Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

191–200 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#191
post #148
post #117

Earlier quoted context omitted.

This is effectively the EU age verification system. Your government (which already has all your details) generates certificates and you just give those out. The other side can the use simple public/private key verification to ensure the cert is valid. Also government does not get information who you gave the cert to and if you create a bunch and single use them the other side can’t follow you between uses using the c…

The EU age verification system requires tying yourself to Google/Apple [0] (ie will not work with GrapheneOS) which is a non-starter. This means you will need a mandatory Google/Apple account. What if your Google account gets banned? [0] https://github.com/eu-digital-identity-wallet/av-doc-technic...

My Google account is in good standing but has other issues. In between startups and side projects I cannot link my phone number as it has been used "too many times". So apparently, to Google, if I want a new account or to set this up, I need a new phone number. Enquiries to support have gone as well as you'd expect with Google.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#192
post #166

If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli... Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)

This comment is worrisome: > My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.

Wouldn't this also mean Gmail, Facebook, etc are no longer safe? The person can simply provide this documentation as proof they own the accounts and claim they were hacked.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#193

Earlier quoted context omitted.

I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)

> think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account) It is not true. You can move passkeys between OSs if you have a password manager or an OS that has this ability. For example, I store my Passkeys in iCloud Keychain and I have them synced on all my Apple devi…

But you don't own your passkey. That's the biggest red flag. It's yet another wall by apple to prevent you from leaving their ecosystem

Re: Hackers had a live feed of every ID verification company scanned for over a year

#194
post #173
post #97

Earlier quoted context omitted.

The argument is that there are parents who are too stupid/lazy to enable parental controls on kids devices and society has a duty to protect kids even if their parents are negligent. Also, kids interact with other kids, so even if you do everything right your kids wind up with access/peer pressure through the kids with bad parents. I dunno if I agree but I think that's the thrust of it.

There are systems in place dealing with negligent parents. They could be better, but they exist. If kids were banned, there couldn't be that much peer pressure. Think about it, how many kids will get a gun just because some of the kids have access to guns through their negligent parents? If it's banned the path to getting it won't be straightforward.

Well I guess this begs the question how do you implement this ban without checking ids?

Re: Hackers had a live feed of every ID verification company scanned for over a year

#195

Earlier quoted context omitted.

I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)

Yes, you can. Either you can physically own the key on the physical device (i.e. Yubikey/Google Titan/HSM) or you can use software (KeepassXC, Bitwarden). Most operating systems and browsers come with a sync mechanism that many people default to, but it's no more than that: the default. As for account recovery, most websites have a way to recover your account when you lose your password, there's no reason why that wo…

> Most operating systems and browsers come with a sync mechanism that many people default to, but it's no more than that: the default.

Assuming the FIDO Consortium approves. Otherwise you might be like KeePass, being unceremoniously threatened with revocation of attestation, for offering to do what the big players are able to do.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#196
post #181

Earlier quoted context omitted.

I feel like that should require an in-person visit, as troublesome as that might be. A picture of an ID is not the same thing as presenting the actual ID

I think Pope Leo would respectfully disagree. https://www.nytimes.com/2026/05/05/us/pope-leo-xiv-bank-cust...

I almost mentioned that situation in my reply, but that's kind of the exception that proves the rule. Even in that case, someone should need to physically intervene, especially with high profile people like politicians or celebrities

Re: Hackers had a live feed of every ID verification company scanned for over a year

#197
post #194
post #173

Earlier quoted context omitted.

There are systems in place dealing with negligent parents. They could be better, but they exist. If kids were banned, there couldn't be that much peer pressure. Think about it, how many kids will get a gun just because some of the kids have access to guns through their negligent parents? If it's banned the path to getting it won't be straightforward.

Well I guess this begs the question how do you implement this ban without checking ids?

Your ISP knows this already, doesn't it? Internet cafés can ask for ID.

Sure, your parents can give you access, but your parents could also give you booze, porn and guns if they feel so inclined.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#198
post #171

Earlier quoted context omitted.

I don't think I care as much for a twelve year old seeing age inappropriate things, as that is what I was seeking out and enjoying at that age. And that was before Internet was a thing people had in their homes. I was watching horror movies like Alien and Terminator uncut on VHS.

im not particularly concerned myself, but any ban like you propose would almost certainly go up to age 12 (at least), making it effectively impossible to enforce. i see your other comment about guns, so just to preempt that a little bit: the internet is far more ubiquitously available than guns are.

I'm not feeling strongly about enforcement. The point would be to not have websites be liable if things go wrong, the way that breweries aren't responsible if some drunk teen drives to his death.

Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky, but it doesn't mean that it shouldn't be banned.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#199
post #116
post #92

Earlier quoted context omitted.

eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs. Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem. Doesn't even need ZKP, the CA can just issue an attestation.

I've experienced this "solved problem" when visiting Germany during COVID. On every entrance to a mall there was somebody with a scanner device, and they only let you in if the scanner showed a green mark. I've been fully vaccinated (not EU) but my code didn't show a green mark on their scanner and I was promptly denied entry. The solution was to show them my German friend's code on my phone, this registered just fin…

That’s not what the new schemes are about, and they aren’t going to be based on a qr code you can just copy, no.

If you’re genuinely interested, look into things like OpenID credentials systems, and similar standards like w3c verifiable credentials.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#200
post #166

If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli... Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)

> "The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit."

Mr Krebs is dealing with all this mayhem and idiocy with remarkable sang froid if I may say so. Good heavens.

Post reply on HN