the institution manages the data that matters.

But the government inherently has that data, as it comes from there. They're the ones issuing the IDs in the first place.

Theres no avoiding this, structurally. So the best thing you can do is not to introduce any additional points of failure.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#72
> This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe.

Yeah just like how the multiple breaches and utter negligence from the incumbent credit bureaus killed the credit file managed by private companies.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#73

Earlier quoted context omitted.

Passkey?

I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)

I think you can do passkeys wile having private key. When os has the private key its just more convenient way of doing passkey.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#74
post #50

Earlier quoted context omitted.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.

I think this is a bit of a non sequitur. The government will still be able to throw you in prison in either scenario. They will also be able to compel disclosure of your records in either scenario. So the difference is really just that in the scenario where apple verifies your identity there's an additional actor in the mix over who you have zero influence. It seems strictly worse.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#75

Earlier quoted context omitted.

I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)

I don´t think I've ever come across a service that only used passkeys. Username/email + password + 2FA is usually the primary form of verification. There's usually a way to recover your account through email.

Doesn't that defeat the purpose? I thought the objective was to get rid of passwords

Re: Hackers had a live feed of every ID verification company scanned for over a year

#76

Earlier quoted context omitted.

I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)

I think you can do passkeys wile having private key. When os has the private key its just more convenient way of doing passkey.

I think you can but it has to be supported by the website that you are using

Re: Hackers had a live feed of every ID verification company scanned for over a year

#77
post #14

Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

But usually gov't will outsource to random 3rd parties, no?

One third party, managed by a public contract, seems much better than a parade of third parties for every service you interact with though right?

Re: Hackers had a live feed of every ID verification company scanned for over a year

#78
post #50

Earlier quoted context omitted.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.

> throw you in jail for expressing support for Palestine Action.

For those unfamiliar, you are, of course, allowed to peacefully protest in support of Palestine in the UK.

Palestine Action is a specific group that was controversially labelled as a terrorist group after they broke onto a runway and spray painted military planes.

https://en.wikipedia.org/wiki/Palestine_Action

Re: Hackers had a live feed of every ID verification company scanned for over a year

#80
post #41

Earlier quoted context omitted.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

> increasingly fascist chauvinist nationalist drifting in the geopolitical landscape What's going on in France?

France has always been chauvinist and nationalist.

The principle reason why the Netherlands joined the EU was to sabotage the French-German alliance- all the alarm bells went off in the 1950s.

Post reply on HN