The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.
maccam912 8 minutes ago [-]
It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.
Nition 7 minutes ago [-]
Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.
samlinnfer 11 minutes ago [-]
The whole point is they keep it forever. You think any id verification services actually delete the data?
Nition 8 minutes ago [-]
I mean, just because all your friends are jumping off a cliff...
kevin_thibedeau 3 minutes ago [-]
If you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.
fishfasell 1 hours ago [-]
So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.
3eb7988a1663 36 minutes ago [-]
153 million puts them at roughly 1/2 of all Americans.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
mulmen 31 minutes ago [-]
I had two active Clear subscriptions at the same time. How did an identity verification company not know both accounts were the same person? They were both using the same credit card!
What does an "identity verification" company even do?
toast0 17 minutes ago [-]
Clear takes your money and zips you through the airport checkpoint line. Because terrorists wouldn't spend money or time to get through the lines faster?
wahern 1 hours ago [-]
Your ID and PII was likely already on the black market, the only question is accessibility and price. You can't exactly advertise on Reddit or sell to every two-bit identity thief and not expect heat.
cute_boi 1 hours ago [-]
I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.
zdragnar 40 minutes ago [-]
You've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
jakevoytko 1 hours ago [-]
As always, friendly reminder to lock your credit and enable your mobile carrier's protections against SIM swapping
fishfasell 1 hours ago [-]
Excellent advice. A compromised phone number is an absolute nightmare, most MFAs default to SMS as a last resort. I lost my Okta verify login at work since I transferred phones, thought I'd need a ticket with our ID team but turns out my phone number is sufficient. Wasn't thrilled about that.
FpUser 50 minutes ago [-]
So they want to see my driver's license "to make the world safer" when in reality all they do is facilitating mass fraud. When the fuck will those brainless infusoria will get punished 9fat chance).
Rendered at 04:06:59 GMT+0000 (Coordinated Universal Time) with Vercel.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
What does an "identity verification" company even do?
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.