FBI Probes Service Selling 153M+ Drivers Licenses

212 pointsposted 10 hours ago
by tatersolid

99 Comments

Nition

6 hours ago

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

analog31

5 hours ago

I believe we need to criminalize possession of the data, with statutory damages per violation.

CamperBob2

4 hours ago

Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.

londons_explore

an hour ago

Estonia has it's ID cards which can sign things....

That suddenly means a data leak doesn't matter - nobody can make new signatures.

Verifying someone's ID would be as simple as asking them to sign your company name and today's date.

mschuster91

an hour ago

The problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about "mark of the beast", the Democrats and the ACLU fear them being used as part of a surveillance state.

[1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...

alistairSH

30 minutes ago

Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver's license, and whatever else.

If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed).

We'll get there eventually, but not before we try everything else first.

nobodyandproud

5 minutes ago

I grew up in that tradition, so I can shed some light: The fear of a national ID isn’t just about tracking and privacy, but that an individual cannot participate in society or survive if the government decides to revoke the id.

Meaning, I can’t buy food; rent or buy a home; or hold any sort of job and earn and save.

What we have today isn’t better, but until recently I was hard pressed to see how such fears were even warranted.

akshatjiwan

5 hours ago

Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.

raverbashing

5 minutes ago

It would be fun if the GDPR naysayers end up coming up to the same conclusion

actionfromafar

an hour ago

But that would be like GDPR and that is EU which is communist which is satanic. QED.

vrganj

4 hours ago

Not quite the same, but the GDPR gives you a right to erasure.

OKRainbowKid

3 hours ago

And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.

vrganj

2 hours ago

Maybe the bureaucracy is there for a reason some times?

Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses?

Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model?

Hm.

OKRainbowKid

a minute ago

In case it wasn't obvious: I do not at all agree with these complaints about the GDPR or EU.

randunel

an hour ago

Actually GDPR is exactly what they're asking to. Possession of personal data that is not required for a service's functionality is illegal under GDPR.

DANmode

5 hours ago

Negligence is already illegal.

Just locate a prosecutor.

DaSHacka

3 hours ago

I'll sleep so much better at night when the company that'll leak my Social Security Number on the internet due to hosting a backup of a database that's assessible publicly gets fined $0.30 per SSN leaked.

Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.

chezelenkoooo

4 hours ago

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.

So most businesses are not permitted to just delete the data.

michaelt

3 hours ago

Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234"

Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.

expedition32

18 minutes ago

Unfortunately letting random companies photocopy your passport leads to identify fraud.

veunes

2 hours ago

Regulatory retention is a valid reason for some of this data to exist. It isn't a blanket justification for every intermediary in the verification chain to retain its own permanent copy. If anything, that makes minimizing the number of copies even more important.

fhub

2 hours ago

IMHO If statutes require it to be kept, then it should get written to storage that can’t be read without being there in person. Have the police actual show up to look at it. Make it really slow to look at too. Cryptographically slow.

maccam912

6 hours ago

It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.

Nition

6 hours ago

Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.

samlinnfer

6 hours ago

It's obvious they are keeping them all. 150 million didn't get all re-scanned at once.

applfanboysbgon

3 hours ago

It's actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker's claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned.

Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.

samlinnfer

6 hours ago

The whole point is they keep it forever. You think any id verification services actually delete the data?

Nition

6 hours ago

I mean, just because all your friends are jumping off a cliff...

mindslight

4 hours ago

It feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...

kevin_thibedeau

6 hours ago

If you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.

Aurornis

5 hours ago

The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.

Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through

veunes

3 hours ago

Yeah, this is the part I don't get either. Verification should produce a yes/no result, not a permanent archive of everyone's identity documents

brador

2 hours ago

Storing personal data should require insurance that increases per data point.

wiredbox

3 hours ago

Which is why you need GDPR equivalent in the US…

lifestyleguru

an hour ago

Every time someone takes photo or photocopy of my documents "for the police" or "for security" I'm just thinking "why are you lying to me".

anonym29

an hour ago

They don't necessarily need to be lying for it to be harmful to you - they could simply be grossly incompetent as a custodian of your data. Most people are grossly incompetent even as stewards of their own data, after all.

tgsovlerkhgsel

4 hours ago

If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold.

Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.

MaKey

3 hours ago

I'm in Europe and got ~$350 because of three data leaks. The amount per instance was vastly different though - $255, $80 and $15.

consp

9 minutes ago

I'd be very interested in which ones, since I've never received anything despite being in several big breaches (and have received the boatload of spam to prove it). I'm pretty sure this is very country specific.

veunes

2 hours ago

Data minimization becomes a lot less abstract once every unnecessary record on disk has an actual dollar value attached to the risk

trollbridge

5 hours ago

One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera.

They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.

Aurornis

5 hours ago

The ID scans in the article weren't submitted by people from their phones. They include IR and UV scans, too. The database might contain multiple sources but at least the big one appears to have a lot of IDs from physical locations where you hand your ID over the counter to someone to scan.

veunes

2 hours ago

Yeah, the irony is that every extra signal added to make verification "safer" also becomes another extremely valuable thing to steal when the verifier gets breached

latchkey

5 hours ago

s/retained/leaked/

trollbridge

5 hours ago

Well, yeah. Retention eventually means leaking.

I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.

rswail

an hour ago

The main question to government is:

1. You already know who everyone is. By definition identification as an individual is by government.

2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?

3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")?

