22 comments

  • ethagnawl2 hours ago
    I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced&#x2F;REAL ID.<p>Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which gets cross-referenced by the legit provider against the id.gov database.<p>Of course the devil is in the details and I wouldn&#x27;t trust GrandePelotas and friends to vibe code such a system but it is absolutely possible and is something we should, at the very least, be thinking about.
    • swingboy11 minutes ago
      This would probably be considered “disenfranchising” because people would have a hard time keeping track of their public key and the process to recover it would involve having to take off work, transportation, etc.
      • lcnPylGDnU4H9OF3 minutes ago
        That could alternatively be seen as a reason we should make employment less hostile to workers and encourage less car-centric city designs.
    • ericmay1 hour ago
      Which “normal, modern countries” have done variations of this?
      • embedding-shape47 minutes ago
        Not sure I&#x27;d call it &quot;normal&quot;, we&#x27;re exceptional! :) But Spain does have this, I have a literal digital certificate linked to my name, sitting in my browser, that I use for logging in to various government services and also use to sign+submit my taxes. Apparently there even is a page in English explaining how it works, in case others are interested: <a href="https:&#x2F;&#x2F;www.fnmt.es&#x2F;en&#x2F;ceres" rel="nofollow">https:&#x2F;&#x2F;www.fnmt.es&#x2F;en&#x2F;ceres</a><p>&gt; The CERES project (Spanish Certification) headed by the FNMT-RCM consists of establishing a Public Certification Entity that will enable authentication and guarantee the confidentiality of communications between citizens, companies or other institutions and the Public Administrations via the open communication networks.<p>So far, in my ~decade here, it&#x27;s been working out great and is so easy to use.
      • MilaM24 minutes ago
        Most European countries offer some kind of government issued digital ID to their citizens, although adoption varies by country. I know two implementations first-hand and use them regularly. They work really well to prove your identity over the Internet. You can use it to open a bank account or use government services.<p>The next step will be EU-DI, an app based wallet with many more features and hopefully better interoperability between EU countries.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Electronic_identification#Usage_of_eID_systems_in_Europe" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Electronic_identification#Usag...</a><p><a href="https:&#x2F;&#x2F;ec.europa.eu&#x2F;digital-building-blocks&#x2F;sites&#x2F;spaces&#x2F;EUDIGITALIDENTITYWALLET&#x2F;pages&#x2F;694487738&#x2F;EU+Digital+Identity+Wallet+Home" rel="nofollow">https:&#x2F;&#x2F;ec.europa.eu&#x2F;digital-building-blocks&#x2F;sites&#x2F;spaces&#x2F;EU...</a>
        • ericmay2 minutes ago
          Interesting that some of these, including some from the Nordic countries are actually run by financial institutions and not the government.
      • ShowalkKama1 hour ago
        Italy doesn&#x27;t have crypto keys (as the average person would just lose&#x2F;leak them) but they offer SSO login with the ID card. Basically whenever you need to verify your identity you pick &quot;sign in with CIEid&quot;, you get redirected to a goverment website where you can authenticate (typically by scanning a qr code + scanning your physical id card on your phone) and then you approve&#x2F;deny the authentication request (you can also clearly see which data is shared (name, last name, dob, etc)).<p>it&#x27;s stupid easy to setup, the app is not overly bloated and it has different options to authenticate.
      • bnkd9255 minutes ago
        UAE has an app called « UAE Pass », and the Emirates ID itself uses Public Key Infrastructure.<p>The private key itself is locked into the Emirates ID, and need my biometrics to unlock.<p>Example: When I get delivery that needs my ID, the delivery man just put my Emirates into a card reader, and they need my biometrics to digitally sign the receipt.<p>It’s often used for important delivery (banks&#x2F;gov documents), and any related gov services (including telecom, if i want to reload my sim card but forgot my pin, i can just insert my Emirates ID and scan my fingerprint and it retrives my SIM card by magic!)<p>You can try to read how they are doing the Emirates ID and the UAE Pass app, it’s super interesting to see this so well intergrated and at scale.
      • Levitating1 hour ago
        European passports are NFC tags and you can prove your identity using your phone.
        • ericmay59 minutes ago
          I think American passports have those as well because I remember all the hax0rs making videos showing where to smash the NFC chip with a hammer or to buy wallets with special NFC blocking properties to keep folks from “stealing their identity” from the NFC chip. Personally I never cared but your comment jogged a memory.<p>Recently I added my passport to my Apple wallet but I’m not sure if that’s used anywhere.
