Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

201–210 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#201
post #50

Earlier quoted context omitted.

I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.

> throw you in jail for expressing support for Palestine Action. For those unfamiliar, you are, of course, allowed to peacefully protest in support of Palestine in the UK. Palestine Action is a specific group that was controversially labelled as a terrorist group after they broke onto a runway and spray painted military planes. https://en.wikipedia.org/wiki/Palestine_Action

Which has now also been declared a terrorist organisation by the US, I believe, off the back of that.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#202
post #198

Earlier quoted context omitted.

im not particularly concerned myself, but any ban like you propose would almost certainly go up to age 12 (at least), making it effectively impossible to enforce. i see your other comment about guns, so just to preempt that a little bit: the internet is far more ubiquitously available than guns are.

I'm not feeling strongly about enforcement. The point would be to not have websites be liable if things go wrong, the way that breweries aren't responsible if some drunk teen drives to his death. Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky, but it doesn't mean that it shouldn't be banned.

>The point would be to not have websites be liable if things go wrong

im mostly on board with that.

>Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky

alcohol bans are way easier to enforce.

the internet is invisibly broadcast everywhere. most of my downtown & surrounding area has free wifi access. devices that can connect to the internet are also everywhere. phones, tablets, tvs, fridges, etc.

on the other hand, alcohol comes from licensed stores and requires a physical transaction to take place.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#203

Earlier quoted context omitted.

This comment is worrisome: > My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.

Wouldn't this also mean Gmail, Facebook, etc are no longer safe? The person can simply provide this documentation as proof they own the accounts and claim they were hacked.

Facebook is definitely safe. I provided my ID to try to regain access to a hacked account and they never even responded to the request.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#204
post #148

Earlier quoted context omitted.

The EU age verification system requires tying yourself to Google/Apple [0] (ie will not work with GrapheneOS) which is a non-starter. This means you will need a mandatory Google/Apple account. What if your Google account gets banned? [0] https://github.com/eu-digital-identity-wallet/av-doc-technic...

My Google account is in good standing but has other issues. In between startups and side projects I cannot link my phone number as it has been used "too many times". So apparently, to Google, if I want a new account or to set this up, I need a new phone number. Enquiries to support have gone as well as you'd expect with Google.

I have a gradfathered account from before Google Workspaces or whatever its name (Google Apps for Domains?) became a paid service, and it's in an extremely weird state after so many changes to what Google offers, integrates, fixes and unfixes, that I sometimes can't even login to Google services.

Ended up moving my mail and info from Google away, just not to deal with it.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#205
post #190

Earlier quoted context omitted.

And then there's the problem of undocummented / illegal immigrants that the US has, which nevertheless can often get some state services and have enough ID to pass by. Because it's a political issue, nobody can either legalize or deport them without getting into the political quagmire that is immigration reform. In functioning ID systems (and not having or wanting one is a valid political position which both the US a…

I'm not quite sure what immigration has to do with a national ID system in the US. Seems like you just wanted to bring that up to be able to say "man that'd be so much easier if you got rid of all the immigrants" which it would have no impact either way on this particular issue Also on the rotating schedule thing, driver's licenses expire in the US, usually on a 5-10 year cadence. Replacing the physical cards was not…

>driver's licenses expire in the US, usually on a 5-10 year cadence

Standard Arizona drivers licenses only expire when the licensee turns 65 years of age, and must be renewed every 5 years thereafter.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#206
post #120

Earlier quoted context omitted.

The difficulty for the US is people seem to be against a Federal Government ID. India doesn't seem to have this stigma and hence rural India can solve this problem.

I don't think people are against it, we already have the social security identifiers as a government layer... it's just that no one in the government is willing to do it for free in a way that is accessible to everyone

America has a substantial fundamentalist christian population who was handed a conspiracy theory about ID cards being a sign of the antichrist as depicted in Revelations decades ago and just will maintain that conspiracy theory for eternity.

The minimum size of this population, people who are adamant that the world is 10k years old, that god created everything as it currently is within those past 10k years, and therefore that all of science is a conspiracy in league with satan to deceive you from god, is about 30 million people. That's the percentage of Americans that willingly state such a belief when an alternative survey option is "Earth is old but god is still real and meaningful and doing everything" ie the current Catholic Dogma.

That exact same cohort is the singular reason for the Satanic Panic back in the 80s, for every child that "wasn't allowed" to participate in Halloween, for kids that weren't allowed to read Harry Potter because it "promoted witchcraft". These people insist we are in a constant and active war against actual physical demons that have infiltrated much of society. They believe they are losing this "war". They believe they are following God's orders. They believe anything is permissible in this war

Re: Hackers had a live feed of every ID verification company scanned for over a year

#208
post #31

> There is no safe age verification. There is no age verification that doesn’t put people at risk. There are zero knowledge proofs

Yep, and there are a variety of other schemes like OpenID Verifiable Credentials which allow you to prove things like age without giving away everything, too.

Collecting images of people’s ID is outdated and really shouldn’t be done.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#209
post #34

Earlier quoted context omitted.

I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.

The US Government is one of the reference implementations of PKI. Unfortunately, IDs are issued 50 different ways by the less competent states. Combine that with accusations that getting new IDs constitutes systematic racism (a widely held belief on HN), ignoring that the ruralest of India has been able to do this successfully, and you're not getting digital ID any time soon.

"India does it!" is not the absolute proof of a lack of racism that you believe it is.

For multiple reasons.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#210

Earlier quoted context omitted.

They do not care about 'secure' part at all.

This is the answer. The more failures, the more justification for more draconian restrictions of civil liberties. I can hear the defense now: "Oh, yeah, you blame the honest, good, handsome people trying their best to protect you and you let the hackers off scot-free! We must make sure that hackers don't have access to the tools that aid them to commit these crimes, like books and computers. Anyone could be a hacker.…

It already works like that. "Identity theft" is entirely framed as a problem for the citizen, affecting them and that it's their responsibility to resolve or face the consequences (credit score, collections, etc.) when all the citizen did "wrong" was choose an institution who cared more about profit than security. For the institution, all their obligation often seems to be is to "partner"[1] with a credit monitoring service.

[1] A credit monitoring service that will give the institution that "free 12 months" at a vastly reduced bulk rate because it knows that in order to sign up for free credit monitoring you actually sign up, with a card, for their top tier product (which might otherwise be $50+ a month) on what is effectively a 12 month trial after which they switch you over to a paid subscription (hell, there may even be commissions paid to the institution for anyone who neglects to cancel quickly enough). The incentives are so perverse.

Post reply on HN