Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

171–180 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#171
post #88

Earlier quoted context omitted.

I still don't understand why the simplest approach isn't used: ban kids from using the Internet unsupervised. There's really no good reason why a six year old should have internet access.

it's pretty easy to enforce that for 6 year olds. not as easy for 12 year olds.

I don't think I care as much for a twelve year old seeing age inappropriate things, as that is what I was seeking out and enjoying at that age. And that was before Internet was a thing people had in their homes. I was watching horror movies like Alien and Terminator uncut on VHS.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#172
post #14

Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

We also have a Danish wallet now, AltID, which implements an anonymized (assuming no collusion between issuer and eavesdropper or service provider) age verification protocol based on batches of single-use tokens which contain no personal information (except that they can be traced back to you by the issuer). It's been released and in production since summer. Since then, several social networks have apparently started…

The problem in much of the west is that even if verification is initially government funded/run and secure, the neoliberal ratchet (underfunding>degraded service>privatize) ensures that it will eventually be privatized and enshittified.

Here in the US, we have login.gov, but many government services use the private ID.me instead.

Any time the government says it needs to “cut spending”, it instead sells off critical infrastructure to friends of government who then permanently extract a private tax on the public.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#173
post #97
post #88

Earlier quoted context omitted.

I still don't understand why the simplest approach isn't used: ban kids from using the Internet unsupervised. There's really no good reason why a six year old should have internet access.

The argument is that there are parents who are too stupid/lazy to enable parental controls on kids devices and society has a duty to protect kids even if their parents are negligent. Also, kids interact with other kids, so even if you do everything right your kids wind up with access/peer pressure through the kids with bad parents. I dunno if I agree but I think that's the thrust of it.

There are systems in place dealing with negligent parents. They could be better, but they exist. If kids were banned, there couldn't be that much peer pressure.

Think about it, how many kids will get a gun just because some of the kids have access to guns through their negligent parents? If it's banned the path to getting it won't be straightforward.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#174

Earlier quoted context omitted.

IDs being required for voting is essentially a poll tax the way that it's argued for in the US. There's a minimum amount you have to spend to even get one that will expire in a certain amount of years. That's also assuming you can get all the documents you need for the initial ID. If you don't already have all the essential documents you'll need multiple appointments at government facilities. The local social securit…

So… requiring an ID to buy a gun is also an unconstitutional tax on a right?

Yes, it is.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#175
post #63

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’

That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain. The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know. I guess the awkward bit is market…

This is kinda my point though - just don’t do it in the first place is the answer. Nothing is unhackable. So don’t create a massive honeypot in the first place.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#176
post #15

Earlier quoted context omitted.

Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?

selling (data you give to the DMV) [to third parties], not selling (data you give) [to the DMV]

My awkward wording on things like this if nothing else I hope helps inspire confidence that I am in fact a human typing each of these characters by hand.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#177
post #171

Earlier quoted context omitted.

it's pretty easy to enforce that for 6 year olds. not as easy for 12 year olds.

I don't think I care as much for a twelve year old seeing age inappropriate things, as that is what I was seeking out and enjoying at that age. And that was before Internet was a thing people had in their homes. I was watching horror movies like Alien and Terminator uncut on VHS.

im not particularly concerned myself, but any ban like you propose would almost certainly go up to age 12 (at least), making it effectively impossible to enforce.

i see your other comment about guns, so just to preempt that a little bit: the internet is far more ubiquitously available than guns are.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#178
The HN title is misleading.

> Hackers Had A Live Feed Of Every ID __This__ Verification Company Scanned. For Over A Year.

The "This" in the the sentence serves an important role. It currently reads like all ID verification companies were compromised at the same time.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#179
post #35

And again, there will be no monetary consequences for the companies that failed to secure our private data.

I can't agree more strongly with this statement. It is mind-blowing how can it be socially acceptable to treat other people's confidential data so mindlessly

We should have a law which penalizes businesses for leaking other people's private data

Got John's driver license exposed? Write him $1k cheque. Second time this happened? Make it $3k. And another 1% of his assets, since you put them at risk. $10k in the bank? That's extra $100. Guy has property worth 500k? Too bad for you, that's another 5 thou.

And no blaming sub-contractors either. You hired them to do validation and they leaked data? Too bad, must have verified that they are reliable. This is when all of these Hertzies and Targets and Fedexes start thinking twice before storing confidential data. Why do they need to hold on to your driver's license? I know why. They hope to make some extra cash by datamining it. Well, get your checkbook ready then.

You are selling alcohol and wanna make sure I'm older than 21? You don't need to scan ID. You definitely don't need to store it. You CHOOSE to store it, and if you do, be prepared to pay if you expose it.

I wish it worked like that, but yeah, it never will

Re: Hackers had a live feed of every ID verification company scanned for over a year

#180
post #166

If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli... Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)

This comment is worrisome:

> My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.

Post reply on HN