      • ethagnawl1 hour ago
        Denmark, for one: <a href="https:&#x2F;&#x2F;lifeindenmark.borger.dk&#x2F;apps-and-digital-services&#x2F;mitid" rel="nofollow">https:&#x2F;&#x2F;lifeindenmark.borger.dk&#x2F;apps-and-digital-services&#x2F;mi...</a>
      • Tangurena241 minutes ago
        Estonia has done several versions of this. One is a &quot;digital nomad&quot; visa that includes a card with digital keys to do business <i>in</i> Estonia while not living there.<p><a href="https:&#x2F;&#x2F;www.e-resident.gov.ee&#x2F;nomadvisa&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.e-resident.gov.ee&#x2F;nomadvisa&#x2F;</a><p>The design standard for US &amp; Canadian driving licenses &amp; ID cards allows for chips on them. Page 27 of<p><a href="https:&#x2F;&#x2F;www.aamva.org&#x2F;getmedia&#x2F;99ac7057-0f4d-4461-b0a2-3a5532e1b35c&#x2F;AAMVA-2020-DLID-Card-Design-Standard.pdf" rel="nofollow">https:&#x2F;&#x2F;www.aamva.org&#x2F;getmedia&#x2F;99ac7057-0f4d-4461-b0a2-3a553...</a><p>A pet hobby of mine is to get my state to adopt something similar to the Estonian standard. With a card reader, one would be able to vote from home with the election board being confident that the vote was cast by an authorized voter. This would address the fearmongering by one political party that has been going on since some black dude got elected President. Other things could include signing tax returns online.<p>Since REAL ID, getting a driving license&#x2F;ID is a lot more controlled.
    • iAMkenough1 hour ago
      And just like the government backpedaled on the Real ID deadline, the federal government is backpedaling on login.gov and is still actively launching agencies on private third-party id.me identity verification.
  • Nition9 hours ago
    The thing that really gets me about this one is that surely you can easily just delete the data after you&#x27;ve verified someone? But instead they decided to keep 153,347,439 of them.
    • krebsonsecurity1 hour ago
      Deleting the data after verification is a good practice. But if you&#x27;re actively compromised, it probably doesn&#x27;t matter how long you keep the data because it&#x27;s already been immediately &quot;backed up&quot; by the intruders the second it is collected.<p>Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies &quot;storing&quot; full credit card records, when in reality the attackers had card-sniffing malware installed on every single cash register at every single store across the country.
      • ericmay1 hour ago
        Ideally it’s not even stored…
        • Tangurena230 minutes ago
          In the Heartland data breach, the custom malware that hackers wrote copied the mag stripe as it passed through the payment system. I got a new credit card after that broke (also after Target&#x27;s breach was reported). Heartland did not store the card details at all.<p>How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type <i>dir</i> or <i>ls</i> at a command prompt, it says something like &quot;X files using Y bytes, Z bytes free&quot;. How do you know those numbers are true&#x2F;correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out).<p>Heartland - #19, Target - #20 at:<p><a href="https:&#x2F;&#x2F;www.upguard.com&#x2F;blog&#x2F;biggest-data-breaches-us" rel="nofollow">https:&#x2F;&#x2F;www.upguard.com&#x2F;blog&#x2F;biggest-data-breaches-us</a><p>You may notice that the poster of the comment you are responding to is mentioned a lot on that page.
        • tbrownaw1 hour ago
          Well at least they need it until they get back a success response from the bank&#x2F;payment processor&#x2F;whoever.
    • analog319 hours ago
      I believe we need to criminalize possession of the data, with statutory damages per violation.
      • analog3119 minutes ago
        Commenting on my own post, I should expand a bit on &quot;statutory damages.&quot; I got the idea from the music industry, where there are automatic civil damages for copying recordings. If you&#x27;re caught, you get to pay X dollars per item.<p>This means the police don&#x27;t get involved. The only thing you need is a tort lawyer willing to take a share of the damages. Also, a data breach is proof that you possessed the data.<p>A business wouldn&#x27;t be able to reduce their liability exposure to zero, but to an acceptably low level, for instance by actively erasing the data before a breach can occur.
      • wolvoleo3 hours ago
        Isn&#x27;t that the case already? Here in many European countries it already is. They&#x27;re always warning about that when there&#x27;s a big breach and people download it to see what&#x27;s in it about them. Not that they&#x27;re going to prosecute half the country of course but still.
        • herbst1 hour ago
          There are also very very strict rules for companies that use or process this kinda of data and how they need to save and handle it. Hence why it&#x27;s basically illegal to use US based services for anything with real data these days.<p>I wish it would be more enforced and controlled tho.
      • CamperBob27 hours ago
        Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.
        • londons_explore4 hours ago
          Estonia has it&#x27;s ID cards which can sign things....<p>That suddenly means a data leak doesn&#x27;t matter - nobody can make new signatures.<p>Verifying someone&#x27;s ID would be as simple as asking them to sign your company name and today&#x27;s date.
          • mschuster914 hours ago
            The problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about &quot;mark of the beast&quot;, the Democrats and the ACLU fear them being used as part of a surveillance state.<p>[1] <a href="https:&#x2F;&#x2F;www.nyclu.org&#x2F;commentary&#x2F;letter-beware-mark-beast-wall-street-journal" rel="nofollow">https:&#x2F;&#x2F;www.nyclu.org&#x2F;commentary&#x2F;letter-beware-mark-beast-wa...</a>
            • vidarh2 hours ago
              You don&#x27;t need a national ID card scheme to do this, though.<p>The EU&#x2F;EEA is rolling out a digital identity mechanism with interoperable wallets that can hold any range of identity documents and other credentials. You don&#x27;t need to pick a single wallet provider - several EU countries are approving multiple, including private providers. You don&#x27;t need to standardise on a single ID.<p>This is already the case for many already in-use ID solutions in Europe. E.g. in Norway, there are at least 3 signing providers, and only one provider is government issued - the by far most popular (BankID) is private. You identify yourself to the provider when requesting issuance, not to the government (unless you sign up with a government provider).
