Rendered at 11:44:28 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
ethagnawl 1 days ago [-]
I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID.
Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which gets cross-referenced by the legit provider against the id.gov database.
Of course the devil is in the details and I wouldn't trust GrandePelotas and friends to vibe code such a system but it is absolutely possible and is something we should, at the very least, be thinking about.
swingboy 23 hours ago [-]
This would probably be considered “disenfranchising” because people would have a hard time keeping track of their public key and the process to recover it would involve having to take off work, transportation, etc.
seniorThrowaway 20 hours ago [-]
it would likely be built into the ID, like a PIV/CAC card. I thought about this same thing many years ago, the state DMV's could be in a PKI web of trust with a federal signer/issuer/cross-signer above them. Proving your identity online would mean inserting your ID into your computer so it could be crypto-graphically validated. Yes there are genuine privacy and other concerns, but we'll probably end up there anyway and could have avoided all the mess of having these crappy third party for profit companies involved. The tech already exists, and has existed for some time.
embedding-shape 9 minutes ago [-]
> the mess of having these crappy third party for profit companies involved
I think the problem that lots of people, including all the people involved in those companies, don't think that's a problem but a feature. Adds "jobs", GDP, filling their own pockets and a whole host of other "benefits" they're willing to look past any drawbacks in order to get.
Teknomadix 15 hours ago [-]
This is essentially how my Estonian ID card works. The ID card is inserted into a USB smartcard reader and grants access to identity verification an thus access to services.
Sabinus 13 hours ago [-]
But the American public is petrified of systems like that because of the leftovers of frontier settler culture and fear of communism. They're apparently far more comfortable with the similar but worse systems being set up by corporations.
Spooky23 22 hours ago [-]
[flagged]
kspacewalk2 19 hours ago [-]
Conservatives seemingly went from the libertarian extreme where everything under the sun is a "threat to liberty" straight to cheer-leading global authoritarianism, skipping the middle altogether.
lcnPylGDnU4H9OF 23 hours ago [-]
That could alternatively be seen as a reason we should make employment less hostile to workers and encourage less car-centric city designs.
thephyber 22 hours ago [-]
Ah yes, a facetious jab at legitimate criticisms of Voter ID laws.
It's worth pointing out that the point of contact for state IDs is the DMV, which is the butt of every government inefficiency complaint. If, instead, it was done at USPS offices or even by postal workers on their routes, no one would complain.
It's entirely about whether the burden is placed on the citizen to maintain their Constitutionally guaranteed rights or whether political agents can use the state to selectively burden neighborhoods, especially ones with no / badly performing DMV offices.
packetlost 21 hours ago [-]
> which is the butt of every government inefficiency complaint
I always find DMV (or whatever your state's equivalent) inefficiency arguments to be hilarious. They're run extremely efficiently for the government. They suck use because of that (long wait times, most important stuff gets shipped by mail weeks later).
autoexec 19 hours ago [-]
> I always find DMV (or whatever your state's equivalent) inefficiency arguments to be hilarious. They're run extremely efficiently for the government.
It's real funny until they pass a law that says you need an ID to vote and then immediately close the only DMV anywhere near where you live specifically because they want to keep you and your neighbors from voting (https://www.yahoo.com/news/feds-called-investigate-alabama-d...)
thegrim33 16 hours ago [-]
Ah yes, the good 'ol "link to an article as proof of my claims, the article then contains multiple links to proof of the article's claims, and the multiple links, when followed, all end up leading to 404 pages with no content." Well, that convinces me.
I've found that the speed of the DMV seems to vary wildly by state, and possibly even city and location, based on anecdotes.
Earlier this year, my license was expiring and I decided to get a Real ID. I was able to create an appointment on the Oregon DMV website. It was set for 10 AM. I got there at 9:50 and checked in. My name was called up at only a couple minutes after my appointment time. I gave my documents and paid, then was instructed to wait by the camera area for my picture. I had barely sat down when my name was called. They took my picture, and I was all set. I was out the door by 10:15. Pretty sure my ID then came in the mail only about a week later.
So when people talk about long waits, I don't know what they're talking about. Maybe their state just sucks.
dghlsakjg 15 hours ago [-]
It can also depend on where you are within the state.
When I lived in Colorado the smart move in Denver was to start lining up about an hour before the DMV opened (for driver licenses, car registration never had much of a line). Out in the mountains, I was able to just walk in just about anytime. The longest wait I had in the small mountain town I lived in was when the one lady working there was doing a driving test, and I had to wait 10 minutes for her to get back.
Living in Washington, they allow private businesses to register vehicles, so transferring a car was normally a 5 minute job. Never did bother to switch my DL, so can't comment on that.
Now I'm up in BC where vehicle and driver licensing is handled by the state owned insurance monopoly. Any agent, private or public, can register your car. You can get the licensing done at public insurance offices, or at provincial service centres that handle all sorts of business by appointment or walk in. It all works pretty well.
18 hours ago [-]
thephyber 11 hours ago [-]
All the more reason to decouple DMV from ID verification.
Like I said, the USPS is in a much better position to be able to scale identity to the national scale.
what 9 hours ago [-]
USPS already handle passport applications no? It’s where I went for my kids and they verify all the documents or whatever.
bigbuppo 19 hours ago [-]
I live in Misissippi. The last time I had to go in-person for a license renewal I was in and out in less than 10 minutes because they had automated kiosks. Then again, Mississippi is a progressive state.
thephyber 11 hours ago [-]
Yes, I'm sure every person in Mississippi has the same super expedient interaction as a HNer when they have to visit to get their ID documents. I bet you even live next door to the DMV so your travel time was negligible.
The point of the government doing it is that it has to be able to service those people who live maximally far from a DMV (say 60 minutes each way by car), who can't drive there, who have to weigh losing pay to take the time to travel there, who have below average intelligence, who are functionally illiterate (because Mississippi created A LOT of those before their recent education reforms), who "can't use technology", who forgot to bring whatever specific document qualifies for Real ID, etc.
what 9 hours ago [-]
The idea that people are unable to get IDs is an absolute myth. You need it to for basically everything a normal adult does.
mulmen 18 hours ago [-]
Given the voter suppression history I’m curious if that experience is consistent across location and racial dimensions.
mulmen 18 hours ago [-]
> They're run extremely efficiently for the government. They suck use because of that (long wait times, most important stuff gets shipped by mail weeks later).
The government is efficient without qualification.
People just like to complain and Reagan was charismatic so we’re cursed with this government inefficiency meme. We’re programmed to repeat it even when providing counter examples.
The overwhelming majority of the waiting I do in life is at the hands of private organizations who are unwilling to invest in proper staffing.
There will no doubt be replies to the contrary but to them I say they have identified corruption, not inefficiency. When the government doesn’t work it is by choice.
dghlsakjg 15 hours ago [-]
People also confuse that government programs have to prioritize many things over and above cost in ways that businesses don't.
The government has to (and should have to) provide the same service to everyone, everywhere. Businesses would never bother putting a DMV office in a small remote county because of cost, even if it was unfair and inconvenient to people living there. Government does do that, and it doesn't look great on a balance sheet.
18 hours ago [-]
sidewndr46 17 hours ago [-]
This has to be a joke right? The USPS is the group that cut down my mailbox, then left it a blank slab for 6 months. After replacing it, I had an employee state that under no circumstance would they be able to provide me a key to my mailbox.
LorenPechtel 16 hours ago [-]
Voter ID laws aren't about fraud. The amount of fraudulent voters required to sway an election would be a massive operation that could not be kept secret. But it's a distraction from the real issue: vote fraud by improperly denying people access to the ballot box.
Sure, you can get an ID cheap. Most of the time. But if all of your ID is lost (which can easily happen to the victim of a purse snatching) it's going to take time and money to fix the problem. And voter registrations are not supposed to be permitted to be challenged too close to the election. Not supposed to be doesn't mean it doesn't happen repeatedly, though. This scales much, much better than sending in fraudulent ballots. We find a handful of fraudulent ballots, often by Republicans trying to prove fraud is easy. 2016 and 2024 both had more people denied access by ID laws, challenges and the like than the margin of victory. And those missing votes would have skewed heavily Democrat.
Almost forgot: SAVE puts a very onerous paper trail on divorced women. They'll need copies of the paperwork changing back to their maiden name--something an awful lot of them don't have. I've already seen a variation on this with RealID. A mistake was made at my wife's naturalization, a hyphen crept into her name that didn't belong, went unnoticed for years. Even when it was discovered it was a so-what. Social security had an errant hyphen, everything else was as intended. No problem. Then RealID came along--and she had to do a legal name change in order to change her name to what her ID and passport said. Weeks and hundreds of dollars.
Denying legitimate voters is just as much fraud as permitting fraudulent ones. A system in which the the former happens at least 10,000x as often as the latter is not a good system.
freedomben 21 hours ago [-]
> If, instead, it was done at USPS offices or even by postal workers on their routes, no one would complain.
You must have had better luck with post offices than I have. Having lived in a dozen states and used many different post offices, the vast majority is an utter nightmare. Between the rudeness and the apathy, I would much prefer the DMV (depending on the state)
ericmay 24 hours ago [-]
Which “normal, modern countries” have done variations of this?
embedding-shape 23 hours ago [-]
Not sure I'd call it "normal", we're exceptional! :) But Spain does have this, I have a literal digital certificate linked to my name, sitting in my browser, that I use for logging in to various government services and also use to sign+submit my taxes. Apparently there even is a page in English explaining how it works, in case others are interested: https://www.fnmt.es/en/ceres
> The CERES project (Spanish Certification) headed by the FNMT-RCM consists of establishing a Public Certification Entity that will enable authentication and guarantee the confidentiality of communications between citizens, companies or other institutions and the Public Administrations via the open communication networks.
So far, in my ~decade here, it's been working out great and is so easy to use.
Dejhavi 19 hours ago [-]
Don't forget the DNIe...you can authenticate using a QR code via the app (like the DGT app)
Estonia's Digital Residency card has done this for nearly 2 decades.
S Korea has had government issued digital IDs for all online transactions, although it was originally implemented as an Internet Explorer 5.5 plug-in (eww). I haven't heard anything about how it works these days.
Japan has new digital IDs cards and a standard little device available at every corner store to use it to digitally sign legal documents.
MilaM 23 hours ago [-]
Most European countries offer some kind of government issued digital ID to their citizens, although adoption varies by country. I know two implementations first-hand and use them regularly. They work really well to prove your identity over the Internet. You can use it to open a bank account or use government services.
The next step will be EU-DI, an app based wallet with many more features and hopefully better interoperability between EU countries.
Interesting that some of these, including some from the Nordic countries are actually run by financial institutions and not the government.
embedding-shape 22 hours ago [-]
Yeah, it's kind of surprising to me, even as a Swede, how the entire society just walked straight into "Yeah sure lets depend on BankID which is run by a for-profit company" without really thinking about it. Sure, it's easier, but there are other ways to solve it, that is a bit more resilient and works in practice, like what Spain has (where I live now), where it's even easier and we don't rely on any for-profit companies to provide this service.
ShowalkKama 24 hours ago [-]
Italy doesn't have crypto keys (as the average person would just lose/leak them) but they offer SSO login with the ID card.
Basically whenever you need to verify your identity you pick "sign in with CIEid", you get redirected to a goverment website where you can authenticate (typically by scanning a qr code + scanning your physical id card on your phone) and then you approve/deny the authentication request (you can also clearly see which data is shared (name, last name, dob, etc)).
it's stupid easy to setup, the app is not overly bloated and it has different options to authenticate.
