106 ms·
America's Driver's License Breach Is a National Security Disaster
- exabrial 21d agoI really want these people handling my healthcare and other details about my life.
- valleyer 21d agoWhich people? This leak was caused completely by private businesses.
- protimewaster 21d agoI'm confused about the read on this too. It reads like a "I don't want the government involved in my healthcare" type of statement, but it's posted in the discussion section of an article about private companies mishandling data.
- deleted 21d ago[deleted]
- max__dev 21d agoPrivate healthcare is much worse, seemingly they have an open access policy. New breaches occur in the order of millions per week. Not remotely newsworthy anymore. (last time this was mainstream worthy was 200M leaked records in 2024). Last week https://www.securityweek.com/4-1-million-impacted-by-adapthealth-data-breach/ https://www.securityweek.com/4-1-million-impacted-by-adapthe... Week before that https://www.yahoo.com/news/us/articles/more-9-5-million-patient-185826616.html https://www.yahoo.com/news/us/articles/more-9-5-million-pati... 2 weeks before that: https://www.msn.com/en-us/health/general/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/ar-AA2atIcb https://www.msn.com/en-us/health/general/carecloud-confirms-...
- Libcat99 21d agoAnd it will remain this was as long as the consequences of not protecting our data remain trivial.
- paimapi 21d agoif only we prosecuted corporations as people instead of just giving them the civil liberties of one
- dlcarrier 21d agoIn my experience, any industry following a security standard halts all effort at security once they're compliant with the standard. HIPAA sets a minimum but seems to also guarantee you will get exactly that minimum and nothing better.
- sidewndr46 21d agoThe only thing HIPAA guarantees is that when your data is handed out, there was a policy around it.
- suburban_strike 21d agoNot true, it makes investigating medical fraud almost impossible.
- deleted 21d ago[deleted]
- deleted 21d ago[deleted]
- triceratops 21d agoYou want an ID verification company handling healthcare? Even if you're a staunch believer in free enterprise this seems like a capability mismatch.
- curuinor 21d agoNear the beginning of my career, I talked to a greybeard who harrumphed at me discussing something-or-other and said "computer security is an oxymoron". I thought he was being too pessimistic, nowadays I realize he was right.
- drdaeman 21d agoHuman security. Computers are fine, they usually do exactly as they’re programmed.
- curuinor 21d agoWe don't care about the computers, humans are what society is for
- iAMkenough 21d agogetting the idea lately that society hates humans
- keybrd-intrrpt 21d agoCaring for humans hurts profits
- drdaeman 21d agoYes, of course. My point was that computers are as secure as human(s) who programmed them were careful and competent. Computer security is ultimately human knowledge and reasoning competence (plus time/money tradeoffs, if made willingly)
- UltraSane 21d agoReal computer security IS possible but takes a lot of effort by very skilled and dedicated people. You don't hear about bank mainframes getting hacked often.
- 21d ago
- maxrev17 21d agoSlackers are always behind this shit
- anxman 21d agoGlad to see someone talking about this
- sandeepkd 21d agoIts unfortunate that the security requirements are expected from the for-profit businesses when the cost of paying penalties for breach of security is way lower than actually implementing the security. Ironically in case of breach they just sell you another of their product where you put your personal information again
- FireBeyond 21d agoThe CRAs compete for breach business, because it's absolutely a profitable enterprise for them: How many people actually sign up for your "free credit monitoring for a year" following a breach? When you do, you typically do so by signing up for the highest tier (sometimes $30 or even $50 a month) product with a redemption code for one year free. You have to enter a credit card to do so, and to no-one's surprise, if you don't cancel in time, it automatically converts to a paid subscription "for your convenience". There are many consumer protection farces in the US, but right up there has to be the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen. You're considered liable until you prove innocence, even though you did nothing wrong. This very nearly burned me when buying my home - having been an AT&T customer in the PNW for nearly two decades, "I" apparently decided to hit up a Walmart on the outskirts of El Paso, sign up for a Verizon service, run up two months of international calls and bail out. Despite a police report, my utility statements, AT&T bills, etc. (all of which were, to be blunt, none of VZWs business), VZW stood by it initially, "On review of your documentation, we remain satisfied that this debt belongs to you based on the documents used to open your account". I asked to see them, since they were, in VZW's own words, "mine". "We can't, for customer privacy reasons." Oh, so "mine when the bill needs paid, may not be mine for privacy purposes".
- sidewndr46 21d agoWas ran through the same gauntlet by a medical provider billing me for services. Insurance wouldn't pay them due to "insufficient documentation". Wouldn't disclose what documentation they had received or what documentation they needed. Just that is was inadequate. Service provider wouldn't tell me what they had sent. Somehow a few hours before our court hearing they by some miracle decided to settle the debt with no fee to me.