            • alistairSH4 hours ago
              Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver&#x27;s license, and whatever else.<p>If we, collectively, don&#x27;t want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed).<p>We&#x27;ll get there eventually, but not before we try everything else first.
              • cucumber37328423 hours ago
                &gt;Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver&#x27;s license, and whatever else.<p>&quot;They can already send a drone to watch you and track your cell location and, and, and, why does it matter if they also slap up a million AI powered cameras?&quot;<p>The comprehensiveness of the system matters.
                • alistairSH1 hour ago
                  Not sure how you jump from &quot;ID with chip&quot; to &quot;AI-based drone and camera network&quot;. We can do one without the other.
                  • skinfaxi25 minutes ago
                    They are already doing the camera thing with flock.
            • bayindirh2 hours ago
              &gt; the Democrats and the ACLU fear them being used as part of a surveillance state.<p>AFAICS from the other side of the pond, United States Government can track people well enough even without a national ID card. They have successfully worked around that problem.<p>So, it&#x27;s a moot point now. No?
            • nobodyandproud3 hours ago
              I grew up in that tradition, so I can shed some light: The fear of a national ID isn’t just about tracking and privacy, but that an individual cannot participate in society or survive if the government decides to revoke the id.<p>Meaning, I can’t buy food; rent or buy a home; or hold any sort of job and earn and save.<p>What we have today isn’t better, but until recently I was hard pressed to see how such fears were even warranted.
              • Tangurena221 minutes ago
                &gt; <i>The fear of a national ID isn’t just about tracking and privacy, but that an individual cannot participate in society or survive if the government decides to revoke the id.</i><p>This is because the US made a critical flaw by tying the authentication and authorization tokens into one single token - your driving license&#x2F;ID. They should be separate things. Your authentication token (who are you?) should have your picture and be forgery resistant. Your authorization token (what can you do?) should be a piece of plastic with zero pictures (like your insurance card). Did you get stopped for DUI? The officer takes your authorization token, instead, the officer confiscates both tokens and hands you a paper receipt.<p>The FAA does it the smart way, your authorization token (pilot&#x27;s license) has no photo. You do something stupid, the ATC tells you to &quot;call this number&quot; and if it is really badly stupid, then the local FAA person confiscates your authorization token.
              • iamnothere2 hours ago
                Exactly. You do not want to hand the US government the ability to “turn off” someone’s daily life at the press of a button.<p>Things are already bad enough as it is, but at least it’s still possible to get by even if the system takes a dislike to you.
                • embedding-shape2 hours ago
                  &gt; Exactly. You do not want to hand the US government the ability to “turn off” someone’s daily life at the press of a button.<p>If you&#x27;re within the borders of the US, this ability already exists, they have a monopoly on violence in the country, something the government is very eager to demonstrate this year.
                  • r3trohack3r32 minutes ago
                    &gt; they have a monopoly on violence in the country<p>I have not seen a definition of this that is simultaneously true and useful<p>The sole provider of violence in the U.S. is not the government.
                  • iamnothere1 hour ago
                    There’s a lot of room between violence and financial isolation. The government has shown multiple times that it is willing to go after otherwise law-abiding citizens who take up disfavored careers, whether it’s gun dealers and payday lenders in Operation Choke Point, cannabis dispensaries in states where it was legal, or online cam girls. In all of these cases, going to cash or using alternatives to the banking system was possible and even necessary for them to survive.
                    • embedding-shape1 hour ago
                      And none of those examples you use, involve SSNs, these are all 100% paperless people&#x2F;companies? Makes me wonder how they got bank accounts in the first place if they&#x27;re so disconnected from society.
                      • iamnothere1 hour ago
                        The individuals had SSNs, but did not have a hypothetical national ID connected to systems that could have been used to fully isolate them. As long as backchannels exist in the system to accommodate those without SSNs&#x2F;DLs, it is possible to get by even if the system tries to cut you off.
                        • embedding-shape50 minutes ago
                          &gt; As long as backchannels exist in the system to accommodate those without SSNs&#x2F;DLs, it is possible to get by even if the system tries to cut you off<p>And again, as long as backchannels exists in the system to accommodate those without a Government ID, it is possible to get by even if the system tries to cut you off.<p>Don&#x27;t you see and understand you already have government ID? You&#x27;re just calling it by another name...
                          • iamnothere9 minutes ago
                            Once the official ID exists, those backchannels will be cut off, as they have been in much of Europe.