Levitating 24 hours ago [-]
European passports are NFC tags and you can prove your identity using your phone.
ericmay 24 hours ago [-]
I think American passports have those as well because I remember all the hax0rs making videos showing where to smash the NFC chip with a hammer or to buy wallets with special NFC blocking properties to keep folks from “stealing their identity” from the NFC chip. Personally I never cared but your comment jogged a memory.
Recently I added my passport to my Apple wallet but I’m not sure if that’s used anywhere.
Aaargh20318 22 hours ago [-]
On US passports stealing the identity is a possibility as the chip in US passports do not implement any clone detection mechanism.
ericmay 22 hours ago [-]
Is that still the case? I recall "back in the day" that part of the reason for smashing these NFC chips was because of security failures like this, but I figured over time they'd be addressed.
I'd love to read more about what security features US passports are missing and what they have implemented. Just out of curiosity.
Geof25 22 hours ago [-]
The whole idea of "voter's fraud" is actually something unheard of in Europe because you will get government issued id (Citizen ID) when you reach 15 y/o and it is renewed every 10 years. You are then using it for voting and in general proving your identity. The later models are biometric so it is very hard to fake it
The fact that USA never finished the Real ID thing as the Citizen ID in Europe is kind of mind blowing for me. It is elegant solution to everything what current administration is complaining about - prove of citizenship for ICE, prevention of voting fraud and especially business owners can tell who is citizen and who is not.
jeffbee 22 hours ago [-]
The United States doesn't have a central registry of citizens. New births are supposed to be recorded by local officials, in about 3000 different jurisdictions, and they're only recorded locally. Many of those local jurisdictions are operated poorly, and in some cases they have refused to issue certificates of birth based on race, or other personal grudges held by officials. So we simply aren't in the position to issue such identifiers, and in particular we can't assume that a person without traceable documentation isn't a citizen.
robhlt 21 hours ago [-]
The social security administration does have a central database of essentially everyone born in the US after 1986, when a law was passed that required you to provide the SSN of anyone you claimed as a dependent on your taxes. As a result essentially every child born in the US is issued an SSN along with their birth certificate.
dataflow 3 hours ago [-]
> after 1986
ericmay 22 hours ago [-]
> and in some cases they have refused to issue certificates of birth based on race, or other personal grudges held by officials.
Just to be clear for our international friends, this is basically as unheard of. "In some cases" you could say well in some cases of murder someone is a cannibal too. It's a big country with over 340 million people under one roof. Shit happens.
jeffbee 21 hours ago [-]
No, it was typical of the Jim Crow South. Black mothers were not permitted in hospitals, and county clerks refused to register home births. It was all part of the system of oppression.
ericmay 21 hours ago [-]
We don't live in the Jim Crow South anymore - you're making an extreme stretch here to try and paint a picture that isn't accurate. My point stands.
jeffbee 20 hours ago [-]
Your point is laying in a ditch bleeding to death. There are loads of people alive today who personally suffered from Jim Crow. These practices continued right through 1968, and were revived in Texas between 2013 and 2016.
gnuplustoejam 19 hours ago [-]
This exaggeration is why we can't have universal digital ID or resilient voter fraud protections — which is what the original question was by the way. Do you also believe voter fraud is unheard of and never happens?
ericmay 20 hours ago [-]
No it's not. It's alive and well and just bought a new house.
Stop fear-mongering. One person doing something wrong one time does not constitute any sort of noticeable or wide-scale practice and the fact that if such an event occurs it makes national news and is fixed goes to show that the public is opposed to these practices, they are exceptionally rare.
Or perhaps there are "some cases" of voter fraud too ;)
jeffbee 20 hours ago [-]
There are about 600,000 American citizens alive today who lack traceable documentation of their birth due to Jim Crow policies.
gnuplustoejam 19 hours ago [-]
We have plenty of naturalized immigrants with no traceable documentation of their birth because they grew up in the middle of nowhere.
Somehow this wasn't a problem for them, while whites-only water fountains still live rent-free in your mind.
Following your logic, no problem is solvable until you have eliminated all potential issues and outliers. No startups would ever get off the ground with that attitude.
jeffbee 19 hours ago [-]
I'm all for solving problems, but I am not for committing a major disenfranchisement under cover of solving a non-problem. People who want to just ram through voter ID laws without solving the problem of undocumented citizens can't be treated as serious members of society.
ericmay 13 hours ago [-]
Maybe you're not helping to solve this problem and you're just making it worse by overstating the problem and causing others to argue over whether there is even a problem?
> People who want to just ram through voter ID laws without solving the problem of undocumented citizens can't be treated as serious members of society.
Maybe we want to be more like Europe with IDs from birth and to use them for all government activities.
Who are you to be the arbiter of who is a serious member of society?
skwirl 22 hours ago [-]
This was something I fully realized when I got married. Where is the official record that we are married? It’s a piece of paper in a filing cabinet in a small town two states away. Unless I provide a copy of my license, there is no way for anyone to see for sure if I’m married except to go to every jurisdiction nationally and see if they have a marriage license that matches my info. You could try to infer it from something like tax returns, but the IRS has never actually validated that I’m married. They just take my word for it unless they have a reason to be suspicious.
If one or both of the two who just got married wants to change their name? The process is downright bizarre. There is no central name database you go update. You just send off forms to a bunch of places saying “this is my name now,” some with a copy of your marriage license.
Very strange system IMO.
ericmay 21 hours ago [-]
Strange, but a little more decentralized and a little more "free", isn't it?
Why go through some centralized, hackable database, wait in line, and maybe get told to go away by some nameless official making minimum wage to update your last name when you can just decide to start using it and that's your prerogative? "I go by this, you don't get to decide". "My gender is this: it's not up to you to decide". I think it's something worth debating whether or not these kinds of things should even have anything to do with the government. I think there are good reasons, but I can certainly see very well-reasoned and principled arguments against the government being involved in some affairs like this.
k33n 22 hours ago [-]
Anyone can request their birth certificate in the jurisdiction of recording. There is absolutely no mechanism by which a request for that documentation could be refused because of someone’s race or a grudge.
Jcowell 21 hours ago [-]
What do you mean no mechanism? People can just say no? What I think you mean is that they’re are mechanisms today to combat folks saying no, but nothing stops (only punushes) people from saying no.
It’s a lot harder these days given the 60 years of progress
jeffbee 20 hours ago [-]
10 years ago we had 50 years of progress but in 2026 we're back down to zero progress.
ericmay 22 hours ago [-]
> The whole idea of "voter's fraud" is actually something unheard of in Europe because you will get government issued id (Citizen ID) when you reach 15 y/o and it is renewed every 10 years. You are then using it for voting and in general proving your identity. The later models are biometric so it is very hard to fake it
> It is elegant solution to everything what current administration is complaining about - prove of citizenship for ICE, prevention of voting fraud and especially business owners can tell who is citizen and who is not.
Well there are two things here. We don't in my opinion, have much of an issue with actual voter fraud - as claimed by those on the right. However, we also have a number of folks on the left who are against voter ID requirements because it might disenfranchise some voters who don't have an ID... an ID you need to do the vast majority of important tasks in life. I've always said if you're not responsible enough to get an ID we don't want you voting anyway (no I don't care about the downvotes).
It's sort of funny how these have seemed to change over time. Folks on the right historically were very much against "big government" ID programs. On the left? In favor! Well, until you start using it for checking who is voting or something. It's also amusing and a little bit irritating that our national ID system is basically 50 state ID systems and they are all centered on having a license to drive a car....
Also Americans can get IDs at a younger age too (children over a certain age need a passport to travel outside the US for example) but we don't really as a society require an ID for many things in practice - it's not really the culture here, we prefer a little bit of anonymity, but once you hit 15 1/2 or 16 you can get a state level driver's license which you'll then carry for the rest of your life. For those who don't drive you are also able to get what counts to just a state ID.
Not to make excuses but the US is a little hard to understand some times with these things because there's so much, especially in the news, emphasis on the federal level of the US government but it really is 50 sovereign states who send representatives to Washington DC. Unlike in, say, Estonia which from my very limited understanding is sort of one people, one country, some divisions. In the US you're from California, or Ohio, or Maine and the state manages most of your lifecycle affairs.
> The fact that USA never finished the Real ID thing as the Citizen ID in Europe is kind of mind blowing for me.
I actually refuse to get a "Real ID". I already have a passport. They can kiss my ass on paying an extra $25 for what amounts to the same ID card I already have. I'll take it for free but I'm not paying for it. I'll just carry my passport when I fly.
k33n 21 hours ago [-]
American States are not sovereign entities. We fought an entire war over that.
ericmay 21 hours ago [-]
American states are sovereign entities. This is very well understood in Constitutional law, albeit a little confusing for the laymen as the common understanding of sovereignty would be something like, well France is sovereign because it has an army and it conducts trade and all of those sorts of sovereign things.
But US states are sovereign entities who have, effectively, joined together to delegate some of their sovereign activities to a federal body (which has increased in power over the years) for the common good. They are very tightly bound to the federal government, but these matters don't refute their sovereignty. It's one of the reasons, maybe the primary one, for the US Senate - it's a vote of sovereignty by any individual state so that states with higher populations don't simply dictate rules to states with lower levels of population. Lower population states wouldn't have agreed to delegate some of their sovereign rights without some mechanism to not be run over by populists.
10th/11th Amendment
jltsiren 4 hours ago [-]
US states are sovereign in the sense the term is understood in US constitutional law, but not in the sense used in international law and international politics. They would be autonomous subdivisions of a sovereign state in the latter sense.
Sovereign states in the latter sense can delegate their powers to external entities (as they do in the EU), but they can also unilaterally choose to take that power back (as the UK did).
The USSR was an interesting case when it comes to sovereignty. Legally its member republics were sovereign states, but that sovereignty meant little in practice. As a result of a weird compromise, Ukraine and Belarus were founding members of the UN, despite not being sovereign in the generally understood sense. There was a legal mechanism for secession, but in the end, the member republics ignored it and dissolved the union.
k33n 21 hours ago [-]
No, US States are not sovereign entities. They have no ability to conduct independent international diplomacy. They do not have independent militaries, and they have no right to secede. The supremacy clause (article 7) makes it clear that states cannot override federal law.
With the way you’re characterizing the idea of sovereignty, every entity in the world is semi-sovereign. But sovereignty isn’t a spectrum. An entity is either sovereign or it’s not.
otterley 21 hours ago [-]
U.S. states are sovereign entities despite these limitations.
"Although the Constitution establishes a National Government with broad, often plenary authority over matters within its recognized competence, the founding document "specifically recognizes the States as sovereign entities." Seminole Tribe of Fla. v. Florida, supra, at 71, n. 15; accord, Blatchford v. Native Village of Noatak, 501 U. S. 775, 779 (1991) ("[T]he States entered the federal system with their sovereignty intact"). Various textual provisions of the Constitution assume the States' continued existence and active participation in the fundamental processes of governance. See Printz v. United States, 521 U. S. 898, 919 (1997) (citing Art. III, § 2; Art. IV, §§ 2-4; Art. V). The limited and enumerated powers granted to the Legislative, Executive, and Judicial Branches of the National Government, moreover, underscore the vital role reserved to the States by the constitutional design, see, e. g., Art. I, § 8; Art. II, §§ 2-3; Art. III, § 2. Any doubt regarding the constitutional role of the States as sovereign entities is removed by the Tenth Amendment, which, like the other provisions of the Bill of Rights, was enacted to allay lingering concerns about the extent of the national power. The Amendment confirms the promise implicit in the original document: "The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people." U. S. Const., Amdt. 10; see also Printz, supra, at 919; New York v. United States, 505 U. S. 144, 156159, 177 (1992).
