We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’
That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain. The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know. I guess the awkward bit is market…
Hackers had a live feed of every ID verification company scanned for over a year
211–220 of 263 posts
Re: Hackers had a live feed of every ID verification company scanned for over a year
#212Brian Krebs' article is, in my opinion, a much better read for this story[0]. [0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
(2 days ago, 276 comments) https://news.ycombinator.com/item?id=49529621
FBI Probes Service Selling 153M+ Drivers Licenses - https://news.ycombinator.com/item?id=49529621 - Sept 2026 (290 comments)
Re: Hackers had a live feed of every ID verification company scanned for over a year
#213Isn't that weird that the very OBVIOUS AND SELF-EVIDENT ISSUES with requiring id to use the internet were, in fact, OBVIOUS AND SELF-EVIDENT ISSUES that were immediately taken advantage of?
Just so so weird. Who could have seen this coming?
Re: Hackers had a live feed of every ID verification company scanned for over a year
#214Re: Hackers had a live feed of every ID verification company scanned for over a year
#215Earlier quoted context omitted.
IDs being required for voting is essentially a poll tax the way that it's argued for in the US. There's a minimum amount you have to spend to even get one that will expire in a certain amount of years. That's also assuming you can get all the documents you need for the initial ID. If you don't already have all the essential documents you'll need multiple appointments at government facilities. The local social securit…
So… requiring an ID to buy a gun is also an unconstitutional tax on a right?
"The right of citizens of the United States to vote in any primary or other election for President or Vice President, for electors for President or Vice President, or for Senator or Representative in Congress, shall not be denied or abridged by the United States or any State by reason of failure to lay pill tax or other tax" - 24th amendment to the United States Constitution
Re: Hackers had a live feed of every ID verification company scanned for over a year
#216Brian Krebs' article is, in my opinion, a much better read for this story[0]. [0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
Re: Hackers had a live feed of every ID verification company scanned for over a year
#217Earlier quoted context omitted.
I still don't understand why the simplest approach isn't used: ban kids from using the Internet unsupervised. There's really no good reason why a six year old should have internet access.
The argument is that there are parents who are too stupid/lazy to enable parental controls on kids devices and society has a duty to protect kids even if their parents are negligent. Also, kids interact with other kids, so even if you do everything right your kids wind up with access/peer pressure through the kids with bad parents. I dunno if I agree but I think that's the thrust of it.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#218Earlier quoted context omitted.
I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.
eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs. Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem. Doesn't even need ZKP, the CA can just issue an attestation.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#219Brian Krebs' article is, in my opinion, a much better read for this story[0]. [0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
Thank you for gifting me a new layer of paranoia I didn't know existed until yesterday. Once you see you can't unsee.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#220> There is no safe age verification. There is no age verification that doesn’t put people at risk. There are zero knowledge proofs
Concrete ZKP age verification schemes are hardly zero knowledge. Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy. Now little Johnny borrows my ID, and uses it to setup some oracle that provide…