Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

121–130 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#121
post #20

Earlier quoted context omitted.

Are you sure? It’s really hard to differentiate nowadays

> Are you sure? It’s really hard to differentiate nowadays Case in point; I can't tell if you're being sarcastic or not! :D

https://en.wikipedia.org/wiki/Poe%27s_law

Re: Hackers had a live feed of every ID verification company scanned for over a year

#122
post #29

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…

> the most you lose

Yep that's the only thing you lose, apart from a huge number of literal images of kids in the hands of literal criminals.

> I don't see any other better alternatives

Not doing age verification!

Re: Hackers had a live feed of every ID verification company scanned for over a year

#123
post #47

Earlier quoted context omitted.

add MFA to the check

To where, the site requesting the verification? Now it is no longer zero knowledge.

No, to the ID to prevent abuse if the card get stolen.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#124
post #47

Earlier quoted context omitted.

add MFA to the check

add a different ID check to the MFA if that doesn't work, then add more MFA to that new ID check. Eventually it has to work, right? It's definitely worth doing infinite security in order to avoid regulating social network algorithms, because

To prevent abuse add MFA to the ID. Problem if stolen cards solved and still zero knowledge.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#125
post #116
post #92

Earlier quoted context omitted.

eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs. Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem. Doesn't even need ZKP, the CA can just issue an attestation.

I've experienced this "solved problem" when visiting Germany during COVID. On every entrance to a mall there was somebody with a scanner device, and they only let you in if the scanner showed a green mark. I've been fully vaccinated (not EU) but my code didn't show a green mark on their scanner and I was promptly denied entry. The solution was to show them my German friend's code on my phone, this registered just fin…

yes, just as age verification can be fooled by an older friend who gets the check mark.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#126
post #14

Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

But usually gov't will outsource to random 3rd parties, no?

In Finland they outsource the system to banks and telephone operators. Its a very strange system. As far as I know, its not possible to access government services just by being a citizen. You also have to have an account with one of these third parties to get in.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#127
post #122
post #29

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…

> the most you lose Yep that's the only thing you lose, apart from a huge number of literal images of kids in the hands of literal criminals. > I don't see any other better alternatives Not doing age verification!

age verification is the current mandate of multiple governments, not doing it for many services means shutting down

Re: Hackers had a live feed of every ID verification company scanned for over a year

#128
post #34

Earlier quoted context omitted.

I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.

The US Government is one of the reference implementations of PKI. Unfortunately, IDs are issued 50 different ways by the less competent states. Combine that with accusations that getting new IDs constitutes systematic racism (a widely held belief on HN), ignoring that the ruralest of India has been able to do this successfully, and you're not getting digital ID any time soon.

It is a problem for millions of Americans: https://voteriders.org/article/who-doesnt-have-an-id-in-amer...

Systemic racism is very much a thing, and while perhaps not foundational in this particular issue, we see still see political fuckery that definitely targets by race: https://www.nbcnews.com/politics/2026-election/tarrant-count...

Re: Hackers had a live feed of every ID verification company scanned for over a year

#129
post #120

Earlier quoted context omitted.

The US Government is one of the reference implementations of PKI. Unfortunately, IDs are issued 50 different ways by the less competent states. Combine that with accusations that getting new IDs constitutes systematic racism (a widely held belief on HN), ignoring that the ruralest of India has been able to do this successfully, and you're not getting digital ID any time soon.

The difficulty for the US is people seem to be against a Federal Government ID. India doesn't seem to have this stigma and hence rural India can solve this problem.

I don't think people are against it, we already have the social security identifiers as a government layer... it's just that no one in the government is willing to do it for free in a way that is accessible to everyone

Re: Hackers had a live feed of every ID verification company scanned for over a year

#130
post #122

Earlier quoted context omitted.

> the most you lose Yep that's the only thing you lose, apart from a huge number of literal images of kids in the hands of literal criminals. > I don't see any other better alternatives Not doing age verification!

age verification is the current mandate of multiple governments, not doing it for many services means shutting down

I don't mean the services I mean the governments.
Post reply on HN