The federal system established by our Constitution preserves the sovereign status of the States in two ways. First, it reserves to them a substantial portion of the N ation's primary sovereignty, together with the dignity and essential attributes inhering in that status. The States "form distinct and independent portions of the supremacy, no more subject, within their respective spheres, to the general authority than the general authority is subject to them, within its own sphere." The Federalist No. 39, p. 245 (C. Rossiter ed. 1961) (J. Madison).
"Second, even as to matters within the competence of the National Government, the constitutional design secures the founding generation's rejection of "the concept of a central government that would act upon and through the States" in favor of "a system in which the State and Federal Governments would exercise concurrent authority over the people who were, in Hamilton's words, 'the only proper objects of government.'" Printz, supra, at 919-920 (quoting The Federalist No. 15, at 109); accord, New York, supra, at 166 ("The Framers explicitly chose a Constitution that confers upon Congress the power to regulate individuals, not States"). In this the Founders achieved a deliberate departure from the Articles of Confederation: Experience under the Articles had "exploded on all hands" the "practicality of making laws, with coercive sanctions, for the States as political bodies." 2 Records of the Federal Convention of 1787, p. 9 (M. Farrand ed. 1911) (J. Madison); accord, The Federalist No. 20, at 138 (J. Madison and A. Hamilton); James Iredell: Some Objections to the Constitution Answered, reprinted in 3 Annals of America 249 (1976).
"The States thus retain "a residuary and inviolable sovereignty." The Federalist No. 39, at 245. They are not relegated to the role of mere provinces or political corporations, but retain the dignity, though not the full authority, of sovereignty."
k33n 20 hours ago [-]
This is a fine debate tactic — dumping a load of text without the proper context. But I’m not debating here. I’m plainly stating the fact that US states are not sovereign entities. In practical terms, there is no such thing as a semi-sovereign entity.
ericmay 20 hours ago [-]
Folks have provided great information. It's up to you to decide to accept the facts or continue to double down on your private worldview, but it won't serve you well to be ignorant of the facts here.
k33n 17 hours ago [-]
You and that other guy made good points from a constitutional law standpoint, don’t misunderstand my disagreement for dismissal of any kind.
A legal term of art is often a bit different than the basic word itself. From a legal term of art perspective, I’m essentially referencing “absolute sovereignty”, which would more closely mirror the actual dictionary definition of sovereignty, as a basic, contextless word.
ericmay 16 hours ago [-]
I would just say that we should be mindful that the legal definition is how things are implemented in practice as well - states exercise their sovereign rights on a daily basis because the exercise of those rights is the exercise of an interpretation of law.
Related to your point about absolute sovereignty I wouldn't disagree with you at all, but I would say that, and I'm not accusing you of doing this by any means, we should be mindful not to shift the goalposts and attempt to depress the meaning and significance of sovereignty just because an entity isn't also absolutely sovereign.
otterley 11 hours ago [-]
It seems disingenuous, or at least antisocial, to insist that you are correct about a broad and unqualified statement you made while also declaring that you meant something narrower all along.
20 hours ago [-]
ycislost 22 hours ago [-]
And no one would ever lie right?
Each and every vote is counted!
The people choose and it’s as simple as that!
In fact the people chose with their hard earned votes for Kamala and Trump to run against each other for president didn’t they?
Didn’t they?
And Europe is even freer!
So much global freedom and democracy where we all have a say :D
bnkd92 23 hours ago [-]
UAE has an app called « UAE Pass », and the Emirates ID itself uses Public Key Infrastructure.
The private key itself is locked into the Emirates ID, and need my biometrics to unlock.
Example: When I get delivery that needs my ID, the delivery man just put my Emirates into a card reader, and they need my biometrics to digitally sign the receipt.
It’s often used for important delivery (banks/gov documents), and any related gov services (including telecom, if i want to reload my sim card but forgot my pin, i can just insert my Emirates ID and scan my fingerprint and it retrives my SIM card by magic!)
You can try to read how they are doing the Emirates ID and the UAE Pass app, it’s super interesting to see this so well intergrated and at scale.
Estonia has done several versions of this. One is a "digital nomad" visa that includes a card with digital keys to do business in Estonia while not living there.
A pet hobby of mine is to get my state to adopt something similar to the Estonian standard. With a card reader, one would be able to vote from home with the election board being confident that the vote was cast by an authorized voter. This would address the fearmongering by one political party that has been going on since some black dude got elected President. Other things could include signing tax returns online.
Since REAL ID, getting a driving license/ID is a lot more controlled.
red-iron-pine 21 hours ago [-]
the average american, even educated and talented ones, have absolutely no serious understanding what keypairs are, or why they need to take care of them
i also have 0 trust in the USG's ability to not lose those, either through hacking or through blatent corruption a la DOGE, et al
seniorThrowaway 20 hours ago [-]
DoD (DoW whatever) has been running the CAC PKI infrastructure for over 20 years, and believe me a good deal of their three quarters of a million employees have no idea what PKI or keypairs are but use it to log into their workstation and do all sorts of online identity validation every single day.
https://www.cac.mil/common-access-card/
I'm not saying the gov is competent in general btw, but they are actually far better about this area than private industry, in my direct experience.
ethagnawl 21 hours ago [-]
> the average american, even educated and talented ones, have absolutely no serious understanding what keypairs are, or why they need to take care of them
You're right. Since a few others have said as much, I was sketching an outline and not suggesting handing people literal RSA keypairs. Any practical, _usable_ solution would involve a physical card, mobile app, web app, etc.
And just like the government backpedaled on the Real ID deadline, the federal government is backpedaling on login.gov and is still actively launching agencies on private third-party id.me identity verification.
mindslight 19 hours ago [-]
The big problem is that there has been, and is still, basically no political will in the US for GDPR-style privacy rights [0]. The current ID systems (DL# and SSN#) are already being flagrantly abused by an unaccountable surveillance industry, which backhauls every bit of data it can get away with, maintaining comprehensive dossiers on each of us. So until this is actually reigned in, then every bit of friction here actually helps as it prevents even more businesses from routinely demanding ID.
[0] due to constant undermining by said surveillance industry, which has now basically become "too big to fail"
LorenPechtel 16 hours ago [-]
And the government keeps the database truly secure? You're providing a single point of compromise that would be incredibly valuable. If nothing else, it would be cracked the XKCD way.
adolph 21 hours ago [-]
> give everyone an RSA keypair
Effectively this allows the keypair issuing government (and thus whoever collects breach data) the ability to impersonate you. Seems like a terrible idea.
creamedpeas 22 hours ago [-]
[dead]
ck2 22 hours ago [-]
[dead]
Nition 1 days ago [-]
The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.
analog31 1 days ago [-]
I believe we need to criminalize possession of the data, with statutory damages per violation.
CamperBob2 1 days ago [-]
Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.
londons_explore 1 days ago [-]
Estonia has it's ID cards which can sign things....
That suddenly means a data leak doesn't matter - nobody can make new signatures.
Verifying someone's ID would be as simple as asking them to sign your company name and today's date.
mschuster91 1 days ago [-]
The problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about "mark of the beast", the Democrats and the ACLU fear them being used as part of a surveillance state.
Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver's license, and whatever else.
If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed).
We'll get there eventually, but not before we try everything else first.
cucumber3732842 1 days ago [-]
>Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver's license, and whatever else.
"They can already send a drone to watch you and track your cell location and, and, and, why does it matter if they also slap up a million AI powered cameras?"
The comprehensiveness of the system matters.
alistairSH 1 days ago [-]
Not sure how you jump from "ID with chip" to "AI-based drone and camera network". We can do one without the other.
skinfaxi 23 hours ago [-]
They are already doing the camera thing with flock.
mulmen 15 hours ago [-]
Your failure of imagination doesn’t make national ID a good idea.
The point was to compare the proposed ID change with the state of surveillance before (bad but still not all that comprehensive) and after Flock et al (more comprehensive).
mulmen 15 hours ago [-]
> […] ability to use the ID as a proof of age or other attribute as needed
What attributes should require proof? Where do you draw the line?
Age?
Gender?
Race?
Religion?
Political party?
Citizenship?
> We'll get there eventually, but not before we try everything else first.
We got here by trying everything else first.
The “good old days” are now. Thousands of years of progress and blood delivered our liberal societies. Don’t give it up so easily.
vidarh 1 days ago [-]
You don't need a national ID card scheme to do this, though.
The EU/EEA is rolling out a digital identity mechanism with interoperable wallets that can hold any range of identity documents and other credentials. You don't need to pick a single wallet provider - several EU countries are approving multiple, including private providers. You don't need to standardise on a single ID.
This is already the case for many already in-use ID solutions in Europe. E.g. in Norway, there are at least 3 signing providers, and only one provider is government issued - the by far most popular (BankID) is private. You identify yourself to the provider when requesting issuance, not to the government (unless you sign up with a government provider).
bayindirh 1 days ago [-]
> the Democrats and the ACLU fear them being used as part of a surveillance state.
AFAICS from the other side of the pond, United States Government can track people well enough even without a national ID card. They have successfully worked around that problem.
So, it's a moot point now. No?
nobodyandproud 1 days ago [-]
I grew up in that tradition, so I can shed some light: The fear of a national ID isn’t just about tracking and privacy, but that an individual cannot participate in society or survive if the government decides to revoke the id.
Meaning, I can’t buy food; rent or buy a home; or hold any sort of job and earn and save.
What we have today isn’t better, but until recently I was hard pressed to see how such fears were even warranted.
Tangurena2 23 hours ago [-]
> The fear of a national ID isn’t just about tracking and privacy, but that an individual cannot participate in society or survive if the government decides to revoke the id.
This is because the US made a critical flaw by tying the authentication and authorization tokens into one single token - your driving license/ID. They should be separate things. Your authentication token (who are you?) should have your picture and be forgery resistant. Your authorization token (what can you do?) should be a piece of plastic with zero pictures (like your insurance card). Did you get stopped for DUI? The officer takes your authorization token, instead, the officer confiscates both tokens and hands you a paper receipt.
The FAA does it the smart way, your authorization token (pilot's license) has no photo. You do something stupid, the ATC tells you to "call this number" and if it is really badly stupid, then the local FAA person confiscates your authorization token.
iamnothere 1 days ago [-]
Exactly. You do not want to hand the US government the ability to “turn off” someone’s daily life at the press of a button.
Things are already bad enough as it is, but at least it’s still possible to get by even if the system takes a dislike to you.
embedding-shape 1 days ago [-]
> Exactly. You do not want to hand the US government the ability to “turn off” someone’s daily life at the press of a button.
If you're within the borders of the US, this ability already exists, they have a monopoly on violence in the country, something the government is very eager to demonstrate this year.
iamnothere 1 days ago [-]
There’s a lot of room between violence and financial isolation. The government has shown multiple times that it is willing to go after otherwise law-abiding citizens who take up disfavored careers, whether it’s gun dealers and payday lenders in Operation Choke Point, cannabis dispensaries in states where it was legal, or online cam girls. In all of these cases, going to cash or using alternatives to the banking system was possible and even necessary for them to survive.
embedding-shape 1 days ago [-]
And none of those examples you use, involve SSNs, these are all 100% paperless people/companies? Makes me wonder how they got bank accounts in the first place if they're so disconnected from society.
iamnothere 24 hours ago [-]
The individuals had SSNs, but did not have a hypothetical national ID connected to systems that could have been used to fully isolate them. As long as backchannels exist in the system to accommodate those without SSNs/DLs, it is possible to get by even if the system tries to cut you off.
embedding-shape 23 hours ago [-]
> As long as backchannels exist in the system to accommodate those without SSNs/DLs, it is possible to get by even if the system tries to cut you off
And again, as long as backchannels exists in the system to accommodate those without a Government ID, it is possible to get by even if the system tries to cut you off.