              • embedding-shape2 hours ago
                &gt; but that an individual cannot participate in society or survive if the government decides to revoke the id<p>What would happen today if your government revokes a SSN which is your de facto &quot;personal identification number&quot; today? Can you still rent&#x2F;buy a home? Can you have a job?
                • iamnothere2 hours ago
                  Some US citizens don’t even have SSNs, believe it or not. The Amish get by just fine.
                  • embedding-shape2 hours ago
                    Is it generally considered that The Amish &quot;participates in society&quot;? I thought the whole point for them was that they&#x27;re &quot;outside of modern society&quot;, to some degree at least.
                    • iamnothere1 hour ago
                      They participate in their own society, which allows them to survive in their own way. In other countries, national IDs have often been followed by mandatory registration requirements for renting or owning property, employment, etc. At present there are ways to get around using ID for many things, and it should stay that way.
                • nobodyandproud2 hours ago
                  Before my time, but I believe SSN was and probably still is controversial in my circle. I definitely recall rumblings about it even 30 years ago.<p>But while cash is printed (physical currency): Not having an SSN becomes a major impediment but not impossible to make transactions and survive.<p>Our migrant workers—who are basically carrying white collar workers like me—are proof of this.
                  • embedding-shape1 hour ago
                    Isn&#x27;t all of those cases then also proof that if the SSN was a government ID instead, all of those things would have been the same? The ID wouldn&#x27;t &quot;impossible to make transactions and survive&quot;, just an impediment, just like not having a SSN is today.<p>Point is, the US already basically have a de facto &quot;ID card&quot;, they just don&#x27;t call it as such (yet?), so claiming somehow correctly labeling this thing would make things worse or more difficult, doesn&#x27;t make much sense.
            • lotsofpulp3 hours ago
              A national ID card scheme has existed for many decades. It’s called a passport.<p>There is no reason a digital equivalent can’t be made using the passport system, and it can be left optional, just like passports are optional.
              • logifail2 hours ago
                &gt; just like passports are optional<p>&quot;Border controls aren’t supposed to exist between EU member states – that’s the promise of the 1985 Schengen treaty. Yet today, travelers routinely face checks when crossing borders within the [European] union&quot;<p><a href="https:&#x2F;&#x2F;euobserver.com&#x2F;198454&#x2F;law-professor-sues-germany-for-illegal-border-controls&#x2F;" rel="nofollow">https:&#x2F;&#x2F;euobserver.com&#x2F;198454&#x2F;law-professor-sues-germany-for...</a>
                • lotsofpulp1 hour ago
                  What relevance does that have to the US federal government offering a digital ID verification system on top of existing passport infrastructure?<p>EU did border checks without digital IDs being a thing, so why couldn’t US states do a border check without digital IDs?<p>Digital IDs are not a causal factor for these concerns, seeing as how those government abuses already happen without digital IDs.
        • GJim1 hour ago
          &gt; Exactly. Personal data should be treated like radioactive material<p>The GDPR in a nutshell......<p>Unnecessary personal data is a liability.
          • Tangurena218 minutes ago
            The GDPR comes from a different direction - you own the data about yourself, no matter where it is stored.<p>In the US, courts have ruled that the compiler of data owns all that data - you have no control about data about yourself (except in a few legal categories like credit reporting). Some of these old court rulings covered telephone books and business directories.<p>&gt; <i>Unnecessary personal data is a liability.</i><p>Absolutely.
      • akshatjiwan8 hours ago
        Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the &#x27;protected&#x27; status of digital storage is actually maintained. What&#x27;s worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.
      • raverbashing3 hours ago
        It would be fun if the GDPR naysayers end up coming up to the same conclusion
        • GJim1 hour ago
          A significant percentage of HN posters and readership are those working in US AdTech, who&#x27;s very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic slants towards opposing decent privacy laws.
      • actionfromafar4 hours ago
        But that would be like GDPR and that is EU which is communist which is satanic. QED.
      • vrganj7 hours ago
        Not quite the same, but the GDPR gives you a right to erasure.
        • OKRainbowKid6 hours ago
          And afaik it also quite strictly regulates which data you&#x27;re allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and&#x2F;or designed to extort money from poor helpless trillion dollar US corporations.
          • vrganj5 hours ago
            Maybe the bureaucracy is there for a reason some times?<p>Maybe the poor helpless US corporations <i>shouldn&#x27;t</i> be collecting 153M+ drivers licenses?<p>Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model?<p>Hm.
            • OKRainbowKid3 hours ago
              In case it wasn&#x27;t obvious: I do not at all agree with these complaints about the GDPR or EU.
        • wokkel2 hours ago
          Unfortunately no right to audit. So deletion is a pinky promise.
        • randunel4 hours ago
          Actually GDPR is exactly what they&#x27;re asking to. Possession of personal data that is not required for a service&#x27;s functionality is illegal under GDPR.
          • wolvoleo3 hours ago
            Well unless it was stored with freely given permission of course.<p>But it has to be freely given. &quot;Give permission or you can&#x27;t use this service&quot; is not ok for data that isn&#x27;t required to provide the service.
