One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera.
They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
The ID scans in the article weren't submitted by people from their phones. They include IR and UV scans, too. The database might contain multiple sources but at least the big one appears to have a lot of IDs from physical locations where you hand your ID over the counter to someone to scan.
The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.
Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.
It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.
The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.
Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.
153 million puts them at roughly 1/2 of all Americans.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
I once tried to reach one of the two Canadian background check companies a prospective employer wanted to use to check me. I eventually found their privacy and security phone number. It had a poorly recorded voicemail to leave a message and they’d call back to answer questions. It’s been 12 years. They haven’t called me back yet but I’m assured they take privacy very seriously.
I didn’t go through with that part of my application and didn’t keep the job.
I had two active Clear subscriptions at the same time. How did an identity verification company not know both accounts were the same person? They were both using the same credit card!
What does an "identity verification" company even do?
Clear takes your money and zips you through the airport checkpoint line. Because terrorists wouldn't spend money or time to get through the lines faster?
From the article, it's some national-chain hotels, car rentals, casinos, dispensaries, and a couple maybes like if you bought alcohol at Target and they scanned your ID or sent something via FedEx that required an ID scan. Your ID might be scanned and in there multiple times.
Your ID and PII was likely already on the black market, the only question is accessibility and price. You can't exactly advertise on Reddit or sell to every two-bit identity thief and not expect heat.
If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold.
Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.
At least reimburse everybody for all the costs involving getting the old drivers license invalidated and apply for a new one. Unfortunately that will not cause to magically dissapear the rest of your harvested profile.
Excellent advice. A compromised phone number is an absolute nightmare, most MFAs default to SMS as a last resort. I lost my Okta verify login at work since I transferred phones, thought I'd need a ticket with our ID team but turns out my phone number is sufficient. Wasn't thrilled about that.
I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.
In Germany, everyone's national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.)
You'd think that 80 million people from a rich first world country would be enough of a market to use this.
No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
You've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
> Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”
So they want to see my driver's license "to make the world safer" when in reality all they do is facilitating mass fraud. When the fuck will those brainless infusoria will get punished 9fat chance).
One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera.
They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
The ID scans in the article weren't submitted by people from their phones. They include IR and UV scans, too. The database might contain multiple sources but at least the big one appears to have a lot of IDs from physical locations where you hand your ID over the counter to someone to scan.
s/retained/leaked/
Well, yeah. Retention eventually means leaking.
I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.
The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.
I believe we need to criminalize possession of the data, with statutory damages per violation.
Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.
Not quite the same, but the GDPR gives you a right to erasure.
Negligence is already illegal.
Just locate a prosecutor.
It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.
Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.
It's obvious they are keeping them all. 150 million didn't get all re-scanned at once.
The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.
Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
The whole point is they keep it forever. You think any id verification services actually delete the data?
I mean, just because all your friends are jumping off a cliff...
It feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...
If you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.
So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.
153 million puts them at roughly 1/2 of all Americans.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
I once tried to reach one of the two Canadian background check companies a prospective employer wanted to use to check me. I eventually found their privacy and security phone number. It had a poorly recorded voicemail to leave a message and they’d call back to answer questions. It’s been 12 years. They haven’t called me back yet but I’m assured they take privacy very seriously.
I didn’t go through with that part of my application and didn’t keep the job.
I had two active Clear subscriptions at the same time. How did an identity verification company not know both accounts were the same person? They were both using the same credit card!
What does an "identity verification" company even do?
Clear takes your money and zips you through the airport checkpoint line. Because terrorists wouldn't spend money or time to get through the lines faster?
From the article, it's some national-chain hotels, car rentals, casinos, dispensaries, and a couple maybes like if you bought alcohol at Target and they scanned your ID or sent something via FedEx that required an ID scan. Your ID might be scanned and in there multiple times.
Your ID and PII was likely already on the black market, the only question is accessibility and price. You can't exactly advertise on Reddit or sell to every two-bit identity thief and not expect heat.
If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold.
Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.
Make Customer Data a Liability
I am so jaded, i cannot help jumping to the conlusion that to me they wanted to data to continue voter supression efforts.
Nah. It they want to make sure that Trump gets his cut from the sale.
Bankrupt this company to serve as a warning to others that hang on to way too much data.
At least reimburse everybody for all the costs involving getting the old drivers license invalidated and apply for a new one. Unfortunately that will not cause to magically dissapear the rest of your harvested profile.
In addition, actual federal prison time for the C-levels would help as a deterrent to future fuckery.
As always, friendly reminder to lock your credit and enable your mobile carrier's protections against SIM swapping
Excellent advice. A compromised phone number is an absolute nightmare, most MFAs default to SMS as a last resort. I lost my Okta verify login at work since I transferred phones, thought I'd need a ticket with our ID team but turns out my phone number is sufficient. Wasn't thrilled about that.
I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.
In Germany, everyone's national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.)
You'd think that 80 million people from a rich first world country would be enough of a market to use this.
No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
You've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
Because physical business are also allowed to collect this information.
It was probably Hertz that was the source of the breaches.
Hertz or the company Hertz uses
> Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”
So they want to see my driver's license "to make the world safer" when in reality all they do is facilitating mass fraud. When the fuck will those brainless infusoria will get punished 9fat chance).