Don't you see and understand you already have government ID? You're just calling it by another name...
iamnothere 23 hours ago [-]
Once the official ID exists, those backchannels will be cut off, as they have been in much of Europe.
embedding-shape 21 hours ago [-]
> Once the official ID exists, those backchannels will be cut off,
Do you seriously not get it yet? You have IDs now, and you claim those backchannels exists now, and haven't been cut off. Why would calling something something else suddenly make those backchannels be cut off? How come they exists today in the first place then?
iamnothere 17 hours ago [-]
Official IDs don’t exist now. The “surrogate” IDs (SSN, DLs) are not universal nor mandatory, and there are legal barriers to using them as an official national ID.
r3trohack3r 23 hours ago [-]
> they have a monopoly on violence in the country
I have not seen a definition of this that is simultaneously true and useful
The sole provider of violence in the U.S. is not the government.
embedding-shape 22 hours ago [-]
"Monopoly on violence" isn't some new concept I just invented here, it's a established concept about "legal use of force", which the government typically is the sole arbiter of. https://en.wikipedia.org/wiki/Monopoly_on_violence
Of course many engage in "violence", or "provide it", that is not in doubt.
r3trohack3r 21 hours ago [-]
I know it’s not new, thus why I said I’ve never seen a definition that is both true and useful.
In the U.S. I can lawfully use violence in many ways under many circumstances. I.E. if you’re in my house and I didn’t invite you there, I can slay you lawfully.
In the U.S. the federal government is not the only institution responsible for law making or law enforcement. It is not only entity that can lawfully use violence. Etc.
embedding-shape 21 hours ago [-]
> In the U.S. I can lawfully use violence in many ways under many circumstances. I.E. if you’re in my house and I didn’t invite you there, I can slay you lawfully.
Yes, and you can do so, because the government and state says it's OK to do so. If they didn't, it wouldn't. This is the core idea.
> In the U.S. the federal government is not the only institution responsible for law making or law enforcement. It is not only entity that can lawfully use violence. Etc.
Hence the whole "sole arbiter of" and last paragraph in my last comment. All those entities are "allowed to use violence" because your government says it's OK.
r3trohack3r 20 hours ago [-]
If you define the entity as “all institutions that are allowed to create and enforce laws” and then say “that entity has a monopoly on creating and enforcing laws” you’ve created a tautology.
There are clear counter examples to your statement in the U.S.
States are not “allowed” to use violence because the Federal government says it’s okay. States have a right to create and enforce laws.
CamperBob2 17 hours ago [-]
All those entities are "allowed to use violence" because your government says it's OK.
I don't know if you're in the US, but that's simply not how our Constitution works. "Monopoly on violence" is just something some people made up. It's meaningless, just some empty words on paper.
(Which is also true for the Constitution itself, of course. But if you're talking about the theoretical and philosophical basis for lawmaking in the US, that's what determines both. Theoretically.)
iamnothere 15 hours ago [-]
It’s funny because the whole notion of a monopoly on violence is very traditional and tightly coupled to the Westphalian notion of statehood, yet I often see that the first people to cite the monopoly on violence are also the ones undermining the Westphalian state model.
In any case all the old gods are dead or dying, including old ideas of statehood, so enjoy the ride, everyone.
iamnothere 21 hours ago [-]
Not to mention the increasing use of private security and even private police, and the increasing use of military PMCs and privately owned/controlled “kill chain” components like Palantir and Starlink/Starshield.
embedding-shape 1 days ago [-]
> but that an individual cannot participate in society or survive if the government decides to revoke the id
What would happen today if your government revokes a SSN which is your de facto "personal identification number" today? Can you still rent/buy a home? Can you have a job?
iamnothere 1 days ago [-]
Some US citizens don’t even have SSNs, believe it or not. The Amish get by just fine.
embedding-shape 1 days ago [-]
Is it generally considered that The Amish "participates in society"? I thought the whole point for them was that they're "outside of modern society", to some degree at least.
iamnothere 1 days ago [-]
They participate in their own society, which allows them to survive in their own way. In other countries, national IDs have often been followed by mandatory registration requirements for renting or owning property, employment, etc. At present there are ways to get around using ID for many things, and it should stay that way.
nobodyandproud 1 days ago [-]
Before my time, but I believe SSN was and probably still is controversial in my circle. I definitely recall rumblings about it even 30 years ago.
But while cash is printed (physical currency): Not having an SSN becomes a major impediment but not impossible to make transactions and survive.
Our migrant workers—who are basically carrying white collar workers like me—are proof of this.
embedding-shape 1 days ago [-]
Isn't all of those cases then also proof that if the SSN was a government ID instead, all of those things would have been the same? The ID wouldn't "impossible to make transactions and survive", just an impediment, just like not having a SSN is today.
Point is, the US already basically have a de facto "ID card", they just don't call it as such (yet?), so claiming somehow correctly labeling this thing would make things worse or more difficult, doesn't make much sense.
dghlsakjg 14 hours ago [-]
You can't really identify someone by their SSN. My card is literally just a piece of cardstock paper with a name and number, and no one has ever asked to see it. There is no photo. There is no security.
lotsofpulp 1 days ago [-]
A national ID card scheme has existed for many decades. It’s called a passport.
There is no reason a digital equivalent can’t be made using the passport system, and it can be left optional, just like passports are optional.
logifail 1 days ago [-]
> just like passports are optional
"Border controls aren’t supposed to exist between EU member states – that’s the promise of the 1985 Schengen treaty. Yet today, travelers routinely face checks when crossing borders within the [European] union"
What relevance does that have to the US federal government offering a digital ID verification system on top of existing passport infrastructure?
EU did border checks without digital IDs being a thing, so why couldn’t US states do a border check without digital IDs?
Digital IDs are not a causal factor for these concerns, seeing as how those government abuses already happen without digital IDs.
GJim 24 hours ago [-]
> Exactly. Personal data should be treated like radioactive material
The GDPR in a nutshell......
Unnecessary personal data is a liability.
Tangurena2 23 hours ago [-]
The GDPR comes from a different direction - you own the data about yourself, no matter where it is stored.
In the US, courts have ruled that the compiler of data owns all that data - you have no control about data about yourself (except in a few legal categories like credit reporting). Some of these old court rulings covered telephone books and business directories.
> Unnecessary personal data is a liability.
Absolutely.
akshatjiwan 1 days ago [-]
Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.
wolvoleo 1 days ago [-]
Isn't that the case already? Here in many European countries it already is. They're always warning about that when there's a big breach and people download it to see what's in it about them. Not that they're going to prosecute half the country of course but still.
herbst 24 hours ago [-]
There are also very very strict rules for companies that use or process this kinda of data and how they need to save and handle it. Hence why it's basically illegal to use US based services for anything with real data these days.
I wish it would be more enforced and controlled tho.
wolvoleo 16 hours ago [-]
Yeah it's not at all.
Everyone just gets away with everything.
Recently a bit dutch ISP was hacked and it turned out they kept millions of former customers' details way way beyond any normal lifecycle term. People were still in there that hadn't had anything to do with that company for a decade. This is illegal in the EU but even after this practice was exposed by the leak, the personal data authority just let it all slide.
They also sent out a press release pooh-poohing the consequences for affected (ex-)customers and all they did in compensation was to give a "free" antimalware subscription that was basically advertising just like the few months of mcafee crap you get with a new computer. But all we get from regulators and politicians alike is crickets.
raverbashing 1 days ago [-]
It would be fun if the GDPR naysayers end up coming up to the same conclusion
GJim 24 hours ago [-]
A significant percentage of HN posters and readership are those working in US AdTech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic slants towards opposing decent privacy laws.
actionfromafar 1 days ago [-]
But that would be like GDPR and that is EU which is communist which is satanic. QED.
vrganj 1 days ago [-]
Not quite the same, but the GDPR gives you a right to erasure.
OKRainbowKid 1 days ago [-]
And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons.
But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.
vrganj 1 days ago [-]
Maybe the bureaucracy is there for a reason some times?
Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses?
Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model?
Hm.
OKRainbowKid 1 days ago [-]
In case it wasn't obvious: I do not at all agree with these complaints about the GDPR or EU.
wokkel 1 days ago [-]
Unfortunately no right to audit. So deletion is a pinky promise.
randunel 1 days ago [-]
Actually GDPR is exactly what they're asking to. Possession of personal data that is not required for a service's functionality is illegal under GDPR.
wolvoleo 1 days ago [-]
Well unless it was stored with freely given permission of course.
But it has to be freely given. "Give permission or you can't use this service" is not ok for data that isn't required to provide the service.
subscribed 1 days ago [-]
It must be freely given anyway, but its still illegal to keep unless proportional and necessary for the stated purpose.
If the purpose wasn't "we keep to resell it later" it's likely illegal.
Well, "illegal" given that this type of criminality is pretty much ignored (I've been fobbed off by the regulator after pointing a systematic law-breaking by a $company many many many times. Still better than not having this).
DANmode 1 days ago [-]
Negligence is already illegal.
Just locate a prosecutor.
DaSHacka 1 days ago [-]
I'll sleep so much better at night when the company that'll leak my Social Security Number on the internet due to hosting a backup of a database that's assessible publicly gets fined $0.30 per SSN leaked.
Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.
DANmode 18 hours ago [-]
Sounds like you’re not going to sleep well at night regardless, choosing to stick around for more of that.
megagpt5 1 days ago [-]
Negligence isn't a crime in itself. It is an explanation or cause for other crimes. And there is nothing illegal in the US about selling pictures of people's drivers licenses.
DANmode 18 hours ago [-]
> Negligence isn't a crime in itself. It is an explanation or cause for other crimes.
Correct, like being criminally negligent of a child, if you leak data through long-known vectors (for argument’s sake), one could argue you are criminally negligent in securing the private data.
It doesn’t really go that way, often, now.
It could, as more e.g. water treatment and energy providing facilities get pwnd.
megagpt5 18 hours ago [-]
Except the US has no law that you have to secure private data or that not securing it is a crime.
DANmode 10 hours ago [-]
Pretty sure I just cited it.
Good luck arguing against their conviction rate.
DANmode 18 hours ago [-]
> there is nothing illegal in the US about selling pictures of people's drivers licenses.
18 U.S.C. § 1028 makes certain transfers involving identification documents criminal. It specifically covers a driver's license or personal identification card and provides enhanced penalties for transferring such documents.
1028 expressly recognizes electronic transfer as satisfying its interstate-commerce requirement.
What are you talking about?
analog31 23 hours ago [-]
Commenting on my own post, I should expand a bit on "statutory damages." I got the idea from the music industry, where there are automatic civil damages for copying recordings. If you're caught, you get to pay X dollars per item.
This means the police don't get involved. The only thing you need is a tort lawyer willing to take a share of the damages. Also, a data breach is proof that you possessed the data.
A business wouldn't be able to reduce their liability exposure to zero, but to an acceptably low level, for instance by actively erasing the data before a breach can occur.
krebsonsecurity 24 hours ago [-]
Deleting the data after verification is a good practice. But if you're actively compromised, it probably doesn't matter how long you keep the data because it's already been immediately "backed up" by the intruders the second it is collected.
Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in reality the attackers had card-sniffing malware installed on every single cash register at every single store across the country.
ericmay 24 hours ago [-]
Ideally it’s not even stored…
Tangurena2 23 hours ago [-]
In the Heartland data breach, the custom malware that hackers wrote copied the mag stripe as it passed through the payment system. I got a new credit card after that broke (also after Target's breach was reported). Heartland did not store the card details at all.
How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type dir or ls at a command prompt, it says something like "X files using Y bytes, Z bytes free". How do you know those numbers are true/correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out).
You may notice that the poster of the comment you are responding to is mentioned a lot on that page.
CrazyMusicians 18 hours ago [-]
That's a pretty decent list of breaches. Never seen it before. Thanks for sharing. I can't believe they didn't mention the Ashley Madison breach, which affected more than 30 million people, ended countless marriages, and led to more than a few suicides.
coredog64 22 hours ago [-]
They're typically stored as "tokenized" values. The tokenized version shares the type and the last 4 digits (so that you can share it with the customer to help them identify the card). You buy this capability from vendors and IIRC there's like 3 or 4 common vendors in the marketplace.
tbrownaw 24 hours ago [-]
Well at least they need it until they get back a success response from the bank/payment processor/whoever.
adolph 21 hours ago [-]
> the attackers had card-sniffing malware installed on every single cash register
Part of the attack was physical, aka skimmers. I still remember the relatively elegant inspection tool blogged by Target Tech on HN 3 years ago:
Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.
So most businesses are not permitted to just delete the data.
michaelt 1 days ago [-]
Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234"
Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.
Unfortunately letting random companies photocopy your passport leads to identify fraud.
Tangurena2 23 hours ago [-]
To abuse that requires physically going to a file cabinet. People in that office are going to question you. If something happens, it is isolated to a single office, limiting suspects to a small number. Putting it online makes it vulnerable to the entire planet with about 8 billion suspects.
embedding-shape 1 days ago [-]
Would it be better if it was a digital copy, or what? Somehow, my drivers license, passport and ID has been photocopied and digitally copied countless of times, in multiple countries, over more than three decades, yet not a single time I've been affected by identity fraud. So somehow, seems it doesn't "lead to" always but I'm sure it does happen sometimes, yes.
veunes 1 days ago [-]
Regulatory retention is a valid reason for some of this data to exist. It isn't a blanket justification for every intermediary in the verification chain to retain its own permanent copy. If anything, that makes minimizing the number of copies even more important.
Aurornis 1 days ago [-]
The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.
Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
maccam912 1 days ago [-]
It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.
Nition 1 days ago [-]
Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.
samlinnfer 1 days ago [-]
It's obvious they are keeping them all. 150 million didn't get all re-scanned at once.
applfanboysbgon 1 days ago [-]
It's actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker's claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned.
Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.
Nition 1 days ago [-]
Yeah. It's a bit unfortunate that I seem to have the top comment in this thread now despite it probably being wrong, at least to some extent, but it's too late to edit it. I agree with your second point as well.
samlinnfer 1 days ago [-]
The whole point is they keep it forever. You think any id verification services actually delete the data?
Nition 1 days ago [-]
I mean, just because all your friends are jumping off a cliff...
mindslight 1 days ago [-]
It feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...
kevin_thibedeau 1 days ago [-]
If you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.
fhub 1 days ago [-]
IMHO If statutes require it to be kept, then it should get written to storage that can’t be read without being there in person. Have the police actual show up to look at it. Make it really slow to look at too. Cryptographically slow.
miohtama 23 hours ago [-]
Often regulation requires companies to keep this data for many years in the case the government wants to check on you.
Not in the US, but in Spain, police gets this data real time when you rent a car or check in to a hotel.
This is of course important for protecting you.
ipsod 21 hours ago [-]
> This is of course important for protecting you.
Well, that's very kind of them. I am constantly impressed at the kindness of our governments, and the recent growth of that kindness. I guess that, with all of the power that modern technology is giving them, they're finally getting to live out their heart's desires of being very, very kind.
veunes 1 days ago [-]
Yeah, this is the part I don't get either. Verification should produce a yes/no result, not a permanent archive of everyone's identity documents
brador 1 days ago [-]
Storing personal data should require insurance that increases per data point.
megagpt5 1 days ago [-]
Legislating insurance prices is illegal for good reason. Either it's too high and the government has just siphoned a lot of money to insurance company shareholders, or it's too low and the government has effectively made it illegal to provide that insurance.
wiredbox 1 days ago [-]
Which is why you need GDPR equivalent in the US…
cucumber3732842 1 days ago [-]
No, you can't, because then when the headline reads "FBI probes service selling <whatever touchy subject you had to verify for in the first place>" and you don't have those records you wind up taking it. And that's before you even start talking about retention laws.
There can be a discussion about retention periods and the like but too short a retention period amounts to "trust us bro" in the eyes of some un-feeling government agency who is trying to screw you either at the behest of the law or at the behest of whoever hates you and has their ear.
Something needs to be done but "just delete it after you've verified it" is not workable at scale. Yes I know it worked fine for brick and mortar forever. Maybe some acceptable technical solution could be reached, idk.
lifestyleguru 1 days ago [-]
Every time someone takes photo or photocopy of my documents "for the police" or "for security" I'm just thinking "why are you lying to me".
anonym29 1 days ago [-]
They don't necessarily need to be lying for it to be harmful to you - they could simply be grossly incompetent as a custodian of your data. Most people are grossly incompetent even as stewards of their own data, after all.
tgsovlerkhgsel 1 days ago [-]
If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold.
Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.
MaKey 1 days ago [-]
I'm in Europe and got ~$350 because of three data leaks. The amount per instance was vastly different though - $255, $80 and $15.
consp 1 days ago [-]
I'd be very interested in which ones, since I've never received anything despite being in several big breaches (and have received the boatload of spam to prove it). I'm pretty sure this is very country specific.
MaKey 4 hours ago [-]
I can't say which ones as it is one condition of the settlement agreements not to talk about specifics and I gave numbers already.
You don't get compensations automatically. I pursued them with the help of a specialized law firm that takes a cut of the settlements.
cbolton 1 days ago [-]
What did you do to get the money?
MaKey 4 hours ago [-]
There are law firms that pursue the compensations for you and take a cut of them as payment. I used one of them.
autoexec 18 hours ago [-]
Some companies have so much money that there's no fine which would ever be punitive enough to matter to them. I'd bet jail time for executives could be extremely effective though.
veunes 1 days ago [-]
Data minimization becomes a lot less abstract once every unnecessary record on disk has an actual dollar value attached to the risk
tencentshill 1 days ago [-]
Make Customer Data a Liability
seniorThrowaway 20 hours ago [-]
Criminal liability for the corporate officers is the correct approach. Can't pass jailtime on to the consumers.
iAMkenough 22 hours ago [-]
If we end up punishing Hertz for the data their private contractor stores, I hope we apply the same logic to local law enforcement agencies and their private surveillance contractors.
2OEH8eoCRo0 24 hours ago [-]
I concur. Liability would go a long way.
trollbridge 1 days ago [-]
One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera.
They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
Aurornis 1 days ago [-]
The ID scans in the article weren't submitted by people from their phones. They include IR and UV scans, too. The database might contain multiple sources but at least the big one appears to have a lot of IDs from physical locations where you hand your ID over the counter to someone to scan.
klausa 1 days ago [-]
I'm now very curious how does a UV/IR scan of an ID card looks like!
dghlsakjg 14 hours ago [-]
There's 153mm available to see if you're interested.
Basically swaps the LED illum with an UV LED instead. Makes all the security features pop right out.
veunes 1 days ago [-]
Yeah, the irony is that every extra signal added to make verification "safer" also becomes another extremely valuable thing to steal when the verifier gets breached
latchkey 1 days ago [-]
s/retained/leaked/
trollbridge 1 days ago [-]
Well, yeah. Retention eventually means leaking.
I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.
ChrisMarshallNY 1 days ago [-]
> vendors who collect this sensitive data need to be held to a higher standard.
They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).
One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.
The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.
thesmtsolver2 1 days ago [-]
Ahem
Some Interrail travellers told to cancel passports as hacked data posted online
Worth noting this dynamic when people overgeneralize “local government good, federal government bad”, a tendency that has been present and growing for at least 50 years.
The theory that local government is more accountable and responsive seems to be pretty deeply broken, what actually seems to happen is that localities lack a critical mass of attention and focus for real responsiveness and accountability.
Or the American character in general does.
michaelt 1 days ago [-]
> They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there
Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is.
And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We're talking a $5 billion company handing 15 million people's credit reports to hackers, and getting fined $15 million.
megagpt5 1 days ago [-]
Germany has Schufa and it keeps getting sued for the whole concept of it being illegal I believe.
miohtama 23 hours ago [-]
GDPR does not prevent leaks, only may punish someone afterwards. A lot of the upcoming EU regulations are to collect more data on you because of the age checks. German and Spanish prime ministers have publicly called for verifying all Internet users and end anonymity,
AndyMcConachie 24 hours ago [-]
> They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there
As an EU citizen and resident I strongly recommend you not take EU privacy controls seriously. The GDPR functions well as a means of tax collection, but it really doesn't work all that well as something that actually protects people's privacy.
shireboy 24 hours ago [-]
What even would be the fix for this? 153m people need new license asap and id verification systems need to block the stolen ones? Also what are some of the bad things this could cause: a risk malicious actors open verified accounts in their name, ability to vote and travel under stolen id, what else?
fishfasell 1 days ago [-]
So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.
3eb7988a1663 1 days ago [-]
153 million puts them at roughly 1/2 of all Americans.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
oogali 1 days ago [-]
Total population (341M) is the wrong divisor. It’s so much worse.
Count the number of Americans who would have an ID worth scanning (aka ages 18 or over): 269M [1].
Or the number of Americans with a driver’s license: 212M (2013) [2].
Excellent catch. Somehow even worse than I first thought.
ornornor 1 days ago [-]
I once tried to reach one of the two Canadian background check companies a prospective employer wanted to use to check me. I eventually found their privacy and security phone number. It had a poorly recorded voicemail to leave a message and they’d call back to answer questions. It’s been 12 years. They haven’t called me back yet but I’m assured they take privacy very seriously.
I didn’t go through with that part of my application and didn’t keep the job.
mulmen 1 days ago [-]
I had two active Clear subscriptions at the same time. How did an identity verification company not know both accounts were the same person? They were both using the same credit card!
What does an "identity verification" company even do?
toast0 1 days ago [-]
Clear takes your money and zips you through the airport checkpoint line. Because terrorists wouldn't spend money or time to get through the lines faster?
mejthemage 21 hours ago [-]
You cut the line but still go through security.
1 days ago [-]
1 days ago [-]
1 days ago [-]
megagpt5 1 days ago [-]
> What does an "identity verification" company even do?
Handles the multitude of ID document standards around the world while providing a simple Boolean flag to websites that are required to check if you're an adult.
mulmen 13 hours ago [-]
Then inexplicably keeps the data and gets hacked in the most obvious way possible.
18 hours ago [-]
3RTB297 1 days ago [-]
From the article, it's some national-chain hotels, car rentals, casinos, dispensaries, and a couple maybes like if you bought alcohol at Target and they scanned your ID or sent something via FedEx that required an ID scan. Your ID might be scanned and in there multiple times.
