8 comments

  • xvilka 2 minutes ago
    The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proofs for particular properties (e.g. if the person has a driver license or not) without de-anonymizing the account.
  • piva00 2 hours ago
    Brian Krebs' article is, in my opinion, a much better read for this story[0].

    [0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

  • padjo 1 hour ago
    Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.
    • wiradikusuma 41 minutes ago
      But usually gov't will outsource to random 3rd parties, no?
      • bryanrasmussen 20 minutes ago
        probably gov will outsource to 3rd party for gov to build system to track and manage ID. Sometimes though also to manage, as in Denmark's MitID mainly managed by NETS under government set rules.
    • psychoslave 38 minutes ago
      As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions.

      Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which of course impact quality of deliveries (not shaming the people who do the hard job without the relevant means). And while more distributed governmental topologies would have their own caveats, at least it would less likely offer opportunities for single point of failure.

      [1] https://francepassoire.com/

  • pelagicAustral 1 hour ago
    I wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!
  • lrvick 1 hour ago
    If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.
    • adiabatichottub 1 hour ago
      CADMV claims on their web site that they cannot accept a P.O. box as a residence address. I have yet to find anything in California state law supporting this policy, though IANAL. Their enforcement seems to be quite lax.
      • lrvick 1 hour ago
        You cannot literally use "P.O. box" but if you use the virtual street address service the USPS offers now it works just fine.
    • spuz 1 hour ago
      Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?
      • tensegrist 50 minutes ago
        selling (data you give to the DMV) [to third parties], not selling (data you give) [to the DMV]
      • tmnvix 52 minutes ago
        The DMV sells the data you give to the DMV. The DMV does not sell the data you give to the DMV to the DMV.
        • tpoacher 34 minutes ago
          your positional encoding vector seems a bit off :D
  • jwilk 1 hour ago
    The HN submission title is a garden-path sentence:

    Hackers Had a Live Feed of Every ID Verification Company Scanned

    (Huh? How do you scan a company?)

    The original title is easier to parse:

    Hackers Had A Live Feed Of Every ID This Verification Company Scanned

  • spwa4 19 minutes ago
    No worries! Governments who used this company are taking responsibility and now have a plan to, at the very least, replace all IDs they forced people to expose and to make sure the old ones are unusable!

    That's a sarcastic joke. It's how governments demand private companies react, but ...

  • saghm 1 hour ago
    This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet
    • walrus01 1 hour ago
      I think there's a number of people reading this who clearly didn't detect the satirical nature of this single sentence. It's blunt and obvious, but even so...
    • vrganj 43 minutes ago
      This is precisely why the authority doing these checks needs to be the government that already issues the IDs.

      Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place.

      I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue.

    • brokenmachine 1 hour ago
      All the kids will be safe now they're logging into porn sites as Pete Hegseth.
      • walrus01 19 minutes ago
        Only after they've had their mandatory scrotum inspection and testosterone check to join the military at age 18.
    • cynicalsecurity 1 hour ago
      That was sarcasm.
      • dgellow 41 minutes ago
        Are you sure? It’s really hard to differentiate nowadays
        • tpoacher 32 minutes ago
          > Are you sure? It’s really hard to differentiate nowadays

          Case in point; I can't tell if you're being sarcastic or not! :D

    • LtWorf 1 hour ago
      Except this helps no child.