- er4hn 21d agoWill anything be different _this time around_? https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Management_data_breach#Investigation https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.
- jmclnx 21d agoJoking right :)
- flerchin 21d agoEquifax's stock price went up when they were hacked.
- selectodude 21d agoElon fucking Musk has literally every single piece of personal information of every person in the country. It’s so far past too late for any of this to matter. I’m not sure how we start over but this data plus LLMs is gonna make it a full time job to keep your parents from sending every penny to a scammer.
- shireboy 21d agoWhen this first landed I asked what the fix could even be. Everyone needs a new ID at a minimum. But then I got to thinking: 1) is that the point? Conspiratorial thinking I know but “hey all Our ids got hacked I guess we need a national id”. And related 2) the current id system from a security standpoint was a band aid fix for outdated world to be shoehorned into a modern one. IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN” but bottom line, at least in US there is no cryptographically secure identity system that proves you are the citizen you say. And that fact bleeds into all sorts of patchwork solutions, fraud, etc. Moreover there are serious philosophical hurdles to getting to one. I’m not even positive I want one. But unless there is some zero-trust way to do this, I’m not sure what the fix would be.
- iugtmkbdfil834 21d agoAnd then, in real life, one discovers that institutions route around in creative ways for all sorts of different reasons ( recently had to 2fa a transaction at a god damn teller window; you just took my DL ).
- AnimalMuppet 21d agoIsn't the DL (which has a picture) and your face the two factors? Isn't that the whole point of having a picture on a DL?
- iugtmkbdfil834 21d agoYes, but it is rather pointless to argue with teller who can't even begin to understand policy dictating it, much less, apparently, make exceptions. Machine told me to do it.
- lotsofpulp 21d agoNo, the teller is not sufficiently qualified to be liable enough to match the picture on the ID to the person in front. The 2nd factor is the phone number on file, which offloads liability for errors in that mechanism to the phone company. The goal is to reduce the amount of decisions the teller makes, so as to reduce the amount of errors they can make, which also reduces the amount of training they need, all of which reduces costs. It’s really interesting how the lack of US federal government stepping in to provide an official electronic identity verification API has resulted in the mobile phone networks becoming the de facto arbiters of identity. Even for government services. I don’t even think I could trust having my phone number on someone else’s mobile phone plan, as I would want to ensure I have as much control over it as possible.
- jsrozner 21d agoThere's a solution: personal liability for the executives and managers at the company, and for the investors. For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealthy-poor.html https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
- schainks 21d agoThis.
- mccauley 21d ago100%
- mahboi 21d agoIt's cleaner to hold some of a corp's money in escrow if they're handling IDs, to ensure they can't avoid fines via bankruptcy.
- jm4 21d agoThis is a little harsh. What about requiring companies to carry management liability insurance? Or to list individual managers on cybersecurity insurance policies? Premiums will rise when a company employs managers with claims history. Eventually, it becomes difficult to employ them in key positions if they have a bad track record.
- charcircuit 21d agoHundreds of millions of American's names, addresses, social security numbers, etc were in the NPD leak which has been publicly downloadable. The idea that any of this information should be considered private, only knowable by the person themself is wrong.
- nullc 21d agoThe breach is bad no doubt-- but this information was already readily available to bad actors e.g. via Lexis Nexis. Practically all states sell DL and registration information to information brokers, and the remaining ones require you to obtain auto insurance, and the insurers all sell the information. Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo. (Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.) In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.
- vjvjvjvjghv 21d ago"but this information was already readily available to bad actors e.g. via Lexis Nexis." My ex had access to Lexis Nexis and I was always shocked how much information about people they have.
- mindslight 21d agoRight on! It's always frustrating reading articles framed in terms of "security breaches" and "dark web", invariably doing hand waving at unspecified harm, when the real threat actor for pretty much everybody is the "above board" surveillance industry. Random people who buy this info outside the law can't really hurt me - it's not like I'm a witch and my DL# is my "true (system-given) name" and I disappear when they say it or something. Rather the parties who can hurt me are the ones who pretend knowledge of this semi-public information is an authentication system, and then hassle me with legal nastygrams when they get defrauded. Or who keep comprehensive dossiers on my behavior to unaccountably sort me into corporate-defined boxes so they can better extract my wealth and otherwise form anti-competitive arrangements against me. These actual attackers operate mostly according to the (very broken) law, and they are what needs fixing. Not just scaremongering when some bogeyman "wrong people" get a small taste of the exact same information.
- farceSpherule 21d ago[dead]
- 0xmattf 21d agoIs there any way to check if your ID was compromised without going on some onion site? I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious. I think IDScan should set something up so we can check if our data was compromised, at the least.
