

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Wow, how could this have happened right before the election? Surely this will not be used as a pretext for anything.
- American national security apparatus do not care about the actual Americans. They are too worried about foreign entanglements, and protecting a specific foreign country than their own country.
- I'd rather tackle this problem from a different angle. If a bank gives a fraudulent loan to someone in your name, its YOUR problem and not the bank's problem. Why don't we make it the bank's problem? They gave the fraudulent loan. How is it not their problem to fix?
If we fix that, then having your ID stolen is a much, much smaller problem.
by techgnosis - I really want these people handling my healthcare and other details about my life.by exabrial
- You want an ID verification company handling healthcare? Even if you're a staunch believer in free enterprise this seems like a capability mismatch.by triceratops
- Which people? This leak was caused completely by private businesses.by valleyer
- Private healthcare is much worse, seemingly they have an open access policy. New breaches occur in the order of millions per week. Not remotely newsworthy anymore. (last time this was mainstream worthy was 200M leaked records in 2024). Last week https://www.securityweek.com/4-1-million-impacted-by-adapthe... Week before that https://www.yahoo.com/news/us/articles/more-9-5-million-pati... 2 weeks before that: https://www.msn.com/en-us/health/general/carecloud-confirms-...by max__dev
- Its unfortunate that the security requirements are expected from the for-profit businesses when the cost of paying penalties for breach of security is way lower than actually implementing the security.
Ironically in case of breach they just sell you another of their product where you put your personal information again
by sandeepkd - The CRAs compete for breach business, because it's absolutely a profitable enterprise for them:
How many people actually sign up for your "free credit monitoring for a year" following a breach?
When you do, you typically do so by signing up for the highest tier (sometimes $30 or even $50 a month) product with a redemption code for one year free. You have to enter a credit card to do so, and to no-one's surprise, if you don't cancel in time, it automatically converts to a paid subscription "for your convenience".
There are many consumer protection farces in the US, but right up there has to be the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen. You're considered liable until you prove innocence, even though you did nothing wrong.
This very nearly burned me when buying my home - having been an AT&T customer in the PNW for nearly two decades, "I" apparently decided to hit up a Walmart on the outskirts of El Paso, sign up for a Verizon service, run up two months of international calls and bail out.
Despite a police report, my utility statements, AT&T bills, etc. (all of which were, to be blunt, none of VZWs business), VZW stood by it initially, "On review of your documentation, we remain satisfied that this debt belongs to you based on the documents used to open your account".
I asked to see them, since they were, in VZW's own words, "mine". "We can't, for customer privacy reasons." Oh, so "mine when the bill needs paid, may not be mine for privacy purposes".
by FireBeyond - Damn. I just received a notice my PII (including SSN) was leaked in the DentaQuest security breach (May 2026). Something between 2.6M - 15M records.
Personally, data security is the AI Doom I’m concerned about, not being turned into paperclips.
by xtiansimon - Is there any way to check if your ID was compromised without going on some onion site?
I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious.
I think IDScan should set something up so we can check if our data was compromised, at the least.
by 0xmattf - What I would love to know is who is selling my info. I get texts from all kinds of politicians but I didn't know who sold them my number. Seems like selling someone's property without their approval should be illegal. It'd be great if I could request who sold them my data, then go to that entity tell them to stop selling (rinse and repeat)by abirch
- Will anything be different _this time around_?
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.
by er4hn - Joking right :)by jmclnx
- Elon fucking Musk has literally every single piece of personal information of every person in the country. It’s so far past too late for any of this to matter.
I’m not sure how we start over but this data plus LLMs is gonna make it a full time job to keep your parents from sending every penny to a scammer.
by selectodude - Equifax's stock price went up when they were hacked.by flerchin
- I'm reminded of the OPM breach back in 2015 [0]. Practically everyone that even applied for a security clearance was compromised. In addition, millions of sets of fingerprints were recovered by the entity that carried out the hack.
[0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
- Near the beginning of my career, I talked to a greybeard who harrumphed at me discussing something-or-other and said "computer security is an oxymoron". I thought he was being too pessimistic, nowadays I realize he was right.by curuinor
- Real computer security IS possible but takes a lot of effort by very skilled and dedicated people. You don't hear about bank mainframes getting hacked often.by UltraSane
- Human security. Computers are fine, they usually do exactly as they’re programmed.by drdaeman
- That's too pessimistic. But it is a spectrum. You can't guarantee 100% success against 100% of potential attackers, but it still matters how easy it is to get into something. There's a pretty big difference between a Windows 95 machine hooked directly to the internet and something like a fully up-to-date iPhone. The iPhone is still hackable, but in practice it's so difficult that you're unlikely to be targeted unless you get the attention of a national government.
It also requires actually caring about security and putting effort into it. These data breaches are usually systems where little attention was paid to security in the first place, and e.g. getting ahold of one user's password is enough to lose the game. Getting companies to care about security is really hard, but it does happen.
by wat10000 - it's silly to think about computer security as binary secure/insecure.
- KYC = kill your customer
It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger.
AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out.
These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked.
The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.
by joshfraser - > The correct answer is probably a new government ID system based on public key encryptio
Check out Estonia
- There's a solution: personal liability for the executives and managers at the company, and for the investors.
For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
by jsrozner - There is no legal basis for this for taking the salaries of everyone who worked at the company in any level of management at any time.
No large undertaking could ever function with such broad exposure to liability, anyways.
- Perhaps you’re right but how about starting with anything at all meaningful against the company itself?
They end up pay some class action lawyers $8 million dollars and we get a letter offering FREE CREDIT MONITORING!!1!
by bradleyjg - Or maybe something bigger should change
like why your driver license or even id should enable someone to do damage to your life?
especially that it isnt difficult to lose it and even needs to be shared with someone (e.g hotel)?
by tester756 - > All VCs in the company should face personal liability up to 10% of their net worth
Unless you have a requirement to also use domestic ID-verification services, this just means you shut that sector down in the U.S. and all our scans go to a country that doesn't extradite.
The solution is simpler: you're not allowed to hold certain special categories of data. ID scans, until we get proper identity verification in America, being one of them.
- This is a little harsh. What about requiring companies to carry management liability insurance? Or to list individual managers on cybersecurity insurance policies? Premiums will rise when a company employs managers with claims history. Eventually, it becomes difficult to employ them in key positions if they have a bad track record.by jm4