DE version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
43% Positive
Analyzed from 1678 words in the discussion.
Trending Topics
#data#identity#verification#ids#need#more#company#million#don#security

Discussion (57 Comments)Read Original on HackerNews
So most businesses are not permitted to just delete the data.
Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.
Just locate a prosecutor.
Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.
Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.
Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
I didn’t go through with that part of my application and didn’t keep the job.
What does an "identity verification" company even do?
They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).
One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.
The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.
Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is.
And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We're talking a $5 billion company handing 15 million people's credit reports to hackers, and getting fined $15 million.
Some Interrail travellers told to cancel passports as hacked data posted online
https://www.theguardian.com/technology/2026/apr/23/some-inte...
I just don’t hear about it anywhere near as much.
[0] https://en.wikipedia.org/wiki/Vastaamo_data_breach
Monetary fines have a tendency to simply be modeled in as a cost of doing business. Going to prison is far more effective when the goal is to concentrate minds.
You'd think that 80 million people from a rich first world country would be enough of a market to use this.
No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.