7 ms·
Hackers had a live feed of every ID verification company scanned for over a year
- piva00 1mo agoBrian Krebs' article is, in my opinion, a much better read for this story[0]. [0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
- altairprime 1mo ago(2 days ago, 276 comments) https://news.ycombinator.com/item?id=49529621 https://news.ycombinator.com/item?id=49529621
- ChrisMarshallNY 1mo agoIt also dropped off the front page, pretty quickly, despite getting a lot of upvotes and comments. I was surprised by that, as this is exactly the type of story that tends to spend a couple of days on the front page. But it’s also the kind of story that won’t stay down, and will definitely be back. It appears as if there are folks here that don’t want to talk about this.
- hurfdurf 1mo agoWas on the front page for ~12 hours. https://hnrankings.com/49529621 https://hnrankings.com/49529621
- ChrisMarshallNY 1mo agoOK. That's how it got all the upvotes. I am here fairly often, and in my neck of the woods, it was only high up for about three of them. I note that it starts its drop (quickly) at about 9AM, East Coast time. I should note that front page is 30 or less, and, according to that graph, it was only there, for about ten hours; most of which wasn't daytime, in the US. I only noticed it, the first time, because I woke up in the middle of the night, and checked the site. But it's still the type of story that should have had a much longer tenure, especially as it was Krebs. I am now thinking that the access may have been through a backdoor. It certainly seems to have operated like a direct intravenous link. BTW: Thanks for this link: https://securitywall.co/tools/ipa-analyzer https://securitywall.co/tools/ipa-analyzer Looks interesting.
- Barbing 1mo agoHadn’t seen this site! More detailed alternative: https://news.social-protocols.org/stats?id=49529621 https://news.social-protocols.org/stats?id=49529621
- dang 1mo agoThanks! Macroexpanded: FBI Probes Service Selling 153M+ Drivers Licenses - https://news.ycombinator.com/item?id=49529621 https://news.ycombinator.com/item?id=49529621 - Sept 2026 (290 comments)
- smallerize 1mo agoDiscussion https://news.ycombinator.com/item?id=49529621 https://news.ycombinator.com/item?id=49529621
- chad_strategic 1mo agoBrian Krebs is able to turn these security breaches / hacks into a compelling crime novel.
- crash-universe 1mo agoI had no idea this even existed. Browsing the whole site is terrifying. Like, I mean this... ? https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/ https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-go... Thank you for gifting me a new layer of paranoia I didn't know existed until yesterday. Once you see you can't unsee.
- pelagicAustral 1mo agoI wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!
- classified 1mo agoI thought that's what LLMs are for?
- andai 1mo agoYou know, it always bugged me that the NSA (and more directly Google, and my phone company, and so on) know where I was at exactly this time a year ago, but that I do not.
- nope1000 1mo agoIn Google Maps Timeline you can definitely see it (if you set it up and you brought your phone)
- pelagicAustral 1mo agoThis is news to me. Never knew you could do that... too late now.
- poilcn 1mo agoIsn't it turn on by default?
- john_strinlai 1mo agocorrect, timeline is opt-in.
- hollow-moe 1mo agoIt was but after enough backlash they made it opt-in. Though it would be foolish to think they didn't just kept collecting and simply let you access from the timestamp you turned the thing on.
- saghm 1mo agoThis is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet
- LtWorf 1mo agoExcept this helps no child.
- Intermernet 1mo agoIsn't that the one that was left behind in 2002?
- saghm 1mo agoAfter a couple decades maybe it's time we do something for them!
- walrus01 1mo agoI think there's a number of people reading this who clearly didn't detect the satirical nature of this single sentence. It's blunt and obvious, but even so...
- saghm 1mo agoYeah, I thought it was obvious enough, but then again, I also seem to get a lot of disagreement every time I directly express the opinion that ID verification for internet use is a terrible idea, so I have no confidence which side the downvotes came from (maybe both!)
- cynicalsecurity 1mo agoThat was sarcasm.
- dgellow 1mo agoAre you sure? It’s really hard to differentiate nowadays
- lrvick 1mo agoIf you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.