            • subscribed2 hours ago
              It must be freely given anyway, but its still illegal to keep unless proportional and necessary for the stated purpose.<p>If the purpose wasn&#x27;t &quot;we keep to resell it later&quot; it&#x27;s likely illegal.<p>Well, &quot;illegal&quot; given that this type of criminality is pretty much ignored (I&#x27;ve been fobbed off by the regulator after pointing a systematic law-breaking by a $company many many many times. Still better than not having this).
      • DANmode8 hours ago
        Negligence is already illegal.<p>Just locate a prosecutor.
        • DaSHacka6 hours ago
          I&#x27;ll sleep so much better at night when the company that&#x27;ll leak my Social Security Number on the internet due to hosting a backup of a database that&#x27;s assessible publicly gets fined $0.30 per SSN leaked.<p>Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow&#x27;s meeting&#x27;s meeting, chuckling before moving onto the next slide.
        • megagpt54 hours ago
          [dead]
    • miohtama18 minutes ago
      Often regulation requires companies to keep this data for many years in the case the government wants to check on you.<p>Not in the US, but in Spain, police gets this data real time when you rent a car or check in to a hotel.<p>This is of course important for protecting you.
    • chezelenkoooo7 hours ago
      Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we&#x27;re talking around five years _post_ account closure.<p>So most businesses are not permitted to just delete the data.
      • michaelt6 hours ago
        Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they&#x27;d photocopy your driver&#x27;s license on paper, and store it in a filing cabinet. The computer record of a customer&#x27;s account would just say &quot;driving license checked, on file at branch #1234&quot;<p>Security-wise this comes with obvious downsides - but as protection against cyberattack, it&#x27;s pretty much the gold standard.
        • SapporoChris6 hours ago
          A system abandoned decades ago? <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Gold_standard" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Gold_standard</a>
          • Tarq0n5 hours ago
            <a href="https:&#x2F;&#x2F;en.wiktionary.org&#x2F;wiki&#x2F;gold_standard" rel="nofollow">https:&#x2F;&#x2F;en.wiktionary.org&#x2F;wiki&#x2F;gold_standard</a>
        • expedition323 hours ago
          Unfortunately letting random companies photocopy your passport leads to identify fraud.
          • Tangurena213 minutes ago
            To abuse that requires physically going to a file cabinet. People in that office are going to question you. If something happens, it is isolated to a single office, limiting suspects to a small number. Putting it online makes it vulnerable to the entire planet with about 8 billion suspects.
          • embedding-shape2 hours ago
            Would it be better if it was a digital copy, or what? Somehow, my drivers license, passport and ID has been photocopied and digitally copied countless of times, in multiple countries, over more than three decades, yet not a single time I&#x27;ve been affected by identity fraud. So somehow, seems it doesn&#x27;t &quot;lead to&quot; always but I&#x27;m sure it does happen sometimes, yes.
      • veunes6 hours ago
        Regulatory retention is a valid reason for some of this data to exist. It isn&#x27;t a blanket justification for every intermediary in the verification chain to retain its own permanent copy. If anything, that makes minimizing the number of copies even more important.
    • Aurornis8 hours ago
      The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.<p>Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn&#x27;t retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
    • maccam9129 hours ago
      It&#x27;s not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that&#x27;s what it sounded like to me.
      • Nition9 hours ago
        Good point, &quot;we have been continuously exfiltrating new data for over a year into our private database&quot;. I missed that line on first read.
        • samlinnfer9 hours ago
          It&#x27;s obvious they are keeping them all. 150 million didn&#x27;t get all re-scanned at once.
          • applfanboysbgon6 hours ago
            It&#x27;s actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker&#x27;s claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned.<p>Which is to say: deleting the data <i>is not enough</i>. As much as possible, this data should not be collected in the first place, and if it absolutely <i>must</i> be collected, it needs to be handled with serious security practices that don&#x27;t enable exfiltration to be an ongoing process for a year. People keep saying this because it&#x27;s true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.
            • Nition2 hours ago
              Yeah. It&#x27;s a bit unfortunate that I seem to have the top comment in this thread now despite it probably being wrong, at least to some extent, but it&#x27;s too late to edit it. I agree with your second point as well.
    • fhub5 hours ago
      IMHO If statutes require it to be kept, then it should get written to storage that can’t be read without being there in person. Have the police actual show up to look at it. Make it really slow to look at too. Cryptographically slow.
    • samlinnfer9 hours ago
      The whole point is they keep it forever. You think any id verification services actually delete the data?
      • Nition9 hours ago
        I mean, just because all your friends are jumping off a cliff...
        • mindslight7 hours ago
          It feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...
        • kevin_thibedeau9 hours ago
          If you and your friends are all sociopaths, you&#x27;re going to feel left out if you don&#x27;t join in on the cliff jumping.
    • veunes6 hours ago
      Yeah, this is the part I don&#x27;t get either. Verification should produce a yes&#x2F;no result, not a permanent archive of everyone&#x27;s identity documents
    • brador5 hours ago
      Storing personal data should require insurance that increases per data point.
