21 ms·
ID verification service for TikTok, Uber, X exposed driver licenses
- classified 2y agoWhat better cracking target than the place where everyone stores their ID info?
- brw 2y agohttps://archive.is/9ywDK https://archive.is/9ywDK
- alecco 2y ago[flagged]
- lizardking 2y agoMy understanding is that X has moved on from AU10TIX to using stripe.
- pbiggar 2y ago[flagged]
- robcohen 2y agoWhy is it absurd? I'm not following.
- pbiggar 2y ago[flagged]
- slg 2y ago[flagged]
- Alupis 2y ago[flagged]
- jedimind 2y agoJust the founder of CircleCI listing some uncomfortable facts such that you instinctively derive the best resolution to it.
- ignoramous 2y ago> dissolution of Israel I mostly read that as Paul calling for the head of tyrants, which is a positive thing for any country. If you read that as "dissolution of Israel", are you presuming Israel won't survive without its tyrants?
- slg 2y ago[flagged]
- sundbry 2y ago[flagged]
- racional 2y ago[flagged]
- davu8 2y ago[flagged]
- raxxorraxor 2y agoYes, this is pretty much a conspiracy theory. There is little to add because you did not say anything substantial, but I also believe you cannot leave statements like these without a comment.
- ignoramous 2y ago> Yes, this is pretty much a conspiracy theory. Which part? Unit 8200 as an incubator for tech startups is well-reported: https://www.calcalistech.com/tags/Unit_8200 https://www.calcalistech.com/tags/Unit_8200 The security complex intertwined with "hitech" and economy is well-tracked: https://www.calcalist.co.il/market/article/jh6p1lmcb https://www.calcalist.co.il/market/article/jh6p1lmcb The intention of its most popular leaders to expand existing territories is well-studied: https://www.jstor.org/stable/2537218 https://www.jstor.org/stable/2537218
- kevingadd 2y agoBecause Israeli intelligence freely and brazenly spies on civilians from allied countries, maybe https://www.theguardian.com/commentisfree/article/2024/may/29/international-criminal-court-israel-spying-intimidation https://www.theguardian.com/commentisfree/article/2024/may/2... I certainly wouldn't trust a startup with IDF/Mossad connections with my data.
- pbiggar 2y ago[flagged]
- racional 2y agoCitation needed. Otherwise, it's a smear. Again: 100 percent, you said.
- kevingadd 2y agoI'm assuming the logic is 'Israel has mandatory conscription, so every citizen has IDF ties', which feels like a bit of a stretch even if it's technically true.
- jedimind 2y agoIt's not a stretch at all - especially when Israelis love to brag about it, but when called out on it, they deny at all costs. The mandatory military service, which you mentioned, where most israeli citizens serve in the IDF, will naturally lead to connections between tech and the military. There is also technology transfer i.e military technologies may be adapted for civilian use by startups e.g. Cybersecurity, AI, that's why the israeli military funds even civilian startups especially when they are "Dual-use technologies" i.e. technologies that have both military and civilian applications It's also common sense to not trust startups in a nation where genocidal[0] sentiment has prevailed. So you can see many israeli "civilian" businesses[1][2] assist & whitewash the genocidal onslaught willingly & enthusiastically. [0] https://www.middleeasteye.net/opinion/how-israels-war-gaza-exposed-zionism-genocidal-cult https://www.middleeasteye.net/opinion/how-israels-war-gaza-e... [1] https://www.irishtimes.com/business/2023/10/28/wix-addressing-internal-messages-on-israel-hamas-conflict/ https://www.irishtimes.com/business/2023/10/28/wix-addressin... [2] https://www.wix.com/app-market/stand-with-israel https://www.wix.com/app-market/stand-with-israel
- zozo-whywhy 2y ago[dead]
- dangs-mama 2y ago[dead]
- deleted 2y ago[deleted]
- ryandrake 2y agoIt's gotten to the point where if a company requires you to upload something to verify your identity, you should treat it as if that something is being posted visibly to the public internet, and decide based on that whether it is worth providing. Companies repeatedly demonstrate their inability to secure personal data that they obtain and store, while always issuing press releases about how "we take security very seriously."