- abirch 21d agoWhat I would love to know is who is selling my info. I get texts from all kinds of politicians but I didn't know who sold them my number. Seems like selling someone's property without their approval should be illegal. It'd be great if I could request who sold them my data, then go to that entity tell them to stop selling (rinse and repeat)
- jolmg 21d ago> It'd be great if I could request who sold them my data, then go to that entity tell them to stop selling (rinse and repeat) There are a number of companies (e.g. Delete Me) that offer that service. They wouldn't have caught the subject of this post since it was a breach. The problem here arose from ID verification where you need to show your ID to an entity that then has the opportunity to store it.
- mitxela 20d agoMost of these companies are themselves data harvesting scams. You have to give them all your data so they know what to delete. Then they sell that data.
- 0xmattf 20d agoThis is true. I think Brian Krebs reported on a scam involving this. Some of those data deletion companies actually own the data companies...
- devinplatt 21d agoAt least here in California (maybe the whole US) I think there is a law requiring the government to give our phone numbers to politicians to spam us. Seems crazy until you realize politicians write the laws
- robinsoncrusue 21d agoAmerican national security apparatus do not care about the actual Americans. They are too worried about foreign entanglements, and protecting a specific foreign country than their own country.
- O3marchnative 21d agoI'm reminded of the OPM breach back in 2015 [0]. Practically everyone that even applied for a security clearance was compromised. In addition, millions of sets of fingerprints were recovered by the entity that carried out the hack. [0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Management_data_breach https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
- deepsquirrelnet 21d agoWow, how could this have happened right before the election? Surely this will not be used as a pretext for anything.
- klaff 21d agoDoes anyone know what "disabling advertising identifiers" actually means?
- JumpCrisscross 21d agoIs there anything comparable going on to the data of Chinese citizens? Or Chinese public servants?
- deleted 21d ago[deleted]
- joshfraser 21d agoKYC = kill your customer It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger. AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out. These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked. The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.
- aucisson_masque 21d ago> The correct answer is probably a new government ID system based on public key encryptio Check out Estonia
- joshfraser 21d agoThe interesting question is how to verify who someone is before issuing them a digital ID. Estonia verifies people using their Estonian ID cards, their mobile devices, or biometric data if they have it recorded. The system is only as strong as its weakest link. ID cards can be faked and mobile devices can be stolen. Biometrics can't be easily faked, but they're horrible to have leaked because you can't change your fingerprints or eyeballs if compromised.
- mitxela 20d agoSo if I steal someone's private key I can be them and nobody can refute that I'm them? And the government retains a record of everything you ever do? How's that any better than the present state of things?
- ChrisMarshallNY 21d agoI'm glad to see this keep popping up. It gets pushed down, very quickly, when it does. I suspect the reason for that (nothing other than a "gut feeling" that I get, seeing the story pushed off the front page so quickly, every time), is that the breach was through a backdoor that was deliberately coded into the system, for TLA use, and what happened, is exactly what people keep warning about; it got breached, and is now a "front door," and The Powers That Be don't want that examined too closely.
- classified 21d agoThere were times when the words “national security” made rules and laws magically evaporate. Now that total surveillance is already here, companies and agencies can have it for close to free, and nobody gives a rat's ass for rules and laws anyway, national security is no longer needed.
- ProllyInfamous 21d agoProTip: US Passport Cards are official identification documents which don't have your home address listed on them. Also: many US states allow you to use a PO Box on your license (e.g: Calif., Tenn., Texas)
- kornork 21d agoWe need a corporate death penalty for these kinds of breaches.
- techgnosis 21d agoI'd rather tackle this problem from a different angle. If a bank gives a fraudulent loan to someone in your name, its YOUR problem and not the bank's problem. Why don't we make it the bank's problem? They gave the fraudulent loan. How is it not their problem to fix? If we fix that, then having your ID stolen is a much, much smaller problem.
- mitxela 20d agohttps://www.youtube.com/watch?v=CS9ptA3Ya9E https://www.youtube.com/watch?v=CS9ptA3Ya9E
- mizzao 20d agoIt's probably related to "the optimal level of fraud in a financial system is not zero" and reducing false positives would make way harder for everyone to get loans, which is bad for both banks and consumers.
- Forged-cs 21d ago[flagged]
- xtiansimon 20d agoDamn. I just received a notice my PII (including SSN) was leaked in the DentaQuest security breach (May 2026). Something between 2.6M - 15M records. Personally, data security is the AI Doom I’m concerned about, not being turned into paperclips. https://haveibeenpwned.com/Breach/DentaQuest https://haveibeenpwned.com/Breach/DentaQuest