Scaled 1 days ago [-]
[dead]
wahern 1 days ago [-]
Your ID and PII was likely already on the black market, the only question is accessibility and price. You can't exactly advertise on Reddit or sell to every two-bit identity thief and not expect heat.
rswail 1 days ago [-]
The main question to government is:
1. You already know who everyone is. By definition identification as an individual is by government.
2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?
3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")?
Governments need to protect the public, not allow businesses open slather on collecting PII.
2legit2quit 1 days ago [-]
> Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?
Generally speaking, it's the narrative of a pushback on a "national id".
Many countries already have this place. Estonia has the Digital ID provided by government[0]. Nordic countries use BankID, which is a form of KYC that is backed by banks (you prove your identity to the bank, the bank issues a bank id - usually back by certificate[s], and you login with this to services[1][2]). Finland is the outlier, here, with their own service[3].
Yes, which is part of a wider narrative in the US that insists everything must be privatized because the government cannot be trusted or is otherwise incompetent.
einsteinx2 16 hours ago [-]
The irony I’ve always found in that statement is that while it’s true that the government can’t be trusted and is generally incompetent, it’s also true of private companies. So even though it’s a true statement at face value, it’s still not a good argument for privatization which is just trading one set of incompetent and corrupt people for another set of the same but with even less oversight.
This is exactly the way its being implemented in EU (Yes, this person is over 18").
European Digital Identity Wallet (EUDI Wallet) framework established under the eIDAS 2.0 regulation (Regulation (EU) 2024/1183)
acchow 1 days ago [-]
This is already present today in California Driver's licenses in your Apple Wallet (mDL).
When you scan your driver's license at a compatible reader, you're given a notice of what information is being requested and the ability to share it (or not).
It can also request some derived attribute (is this person above the age of 21?) instead of the actual data field itself.
Most of this is from ISO/IEC 18013-5
Hobadee 1 days ago [-]
We can't do any of that because it is forward-thinking and doesn't involve clear-cutting a rainforest to make the stacks of paperwork that are otherwise required to fill out forms in triplicate, run everything through 17 different departments, and ensure an army of bereaucrats have something to do with their day.
navigate8310 1 days ago [-]
One can argue, this would be an unintentional tracking of the population by government
rswail 5 hours ago [-]
One could argue that, but with a properly designed API, it could preserve anonymity while still providing businesses with the necessary validation.
ChrisMarshallNY 10 hours ago [-]
It’s interesting how quickly this story dropped in the rankings. It’s a highly relevant story, that is likely to spawn more notice.
I’ve had more than one client tell me they want to collect drivers license images for various reasons.
Somewhere in the inane executive brain world there are some folks who seem to see some unspecified value in collecting driver’s license images. They never have given me a sensible justification. They seemed to think it provided some assurance that the providing it is in fact who they really are and they can validate…. something.
I’ve managed to push back on that and told them I didn’t want the legal responsibility of managing such data and tracking all the legal responsibilities for any number of countries and ect.
It doesn’t surprise me that there is a ready made service to bypass this kind of absurd requirement.
wolvoleo 1 days ago [-]
Ooh I thought they sold that many fake ones lol. I know fake IDs are a big thing in the US because of the really high drinking age (were I'm from it was 16). But even then it's a lot.
But no it's about leaked data. That wasn't very clear from the title.
VladVladikoff 22 hours ago [-]
Startup idea for these darknet guys, use AI to select the best matching face in your collection of IDs to your customers face, so you can generate them a fairly realistic fake ID.
cute_boi 1 days ago [-]
I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.
stephbook 1 days ago [-]
In Germany, everyone's national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.)
You'd think that 80 million people from a rich first world country would be enough of a market to use this.
No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
Tangurena2 22 hours ago [-]
Our lobbyists have more money than your lobbyists.
lifestyleguru 1 days ago [-]
You want to have it done cheaply on a dumb computer, so you have it.
AnthonyMouse 1 days ago [-]
> They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.
Because then that website would get compromised and lose the data on 350 million people instead of 153.
Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.
People throw around terms like "zero trust" like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you'll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.
Using government ID on the internet should simply be banned. 99% of things shouldn't require government ID to begin with and the 1% that do should always be done in person.
zdragnar 1 days ago [-]
You've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
megagpt5 1 days ago [-]
Because the word "simply" isn't. Every time a programmer says "just" or "simply" about someone else's system, it's a lie.
charcircuit 1 days ago [-]
Because physical business are also allowed to collect this information.
astura 23 hours ago [-]
Not just allowed, required. Banks, doctors, etc.
trivet 1 days ago [-]
Wild how many states seem to have had their DMV systems compromised. Guess mine's in the mix by now too.
ungreased0675 1 days ago [-]
Bankrupt this company to serve as a warning to others that hang on to way too much data.
walrus01 1 days ago [-]
In addition, actual federal prison time for the C-levels would help as a deterrent to future fuckery.
bilbo0s 1 days ago [-]
This is the actual answer. Things like this need to be a criminal offense.
Monetary fines have a tendency to simply be modeled in as a cost of doing business. Going to prison is far more effective when the goal is to concentrate minds.
b3lvedere 1 days ago [-]
At least reimburse everybody for all the costs involving getting the old drivers license invalidated and apply for a new one. Unfortunately that will not cause to magically dissapear the rest of your harvested profile.
Tangurena2 22 hours ago [-]
You can change your credit card number. You cannot change your face.
And because REAL ID requires mailing your DL/ID to you (in order to prove you live at that address), the address will not change (most states require you to get a new DL/ID within 30 days of moving - my state is 15 days). Replacing the driving license will not change any of the data. Only the DL/ID number. For other identity theft, the old data will not change.
jakevoytko 1 days ago [-]
As always, friendly reminder to lock your credit and enable your mobile carrier's protections against SIM swapping
fishfasell 1 days ago [-]
Excellent advice. A compromised phone number is an absolute nightmare, most MFAs default to SMS as a last resort. I lost my Okta verify login at work since I transferred phones, thought I'd need a ticket with our ID team but turns out my phone number is sufficient. Wasn't thrilled about that.
grommet_kit 1 days ago [-]
It's always the driver's license data that seems to find its way out. Another reminder to freeze your credit.
Razengan 1 days ago [-]
How about probing the laws (and politicians who pushed for them) about making IDs mandatory for using the internet?
tgrowazay 1 days ago [-]
> Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”
1 days ago [-]
morkalork 11 hours ago [-]
Stupid side comment but lmao the website looks like it was designed in 2002 rock on you crazy diamonds!
guelo 1 days ago [-]
Now I feel justified that I started boycotting my neighborhood bar when they started scanning IDs at the door with some unknown app.
megagpt5 1 days ago [-]
Those apps are internet ID checks brought to the real world. You're right to be suspicious. They do keep leaking data or getting found out to be storing everything forever or forming profiles of a person's movements.
veunes 1 days ago [-]
[dead]
SpaceL10n 23 hours ago [-]
[dead]
FpUser 1 days ago [-]
So they want to see my driver's license "to make the world safer" when in reality all they do is facilitating mass fraud. When the fuck will those brainless infusoria will get punished 9fat chance).
htrp 1 days ago [-]
It was probably Hertz that was the source of the breaches.
tgsovlerkhgsel 1 days ago [-]
Hertz or the company Hertz uses
rio517 1 days ago [-]
I am so jaded, i cannot help jumping to the conlusion that to me they wanted to data to continue voter supression efforts.
GolfPopper 1 days ago [-]
Nah. It they want to make sure that Trump gets his cut from the sale.
Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which gets cross-referenced by the legit provider against the id.gov database.
Of course the devil is in the details and I wouldn't trust GrandePelotas and friends to vibe code such a system but it is absolutely possible and is something we should, at the very least, be thinking about.
I think the problem that lots of people, including all the people involved in those companies, don't think that's a problem but a feature. Adds "jobs", GDP, filling their own pockets and a whole host of other "benefits" they're willing to look past any drawbacks in order to get.
It's worth pointing out that the point of contact for state IDs is the DMV, which is the butt of every government inefficiency complaint. If, instead, it was done at USPS offices or even by postal workers on their routes, no one would complain.
It's entirely about whether the burden is placed on the citizen to maintain their Constitutionally guaranteed rights or whether political agents can use the state to selectively burden neighborhoods, especially ones with no / badly performing DMV offices.
I always find DMV (or whatever your state's equivalent) inefficiency arguments to be hilarious. They're run extremely efficiently for the government. They suck use because of that (long wait times, most important stuff gets shipped by mail weeks later).
It's real funny until they pass a law that says you need an ID to vote and then immediately close the only DMV anywhere near where you live specifically because they want to keep you and your neighbors from voting (https://www.yahoo.com/news/feds-called-investigate-alabama-d...)
Earlier this year, my license was expiring and I decided to get a Real ID. I was able to create an appointment on the Oregon DMV website. It was set for 10 AM. I got there at 9:50 and checked in. My name was called up at only a couple minutes after my appointment time. I gave my documents and paid, then was instructed to wait by the camera area for my picture. I had barely sat down when my name was called. They took my picture, and I was all set. I was out the door by 10:15. Pretty sure my ID then came in the mail only about a week later.
So when people talk about long waits, I don't know what they're talking about. Maybe their state just sucks.
When I lived in Colorado the smart move in Denver was to start lining up about an hour before the DMV opened (for driver licenses, car registration never had much of a line). Out in the mountains, I was able to just walk in just about anytime. The longest wait I had in the small mountain town I lived in was when the one lady working there was doing a driving test, and I had to wait 10 minutes for her to get back.
Living in Washington, they allow private businesses to register vehicles, so transferring a car was normally a 5 minute job. Never did bother to switch my DL, so can't comment on that.
Now I'm up in BC where vehicle and driver licensing is handled by the state owned insurance monopoly. Any agent, private or public, can register your car. You can get the licensing done at public insurance offices, or at provincial service centres that handle all sorts of business by appointment or walk in. It all works pretty well.
Like I said, the USPS is in a much better position to be able to scale identity to the national scale.
The point of the government doing it is that it has to be able to service those people who live maximally far from a DMV (say 60 minutes each way by car), who can't drive there, who have to weigh losing pay to take the time to travel there, who have below average intelligence, who are functionally illiterate (because Mississippi created A LOT of those before their recent education reforms), who "can't use technology", who forgot to bring whatever specific document qualifies for Real ID, etc.
The government is efficient without qualification.
People just like to complain and Reagan was charismatic so we’re cursed with this government inefficiency meme. We’re programmed to repeat it even when providing counter examples.
The overwhelming majority of the waiting I do in life is at the hands of private organizations who are unwilling to invest in proper staffing.
There will no doubt be replies to the contrary but to them I say they have identified corruption, not inefficiency. When the government doesn’t work it is by choice.
The government has to (and should have to) provide the same service to everyone, everywhere. Businesses would never bother putting a DMV office in a small remote county because of cost, even if it was unfair and inconvenient to people living there. Government does do that, and it doesn't look great on a balance sheet.
Sure, you can get an ID cheap. Most of the time. But if all of your ID is lost (which can easily happen to the victim of a purse snatching) it's going to take time and money to fix the problem. And voter registrations are not supposed to be permitted to be challenged too close to the election. Not supposed to be doesn't mean it doesn't happen repeatedly, though. This scales much, much better than sending in fraudulent ballots. We find a handful of fraudulent ballots, often by Republicans trying to prove fraud is easy. 2016 and 2024 both had more people denied access by ID laws, challenges and the like than the margin of victory. And those missing votes would have skewed heavily Democrat.