- bangaroo 2y agoi mean i have worked in the industry (including a long stint in fintech!) for something like 20 years now and i genuinely have yet to work at a place that didn't just nod knowingly at the need for it. i genuinely struggle to recall an active effort to continuously train, test, and improve security that had any impact across any company i've worked at. it's super costly work that feels like a pure expense to folks who don't know any better. i recall substantially longer discussions - at the company i worked at that handled people's banking credentials and is part of one of the largest financial institutions in the world - about how we could spin "the disks that your secure data is stored on are encrypted at the OS level" to sound as secure as possible without lying. far, far fewer meaningful discussions were had about how to audit for real security issues or train folks to write more secure code or build more secure systems. i know that anecdotes aren't evidence but i've really met very few folks in my time in engineering who had experiences different from mine.
- TacticalCoder 2y agoAnd the real scary stuff is that they demand more than the law requires. They're not just doing the minimal KYC/AML stuff (which is already a huge endeavor btw): they're going out of their way to get as much infos as they can. For example for AirBnB (well, granted some "conciergerie" service belonging to AirBnB, in France: but even if it's top-end it's still AirBnB) they wanted me to record a video of me of 20 seconds. They're not the only ones to do that: I've seen other sites asking these vids. The more regulated stuff, like brokers, banks, etc. shall ask what's legally required: proof of address (a utility bill), scan of the driving license, etc. but nothing more (at least in my experience). But the non-regulated players: they invent stuff. They make up shit, apparently on the spot. At some point they'll ask a blood and urine sample to "verify my identity". Which would be okay'ish, I guess, if they weren't so incompetent as to invariably leak those data when a hacker shows them who can code. I take it the KYC/AML will have to be modified to prevent anything more than what is legally required from being collected.
- dinglestepup 2y ago"Our customers’ security is of the utmost importance" They don't even have 2FA enabled for logging into such a sensitive portal?
- asadm 2y agoUsers aren't their customers, Israeli govt / Mossad is.
- alwa 2y agoIt says the company claimed that the credential leak was discovered and remediated 18 months ago, meanwhile the leaked credentials were still working as of a month ago. Is this level of governance and sophistication really typical of vendors in this space? Sprawling enterprises I can imagine losing track of the odd place or two where the credentials are used, but a vendor who only does one thing, specifically a high-trust thing like this? Even if they don’t have the wherewithal to be thorough in-house, am I confused to imagine that such a firm would have to carry insurance, which would tend to bring in specialists to make sure this kind of remediation is done right?
- jdp23 2y agoYes, it's very typical. There are almost never any consequences for actions like this.
- wepple 2y ago> but a vendor who only does one thing, specifically a high-trust thing like this? They’re not in the business of being trustworthy or secure, it’s just another software shop trying to grow product. > which would tend to bring in specialists to make sure this kind of remediation is done right? Ideally, sure. In reality an insurance company has many thousands of customers, they can’t possibly do any real assurance beyond basic compliance. Managing access and credentials is a hard problem for well staffed security teams, let alone a single compliance auditor.
- dragonwriter 2y agoIts not a high-trust thing, these vendors exist largely because it gives the organizations with direct relations with consumers a step of removal when a breach occurs; they are blame-outsourcing firms.
- judge2020 2y agoSure, but companies also don’t want to deal with building the system themselves (especially if you want to support multiple countries) and dealing with potentially doing something wrong like violating anti-discrimination laws.
- diebeforei485 2y agoI've noticed that companies are generally happy to say they use (for example) Plaid to handle your bank account details, but often bury or hide who is handling your passport details. This is unacceptable. If you want my ID, you'd better disclose who you're sharing my ID with. And ideally give me a choice of providers.
- aketchum 2y ago> And ideally give me a choice of providers. This sounds good I guess but would be pretty annoying in practice for basically no upside for the business. I could see having 2 providers that are both randomly used so that we can continue business when one has an outage. But even then I would not be showing the option to my customers. The vast majority of users would be more confused by the options than happy about having options, and likely hurt conversion.
- diebeforei485 2y agoWould you say that offering both "Sign-in with Google" and "Sign-in with Facebook" hurts conversion? Why would, say, offering both "Verify ID with CLEAR" and "Verify ID with ID.me" create confusion then? Lots of people already use CLEAR at stadiums and airports. And a lot of people - particularly students and veterans - already use ID.me to verify their ID (so far, largely for the purpose of eligibility for relevant student/veteran pricing, but it could be used to verify their ID in general).