    • cucumber37328423 hours ago
      No, you can&#x27;t, because then when the headline reads &quot;FBI probes service selling &lt;whatever touchy subject you had to verify for in the first place&gt;&quot; and you don&#x27;t have those records you wind up taking it. And that&#x27;s before you even start talking about retention laws.<p>There can be a discussion about retention periods and the like but too short a retention period amounts to &quot;trust us bro&quot; in the eyes of some un-feeling government agency who is trying to screw you either at the behest of the law or at the behest of whoever hates you and has their ear.<p>Something needs to be done but &quot;just delete it after you&#x27;ve verified it&quot; is not workable at scale. Yes I know it worked fine for brick and mortar forever. Maybe some acceptable technical solution could be reached, idk.
    • wiredbox6 hours ago
      Which is why you need GDPR equivalent in the US…
    • lifestyleguru5 hours ago
      Every time someone takes photo or photocopy of my documents &quot;for the police&quot; or &quot;for security&quot; I&#x27;m just thinking &quot;why are you lying to me&quot;.
      • anonym294 hours ago
        They don&#x27;t necessarily need to be lying for it to be harmful to you - they could simply be grossly incompetent as a custodian of your data. Most people are grossly incompetent even as stewards of their own data, after all.
  • tgsovlerkhgsel7 hours ago
    If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn&#x27;t matter how you allegedly did everything to protect the data, if it leaked it&#x27;s on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold.<p>Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they&#x27;d think twice.
    • MaKey6 hours ago
      I&#x27;m in Europe and got ~$350 because of three data leaks. The amount per instance was vastly different though - $255, $80 and $15.
      • consp3 hours ago
        I&#x27;d be very interested in which ones, since I&#x27;ve never received anything despite being in several big breaches (and have received the boatload of spam to prove it). I&#x27;m pretty sure this is very country specific.
      • cbolton2 hours ago
        What did you do to get the money?
    • veunes5 hours ago
      Data minimization becomes a lot less abstract once every unnecessary record on disk has an actual dollar value attached to the risk
    • tencentshill7 hours ago
      Make Customer Data a Liability
    • 2OEH8eoCRo01 hour ago
      I concur. Liability would go a long way.
  • trollbridge8 hours ago
    One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera.<p>They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
    • Aurornis8 hours ago
      The ID scans in the article weren&#x27;t submitted by people from their phones. They include IR and UV scans, too. The database might contain multiple sources but at least the big one appears to have a lot of IDs from physical locations where you hand your ID over the counter to someone to scan.
      • klausa5 hours ago
        I&#x27;m now very curious how does a UV&#x2F;IR scan of an ID card looks like!
        • kotaKat4 hours ago
          <a href="https:&#x2F;&#x2F;www.microptik.eu&#x2F;product&#x2F;id-card-verification" rel="nofollow">https:&#x2F;&#x2F;www.microptik.eu&#x2F;product&#x2F;id-card-verification</a><p>Basically swaps the LED illum with an UV LED instead. Makes all the security features pop right out.
    • veunes5 hours ago
      Yeah, the irony is that every extra signal added to make verification &quot;safer&quot; also becomes another extremely valuable thing to steal when the verifier gets breached
    • latchkey8 hours ago
      s&#x2F;retained&#x2F;leaked&#x2F;
      • trollbridge8 hours ago
        Well, yeah. Retention eventually means leaking.<p>I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.
  • shireboy1 hour ago
    What even would be the fix for this? 153m people need new license asap and id verification systems need to block the stolen ones? Also what are some of the bad things this could cause: a risk malicious actors open verified accounts in their name, ability to vote and travel under stolen id, what else?
  • ChrisMarshallNY7 hours ago
    <i>&gt; vendors who collect this sensitive data need to be held to a higher standard.</i><p>They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).<p>One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.<p>The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.
    • thesmtsolver27 hours ago
      Ahem<p>Some Interrail travellers told to cancel passports as hacked data posted online<p><a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2026&#x2F;apr&#x2F;23&#x2F;some-interrail-travellers-told-to-cancel-passports-as-hacked-data-posted-online" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2026&#x2F;apr&#x2F;23&#x2F;some-inte...</a>
      • ChrisMarshallNY6 hours ago
        True, and there’s the notorious story of the Finnish psych data leak[0].<p>I just don’t hear about it anywhere near as much.<p>[0] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Vastaamo_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Vastaamo_data_breach</a>
    • miohtama13 minutes ago
      GDPR does not prevent leaks, only may punish someone afterwards. A lot of the upcoming EU regulations are to collect more data on you because of the age checks. German and Spanish prime ministers have publicly called for verifying all Internet users and end anonymity,
    • michaelt6 hours ago
      <i>&gt; They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there</i><p>Often it&#x27;s straight up the same companies - a Brit&#x27;s PII is held by Experian, Equifax and Transunion just like an American&#x27;s is.<p>And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We&#x27;re talking a $5 billion company handing 15 million people&#x27;s credit reports to hackers, and getting fined $15 million.
