Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

161–170 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#161
post #120

Earlier quoted context omitted.

The difficulty for the US is people seem to be against a Federal Government ID. India doesn't seem to have this stigma and hence rural India can solve this problem.

I don't think people are against it, we already have the social security identifiers as a government layer... it's just that no one in the government is willing to do it for free in a way that is accessible to everyone

> I don't think people are against it

Every time national ID gets moderately serious discussion it is revealed very clearly that yes, the people are against it.

RealID—which was simply national standardization of state issued ID (when used for a variety of important purposes) had intense resistance, too—and its the closest policy to national ID that has passed.

Social Security identifiers are not ID for the person, and anyway were adopted nearly a century ago at a moment of higher-than-current trust in the federal government.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#162
post #63

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’

That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain. The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know. I guess the awkward bit is market…

As Ops person, massive doubt. I've been at companies that have gotten hacked twice now, neither my department though. Both times, security vulnerabilities that hackers got into were well known, the tickets were in the backlog and deprioritized over feature requests.

I've also seen cases where it's like, maybe we shouldn't share S3 Root Creds or put it on the VPC so we can monitor outgoing traffic but too many applications would need to be redeployed for that so skip it. Those 2 year old tickets were still sitting in the backlog when I left.

If we ever get report, it's extremely likely going to be massive failure and only way to change this is fines for company that are bankrupting.

EDIT: Oh yea, SOC2 needs to go away. It's security theater that's just giving cover to companies.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#163

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’

[dead]

Re: Hackers had a live feed of every ID verification company scanned for over a year

#164
post #34

Earlier quoted context omitted.

I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.

or just not ask for it at all. The three times I've needed to provide a scan of my passport were: to enroll in a university course, to buy from an e-commerce site, and to become an app developer. None of those orgs really needed a scan of my passport, which can't be revoked like a cracked password, and will now sit unencrypted somewhere until the end of time or until they are hacked and subsequently shamed into handl…

In my experience, hotels in other countries also take a copy of the passports of all guests.

Also learned “know your customer” laws require US people to give passport + SSN to a foreign bank who then reports it back to the US. Given that such bank’s website involves disabling right-click for “security”, the only glimmer of hope is that the data is catastrophically lost due to stupidity before it can be compromised.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#165
post #34

Earlier quoted context omitted.

I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.

The US Government is one of the reference implementations of PKI. Unfortunately, IDs are issued 50 different ways by the less competent states. Combine that with accusations that getting new IDs constitutes systematic racism (a widely held belief on HN), ignoring that the ruralest of India has been able to do this successfully, and you're not getting digital ID any time soon.

every application packet for a US National Security clearance for twenty years, was stolen in bulk, by Chinese agents. Your characterization of the perfection of US Federal data management appears to be lacking nuance.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#166
If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)

Re: Hackers had a live feed of every ID verification company scanned for over a year

#167

Earlier quoted context omitted.

I don't think people are against it, we already have the social security identifiers as a government layer... it's just that no one in the government is willing to do it for free in a way that is accessible to everyone

> I don't think people are against it Every time national ID gets moderately serious discussion it is revealed very clearly that yes, the people are against it. RealID—which was simply national standardization of state issued ID (when used for a variety of important purposes) had intense resistance, too—and its the closest policy to national ID that has passed. Social Security identifiers are not ID for the person, a…

It would help if the federal government didn’t show itself to abuse ID databases every time it gets ahold of one.

I don’t see how we could develop a national ID in an environment of such low trust (bidirectionally). You need a government that’s responsive to citizens and obeys constitutional guardrails, and citizens who trust the government to protect their best interests. We haven’t had that since the prior century (and last century the government was still breaking our trust, it just didn’t make the news).

Re: Hackers had a live feed of every ID verification company scanned for over a year

#169

Earlier quoted context omitted.

I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)

Yes, you can. Either you can physically own the key on the physical device (i.e. Yubikey/Google Titan/HSM) or you can use software (KeepassXC, Bitwarden). Most operating systems and browsers come with a sync mechanism that many people default to, but it's no more than that: the default. As for account recovery, most websites have a way to recover your account when you lose your password, there's no reason why that wo…

There are even open source hardware passkeys (NitroKey) so you can have security with freedom.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#170
post #61
post #56

How exactly does that work? How can you sneak a live feed past detection systems? It is incomprehensible to me, considering this is highly regulated and sensitive data. It is just open ports sending what they shouldn't be sending all the way out or what?

Brian Krebs' article makes a good case for the ID source being a harvester on the internal Hertz Car Rental network, and likely other similar consumer services that log ID for asset security and recovery. These are hardly military grade networks, as long as the driver licence scans make it to the database and can be used to identify and recover damages from accident or theft it's unlikely anybody has cared much past…

one would think that a reasonable, modern country would have regulatory requirements for storing PII like that but alas we live in the USA [0]

[0] https://www.politico.com/news/2024/09/17/andrew-kingman-data...

Post reply on HN