Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • The HN submission title is a garden-path sentence:

    Hackers Had a Live Feed of Every ID Verification Company Scanned

    (Huh? How do you scan a company?)

    The original title is easier to parse:

    Hackers Had A Live Feed Of Every ID This Verification Company Scanned

  • Thank you, it was very confusing indeed, the HN post should be fixed to something directly clearer
  • Isn't it weird that every opponent to ID verification screamed at the top of their lungs the whole time that this would cause a massive privacy breach and would be used by bad actors to defraud the public, steal their identity, and by the private sector to track their every web search and activity Big brother style, and they passed it anyway?

    Isn't that weird that the very OBVIOUS AND SELF-EVIDENT ISSUES with requiring id to use the internet were, in fact, OBVIOUS AND SELF-EVIDENT ISSUES that were immediately taken advantage of?

    Just so so weird. Who could have seen this coming?

  • The HN title is misleading.

    > Hackers Had A Live Feed Of Every ID __This__ Verification Company Scanned. For Over A Year.

    The "This" in the the sentence serves an important role. It currently reads like all ID verification companies were compromised at the same time.

  • There are only two types of scanned ID documents, those that are known to be compromised and those that are not
  • No worries! Governments who used this company are taking responsibility and now have a plan to, at the very least, replace all IDs they forced people to expose and to make sure the old ones are unusable!

    That's a sarcastic joke. It's how governments demand private companies react, but ...

  • And again, there will be no monetary consequences for the companies that failed to secure our private data.
  • More like class action lawsuit, $500m settlement, $300m for lawyers and $0.50 for every victim.
  • And governments will continue to force citizens to use these shitty companies for whenever they need id verification.
  • I can't agree more strongly with this statement. It is mind-blowing how can it be socially acceptable to treat other people's confidential data so mindlessly

    We should have a law which penalizes businesses for leaking other people's private data

    Got John's driver license exposed? Write him $1k cheque. Second time this happened? Make it $3k. And another 1% of his assets, since you put them at risk. $10k in the bank? That's extra $100. Guy has property worth 500k? Too bad for you, that's another 5 thou.

    And no blaming sub-contractors either. You hired them to do validation and they leaked data? Too bad, must have verified that they are reliable. This is when all of these Hertzies and Targets and Fedexes start thinking twice before storing confidential data. Why do they need to hold on to your driver's license? I know why. They hope to make some extra cash by datamining it. Well, get your checkbook ready then.

    You are selling alcohol and wanna make sure I'm older than 21? You don't need to scan ID. You definitely don't need to store it. You CHOOSE to store it, and if you do, be prepared to pay if you expose it.

    I wish it worked like that, but yeah, it never will

  • I wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!
  • I thought that's what LLMs are for?
  • You know, it always bugged me that the NSA (and more directly Google, and my phone company, and so on) know where I was at exactly this time a year ago, but that I do not.
  • If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.
  • Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?
    by spuz
  • CADMV claims on their web site that they cannot accept a P.O. box as a residence address. I have yet to find anything in California state law supporting this policy, though IANAL. Their enforcement seems to be quite lax.
  • Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.
  • As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions.

    Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which of course impact quality of deliveries (not shaming the people who do the hard job without the relevant means). And while more distributed governmental topologies would have their own caveats, at least it would less likely offer opportunities for single point of failure.

    [1] https://francepassoire.com/

  • But usually gov't will outsource to random 3rd parties, no?
  • We also have a Danish wallet now, AltID, which implements an anonymized (assuming no collusion between issuer and eavesdropper or service provider) age verification protocol based on batches of single-use tokens which contain no personal information (except that they can be traced back to you by the issuer).

    It's been released and in production since summer. Since then, several social networks have apparently started A/B testing age verification for their EU users, but how many of them actually integrate with the anonymous solution that is now available and in production? To my knowledge: 0. They all use Persona.

    This highlights one of my main criticisms of EU's naive approach to regulation of tech companies. They fail to realize that any regulation that they impose will be complied with in the most malicious way possible, which is how we got cookie banners with dark patterns instead of a simple HTTP header saying no thanks to cookies.

  • We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible.

    ‘Just make the encryption secure and so we can read it’

    ‘Just check everyone’s id but make it totally secure’

  • That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain.

    The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know.

    I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"?

  • They do not care about 'secure' part at all.
  • If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

    Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)

  • > "The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit."

    Mr Krebs is dealing with all this mayhem and idiocy with remarkable sang froid if I may say so. Good heavens.

  • This comment is worrisome:

    > My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.

  • The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proofs for particular properties (e.g. if the person has a driver license or not) without de-anonymizing the account. In the rare even of root key leak you should be able to physically go to the authority and make a new one, while revoking the old key. I don't see any other better alternatives than this.
  • Passkey?
  • That sounds like this prediction from 2003

    https://www.fourmilab.ch/documents/digital-imprimatur/#SI_an...

  • > the most you lose

    Yep that's the only thing you lose, apart from a huge number of literal images of kids in the hands of literal criminals.

    > I don't see any other better alternatives

    Not doing age verification!