7 ms·
The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep
by Nition 15d ago
The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.
- veunes 15d agoYeah, this is the part I don't get either. Verification should produce a yes/no result, not a permanent archive of everyone's identity documents
- samlinnfer 15d agoThe whole point is they keep it forever. You think any id verification services actually delete the data?
- Nition 15d agoI mean, just because all your friends are jumping off a cliff...
- kevin_thibedeau 15d agoIf you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.
- mindslight 15d agoIt feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...
- maccam912 15d agoIt's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.
- Nition 15d agoGood point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.
- samlinnfer 15d agoIt's obvious they are keeping them all. 150 million didn't get all re-scanned at once.
- applfanboysbgon 15d agoIt's actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker's claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned. Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.
- Nition 15d agoYeah. It's a bit unfortunate that I seem to have the top comment in this thread now despite it probably being wrong, at least to some extent, but it's too late to edit it. I agree with your second point as well.
- analog31 15d agoI believe we need to criminalize possession of the data, with statutory damages per violation.
- DANmode 15d agoNegligence is already illegal. Just locate a prosecutor.
- DaSHacka 15d agoI'll sleep so much better at night when the company that'll leak my Social Security Number on the internet due to hosting a backup of a database that's assessible publicly gets fined $0.30 per SSN leaked. Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.
- DANmode 14d agoSounds like you’re not going to sleep well at night regardless, choosing to stick around for more of that.
- megagpt5 15d agoNegligence isn't a crime in itself. It is an explanation or cause for other crimes. And there is nothing illegal in the US about selling pictures of people's drivers licenses.
- DANmode 14d ago> there is nothing illegal in the US about selling pictures of people's drivers licenses. 18 U.S.C. § 1028 makes certain transfers involving identification documents criminal. It specifically covers a driver's license or personal identification card and provides enhanced penalties for transferring such documents. 1028 expressly recognizes electronic transfer as satisfying its interstate-commerce requirement. What are you talking about?
- 14d ago
- Aurornis 15d agoThe last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation. Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
- chezelenkoooo 15d agoAny kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure. So most businesses are not permitted to just delete the data.
- michaelt 15d agoBack In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234" Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.
- SapporoChris 15d agoA system abandoned decades ago? https://en.wikipedia.org/wiki/Gold_standard https://en.wikipedia.org/wiki/Gold_standard
- Tarq0n 15d agohttps://en.wiktionary.org/wiki/gold_standard https://en.wiktionary.org/wiki/gold_standard
- expedition32 15d agoUnfortunately letting random companies photocopy your passport leads to identify fraud.
- embedding-shape 15d agoWould it be better if it was a digital copy, or what? Somehow, my drivers license, passport and ID has been photocopied and digitally copied countless of times, in multiple countries, over more than three decades, yet not a single time I've been affected by identity fraud. So somehow, seems it doesn't "lead to" always but I'm sure it does happen sometimes, yes.
- wiredbox 15d agoWhich is why you need GDPR equivalent in the US…
- brador 15d agoStoring personal data should require insurance that increases per data point.
- megagpt5 15d agoLegislating insurance prices is illegal for good reason. Either it's too high and the government has just siphoned a lot of money to insurance company shareholders, or it's too low and the government has effectively made it illegal to provide that insurance.
- fhub 15d agoIMHO If statutes require it to be kept, then it should get written to storage that can’t be read without being there in person. Have the police actual show up to look at it. Make it really slow to look at too. Cryptographically slow.
- lifestyleguru 15d agoEvery time someone takes photo or photocopy of my documents "for the police" or "for security" I'm just thinking "why are you lying to me".
- anonym29 15d agoThey don't necessarily need to be lying for it to be harmful to you - they could simply be grossly incompetent as a custodian of your data. Most people are grossly incompetent even as stewards of their own data, after all.
- cucumber3732842 15d agoNo, you can't, because then when the headline reads "FBI probes service selling <whatever touchy subject you had to verify for in the first place>" and you don't have those records you wind up taking it. And that's before you even start talking about retention laws. There can be a discussion about retention periods and the like but too short a retention period amounts to "trust us bro" in the eyes of some un-feeling government agency who is trying to screw you either at the behest of the law or at the behest of whoever hates you and has their ear. Something needs to be done but "just delete it after you've verified it" is not workable at scale. Yes I know it worked fine for brick and mortar forever. Maybe some acceptable technical solution could be reached, idk.
- krebsonsecurity 14d agoDeleting the data after verification is a good practice. But if you're actively compromised, it probably doesn't matter how long you keep the data because it's already been immediately "backed up" by the intruders the second it is collected. Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in reality the attackers had card-sniffing malware installed on every single cash register at every single store across the country.
- ericmay 14d agoIdeally it’s not even stored…
- tbrownaw 14d agoWell at least they need it until they get back a success response from the bank/payment processor/whoever.
- Tangurena2 14d agoIn the Heartland data breach, the custom malware that hackers wrote copied the mag stripe as it passed through the payment system. I got a new credit card after that broke (also after Target's breach was reported). Heartland did not store the card details at all. How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type dir or ls at a command prompt, it says something like "X files using Y bytes, Z bytes free". How do you know those numbers are true/correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out). Heartland - #19, Target - #20 at: https://www.upguard.com/blog/biggest-data-breaches-us https://www.upguard.com/blog/biggest-data-breaches-us You may notice that the poster of the comment you are responding to is mentioned a lot on that page.
- CrazyMusicians 14d agoThat's a pretty decent list of breaches. Never seen it before. Thanks for sharing. I can't believe they didn't mention the Ashley Madison breach, which affected more than 30 million people, ended countless marriages, and led to more than a few suicides.
- miohtama 14d agoOften regulation requires companies to keep this data for many years in the case the government wants to check on you. Not in the US, but in Spain, police gets this data real time when you rent a car or check in to a hotel. This is of course important for protecting you.
- ipsod 14d ago> This is of course important for protecting you. Well, that's very kind of them. I am constantly impressed at the kindness of our governments, and the recent growth of that kindness. I guess that, with all of the power that modern technology is giving them, they're finally getting to live out their heart's desires of being very, very kind.