Earlier quoted context omitted.
Except this helps no child.
Isn't that the one that was left behind in 2002?
Hackers had a live feed of every ID verification company scanned for over a year
231–240 of 264 posts
Re: Hackers had a live feed of every ID verification company scanned for over a year
#232Earlier quoted context omitted.
I used to work for my state's DMV. They'd sell vehicle registration data to various companies, which is how and why you get those "we've been trying to reach you about your car warranty" phone calls. I don't know about CA, but KY had a problem with tracking who ordered and who paid for that data. When I worked there, we found a number of "purchasers" who only paid for Year 1 but stopped paying afterwards. Federal law…
I suppose one other industry interested in this information is the bounty hunter industry (bail enforcement). I believe there are several platforms for licensed bounty hunters where they can receive this and similar information about a person/vehicle.
One such platform used to be called Vigilant Systems. They'd sell details of where a car has passed a police/Flock ALPR camera, mostly to repo companies, but also bail/bounty hunters. Using details of license plate scans are more up-to-date than the DMV registration. People on the run from courts are extremely unlikely to keep their vehicle registration or driving licenses up to date.
https://www.youtube.com/watch?v=AKxkokoQdkc&t=238
The governing law is Driver's Privacy Protection Act.
https://en.wikipedia.org/wiki/Driver%27s_Privacy_Protection_...
Re: Hackers had a live feed of every ID verification company scanned for over a year
#233Earlier quoted context omitted.
This comment is worrisome: > My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.
I feel like that should require an in-person visit, as troublesome as that might be. A picture of an ID is not the same thing as presenting the actual ID
Re: Hackers had a live feed of every ID verification company scanned for over a year
#234Earlier quoted context omitted.
This is effectively the EU age verification system. Your government (which already has all your details) generates certificates and you just give those out. The other side can the use simple public/private key verification to ensure the cert is valid. Also government does not get information who you gave the cert to and if you create a bunch and single use them the other side can’t follow you between uses using the c…
The problem in the US is that the government doesn't necessarily have all of your details. Most people's ID is a driver's license, but you're not mandated to have one of those. The federal government doesn't control those databases (hi, REAL ID), and few people actually have passports. Your citizenship documents are just a birth certificate that is an image on file with a particular state's health department. A centr…
Cultural pushback has so far prevented such a system from being created. I hope that continues but am not optimistic.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#235Earlier quoted context omitted.
And then there's the problem of undocummented / illegal immigrants that the US has, which nevertheless can often get some state services and have enough ID to pass by. Because it's a political issue, nobody can either legalize or deport them without getting into the political quagmire that is immigration reform. In functioning ID systems (and not having or wanting one is a valid political position which both the US a…
I'm not quite sure what immigration has to do with a national ID system in the US. Seems like you just wanted to bring that up to be able to say "man that'd be so much easier if you got rid of all the immigrants" which it would have no impact either way on this particular issue Also on the rotating schedule thing, driver's licenses expire in the US, usually on a 5-10 year cadence. Replacing the physical cards was not…
It was explained right there in the comment. Illegal immigrants are often able to get services because the ID system is such a patchwork that they can manage to slip through the cracks.
And attempting to implement any sort of widespread centralized ID is going to be met with resistance not just from people such as myself but also from those who attempt to shield illegal aliens on the basis of opposing those who want to reduce immigration.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#236Earlier quoted context omitted.
I'm not quite sure what immigration has to do with a national ID system in the US. Seems like you just wanted to bring that up to be able to say "man that'd be so much easier if you got rid of all the immigrants" which it would have no impact either way on this particular issue Also on the rotating schedule thing, driver's licenses expire in the US, usually on a 5-10 year cadence. Replacing the physical cards was not…
>driver's licenses expire in the US, usually on a 5-10 year cadence Standard Arizona drivers licenses only expire when the licensee turns 65 years of age, and must be renewed every 5 years thereafter.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#237Earlier quoted context omitted.
eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs. Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem. Doesn't even need ZKP, the CA can just issue an attestation.
If the scan also included a picture, that was signed with your private key, then it would be harder to spoof.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#238Earlier quoted context omitted.
If the scan also included a picture, that was signed with your private key, then it would be harder to spoof.
Not really, the attacker would just need a picture of you which he could then sign (since we're assuming here that he gained access to your key IIUC). That's a pretty low bar compared to the first step of gaining the key.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#239Earlier quoted context omitted.
> I don't think people are against it Every time national ID gets moderately serious discussion it is revealed very clearly that yes, the people are against it. RealID—which was simply national standardization of state issued ID (when used for a variety of important purposes) had intense resistance, too—and its the closest policy to national ID that has passed. Social Security identifiers are not ID for the person, a…
People are against national IDs because of privacy, not racism like a previous comment in this thread suggested People are against requiring certain types of IDs to vote as racism or other forms of voter suppression because it may cost money to get those IDs or be very very hard to do so, when there are other methods to authenticate a person for voting Those are two separate issues and complaints.
When I lived near the ghetto in a different state I had roughly 2 choices, one 30 minutes out and the other over an hour (by car without traffic). Bus? Hah! Have fun. Arriving at the nearer of the two within an hour or so of opening in the morning there was already a multi-hour line for service.
Don't worry though, there's definitely not any sort of institutional racism behind the various efforts to require certain forms of ID to vote. /s
Re: Hackers had a live feed of every ID verification company scanned for over a year
#240Earlier quoted context omitted.
I don't think people are against it, we already have the social security identifiers as a government layer... it's just that no one in the government is willing to do it for free in a way that is accessible to everyone
America has a substantial fundamentalist christian population who was handed a conspiracy theory about ID cards being a sign of the antichrist as depicted in Revelations decades ago and just will maintain that conspiracy theory for eternity. The minimum size of this population, people who are adamant that the world is 10k years old, that god created everything as it currently is within those past 10k years, and there…