- astroid 2y agoDidn't X switch to Stripe already? There was a huge uproar over people protesting Palestine being concerned about having their ID (with home address), biometrics (which they admitted to collecting), and other info to a company with such direct ties to Israel. I don't know about this company specifically, but I know it's common for the government to essentially act as an incubator for tech companies, so the concerns probably weren't unwarranted. I guess even with the switch, some people probably verified prior so it likely has some impact on X still -- and maybe this is actually what moved the needle internally, since the users were calling it out as a concern for quite some time. I had no clue uber and tiktok used them though, so that's good to know - thankfully I haven't given them my biometrics as of yet.
- octopoc 2y agoOh wow didn’t know that stripe has Israeli ties. Thanks for the heads up—I’ll try to shop around for a more ethical alternative. May not be able to though—launch is imminent!
- astroid 2y agoTo clarify, Stripe does not - Au10tix does, which they moved away from. Stripe is Headquartered in US / and I believe Ireland - not Israel. Sorry for the confusion.
- thephyber 2y agoSo you commented without verifying the fact was true? And it turns out it isn’t. Slow down. Don’t trust vague statements that don’t cite sources. Look for the nuance in the situation. Be curious and try to learn, don’t just follow the crowd. Also, it’s fucking weird to me to assume that all Israeli private businesses are unethical. Sure, there’s probably some. Sure, their tax dollars are fungible with the government actions you consider unethical. But aren’t you penalizing the secular tech entrepreneurs of Israel by divesting from anything related to the country? These are the same demographic that spent every weekend for most of 2023 protesting their own government’s attempt to become more subservient to the Netanyahu coalition.
- JumpCrisscross 2y agoWow, look at that list of clients: eToro, Coinbase, Payoneer [1]. Is there any way to determine if your information was leaked? The driver's license picture should qualify as biometric information under some states' laws [2]. [1] https://www.au10tix.com https://www.au10tix.com [2] https://www.huschblackwell.com/2023-state-biometric-privacy-law-tracker https://www.huschblackwell.com/2023-state-biometric-privacy-...
- smittywerben 2y agoI could be wrong here but I want to say that a driver's license ID number would even be protected under the pre biometric data privacy laws.
- tptacek 2y agoUntil pretty recently drivers license ID numbers in many states were effectively public, and if your license was issued at least 10 years ago, it probably still is.
- smittywerben 2y agoCalifornia was among the first to include driver's license numbers among personal information. The earliest I can find for my state is 2019. I'd not be surprised if some double standards continue to exist where the DMV itself is selling your personal information. > "Personal information" means an individual's first name or first initial and last name in combination with any one or more of the following data elements... > 2. Driver's license number or California Identification Card number. https://en.wikipedia.org/wiki/California_Senate_Bill_1386_(2002) https://en.wikipedia.org/wiki/California_Senate_Bill_1386_(2...
- tptacek 2y agoI don't mean simply that the DMV might sell your information; I mean that given your name and some basic information, I can potentially just generate your valid ID. Millions of drivers license IDs are essentially public. It's always a little weird to me to see people treating them like hazmat. I sort of get why? Hazmat whatever you can? But an Illinois drivers license for a 40-year-old is public. Imagine if, until relatively recently, a social security number was a truncated MD5 hash of your name and birthday. That's the flavor of the problem here.
- miki123211 2y agoI'm surprised identity verification by logging into your bank and/or carrier isn't more common in the US. They have your data anyway, it's much harder to impersonate somebody this way, it doesn't require the verifying company to hire any workers to do the verification, you could even do it without the site you're verifying yourself at learning anything about you.
- thephyber 2y ago> identity verification by logging into your bank Do you mean you expect me to give my banking site/app credentials to X? PayPal used two small (less than $1) transactions and the verification that I own the bank account was verified by correctly identifying the two transaction values. Plaid, I believe, uses 3rd party auth with some banking institutions that support it, to pull read-only data from my bank account on my behalf. South Korea and Estonia use government-issued digital certificates that private institutions can use. There are lots of ways to deal with high assurance authentication, but very few are popular in the US.
- derf_ 2y ago> PayPal used two small (less than $1) transactions and the verification that I own the bank account was verified by correctly identifying the two transaction values. Based on my experience with (non-PayPal) financial institutions in the past year, this is going away. For now, it appears you can still force them to fall back to this when providing your login credentials does not work, but who knows how much longer.
