Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

31–40 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#33
post #14

Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…

On the end of the day, it is the state that issues these ID documents. So if you let the government go bad, IMHO the form of the documents does not matter that much.

During the totalitarian communist rule in Czechoslovakia, the state would regularly interfere with passports of people considered not loyal enough - withholding them outright or inventing extra paperwork that was necessary for the border police to let you out of the country. They also controlled all supply of foreign currency, both in an out.

Then if someone was actually allowed to travel outside the country but failed to return, their family and relatives would be punished, including demotion at work & prohibition of higher education.

So if your government goes bad, this is what will happen - the form of the ID takes at that point does not make much difference.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#34
post #29

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…

I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through.

The alternative is do it offline.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#36
post #35

And again, there will be no monetary consequences for the companies that failed to secure our private data.

And governments will continue to force citizens to use these shitty companies for whenever they need id verification.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#37
post #8

The HN submission title is a garden-path sentence: Hackers Had a Live Feed of Every ID Verification Company Scanned (Huh? How do you scan a company?) The original title is easier to parse: Hackers Had A Live Feed Of Every ID This Verification Company Scanned

Thank you, it was very confusing indeed, the HN post should be fixed to something directly clearer

Re: Hackers had a live feed of every ID verification company scanned for over a year

#38
We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible.

‘Just make the encryption secure and so we can read it’

‘Just check everyone’s id but make it totally secure’

Re: Hackers had a live feed of every ID verification company scanned for over a year

#39
post #20

Earlier quoted context omitted.

Are you sure? It’s really hard to differentiate nowadays

> Are you sure? It’s really hard to differentiate nowadays Case in point; I can't tell if you're being sarcastic or not! :D

I cant event tell if you are being sarcastic or not :)

Re: Hackers had a live feed of every ID verification company scanned for over a year

#40

I wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!

You know, it always bugged me that the NSA (and more directly Google, and my phone company, and so on) know where I was at exactly this time a year ago, but that I do not.
Post reply on HN