Almost forgot: SAVE puts a very onerous paper trail on divorced women. They'll need copies of the paperwork changing back to their maiden name--something an awful lot of them don't have. I've already seen a variation on this with RealID. A mistake was made at my wife's naturalization, a hyphen crept into her name that didn't belong, went unnoticed for years. Even when it was discovered it was a so-what. Social security had an errant hyphen, everything else was as intended. No problem. Then RealID came along--and she had to do a legal name change in order to change her name to what her ID and passport said. Weeks and hundreds of dollars.
Denying legitimate voters is just as much fraud as permitting fraudulent ones. A system in which the the former happens at least 10,000x as often as the latter is not a good system.
You must have had better luck with post offices than I have. Having lived in a dozen states and used many different post offices, the vast majority is an utter nightmare. Between the rudeness and the apathy, I would much prefer the DMV (depending on the state)
> The CERES project (Spanish Certification) headed by the FNMT-RCM consists of establishing a Public Certification Entity that will enable authentication and guarantee the confidentiality of communications between citizens, companies or other institutions and the Public Administrations via the open communication networks.
So far, in my ~decade here, it's been working out great and is so easy to use.
- MiDNI > https://play.google.com/store/apps/details?id=es.gob.interio... - Mi DGT > https://play.google.com/store/apps/details?id=com.dgt.midgt
S Korea has had government issued digital IDs for all online transactions, although it was originally implemented as an Internet Explorer 5.5 plug-in (eww). I haven't heard anything about how it works these days.
Japan has new digital IDs cards and a standard little device available at every corner store to use it to digitally sign legal documents.
The next step will be EU-DI, an app based wallet with many more features and hopefully better interoperability between EU countries.
https://en.wikipedia.org/wiki/Electronic_identification#Usag...
https://ec.europa.eu/digital-building-blocks/sites/spaces/EU...
it's stupid easy to setup, the app is not overly bloated and it has different options to authenticate.
Recently I added my passport to my Apple wallet but I’m not sure if that’s used anywhere.
I'd love to read more about what security features US passports are missing and what they have implemented. Just out of curiosity.
The fact that USA never finished the Real ID thing as the Citizen ID in Europe is kind of mind blowing for me. It is elegant solution to everything what current administration is complaining about - prove of citizenship for ICE, prevention of voting fraud and especially business owners can tell who is citizen and who is not.
Just to be clear for our international friends, this is basically as unheard of. "In some cases" you could say well in some cases of murder someone is a cannibal too. It's a big country with over 340 million people under one roof. Shit happens.
Stop fear-mongering. One person doing something wrong one time does not constitute any sort of noticeable or wide-scale practice and the fact that if such an event occurs it makes national news and is fixed goes to show that the public is opposed to these practices, they are exceptionally rare.
Or perhaps there are "some cases" of voter fraud too ;)
Somehow this wasn't a problem for them, while whites-only water fountains still live rent-free in your mind.
Following your logic, no problem is solvable until you have eliminated all potential issues and outliers. No startups would ever get off the ground with that attitude.
> People who want to just ram through voter ID laws without solving the problem of undocumented citizens can't be treated as serious members of society.
Maybe we want to be more like Europe with IDs from birth and to use them for all government activities.
Who are you to be the arbiter of who is a serious member of society?
If one or both of the two who just got married wants to change their name? The process is downright bizarre. There is no central name database you go update. You just send off forms to a bunch of places saying “this is my name now,” some with a copy of your marriage license.
Very strange system IMO.
Why go through some centralized, hackable database, wait in line, and maybe get told to go away by some nameless official making minimum wage to update your last name when you can just decide to start using it and that's your prerogative? "I go by this, you don't get to decide". "My gender is this: it's not up to you to decide". I think it's something worth debating whether or not these kinds of things should even have anything to do with the government. I think there are good reasons, but I can certainly see very well-reasoned and principled arguments against the government being involved in some affairs like this.
It’s a lot harder these days given the 60 years of progress
> It is elegant solution to everything what current administration is complaining about - prove of citizenship for ICE, prevention of voting fraud and especially business owners can tell who is citizen and who is not.
Well there are two things here. We don't in my opinion, have much of an issue with actual voter fraud - as claimed by those on the right. However, we also have a number of folks on the left who are against voter ID requirements because it might disenfranchise some voters who don't have an ID... an ID you need to do the vast majority of important tasks in life. I've always said if you're not responsible enough to get an ID we don't want you voting anyway (no I don't care about the downvotes).
It's sort of funny how these have seemed to change over time. Folks on the right historically were very much against "big government" ID programs. On the left? In favor! Well, until you start using it for checking who is voting or something. It's also amusing and a little bit irritating that our national ID system is basically 50 state ID systems and they are all centered on having a license to drive a car....
Also Americans can get IDs at a younger age too (children over a certain age need a passport to travel outside the US for example) but we don't really as a society require an ID for many things in practice - it's not really the culture here, we prefer a little bit of anonymity, but once you hit 15 1/2 or 16 you can get a state level driver's license which you'll then carry for the rest of your life. For those who don't drive you are also able to get what counts to just a state ID.
Not to make excuses but the US is a little hard to understand some times with these things because there's so much, especially in the news, emphasis on the federal level of the US government but it really is 50 sovereign states who send representatives to Washington DC. Unlike in, say, Estonia which from my very limited understanding is sort of one people, one country, some divisions. In the US you're from California, or Ohio, or Maine and the state manages most of your lifecycle affairs.
> The fact that USA never finished the Real ID thing as the Citizen ID in Europe is kind of mind blowing for me.
I actually refuse to get a "Real ID". I already have a passport. They can kiss my ass on paying an extra $25 for what amounts to the same ID card I already have. I'll take it for free but I'm not paying for it. I'll just carry my passport when I fly.
But US states are sovereign entities who have, effectively, joined together to delegate some of their sovereign activities to a federal body (which has increased in power over the years) for the common good. They are very tightly bound to the federal government, but these matters don't refute their sovereignty. It's one of the reasons, maybe the primary one, for the US Senate - it's a vote of sovereignty by any individual state so that states with higher populations don't simply dictate rules to states with lower levels of population. Lower population states wouldn't have agreed to delegate some of their sovereign rights without some mechanism to not be run over by populists.
10th/11th Amendment
Sovereign states in the latter sense can delegate their powers to external entities (as they do in the EU), but they can also unilaterally choose to take that power back (as the UK did).
The USSR was an interesting case when it comes to sovereignty. Legally its member republics were sovereign states, but that sovereignty meant little in practice. As a result of a weird compromise, Ukraine and Belarus were founding members of the UN, despite not being sovereign in the generally understood sense. There was a legal mechanism for secession, but in the end, the member republics ignored it and dissolved the union.
With the way you’re characterizing the idea of sovereignty, every entity in the world is semi-sovereign. But sovereignty isn’t a spectrum. An entity is either sovereign or it’s not.
See, e.g., Alden v. Maine, 527 U.S. 706 (1999) https://supreme.justia.com/cases/federal/us/527/706/
"Although the Constitution establishes a National Government with broad, often plenary authority over matters within its recognized competence, the founding document "specifically recognizes the States as sovereign entities." Seminole Tribe of Fla. v. Florida, supra, at 71, n. 15; accord, Blatchford v. Native Village of Noatak, 501 U. S. 775, 779 (1991) ("[T]he States entered the federal system with their sovereignty intact"). Various textual provisions of the Constitution assume the States' continued existence and active participation in the fundamental processes of governance. See Printz v. United States, 521 U. S. 898, 919 (1997) (citing Art. III, § 2; Art. IV, §§ 2-4; Art. V). The limited and enumerated powers granted to the Legislative, Executive, and Judicial Branches of the National Government, moreover, underscore the vital role reserved to the States by the constitutional design, see, e. g., Art. I, § 8; Art. II, §§ 2-3; Art. III, § 2. Any doubt regarding the constitutional role of the States as sovereign entities is removed by the Tenth Amendment, which, like the other provisions of the Bill of Rights, was enacted to allay lingering concerns about the extent of the national power. The Amendment confirms the promise implicit in the original document: "The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people." U. S. Const., Amdt. 10; see also Printz, supra, at 919; New York v. United States, 505 U. S. 144, 156159, 177 (1992). The federal system established by our Constitution preserves the sovereign status of the States in two ways. First, it reserves to them a substantial portion of the N ation's primary sovereignty, together with the dignity and essential attributes inhering in that status. The States "form distinct and independent portions of the supremacy, no more subject, within their respective spheres, to the general authority than the general authority is subject to them, within its own sphere." The Federalist No. 39, p. 245 (C. Rossiter ed. 1961) (J. Madison).
"Second, even as to matters within the competence of the National Government, the constitutional design secures the founding generation's rejection of "the concept of a central government that would act upon and through the States" in favor of "a system in which the State and Federal Governments would exercise concurrent authority over the people who were, in Hamilton's words, 'the only proper objects of government.'" Printz, supra, at 919-920 (quoting The Federalist No. 15, at 109); accord, New York, supra, at 166 ("The Framers explicitly chose a Constitution that confers upon Congress the power to regulate individuals, not States"). In this the Founders achieved a deliberate departure from the Articles of Confederation: Experience under the Articles had "exploded on all hands" the "practicality of making laws, with coercive sanctions, for the States as political bodies." 2 Records of the Federal Convention of 1787, p. 9 (M. Farrand ed. 1911) (J. Madison); accord, The Federalist No. 20, at 138 (J. Madison and A. Hamilton); James Iredell: Some Objections to the Constitution Answered, reprinted in 3 Annals of America 249 (1976).
"The States thus retain "a residuary and inviolable sovereignty." The Federalist No. 39, at 245. They are not relegated to the role of mere provinces or political corporations, but retain the dignity, though not the full authority, of sovereignty."
A legal term of art is often a bit different than the basic word itself. From a legal term of art perspective, I’m essentially referencing “absolute sovereignty”, which would more closely mirror the actual dictionary definition of sovereignty, as a basic, contextless word.
Related to your point about absolute sovereignty I wouldn't disagree with you at all, but I would say that, and I'm not accusing you of doing this by any means, we should be mindful not to shift the goalposts and attempt to depress the meaning and significance of sovereignty just because an entity isn't also absolutely sovereign.
Each and every vote is counted!
The people choose and it’s as simple as that!
In fact the people chose with their hard earned votes for Kamala and Trump to run against each other for president didn’t they?
Didn’t they?
And Europe is even freer!
So much global freedom and democracy where we all have a say :D
The private key itself is locked into the Emirates ID, and need my biometrics to unlock.
Example: When I get delivery that needs my ID, the delivery man just put my Emirates into a card reader, and they need my biometrics to digitally sign the receipt.
It’s often used for important delivery (banks/gov documents), and any related gov services (including telecom, if i want to reload my sim card but forgot my pin, i can just insert my Emirates ID and scan my fingerprint and it retrives my SIM card by magic!)
You can try to read how they are doing the Emirates ID and the UAE Pass app, it’s super interesting to see this so well intergrated and at scale.
https://www.e-resident.gov.ee/nomadvisa/
The design standard for US & Canadian driving licenses & ID cards allows for chips on them. Page 27 of
https://www.aamva.org/getmedia/99ac7057-0f4d-4461-b0a2-3a553...
A pet hobby of mine is to get my state to adopt something similar to the Estonian standard. With a card reader, one would be able to vote from home with the election board being confident that the vote was cast by an authorized voter. This would address the fearmongering by one political party that has been going on since some black dude got elected President. Other things could include signing tax returns online.