- thephyber 2y agoIt was pretty good trick for validating ownership of a bank account back in 1998, but I’m happy they are moving to something else. There are far better options, and most banks are capable of much higher assurance validation now.
- miki123211 2y ago> Do you mean you expect me to give my banking site/app credentials to X? No no. Over here (Poland), the way this works is that you get a big list of banks, you click on one, get redirected to their site, log in there, complete any 2FA they need you to complete, are given the typical oAuth "this application wants to access this sort of data" consent screen, and then are redirected back if you consent. This is mostly used for fast online bank transfers, which we often use for online payments instead of credit cards, but there's also a system to use this for ID verification.
- callalex 2y agoWhat are the chances that anyone goes to prison for this? If the answer is “none” this will just keep happening.
- gurchik 2y ago> While PII data was potentially accessible, based on our current findings, we see no evidence that such data has been exploited. How is this possible, when the journalist accessed the data to confirm it contained PII? Each day I am more and more interpreting "we see no evidence" as "we didn't really look." That way their statement can be technically correct, without divulging any evidence that might be used against them when users sue for damages.
- ThePowerOfFuet 2y ago> Each day I am more and more interpreting "we see no evidence" as "we didn't really look." They see no evidence of it because there were no log entries telling them so. Why there weren't, on the other hand, is a question far outside the scope of such statements.
- treeFall 2y agoSee no evidence, hear no evidence
- notaustinpowers 2y agoIt's even a more blatant lie because 404media found the credentials in a Telegram group. So, yeah, there's no way this wasn't exploited by multiple people.
- schwarzrules 2y agothat statement really bothered me. they can of course say that they don't see any evidence of exploitation, but this kind of personal data is valuable to bad actors because they can take it from au10tix and then use it to exploit other services or the individuals directly. au10tix would never know about that exploitation.
- hanniabu 2y agoHigh-profile fintech partners: Mercury, Stripe, Affirm, Airwallex, Alloy, Bond (now part of FIS), Branch, Dave, EarnIn, TabaPay, and previously worked with Wise and Rho, though both have since migrated to other bank partners Leaked account holder info: name & address, email, phone, unencrypted SSN/TIN, DOB, fintech platform Leaked account info: status, type, balance, last activity, opened date, account number, daily limits
- stefan_ 2y agoWhy on earth are these identity verification companies storing this data? Once the verification is done, the data must surely be promptly deleted?
- toast0 2y agoI imagine they save the data in case there's a question about a verification. Then they can go back to the archive and say we got these images, we took steps X and Y to validate them, so we were good. If they destroy the verification images, they wouldn't be able to defend a verification claim. OTOH, they wouldn't have to worry about the security of storage for those images. (They'd still need to worry about security of the images during processing)
- neop1x 2y agoOnce verification is done, they could copy the data into an encrypted cold storage with a very limited read access. I.e. make it easy to store but difficult to read. That way they could read data if needed in specific, limitedz audited and properly authorized, cases. It's all about a proper design.
- neilv 2y agoOf course they leaked the data. Any seasoned techie could've seen that coming from the start. One of these days, some seasoned and principled lawyer, who knows a bit about tech, is going to get ticked off, and decide to make one of these companies truly pay for their gross negligence. Then, gazing at the obliterated company, other companies will try to get legislation to let them let them off the hook, but some of those companies will decide the party of recklessness is probably over, and that they need to start acting responsibly and competently.
- ryandrake 2y agoProblem is, "Evil Hackers" always get the blame rather than the negligent companies, who play the victims. They trot out all the usual flawed analogies about locked doors and burglars, to excuse their negligence, and it works! So, the only legislation we ever see is to be Tougher And Tougher On Hackers instead of holding these clown companies responsible for the data they act as custodians of.
- singleshot_ 2y agoFor negligence to arise there must be, inter Alia, duty and proximate harm. I think you’ll find the identity services have a duty to their contractual partner, the website, but not to the victim whose identity was stolen. And there’s a circuit split as to whether any of these people were even harmed. While litigation seems appealing, the answer here is legislation.
- arp242 2y agoSometimes there's probably negligence involved; sometimes not. You don't know without having access to the specifics. Always blaming "negligent companies" is just as wrong as always blaming "evil hackers".