- adiabatichottub 1mo agoCADMV claims on their web site that they cannot accept a P.O. box as a residence address. I have yet to find anything in California state law supporting this policy, though IANAL. Their enforcement seems to be quite lax.
- lrvick 1mo agoYou cannot literally use "P.O. box" but if you use the virtual street address service the USPS offers now it works just fine.
- Tangurena2 1mo agoIt is a REAL ID requirement. It is federal law. States issuing REAL ID compliant identity documents must mail them to your physical address. USPS provides that data for address validation. DPVCMRA = delivery point is a commercial mail receiving agent. Any sort of location with PO Boxes. https://developers.usps.com/addressesv3#tag/Resources/operation/get-address https://developers.usps.com/addressesv3#tag/Resources/operat... Disclaimer: I used to work for my state's DMV.
- lrvick 1mo agoAs someone who spent years homeless off and on, I resent REAL ID discriminating against the unhoused, so I choose to use the privilege I now have these days to reject it. I do not have or need REAL ID and my passport does not need a current residential address.
- spuz 1mo agoAm I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?
- jwilk 1mo agoThe HN submission title is a garden-path sentence: Hackers Had a Live Feed of Every ID Verification Company Scanned (Huh? How do you scan a company?) The original title is easier to parse: Hackers Had A Live Feed Of Every ID This Verification Company Scanned
- HelloUsername 1mo agoThank you, it was very confusing indeed, the HN post should be fixed to something directly clearer
- padjo 1mo agoFunny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.
- wiradikusuma 1mo agoBut usually gov't will outsource to random 3rd parties, no?
- bryanrasmussen 1mo agoprobably gov will outsource to 3rd party for gov to build system to track and manage ID. Sometimes though also to manage, as in Denmark's MitID mainly managed by NETS under government set rules.
- padjo 1mo agoOne third party, managed by a public contract, seems much better than a parade of third parties for every service you interact with though right?
- weberer 1mo agoIn Finland they outsource the system to banks and telephone operators. Its a very strange system. As far as I know, its not possible to access government services just by being a citizen. You also have to have an account with one of these third parties to get in.
- gorbachev 1mo agoIt's also impossible to use if you're an expat, and you get locked out of every Government online system that requires strong identification.
- weberer 1mo agoYou can, but there's a couple extra hoops to jump through. You first have to go to the police station and get a state ID because banks don't accept US passports or Finnish residence permits for whatever reason. Then you can open an account at Nordea. Then you can go through Nordea's system for e-identification.
- spwa4 1mo agoNo worries! Governments who used this company are taking responsibility and now have a plan to, at the very least, replace all IDs they forced people to expose and to make sure the old ones are unusable! That's a sarcastic joke. It's how governments demand private companies react, but ...
- xvilka 1mo agoThe original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proofs for particular properties (e.g. if the person has a driver license or not) without de-anonymizing the account. In the rare even of root key leak you should be able to physically go to the authority and make a new one, while revoking the old key. I don't see any other better alternatives than this.
- giancarlostoro 1mo agoPasskey?
- gonzalohm 1mo agoI think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)
- vincnetas 1mo agoI think you can do passkeys wile having private key. When os has the private key its just more convenient way of doing passkey.
- gonzalohm 1mo agoI think you can but it has to be supported by the website that you are using
- cassianoleal 1mo agoI don´t think I've ever come across a service that only used passkeys. Username/email + password + 2FA is usually the primary form of verification. There's usually a way to recover your account through email.
- croes 1mo ago> There is no safe age verification. There is no age verification that doesn’t put people at risk. There are zero knowledge proofs
- nullc 1mo agoConcrete ZKP age verification schemes are hardly zero knowledge. Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy. Now little Johnny borrows my ID, and uses it to setup some oracle that provides ID validation for every kid and bot in the country. Woops. To stop that you must compromise the idealized zero knowledge properties of the scheme, and in doing so you create the potential for harm/risk for everyone. Sure, it's better than sending an ID card live feed to the dark web, but the risks of ID card theft are at least somewhat easy to understand. Some of the threats to human rights don't even require the departure from the 'idealized' model-- as even the idealized model requires an ID issuer to issue the of-age person an ID. And so if the ID ZKP is widely required then the issuer can unperson you by simply declining to issue you an ID.
