| ▲ | Nition 6 hours ago |
| The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them. |
|
| ▲ | analog31 5 hours ago | parent | next [-] |
| I believe we need to criminalize possession of the data, with statutory damages per violation. |
| |
| ▲ | CamperBob2 3 hours ago | parent | next [-] | | Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely. | | |
| ▲ | londons_explore an hour ago | parent [-] | | Estonia has it's ID cards which can sign things.... That suddenly means a data leak doesn't matter - nobody can make new signatures. Verifying someone's ID would be as simple as asking them to sign your company name and today's date. | | |
| ▲ | mschuster91 35 minutes ago | parent [-] | | The problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about "mark of the beast", the Democrats and the ACLU fear them being used as part of a surveillance state. [1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa... | | |
| ▲ | alistairSH 14 minutes ago | parent [-] | | Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver's license, and whatever else. If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed). We'll get there eventually, but not before we try everything else first. |
|
|
| |
| ▲ | akshatjiwan 5 hours ago | parent | prev | next [-] | | Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity. | |
| ▲ | actionfromafar 35 minutes ago | parent | prev | next [-] | | But that would be like GDPR and that is EU which is communist which is satanic. QED. | |
| ▲ | vrganj 4 hours ago | parent | prev | next [-] | | Not quite the same, but the GDPR gives you a right to erasure. | | |
| ▲ | OKRainbowKid 3 hours ago | parent | next [-] | | And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons.
But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations. | | |
| ▲ | vrganj 2 hours ago | parent [-] | | Maybe the bureaucracy is there for a reason some times? Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses? Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model? Hm. |
| |
| ▲ | randunel an hour ago | parent | prev [-] | | Actually GDPR is exactly what they're asking to. Possession of personal data that is not required for a service's functionality is illegal under GDPR. |
| |
| ▲ | DANmode 5 hours ago | parent | prev [-] | | Negligence is already illegal. Just locate a prosecutor. | | |
| ▲ | DaSHacka 3 hours ago | parent | next [-] | | I'll sleep so much better at night when the company that'll leak my Social Security Number on the internet due to hosting a backup of a database that's assessible publicly gets fined $0.30 per SSN leaked. Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide. | |
| ▲ | megagpt5 an hour ago | parent | prev [-] | | [dead] |
|
|
|
| ▲ | chezelenkoooo 3 hours ago | parent | prev | next [-] |
| Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure. So most businesses are not permitted to just delete the data. |
| |
| ▲ | michaelt 3 hours ago | parent | next [-] | | Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234" Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard. | | | |
| ▲ | veunes 2 hours ago | parent | prev [-] | | Regulatory retention is a valid reason for some of this data to exist. It isn't a blanket justification for every intermediary in the verification chain to retain its own permanent copy. If anything, that makes minimizing the number of copies even more important. |
|
|
| ▲ | fhub an hour ago | parent | prev | next [-] |
| IMHO If statutes require it to be kept, then it should get written to storage that can’t be read without being there in person. Have the police actual show up to look at it. Make it really slow to look at too. Cryptographically slow. |
|
| ▲ | maccam912 5 hours ago | parent | prev | next [-] |
| It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me. |
| |
| ▲ | Nition 5 hours ago | parent [-] | | Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read. | | |
| ▲ | samlinnfer 5 hours ago | parent [-] | | It's obvious they are keeping them all. 150 million didn't get all re-scanned at once. | | |
| ▲ | applfanboysbgon 3 hours ago | parent [-] | | It's actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker's claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned. Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private. |
|
|
|
|
| ▲ | samlinnfer 5 hours ago | parent | prev | next [-] |
| The whole point is they keep it forever. You think any id verification services actually delete the data? |
| |
| ▲ | Nition 5 hours ago | parent [-] | | I mean, just because all your friends are jumping off a cliff... | | |
| ▲ | mindslight 4 hours ago | parent | next [-] | | It feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff... | |
| ▲ | kevin_thibedeau 5 hours ago | parent | prev [-] | | If you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping. |
|
|
|
| ▲ | Aurornis 5 hours ago | parent | prev | next [-] |
| The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation. Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through |
|
| ▲ | veunes 2 hours ago | parent | prev | next [-] |
| Yeah, this is the part I don't get either. Verification should produce a yes/no result, not a permanent archive of everyone's identity documents |
|
| ▲ | brador 2 hours ago | parent | prev | next [-] |
| Storing personal data should require insurance that increases per data point. |
| |
|
| ▲ | wiredbox 2 hours ago | parent | prev | next [-] |
| Which is why you need GDPR equivalent in the US… |
|
| ▲ | lifestyleguru an hour ago | parent | prev [-] |
| Every time someone takes photo or photocopy of my documents "for the police" or "for security" I'm just thinking "why are you lying to me". |
| |
| ▲ | anonym29 an hour ago | parent [-] | | They don't necessarily need to be lying for it to be harmful to you - they could simply be grossly incompetent as a custodian of your data. Most people are grossly incompetent even as stewards of their own data, after all. |
|