- throwaway48476 2y agoThe problem is there are zero consequences for leaks. Customers should be owed automatic compensation for the companies giving their data away.
- neilv 2y agodupe: https://news.ycombinator.com/item?id=40812118 https://news.ycombinator.com/item?id=40812118
- brw 2y agoThis is the original article (as mentioned by Gizmodo) which I submitted to HN yesterday, but it got killed immediately because of the signup wall. It went into the second chance pool (https://news.ycombinator.com/item?id=26998308 https://news.ycombinator.com/item?id=26998308) just now but not before another article on the same matter was submitted it seems. Not sure what the procedure is in that case. I'll ask dang.
- dang 2y agoAh ok since this is the original article we'll merge the other thread hither. Thanks!
- deleted 2y ago[deleted]
- treeFall 2y agoWhy are US citizens biometric identities being sent to Israel? Aren't there laws about sensitive information like this leaving US data centers?
- deleted 2y ago[deleted]
- sundbry 2y agoGood question. I was required to submit ID to Au10Tix for an Azure vendor account, and noticed that was outsourcing the data to Israel.
- Lamad1234 2y ago[dead]
- pylua 2y agoYou would be surprised. Banking companies / their vendors for instance will outsource to india and Poland. Some of the people in Poland are citizens of Belarus. Us customer data is all over the world (account numbers / ssn / other personal info ). It may be stored in the us but accessed by people in lcol areas.
- frugalmail 2y agoRecently there was mass infringement by the Democrat politicians or government reps of our 1st Amendment rights indirectly through social media as proven by the #TwitterFiles. The fact that these sites are now forcing users to submit to these identity disclosures simply because of some potentially fabricated rationale is really concerning. All of that with the nonchalant attitude of these data service providers, I'm deeply concerned.
- leni536 2y agoDoes the ID verification service retain personal information after verification? If so, why?
- Grimblewald 2y agoso that they can sell it of course. Naturally they have to claim it was leaked afterwards, but that sale is a hefty bit of cash, all for zero repercussions? if you're an amoral megacorp, its a no brainer.
- Mindwipe 2y agoBecause it has to or there's no verifiable audit trail that any verification was ever performed. Any service that claims otherwise is lying or will get sued to oblivion very quickly.
- dangs-mama 2y ago[dead]
- teeray 2y ago[flagged]
- qchris 2y agoI sometimes think that situations like this are eventually going to lead to legally-required professional licensing for certain tasks in software development. Obviously, not everyone who writes code needs a development license (what, I'm going to get licensed to write a blog or put up a site with fruit jokes?"), but if your business is going to involve personally-identifiable information, then you need actual engineering, and the folks that do that engineering need certification. This is a similar mechanism to how engineering licensing even started (in the US anyway), where Wyoming basically got tired of water infrastructure being built by people who didn't know what they were doing. Licensing could also help provide individual engineers with leverage against managers or C-suite folks who want to move fast & break things. When you're in a professional class with exclusive sign-off capabilities, it's easier to be say "we have to do this right or it's my ass, back off" and should the company says "fine, you're fired", goes ahead with managing the PII, and a leak like this happens, the company's liability goes way way up. That situation overall tends to improve the leverage that skilled workers (like those who know how about database management for PII and endpoint configuration) have to do things right. There's a number of pitfalls that can happen with licensing as well, but I'd be curious to see if a push for something like this emerges over the next few years.
- doe_eyes 2y ago> Obviously, not everyone who writes code needs a development license That's actually a very likely outcome. The startling statistic is that roughly half of professions require occupational licensing. In some places, you need licensing to become a florist. In several states, being an interior designer or a gas pump attendant requires a permit. Software engineering is an absolute outlier as far as highly-paid jobs go. I don't think this is right, but that's the world we're living in and we should stop fooling ourselves. There's a lot of SWEs who are talking about wanting some helpful, laser-focused regulation. Well, it's coming wholesale, and a fruit joke website is not going to be exempt.
- envp 2y agoThere’s already regulation affecting SDLC practices in the financial industry (SSDF in the US, DORA in the EU). Definitely not a stretch for other (“important”) areas to start receiving such attention in the future.
- derbOac 2y agoThis all feels like some Orwellian nightmare to me. Things like TikTok and X shouldn't require any ID verification in my mind; the rest of this fiasco just underscores all the other reasons why this is a bad idea.
