Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

38% Positive

Analyzed from 1293 words in the discussion.

Trending Topics

#verification#dmv#data#https#government#age#com#knowledge#don#company

Discussion (52 Comments)Read Original on HackerNews

xvilkaabout 2 hours ago
The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proofs for particular properties (e.g. if the person has a driver license or not) without de-anonymizing the account. In the rare even of root key leak you should be able to physically go to the authority and make a new one, while revoking the old key. I don't see any other better alternatives than this.
grebcabout 1 hour ago
I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through.

The alternative is do it offline.

piva00about 4 hours ago
Brian Krebs' article is, in my opinion, a much better read for this story[0].

[0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

altairprimeabout 3 hours ago
ChrisMarshallNYabout 2 hours ago
It also dropped off the front page, pretty quickly, despite getting a lot of upvotes and comments. I was surprised by that, as this is exactly the type of story that tends to spend a couple of days on the front page.

But it’s also the kind of story that won’t stay down, and will definitely be back.

It appears as if there are folks here that don’t want to talk about this.

hurfdurf20 minutes ago
Was on the front page for ~12 hours.

https://hnrankings.com/49529621

smallerizeabout 3 hours ago
padjoabout 3 hours ago
Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.
wiradikusumaabout 2 hours ago
But usually gov't will outsource to random 3rd parties, no?
bryanrasmussenabout 2 hours ago
probably gov will outsource to 3rd party for gov to build system to track and manage ID. Sometimes though also to manage, as in Denmark's MitID mainly managed by NETS under government set rules.
psychoslaveabout 2 hours ago
As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions.

Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which of course impact quality of deliveries (not shaming the people who do the hard job without the relevant means). And while more distributed governmental topologies would have their own caveats, at least it would less likely offer opportunities for single point of failure.

[1] https://francepassoire.com/

m4rtinkabout 1 hour ago
On the end of the day, it is the state that issues these ID documents. So if you let the government go bad, IMHO the form of the documents does not matter that much.

During the totalitarian communist rule in Czechoslovakia, the state would regularly interfere with passports of people considered not loyal enough - withholding them outright or inventing extra paperwork that was necessary for the border police to let you out of the country. They also controlled all supply of foreign currency, both in an out.

Then if someone was actually allowed to travel outside the country but failed to return, their family and relatives would be punished, including demotion at work & prohibition of higher education.

So if your government goes bad, this is what will happen - the form of the ID takes at that point does not make much difference.

drcongo18 minutes ago
I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.
andaiabout 1 hour ago
> increasingly fascist chauvinist nationalist drifting in the geopolitical landscape

What's going on in France?

pelagicAustralabout 3 hours ago
I wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!
andaiabout 1 hour ago
You know, it always bugged me that the NSA (and more directly Google, and my phone company, and so on) know where I was at exactly this time a year ago, but that I do not.
nope100042 minutes ago
In Google Maps Timeline you can definitely see it (if you set it up and you brought your phone)
classifiedabout 1 hour ago
I thought that's what LLMs are for?
jonplackettabout 1 hour ago
We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible.

‘Just make the encryption secure and so we can read it’

‘Just check everyone’s id but make it totally secure’

lrvickabout 3 hours ago
If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.
adiabatichottubabout 3 hours ago
CADMV claims on their web site that they cannot accept a P.O. box as a residence address. I have yet to find anything in California state law supporting this policy, though IANAL. Their enforcement seems to be quite lax.
lrvickabout 3 hours ago
You cannot literally use "P.O. box" but if you use the virtual street address service the USPS offers now it works just fine.
spuzabout 3 hours ago
Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?
tensegristabout 2 hours ago
selling (data you give to the DMV) [to third parties], not selling (data you give) [to the DMV]
tmnvixabout 2 hours ago
The DMV sells the data you give to the DMV. The DMV does not sell the data you give to the DMV to the DMV.
Melatonic17 minutes ago
In guessing you can't choose to opt out ?
spuz43 minutes ago
Haha, damn not enough caffeine this morning to parse correctly
tpoacherabout 2 hours ago
your positional encoding vector seems a bit off :D
kleiba2about 1 hour ago
And again, there will be no monetary consequences for the companies that failed to secure our private data.
subscribed15 minutes ago
More like class action lawsuit, $500m settlement, $300m for lawyers and $0.50 for every victim.
freehorseabout 1 hour ago
And governments will continue to force citizens to use these shitty companies for whenever they need id verification.
jwilkabout 3 hours ago
The HN submission title is a garden-path sentence:

Hackers Had a Live Feed of Every ID Verification Company Scanned

(Huh? How do you scan a company?)

The original title is easier to parse:

Hackers Had A Live Feed Of Every ID This Verification Company Scanned

HelloUsernameabout 1 hour ago
Thank you, it was very confusing indeed, the HN post should be fixed to something directly clearer
addagabout 1 hour ago
Crazy hack considering the order of magnitude...
spwa4about 2 hours ago
No worries! Governments who used this company are taking responsibility and now have a plan to, at the very least, replace all IDs they forced people to expose and to make sure the old ones are unusable!

That's a sarcastic joke. It's how governments demand private companies react, but ...

saghmabout 3 hours ago
This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet
walrus01about 3 hours ago
I think there's a number of people reading this who clearly didn't detect the satirical nature of this single sentence. It's blunt and obvious, but even so...
brokenmachineabout 3 hours ago
All the kids will be safe now they're logging into porn sites as Pete Hegseth.
walrus01about 2 hours ago
Only after they've had their mandatory scrotum inspection and testosterone check to join the military at age 18.
vrganjabout 2 hours ago
This is precisely why the authority doing these checks needs to be the government that already issues the IDs.

Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place.

I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue.

cynicalsecurityabout 3 hours ago
That was sarcasm.
dgellowabout 2 hours ago
Are you sure? It’s really hard to differentiate nowadays
tpoacherabout 2 hours ago
> Are you sure? It’s really hard to differentiate nowadays

Case in point; I can't tell if you're being sarcastic or not! :D

LtWorfabout 3 hours ago
Except this helps no child.
Intermernet41 minutes ago
Isn't that the one that was left behind in 2002?
Advertisement
croesabout 1 hour ago
> There is no safe age verification. There is no age verification that doesn’t put people at risk.

There are zero knowledge proofs

miatrwa32 minutes ago
True. I built a ZK age verification based on Polish digital identity https://x.com/maciejlotkowski/status/1899896737688436844, but I didn't find a business case for it at the time.

There's a EU initiative https://digital-strategy.ec.europa.eu/en/news/commission-mak.... The direction is generally good, but I'm not very positive about the implementation (as with everything comes from the govs).

nullc33 minutes ago
Concrete ZKP age verification schemes are hardly zero knowledge.

Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy.

Now little Johnny borrows my ID, and uses it to setup some oracle that provides ID validation for every kid and bot in the country. Woops.

To stop that you must compromise the idealized zero knowledge properties of the scheme, and in doing so you create the potential for harm/risk for everyone.

Sure, it's better than sending an ID card live feed to the dark web, but the risks of ID card theft are at least somewhat easy to understand.

Some of the threats to human rights don't even require the departure from the 'idealized' model-- as even the idealized model requires an ID issuer to issue the of-age person an ID. And so if the ID ZKP is widely required then the issuer can unperson you by simply declining to issue you an ID.

croes29 minutes ago
add MFA to the check
khalic27 minutes ago
"Nobody could have predicted this"

It's getting really tiresome