Governments need to protect the public, not allow businesses open slather on collecting PII.

vincnetas

38 minutes ago

This is exactly the way its being implemented in EU (Yes, this person is over 18").

European Digital Identity Wallet (EUDI Wallet) framework established under the eIDAS 2.0 regulation (Regulation (EU) 2024/1183)

acchow

24 minutes ago

This is already present today in California Driver's licenses in your Apple Wallet (mDL).

When you scan your driver's license at a compatible reader, you're given a notice of what information is being requested and the ability to share it (or not).

It can also request some derived attribute (is this person above the age of 21?) instead of the actual data field itself.

Most of this is from ISO/IEC 18013-5

Hobadee

41 minutes ago

We can't do any of that because it is forward-thinking and doesn't involve clear-cutting a rainforest to make the stacks of paperwork that are otherwise required to fill out forms in triplicate, run everything through 17 different departments, and ensure an army of bereaucrats have something to do with their day.

fishfasell

7 hours ago

So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.

3eb7988a1663

6 hours ago

153 million puts them at roughly 1/2 of all Americans.

Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.

ornornor

4 hours ago

I once tried to reach one of the two Canadian background check companies a prospective employer wanted to use to check me. I eventually found their privacy and security phone number. It had a poorly recorded voicemail to leave a message and they’d call back to answer questions. It’s been 12 years. They haven’t called me back yet but I’m assured they take privacy very seriously.

I didn’t go through with that part of my application and didn’t keep the job.

mulmen

6 hours ago

I had two active Clear subscriptions at the same time. How did an identity verification company not know both accounts were the same person? They were both using the same credit card!

What does an "identity verification" company even do?

toast0

6 hours ago

Clear takes your money and zips you through the airport checkpoint line. Because terrorists wouldn't spend money or time to get through the lines faster?

user

6 hours ago

[deleted]

user

5 hours ago

[deleted]

user

5 hours ago

[deleted]

3RTB297

4 hours ago

From the article, it's some national-chain hotels, car rentals, casinos, dispensaries, and a couple maybes like if you bought alcohol at Target and they scanned your ID or sent something via FedEx that required an ID scan. Your ID might be scanned and in there multiple times.

wahern

7 hours ago

Your ID and PII was likely already on the black market, the only question is accessibility and price. You can't exactly advertise on Reddit or sell to every two-bit identity thief and not expect heat.

trivet

2 hours ago

Wild how many states seem to have had their DMV systems compromised. Guess mine's in the mix by now too.

ChrisMarshallNY

4 hours ago

> vendors who collect this sensitive data need to be held to a higher standard.

They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).

One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.

The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.

michaelt

3 hours ago

> They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there

Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is.

And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We're talking a $5 billion company handing 15 million people's credit reports to hackers, and getting fined $15 million.

grommet_kit

2 hours ago

It's always the driver's license data that seems to find its way out. Another reminder to freeze your credit.

ungreased0675

5 hours ago

Bankrupt this company to serve as a warning to others that hang on to way too much data.

walrus01

5 hours ago

In addition, actual federal prison time for the C-levels would help as a deterrent to future fuckery.

bilbo0s

3 hours ago

This is the actual answer. Things like this need to be a criminal offense.

Monetary fines have a tendency to simply be modeled in as a cost of doing business. Going to prison is far more effective when the goal is to concentrate minds.

b3lvedere

4 hours ago

At least reimburse everybody for all the costs involving getting the old drivers license invalidated and apply for a new one. Unfortunately that will not cause to magically dissapear the rest of your harvested profile.

cute_boi

7 hours ago

I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

stephbook

5 hours ago

In Germany, everyone's national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.)

You'd think that 80 million people from a rich first world country would be enough of a market to use this.

No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.

lifestyleguru

2 hours ago

You want to have it done cheaply on a dumb computer, so you have it.

AnthonyMouse

an hour ago

> They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

Because then that website would get compromised and lose the data on 350 million people instead of 153.

Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.

People throw around terms like "zero trust" like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you'll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.

Using government ID on the internet should simply be banned. 99% of things shouldn't require government ID to begin with and the 1% that do should always be done in person.

zdragnar

6 hours ago

You've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud.

So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.

charcircuit

5 hours ago

Because physical business are also allowed to collect this information.

jakevoytko

7 hours ago

As always, friendly reminder to lock your credit and enable your mobile carrier's protections against SIM swapping

fishfasell

7 hours ago

Excellent advice. A compromised phone number is an absolute nightmare, most MFAs default to SMS as a last resort. I lost my Okta verify login at work since I transferred phones, thought I'd need a ticket with our ID team but turns out my phone number is sufficient. Wasn't thrilled about that.

Razengan

3 hours ago

How about probing the laws (and politicians who pushed for them) about making IDs mandatory for using the internet?

tgrowazay

5 hours ago

> Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”

user

3 hours ago

[deleted]

guelo

2 hours ago

Now I feel justified that I started boycotting my neighborhood bar when they started scanning IDs at the door with some unknown app.

FpUser

6 hours ago

So they want to see my driver's license "to make the world safer" when in reality all they do is facilitating mass fraud. When the fuck will those brainless infusoria will get punished 9fat chance).

htrp

5 hours ago

It was probably Hertz that was the source of the breaches.

rio517

5 hours ago

I am so jaded, i cannot help jumping to the conlusion that to me they wanted to data to continue voter supression efforts.

GolfPopper

4 hours ago

Nah. It they want to make sure that Trump gets his cut from the sale.