- croes 1mo agoadd MFA to the check
- deltoidmaximus 1mo agoTo where, the site requesting the verification? Now it is no longer zero knowledge.
- addag 1mo agoCrazy hack considering the order of magnitude...
- kleiba2 1mo agoAnd again, there will be no monetary consequences for the companies that failed to secure our private data.
- freehorse 1mo agoAnd governments will continue to force citizens to use these shitty companies for whenever they need id verification.
- deltoidmaximus 1mo agoAnd create new requirements normalizing id verification for increasingly mundane things assuring citizens are exposed to ever more breaches.
- Tangurena2 1mo agoThat's why I say "Our lobbyists have more money than your lobbyists". Every state has sunshine laws to show who the lobbyists are, what they lobbied on, and to whom. Some states separate those lobbyists into legislative & executive branch lobbying. I suggest you look at who voted for those bills, who lobbied them and who hired those lobbyists.
- bugbull 1mo ago[dead]
- subscribed 1mo agoMore like class action lawsuit, $500m settlement, $300m for lawyers and $0.50 for every victim.
- kova12 1mo agoI can't agree more strongly with this statement. It is mind-blowing how can it be socially acceptable to treat other people's confidential data so mindlessly We should have a law which penalizes businesses for leaking other people's private data Got John's driver license exposed? Write him $1k cheque. Second time this happened? Make it $3k. And another 1% of his assets, since you put them at risk. $10k in the bank? That's extra $100. Guy has property worth 500k? Too bad for you, that's another 5 thou. And no blaming sub-contractors either. You hired them to do validation and they leaked data? Too bad, must have verified that they are reliable. This is when all of these Hertzies and Targets and Fedexes start thinking twice before storing confidential data. Why do they need to hold on to your driver's license? I know why. They hope to make some extra cash by datamining it. Well, get your checkbook ready then. You are selling alcohol and wanna make sure I'm older than 21? You don't need to scan ID. You definitely don't need to store it. You CHOOSE to store it, and if you do, be prepared to pay if you expose it. I wish it worked like that, but yeah, it never will
- jonplackett 1mo agoWe have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’
- 11mariom 1mo agoThey do not care about 'secure' part at all.
- pessimizer 1mo agoThis is the answer. The more failures, the more justification for more draconian restrictions of civil liberties. I can hear the defense now: "Oh, yeah, you blame the honest, good, handsome people trying their best to protect you and you let the hackers off scot-free! We must make sure that hackers don't have access to the tools that aid them to commit these crimes, like books and computers. Anyone could be a hacker."
- FireBeyond 1mo agoIt already works like that. "Identity theft" is entirely framed as a problem for the citizen, affecting them and that it's their responsibility to resolve or face the consequences (credit score, collections, etc.) when all the citizen did "wrong" was choose an institution who cared more about profit than security. For the institution, all their obligation often seems to be is to "partner"[1] with a credit monitoring service. [1] A credit monitoring service that will give the institution that "free 12 months" at a vastly reduced bulk rate because it knows that in order to sign up for free credit monitoring you actually sign up, with a card, for their top tier product (which might otherwise be $50+ a month) on what is effectively a 12 month trial after which they switch you over to a paid subscription (hell, there may even be commissions paid to the institution for anyone who neglects to cancel quickly enough). The incentives are so perverse.
- lbriner 1mo agoThat is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain. The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know. I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"?
- khalic 1mo ago"Nobody could have predicted this" It's getting really tiresome
- bnj 1mo agoI’ve been following the development of the drivers license sharing system from Apple where different fields can be selected; are there any implementations of PKI based identification systems where multiple certificates can be generated and revoked when compromised? I’ve often thought that replacing the US social security number with a more robust root key makes for a fun thought experiment. Hard to imagine how such a system could securely serve so many people but passports with embedded chips seem to be doing okay.