    • AndyMcConachie1 hour ago
      &gt; They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there<p>As an EU citizen and resident I strongly recommend you not take EU privacy controls seriously. The GDPR functions well as a means of tax collection, but it really doesn&#x27;t work all that well as something that actually protects people&#x27;s privacy.
  • fishfasell10 hours ago
    So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.
    • 3eb7988a16639 hours ago
      153 million puts them at roughly 1&#x2F;2 of all Americans.<p>Naturally these &quot;identity verification&quot; companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
      • oogali1 hour ago
        Total population (341M) is the wrong divisor. It’s so much worse.<p>Count the number of Americans who would have an ID worth scanning (aka ages 18 or over): 269M [1].<p>Or the number of Americans with a driver’s license: 212M (2013) [2].<p>1: <a href="https:&#x2F;&#x2F;www2.census.gov&#x2F;programs-surveys&#x2F;popest&#x2F;tables&#x2F;2020-2025&#x2F;state&#x2F;detail&#x2F;SCPRC-EST2025-18+POP.xlsx" rel="nofollow">https:&#x2F;&#x2F;www2.census.gov&#x2F;programs-surveys&#x2F;popest&#x2F;tables&#x2F;2020-...</a><p>2: <a href="https:&#x2F;&#x2F;www.bts.gov&#x2F;content&#x2F;licensed-drivers" rel="nofollow">https:&#x2F;&#x2F;www.bts.gov&#x2F;content&#x2F;licensed-drivers</a>
      • ornornor7 hours ago
        I once tried to reach one of the two Canadian background check companies a prospective employer wanted to use to check me. I eventually found their privacy and security phone number. It had a poorly recorded voicemail to leave a message and they’d call back to answer questions. It’s been 12 years. They haven’t called me back yet but I’m assured they take privacy very seriously.<p>I didn’t go through with that part of my application and didn’t keep the job.
      • mulmen9 hours ago
        I had two active Clear subscriptions at the same time. How did an identity verification company not know both accounts were the same person? They were both using the same credit card!<p>What does an &quot;identity verification&quot; company even do?
        • toast09 hours ago
          Clear takes your money and zips you through the airport checkpoint line. Because terrorists wouldn&#x27;t spend money or time to get through the lines faster?
        • megagpt54 hours ago
          [dead]
    • 3RTB2978 hours ago
      From the article, it&#x27;s some national-chain hotels, car rentals, casinos, dispensaries, and a couple maybes like if you bought alcohol at Target and they scanned your ID or sent something via FedEx that required an ID scan. Your ID might be scanned and in there multiple times.
    • wahern10 hours ago
      Your ID and PII was likely already on the black market, the only question is accessibility and price. You can&#x27;t exactly advertise on Reddit or sell to every two-bit identity thief and not expect heat.
  • rswail4 hours ago
    The main question to government is:<p>1. You already know who everyone is. By definition identification as an individual is by government.<p>2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?<p>3. Why is that evidence not provided directly, but as a confirmation from the government service (&quot;Yes, this person is over 18&quot;, not &quot;Yes, this person is 37&quot;)?<p>Governments need to protect the public, not allow businesses open slather on collecting PII.
    • 2legit2quit3 hours ago
      &gt; <i>Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?</i><p>Generally speaking, it&#x27;s the narrative of a pushback on a &quot;national id&quot;.<p>Many countries already have this place. Estonia has the Digital ID provided by government[0]. Nordic countries use BankID, which is a form of KYC that is backed by banks (you prove your identity to the bank, the bank issues a bank id - usually back by certificate[s], and you login with this to services[1][2]). Finland is the outlier, here, with their own service[3].<p>0 - <a href="https:&#x2F;&#x2F;e-estonia.com&#x2F;service&#x2F;estonian-e-identity&#x2F;id-card&#x2F;" rel="nofollow">https:&#x2F;&#x2F;e-estonia.com&#x2F;service&#x2F;estonian-e-identity&#x2F;id-card&#x2F;</a><p>1 - <a href="https:&#x2F;&#x2F;www.bankid.com&#x2F;en&#x2F;individuals&#x2F;get-bankid" rel="nofollow">https:&#x2F;&#x2F;www.bankid.com&#x2F;en&#x2F;individuals&#x2F;get-bankid</a><p>2 - <a href="https:&#x2F;&#x2F;bankid.no&#x2F;en&#x2F;how-to-get-bankid" rel="nofollow">https:&#x2F;&#x2F;bankid.no&#x2F;en&#x2F;how-to-get-bankid</a><p>3 - <a href="https:&#x2F;&#x2F;www.suomi.fi&#x2F;instructions-and-support&#x2F;identification&#x2F;what-is-suomifi-e-identification" rel="nofollow">https:&#x2F;&#x2F;www.suomi.fi&#x2F;instructions-and-support&#x2F;identification...</a>
      • gnz113 hours ago
        Yes, which is part of a wider narrative in the US that insists everything must be privatized because the government cannot be trusted or is otherwise incompetent.