- BLKNSLVR 2y agoI agree wholeheartedly, and I'm going to go a bit further... I think that I'm either out-of-touch or far enough outside the bubble to be able to provide an objective viewpoint, but: Needing to verify government issued ID to create an account for high-in-the-clouds pure "lifestyle" services such as Twitter and TikTok? Fuck me, is this how far we've come? Is this the destination anyone actually wanted to reach?
- raxxorraxor 2y ago> Is this the destination anyone actually wanted to reach? The services you register at love to ID you. Government pretents it tries to protect minors, but I simply do not believe them. And if so, this certainly would not be the way, on the contrary, they expose them to additional threats.
- heavyset_go 2y agoSeveral states passed legislation that requires age verification for social media, and this is how it's implemented. Companies are also incentivized to do it to prove their actual active user counts versus bots.
- Grimblewald 2y agoThe thing with all these leaks is that ID's are rapidly becoming worth less and less for the sake of actually proving your identity. Part of me believes a lot of this is intentional to try force people into using bio-metric ID like iris scans or finger prints to verify, since physical ID's are so widely leaked and so thoroughly distributed to criminals that they're no longer trustworthy documents.
- 2y ago
- StiffFreeze9 2y agoBeyond any ID theft - Oppress homeless who lost papers and can't navigate replacing them. Under pay and abuse hard-working immigrant families. _Papers, Please_ by Lucas Pope. _Engage and Evade_ by Asad L. Asad.
- heavyset_go 2y agoIt's going to be fun when there's repeated incidents like this each week because every site will require your driver's license to prove you're 18 so you're allowed to post on the internet.
- matrix87 2y agoI wonder if companies like coinbase use these authenticators as some kind of liability shield
- AzzyHN 2y agoShocker.
- steelframe 2y agoI had to use one of these services once after I lost the MFA app for a domain registrar when switching phones. I wouldn't be at all surprised if my driver's license has been compromised from that company's S3 bucket (or wherever they're stuffing the images) since then. Regardless I was super-annoyed to have to jump through that hoop. The subsequent emails from them pleading with me to re-enable MFA have since gone straight to the bit bucket.
- Throw_Away_1049 2y agoJust yesterday I had to do this for the first time with Robinhood. Driver’s License and face scan. No clue why. I had access to my email and phone but it required it.
- benreesman 2y agoJesus, let’s skip the foreplay and let the under-endowed cousins of someone important off with a warning and get tough on crime with some normal people. inb4 the usual chorus of people who are rabid originalists when it’s a tech titan but concerned with the budget when it’s a kid who hasn’t invented Reardon Steel yet. edit: I apologize for the low value comment. as someone who had their community devastated by synthetic opioids and spent all day reading people defend the Sackler family I was just lashing out at rich evil people and I apologize for the negative-signal comment.
- mrweasel 2y agoWhile we complain about it a lot, more and more I have come to appreciate the Danish governments online ID solution (MitID). It's certainly not perfect, but it does allow you to do ID verification, without exposing PII to companies. Understandably not everyone who needs to verify your identity is going to implement MitID, I can understand X not wanting to do that for the limited amount of users they have in Denmark. It's simply not worth the cost. What I don't get is why more countries doesn't have this. The US sure seem like it would benefit greatly from having a standardized, safe and secure online ID (MitID may or may not be as secure as it could be).
- anal_reactor 2y agoEU is working on this, but it's going to take a lot of time before the system actually works for all member countries.
- 6510 2y agoI haven't looked into it much but if the EU digital identity turns out something nice and usable the platforms should love implementing it. (Not holding my breath) All I really want is to obtain a link by posting a key and some identifier, redirect the user there, have them log in, redirect them back and send my webhook a code that represents that user on my website. A registered business would be able to (for example) request/buy age restriction. Ideally non EU citizen could also obtain a digital ID. That way I can stay blissfully ignorant about who you are and where you live. All I want is a single account per user (in stead of 100 000 and/or captchas)
- Brybry 2y agoThe US has no national ID and for historical ideological reasons the pushes for a national ID fail. That's why social security numbers are abused as a form of national ID number. The closest thing we have is the "Real ID" standard for state IDs/driver's licenses (well, ignoring passports). [1] So right now government solutions are done individually by states (if at all), usually as some form of "wallet" / "mDL" (mobile driver's license) phone app. All the state ID databases are supposed to be able to talk to each other, eventually, so maybe some day a big state's system will allow verifying IDs from other states but there might be political issues that block that. I guess the other option is that a big state's system (like say California's OpenCred[2]) gets popular enough for all the other states to implement it. But I'm not hopeful. [1] https://en.wikipedia.org/wiki/Real_ID_Act https://en.wikipedia.org/wiki/Real_ID_Act [2] https://www.dmv.ca.gov/portal/ca-dmv-wallet/opencred-for-developers/ https://www.dmv.ca.gov/portal/ca-dmv-wallet/opencred-for-dev...
