Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

101–110 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#101

Earlier quoted context omitted.

We also have a Danish wallet now, AltID, which implements an anonymized (assuming no collusion between issuer and eavesdropper or service provider) age verification protocol based on batches of single-use tokens which contain no personal information (except that they can be traced back to you by the issuer). It's been released and in production since summer. Since then, several social networks have apparently started…

In 2027 it will become mandatory for big tech to accept the EU digital wallets, so soonish they'll have to integrate with them.

Well, that's at least a positive. I hope this means they are also forced to accept the weakest credential type, and that they can't require you to present the identity proof that the wallet also provides when verifying your age. Because if they are allowed to do that, then that is what will happen.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#102
post #50

Earlier quoted context omitted.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.

It would be best for any such ID system to capture only the minimum data to fulfil their function. Pre-WW2 Dutch records also listed religion, which made it very easy for the Nazis to round up and murder them. Some examples from Kansas show that even recording sex/gender is risky - state law requires driving licenses to record the original sex/gender from the first birth certificate leading to trans women having an M sex/gender marker getting arrested and prosecuted for identity fraud.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#103
post #6

If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.

CADMV claims on their web site that they cannot accept a P.O. box as a residence address. I have yet to find anything in California state law supporting this policy, though IANAL. Their enforcement seems to be quite lax.

It is a REAL ID requirement. It is federal law. States issuing REAL ID compliant identity documents must mail them to your physical address. USPS provides that data for address validation.

DPVCMRA = delivery point is a commercial mail receiving agent. Any sort of location with PO Boxes.

https://developers.usps.com/addressesv3#tag/Resources/operat...

Disclaimer: I used to work for my state's DMV.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#104

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’

They do not care about 'secure' part at all.

This is the answer. The more failures, the more justification for more draconian restrictions of civil liberties.

I can hear the defense now: "Oh, yeah, you blame the honest, good, handsome people trying their best to protect you and you let the hackers off scot-free! We must make sure that hackers don't have access to the tools that aid them to commit these crimes, like books and computers. Anyone could be a hacker."

Re: Hackers had a live feed of every ID verification company scanned for over a year

#105
post #15
post #6

If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.

Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?

I used to work for my state's DMV. They'd sell vehicle registration data to various companies, which is how and why you get those "we've been trying to reach you about your car warranty" phone calls. I don't know about CA, but KY had a problem with tracking who ordered and who paid for that data. When I worked there, we found a number of "purchasers" who only paid for Year 1 but stopped paying afterwards.

Federal law requires state DMVs to supply that data to the car manufacturers. So if you own a Chevy, they have to send your data to Chevy in case there is a recall.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#106
post #35

And again, there will be no monetary consequences for the companies that failed to secure our private data.

And governments will continue to force citizens to use these shitty companies for whenever they need id verification.

That's why I say "Our lobbyists have more money than your lobbyists". Every state has sunshine laws to show who the lobbyists are, what they lobbied on, and to whom. Some states separate those lobbyists into legislative & executive branch lobbying.

I suggest you look at who voted for those bills, who lobbied them and who hired those lobbyists.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#107
post #34
post #29

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…

I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.

The US Government is one of the reference implementations of PKI.

Unfortunately, IDs are issued 50 different ways by the less competent states.

Combine that with accusations that getting new IDs constitutes systematic racism (a widely held belief on HN), ignoring that the ruralest of India has been able to do this successfully, and you're not getting digital ID any time soon.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#108

Earlier quoted context omitted.

It also dropped off the front page, pretty quickly, despite getting a lot of upvotes and comments. I was surprised by that, as this is exactly the type of story that tends to spend a couple of days on the front page. But it’s also the kind of story that won’t stay down, and will definitely be back. It appears as if there are folks here that don’t want to talk about this.

Was on the front page for ~12 hours. https://hnrankings.com/49529621

Hadn’t seen this site! More detailed alternative: https://news.social-protocols.org/stats?id=49529621

Re: Hackers had a live feed of every ID verification company scanned for over a year

#109
post #71

Earlier quoted context omitted.

Government systems leak information all the time. The type of institution managing the data makes little difference. Its how the institution manages the data that matters.

But the government inherently has that data, as it comes from there. They're the ones issuing the IDs in the first place. Theres no avoiding this, structurally. So the best thing you can do is not to introduce any additional points of failure.

All previous systems avoided this. The government issued me an ID in the past, yet had no record of when I used it, or for what.

I am so much more afraid of monopolies invading my privacy than roving hackers, or my corner store. Governments are the ultimate monopoly.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#110

Earlier quoted context omitted.

I understand the sentiment, but your government you can actually fix by voting. If Apple (or another large international company) suffers from decreasing margins, gets a new CEO and decides to turn the data it sits on into money there is absolutely nothing you can do, and you might in fact still stay a "forced" customer because of network effects (=> just consider whatsapp being an important communication channel in…

You can fix companies by voting a government too. In fact, governments are quicker at fixing companies than themselves.

Sure but even when it works it slower and less total than good policy. Of course, good policy is a rare bird, too.
Post reply on HN