      • Gander57392 hours ago
        <a href="https:&#x2F;&#x2F;youtu.be&#x2F;ZVYqB0uTKlE" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;ZVYqB0uTKlE</a> (Yes, Prime Minister)
    • vincnetas4 hours ago
      This is exactly the way its being implemented in EU (Yes, this person is over 18&quot;).<p>European Digital Identity Wallet (EUDI Wallet) framework established under the eIDAS 2.0 regulation (Regulation (EU) 2024&#x2F;1183)
    • navigate83101 hour ago
      One can argue, this would be an unintentional tracking of the population by government
    • acchow3 hours ago
      This is already present today in California Driver&#x27;s licenses in your Apple Wallet (mDL).<p>When you scan your driver&#x27;s license at a compatible reader, you&#x27;re given a notice of what information is being requested and the ability to share it (or not).<p>It can also request some derived attribute (is this person above the age of 21?) instead of the actual data field itself.<p>Most of this is from ISO&#x2F;IEC 18013-5
    • Hobadee4 hours ago
      We can&#x27;t do any of that because it is forward-thinking and doesn&#x27;t involve clear-cutting a rainforest to make the stacks of paperwork that are otherwise required to fill out forms in triplicate, run everything through 17 different departments, and ensure an army of bereaucrats have something to do with their day.
  • wolvoleo3 hours ago
    Ooh I thought they sold that many fake ones lol. I know fake IDs are a big thing in the US because of the really high drinking age (were I&#x27;m from it was 16). But even then it&#x27;s a lot.<p>But no it&#x27;s about leaked data. That wasn&#x27;t very clear from the title.
  • trivet5 hours ago
    Wild how many states seem to have had their DMV systems compromised. Guess mine&#x27;s in the mix by now too.
  • cute_boi10 hours ago
    I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.
    • stephbook8 hours ago
      In Germany, everyone&#x27;s national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.)<p>You&#x27;d think that 80 million people from a rich first world country would be enough of a market to use this.<p>No, we&#x27;re showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
      • lifestyleguru5 hours ago
        You want to have it done cheaply on a dumb computer, so you have it.
    • AnthonyMouse4 hours ago
      &gt; They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.<p>Because then <i>that</i> website would get compromised and lose the data on 350 million people instead of 153.<p>Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.<p>People throw around terms like &quot;zero trust&quot; like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you&#x27;ll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.<p>Using government ID on the internet should simply be banned. 99% of things shouldn&#x27;t require government ID to begin with and the 1% that do should always be done in person.
    • zdragnar9 hours ago
      You&#x27;ve already answered your own question. They don&#x27;t provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old &quot;red flag rule&quot; intended to prevent insurance and Medicaid fraud.<p>So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
    • charcircuit8 hours ago
      Because physical business are also allowed to collect this information.
      • astura44 minutes ago
        Not just allowed, required. Banks, doctors, etc.
    • megagpt54 hours ago
      [dead]
  • ungreased06758 hours ago
    Bankrupt this company to serve as a warning to others that hang on to way too much data.
    • walrus018 hours ago
      In addition, actual federal prison time for the C-levels would help as a deterrent to future fuckery.
      • bilbo0s6 hours ago
        This is the actual answer. Things like this need to be a criminal offense.<p>Monetary fines have a tendency to simply be modeled in as a cost of doing business. Going to prison is far more effective when the goal is to concentrate minds.
    • b3lvedere7 hours ago
      At least reimburse everybody for all the costs involving getting the old drivers license invalidated and apply for a new one. Unfortunately that will not cause to magically dissapear the rest of your harvested profile.
  • grommet_kit5 hours ago
    It&#x27;s always the driver&#x27;s license data that seems to find its way out. Another reminder to freeze your credit.
  • jakevoytko10 hours ago
    As always, friendly reminder to lock your credit and enable your mobile carrier&#x27;s protections against SIM swapping
    • fishfasell10 hours ago
      Excellent advice. A compromised phone number is an absolute nightmare, most MFAs default to SMS as a last resort. I lost my Okta verify login at work since I transferred phones, thought I&#x27;d need a ticket with our ID team but turns out my phone number is sufficient. Wasn&#x27;t thrilled about that.
  • Razengan6 hours ago
    How about probing the laws (and politicians who pushed for them) about making IDs mandatory for using the internet?
  • tgrowazay9 hours ago
    &gt; Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”
  • guelo5 hours ago
    Now I feel justified that I started boycotting my neighborhood bar when they started scanning IDs at the door with some unknown app.
  • SpaceL10n32 minutes ago
    [dead]
  • veunes6 hours ago
    [dead]
  • FpUser9 hours ago
    So they want to see my driver&#x27;s license &quot;to make the world safer&quot; when in reality all they do is facilitating mass fraud. When the fuck will those brainless infusoria will get punished 9fat chance).
  • htrp8 hours ago
    It was probably Hertz that was the source of the breaches.
  • rio5178 hours ago
    I am so jaded, i cannot help jumping to the conlusion that to me they wanted to data to continue voter supression efforts.
    • GolfPopper7 hours ago
      Nah. It they want to make sure that Trump gets his cut from the sale.