- deleted 1mo ago[deleted]
- Tangurena2 1mo agoNot in the US. Several EU countries have PKI systems integrated with identity documents that let the requester to ask for age (for example) and then only age is supplied. But their PKI systems are for the whole ID document. As for the passport, the key/PIN you need to authenticate to the chip are printed on the page with the photo. Otherwise "hackers" can only determine nationality of passport. The standard is ICAO 9303. https://www.icao.int/publications/doc-series/doc-9303 https://www.icao.int/publications/doc-series/doc-9303 SSN was never intended for identification. My original card, issued in the 1970s was clearly marked "not for identification". In the original numbering system, the first 3 digits identified the office/area where the card/number was issued and the next 2 digits identified the filing cabinet. 700s were set aside for railroad workers (until 1963) because the legislators did not want railroad workers to be included in social security. https://secure.ssa.gov/poms.nsf/lnx/0110225045 https://secure.ssa.gov/poms.nsf/lnx/0110225045
- mawadev 1mo agoHow exactly does that work? How can you sneak a live feed past detection systems? It is incomprehensible to me, considering this is highly regulated and sensitive data. It is just open ports sending what they shouldn't be sending all the way out or what?
- defrost 1mo agoBrian Krebs' article makes a good case for the ID source being a harvester on the internal Hertz Car Rental network, and likely other similar consumer services that log ID for asset security and recovery. These are hardly military grade networks, as long as the driver licence scans make it to the database and can be used to identify and recover damages from accident or theft it's unlikely anybody has cared much past that functionality.
- paimapi 1mo agoone would think that a reasonable, modern country would have regulatory requirements for storing PII like that but alas we live in the USA [0] [0] https://www.politico.com/news/2024/09/17/andrew-kingman-data-privacy-lobbying-00179630 https://www.politico.com/news/2024/09/17/andrew-kingman-data...
- ornornor 1mo ago> This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. Yeah just like how the multiple breaches and utter negligence from the incumbent credit bureaus killed the credit file managed by private companies.
- luciana1u 1mo ago[flagged]
- zero_k 1mo agoIf you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ https://krebsonsecurity.com/2026/09/fbi-probes-service-selli... Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)
- macintux 1mo agoThis comment is worrisome: > My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.
- mixdup 1mo agoI feel like that should require an in-person visit, as troublesome as that might be. A picture of an ID is not the same thing as presenting the actual ID
- miki123211 1mo agoI think Pope Leo would respectfully disagree. https://www.nytimes.com/2026/05/05/us/pope-leo-xiv-bank-customer-service.html https://www.nytimes.com/2026/05/05/us/pope-leo-xiv-bank-cust...
- mixdup 1mo agoI almost mentioned that situation in my reply, but that's kind of the exception that proves the rule. Even in that case, someone should need to physically intervene, especially with high profile people like politicians or celebrities
- podocarp 1mo agoCan't read the article, is there a summary
- 1mo ago
- mistrial9 1mo agoI cannot get over the volume of techies calling for more centralized systems, in response to an obvious corruption of a mass scale of a crucial centralized system
- hobofan 1mo agoThe HN title is misleading. > Hackers Had A Live Feed Of Every ID __This__ Verification Company Scanned. For Over A Year. The "This" in the the sentence serves an important role. It currently reads like all ID verification companies were compromised at the same time.
- akersten 1mo agoThere are only two types of scanned ID documents, those that are known to be compromised and those that are not
- Yhippa 1mo ago“Prove you are Alice by sending us enough information to impersonate Alice.”
- BizarroLand 1mo agoIsn't it weird that every opponent to ID verification screamed at the top of their lungs the whole time that this would cause a massive privacy breach and would be used by bad actors to defraud the public, steal their identity, and by the private sector to track their every web search and activity Big brother style, and they passed it anyway? Isn't that weird that the very OBVIOUS AND SELF-EVIDENT ISSUES with requiring id to use the internet were, in fact, OBVIOUS AND SELF-EVIDENT ISSUES that were immediately taken advantage of? Just so so weird. Who could have seen this coming?