- totorovirus 2y agothis is why we need zero knowledge proof
- joshribakoff 2y agoUber wouldn’t delete my data when I demanded them to, they just hung up on me rudely. I escalated to the CEO and they sent me this message explaining why and assuring my fears of a data leak were “unfounded”: Maribel again with Uber Support. Thank you for your patience while I took a further look at the deletion request. Unfortunately, we are unable to delete all of your information on the account due to security measures. Please visit our Privacy Notice for more details, specifically the sections titled E. Data retention and deletion. As of May 12, 2024, your account was marked for deletion. Keep in mind that deleting your driver account is permanent and will automatically delete your rider account as well. Any credits associated with your accounts will be lost. Additionally, I want to emphasize that we have strict security measures on the platform to ensure that your personal information and your safety are secured. Your understanding is appreciated.
- BiteCode_dev 2y agoPlus, they can delete all your informations, because GDPR mandates it in Europe.
- hnbad 2y agoGDPR allows retaining any information necessary for complying with legal requirements (e.g. taxes). But that exception is to be interpreted as narrowly as possible.
- Kevcmk 2y agoPro tip, sites don't have the means/motivation to challenge a user's assertion that they're in France (GDPR) or California (CCPA). Just pick a Paris address and demand a GDPR Data Subject Request (DSR) to delete your data.
- m11a 2y agoGDPR also allows for processing for a company's "legitimate interests", which is supposed to be a balancing test, but Uber could argue it needs to process ID documents to ensure safety on its platform. If the company refuses to delete, the only option you have is to escalate to a data supervisory authority and have them adjudicate on it. But more generally, GDPR has multiple legal bases for processing other than consent, and for any other than consent the processor might still be able to process data despite the right to be forgotten. And IME big company data processors tend to interpret these exceptions quite liberally, hoping people won't have the means to challenge their decision.
- bux93 2y agoLinkedIn is badgering me to "verify" my identity using some app I've never heard every time I log on. I won't, because this will inevitably happen, and Microsoft will shrug and blame the outside company.
- charles_f 2y agoSecurity theater cycle at this is stage: 1. Develop features at any cost, over-collect data, neglect security 2. Hacker gets in, pick the entirety of the data made readily available, credit card numbers, social security numbers, prod credentials, sexual orientation predictions that the company made on their customers for some reason, all of the pay history of the company, instagram creds of the ceo's girlfriend, and takes a dump in their bathroom 3. Try to shush the story 4. It gets exposed by an independent journalist in Kazakhstan who just reads /r/leaks 5. "we recently discovered that a malicious individual got access to a few logs on a random test server. Oops! So far we didn't find proof that it was used. Rest assured that security is our utmost priority. We love security here at ACME corp. Our teams have matching 'security' shirts, and every thursday we pray to Glombo, the security god. As a gesture to our customers we offer everyone a free 2 week trial of our 'security+' package ($15.99/M after trial, don't forget to cancel). Once again, sleep well knowing your data is safe with us!". 6. 6 months later the security gap is half plugged by an intern developing a novel password management system that encrypts passwords in base64 7. Go to 1. because no-one cares
- rtaylorgarlock 2y agoI hate to critique such a fine piece of work as your comment, yet I must add a 5.a) as an option taken by especially high-quality Profit corps: Blaming their customers for the leak (e.g. 23andMe).
- charles_f 2y agoYou have the right to critique, especially if that's to point out such a blaring miss from my part. OF COURSE IT'S THE CUSTOMER'S FAULT!
- 1oooqooq 2y agocan't wait for id.me if you don't know id.me, it's the new gatekeeper to your ID for any interaction with the USA govt in the near future. If you still don't have one, you are just not poor enough. But the time will come. enjoy.
- mirajkld 2y ago[dead]