Earlier quoted context omitted.
This is effectively the EU age verification system. Your government (which already has all your details) generates certificates and you just give those out. The other side can the use simple public/private key verification to ensure the cert is valid. Also government does not get information who you gave the cert to and if you create a bunch and single use them the other side can’t follow you between uses using the c…
The EU age verification system requires tying yourself to Google/Apple [0] (ie will not work with GrapheneOS) which is a non-starter. This means you will need a mandatory Google/Apple account. What if your Google account gets banned? [0] https://github.com/eu-digital-identity-wallet/av-doc-technic...
Hackers had a live feed of every ID verification company scanned for over a year
191–200 of 263 posts
Re: Hackers had a live feed of every ID verification company scanned for over a year
#192If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli... Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)
This comment is worrisome: > My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#193Earlier quoted context omitted.
I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)
> think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account) It is not true. You can move passkeys between OSs if you have a password manager or an OS that has this ability. For example, I store my Passkeys in iCloud Keychain and I have them synced on all my Apple devi…
Re: Hackers had a live feed of every ID verification company scanned for over a year
#194Earlier quoted context omitted.
The argument is that there are parents who are too stupid/lazy to enable parental controls on kids devices and society has a duty to protect kids even if their parents are negligent. Also, kids interact with other kids, so even if you do everything right your kids wind up with access/peer pressure through the kids with bad parents. I dunno if I agree but I think that's the thrust of it.
There are systems in place dealing with negligent parents. They could be better, but they exist. If kids were banned, there couldn't be that much peer pressure. Think about it, how many kids will get a gun just because some of the kids have access to guns through their negligent parents? If it's banned the path to getting it won't be straightforward.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#195Earlier quoted context omitted.
I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)
Yes, you can. Either you can physically own the key on the physical device (i.e. Yubikey/Google Titan/HSM) or you can use software (KeepassXC, Bitwarden). Most operating systems and browsers come with a sync mechanism that many people default to, but it's no more than that: the default. As for account recovery, most websites have a way to recover your account when you lose your password, there's no reason why that wo…
Assuming the FIDO Consortium approves. Otherwise you might be like KeePass, being unceremoniously threatened with revocation of attestation, for offering to do what the big players are able to do.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#196Earlier quoted context omitted.
I feel like that should require an in-person visit, as troublesome as that might be. A picture of an ID is not the same thing as presenting the actual ID
I think Pope Leo would respectfully disagree. https://www.nytimes.com/2026/05/05/us/pope-leo-xiv-bank-cust...
Re: Hackers had a live feed of every ID verification company scanned for over a year
#197Earlier quoted context omitted.
There are systems in place dealing with negligent parents. They could be better, but they exist. If kids were banned, there couldn't be that much peer pressure. Think about it, how many kids will get a gun just because some of the kids have access to guns through their negligent parents? If it's banned the path to getting it won't be straightforward.
Well I guess this begs the question how do you implement this ban without checking ids?
Sure, your parents can give you access, but your parents could also give you booze, porn and guns if they feel so inclined.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#198Earlier quoted context omitted.
I don't think I care as much for a twelve year old seeing age inappropriate things, as that is what I was seeking out and enjoying at that age. And that was before Internet was a thing people had in their homes. I was watching horror movies like Alien and Terminator uncut on VHS.
im not particularly concerned myself, but any ban like you propose would almost certainly go up to age 12 (at least), making it effectively impossible to enforce. i see your other comment about guns, so just to preempt that a little bit: the internet is far more ubiquitously available than guns are.
Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky, but it doesn't mean that it shouldn't be banned.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#199Earlier quoted context omitted.
eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs. Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem. Doesn't even need ZKP, the CA can just issue an attestation.
I've experienced this "solved problem" when visiting Germany during COVID. On every entrance to a mall there was somebody with a scanner device, and they only let you in if the scanner showed a green mark. I've been fully vaccinated (not EU) but my code didn't show a green mark on their scanner and I was promptly denied entry. The solution was to show them my German friend's code on my phone, this registered just fin…
If you’re genuinely interested, look into things like OpenID credentials systems, and similar standards like w3c verifiable credentials.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#200If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli... Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)
Mr Krebs is dealing with all this mayhem and idiocy with remarkable sang froid if I may say so. Good heavens.