Since REAL ID, getting a driving license/ID is a lot more controlled.
i also have 0 trust in the USG's ability to not lose those, either through hacking or through blatent corruption a la DOGE, et al
I'm not saying the gov is competent in general btw, but they are actually far better about this area than private industry, in my direct experience.
You're right. Since a few others have said as much, I was sketching an outline and not suggesting handing people literal RSA keypairs. Any practical, _usable_ solution would involve a physical card, mobile app, web app, etc.
https://en.wikipedia.org/wiki/Biometric_passport
[0] due to constant undermining by said surveillance industry, which has now basically become "too big to fail"
Effectively this allows the keypair issuing government (and thus whoever collects breach data) the ability to impersonate you. Seems like a terrible idea.
That suddenly means a data leak doesn't matter - nobody can make new signatures.
Verifying someone's ID would be as simple as asking them to sign your company name and today's date.
[1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...
If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed).
We'll get there eventually, but not before we try everything else first.
"They can already send a drone to watch you and track your cell location and, and, and, why does it matter if they also slap up a million AI powered cameras?"
The comprehensiveness of the system matters.
This is Chesterton’s Fence.
https://en.wikipedia.org/wiki/G._K._Chesterton#Chesterton's_...
What attributes should require proof? Where do you draw the line?
Age?
Gender?
Race?
Religion?
Political party?
Citizenship?
> We'll get there eventually, but not before we try everything else first.
We got here by trying everything else first.
The “good old days” are now. Thousands of years of progress and blood delivered our liberal societies. Don’t give it up so easily.
The EU/EEA is rolling out a digital identity mechanism with interoperable wallets that can hold any range of identity documents and other credentials. You don't need to pick a single wallet provider - several EU countries are approving multiple, including private providers. You don't need to standardise on a single ID.
This is already the case for many already in-use ID solutions in Europe. E.g. in Norway, there are at least 3 signing providers, and only one provider is government issued - the by far most popular (BankID) is private. You identify yourself to the provider when requesting issuance, not to the government (unless you sign up with a government provider).
AFAICS from the other side of the pond, United States Government can track people well enough even without a national ID card. They have successfully worked around that problem.
So, it's a moot point now. No?
Meaning, I can’t buy food; rent or buy a home; or hold any sort of job and earn and save.
What we have today isn’t better, but until recently I was hard pressed to see how such fears were even warranted.
This is because the US made a critical flaw by tying the authentication and authorization tokens into one single token - your driving license/ID. They should be separate things. Your authentication token (who are you?) should have your picture and be forgery resistant. Your authorization token (what can you do?) should be a piece of plastic with zero pictures (like your insurance card). Did you get stopped for DUI? The officer takes your authorization token, instead, the officer confiscates both tokens and hands you a paper receipt.
The FAA does it the smart way, your authorization token (pilot's license) has no photo. You do something stupid, the ATC tells you to "call this number" and if it is really badly stupid, then the local FAA person confiscates your authorization token.
Things are already bad enough as it is, but at least it’s still possible to get by even if the system takes a dislike to you.
If you're within the borders of the US, this ability already exists, they have a monopoly on violence in the country, something the government is very eager to demonstrate this year.
And again, as long as backchannels exists in the system to accommodate those without a Government ID, it is possible to get by even if the system tries to cut you off.
Don't you see and understand you already have government ID? You're just calling it by another name...
Do you seriously not get it yet? You have IDs now, and you claim those backchannels exists now, and haven't been cut off. Why would calling something something else suddenly make those backchannels be cut off? How come they exists today in the first place then?
I have not seen a definition of this that is simultaneously true and useful
The sole provider of violence in the U.S. is not the government.
Of course many engage in "violence", or "provide it", that is not in doubt.
In the U.S. I can lawfully use violence in many ways under many circumstances. I.E. if you’re in my house and I didn’t invite you there, I can slay you lawfully.
In the U.S. the federal government is not the only institution responsible for law making or law enforcement. It is not only entity that can lawfully use violence. Etc.
Yes, and you can do so, because the government and state says it's OK to do so. If they didn't, it wouldn't. This is the core idea.
> In the U.S. the federal government is not the only institution responsible for law making or law enforcement. It is not only entity that can lawfully use violence. Etc.
Hence the whole "sole arbiter of" and last paragraph in my last comment. All those entities are "allowed to use violence" because your government says it's OK.
There are clear counter examples to your statement in the U.S.
States are not “allowed” to use violence because the Federal government says it’s okay. States have a right to create and enforce laws.
I don't know if you're in the US, but that's simply not how our Constitution works. "Monopoly on violence" is just something some people made up. It's meaningless, just some empty words on paper.
(Which is also true for the Constitution itself, of course. But if you're talking about the theoretical and philosophical basis for lawmaking in the US, that's what determines both. Theoretically.)
In any case all the old gods are dead or dying, including old ideas of statehood, so enjoy the ride, everyone.
What would happen today if your government revokes a SSN which is your de facto "personal identification number" today? Can you still rent/buy a home? Can you have a job?
But while cash is printed (physical currency): Not having an SSN becomes a major impediment but not impossible to make transactions and survive.
Our migrant workers—who are basically carrying white collar workers like me—are proof of this.
Point is, the US already basically have a de facto "ID card", they just don't call it as such (yet?), so claiming somehow correctly labeling this thing would make things worse or more difficult, doesn't make much sense.
There is no reason a digital equivalent can’t be made using the passport system, and it can be left optional, just like passports are optional.
"Border controls aren’t supposed to exist between EU member states – that’s the promise of the 1985 Schengen treaty. Yet today, travelers routinely face checks when crossing borders within the [European] union"
https://euobserver.com/198454/law-professor-sues-germany-for...
EU did border checks without digital IDs being a thing, so why couldn’t US states do a border check without digital IDs?
Digital IDs are not a causal factor for these concerns, seeing as how those government abuses already happen without digital IDs.
The GDPR in a nutshell......
Unnecessary personal data is a liability.
In the US, courts have ruled that the compiler of data owns all that data - you have no control about data about yourself (except in a few legal categories like credit reporting). Some of these old court rulings covered telephone books and business directories.
> Unnecessary personal data is a liability.
Absolutely.
I wish it would be more enforced and controlled tho.
Everyone just gets away with everything.
Recently a bit dutch ISP was hacked and it turned out they kept millions of former customers' details way way beyond any normal lifecycle term. People were still in there that hadn't had anything to do with that company for a decade. This is illegal in the EU but even after this practice was exposed by the leak, the personal data authority just let it all slide.
They also sent out a press release pooh-poohing the consequences for affected (ex-)customers and all they did in compensation was to give a "free" antimalware subscription that was basically advertising just like the few months of mcafee crap you get with a new computer. But all we get from regulators and politicians alike is crickets.
Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses?
Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model?
Hm.
But it has to be freely given. "Give permission or you can't use this service" is not ok for data that isn't required to provide the service.
If the purpose wasn't "we keep to resell it later" it's likely illegal.
Well, "illegal" given that this type of criminality is pretty much ignored (I've been fobbed off by the regulator after pointing a systematic law-breaking by a $company many many many times. Still better than not having this).
Just locate a prosecutor.
Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.
Correct, like being criminally negligent of a child, if you leak data through long-known vectors (for argument’s sake), one could argue you are criminally negligent in securing the private data.
It doesn’t really go that way, often, now.
It could, as more e.g. water treatment and energy providing facilities get pwnd.
Good luck arguing against their conviction rate.
18 U.S.C. § 1028 makes certain transfers involving identification documents criminal. It specifically covers a driver's license or personal identification card and provides enhanced penalties for transferring such documents.
1028 expressly recognizes electronic transfer as satisfying its interstate-commerce requirement.
What are you talking about?
This means the police don't get involved. The only thing you need is a tort lawyer willing to take a share of the damages. Also, a data breach is proof that you possessed the data.
A business wouldn't be able to reduce their liability exposure to zero, but to an acceptably low level, for instance by actively erasing the data before a breach can occur.
Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in reality the attackers had card-sniffing malware installed on every single cash register at every single store across the country.
How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type dir or ls at a command prompt, it says something like "X files using Y bytes, Z bytes free". How do you know those numbers are true/correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out).
Heartland - #19, Target - #20 at:
https://www.upguard.com/blog/biggest-data-breaches-us
You may notice that the poster of the comment you are responding to is mentioned a lot on that page.
Part of the attack was physical, aka skimmers. I still remember the relatively elegant inspection tool blogged by Target Tech on HN 3 years ago:
Target's EasySweep – Simplifying Skimmer Detection: https://news.ycombinator.com/item?id=36788831
So most businesses are not permitted to just delete the data.
Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.
Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.
Not in the US, but in Spain, police gets this data real time when you rent a car or check in to a hotel.
This is of course important for protecting you.
Well, that's very kind of them. I am constantly impressed at the kindness of our governments, and the recent growth of that kindness. I guess that, with all of the power that modern technology is giving them, they're finally getting to live out their heart's desires of being very, very kind.
There can be a discussion about retention periods and the like but too short a retention period amounts to "trust us bro" in the eyes of some un-feeling government agency who is trying to screw you either at the behest of the law or at the behest of whoever hates you and has their ear.
Something needs to be done but "just delete it after you've verified it" is not workable at scale. Yes I know it worked fine for brick and mortar forever. Maybe some acceptable technical solution could be reached, idk.
Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.
They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
Basically swaps the LED illum with an UV LED instead. Makes all the security features pop right out.
I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.
They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).
One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.
The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.
Some Interrail travellers told to cancel passports as hacked data posted online
https://www.theguardian.com/technology/2026/apr/23/some-inte...
I just don’t hear about it anywhere near as much.
[0] https://en.wikipedia.org/wiki/Vastaamo_data_breach
The theory that local government is more accountable and responsive seems to be pretty deeply broken, what actually seems to happen is that localities lack a critical mass of attention and focus for real responsiveness and accountability.
Or the American character in general does.
Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is.
And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We're talking a $5 billion company handing 15 million people's credit reports to hackers, and getting fined $15 million.
As an EU citizen and resident I strongly recommend you not take EU privacy controls seriously. The GDPR functions well as a means of tax collection, but it really doesn't work all that well as something that actually protects people's privacy.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
Count the number of Americans who would have an ID worth scanning (aka ages 18 or over): 269M [1].
Or the number of Americans with a driver’s license: 212M (2013) [2].
1: https://www2.census.gov/programs-surveys/popest/tables/2020-...
2: https://www.bts.gov/content/licensed-drivers
I didn’t go through with that part of my application and didn’t keep the job.
What does an "identity verification" company even do?
Handles the multitude of ID document standards around the world while providing a simple Boolean flag to websites that are required to check if you're an adult.
1. You already know who everyone is. By definition identification as an individual is by government.
2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?
3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")?
Governments need to protect the public, not allow businesses open slather on collecting PII.
Generally speaking, it's the narrative of a pushback on a "national id".
Many countries already have this place. Estonia has the Digital ID provided by government[0]. Nordic countries use BankID, which is a form of KYC that is backed by banks (you prove your identity to the bank, the bank issues a bank id - usually back by certificate[s], and you login with this to services[1][2]). Finland is the outlier, here, with their own service[3].
0 - https://e-estonia.com/service/estonian-e-identity/id-card/
1 - https://www.bankid.com/en/individuals/get-bankid
2 - https://bankid.no/en/how-to-get-bankid
3 - https://www.suomi.fi/instructions-and-support/identification...
European Digital Identity Wallet (EUDI Wallet) framework established under the eIDAS 2.0 regulation (Regulation (EU) 2024/1183)
When you scan your driver's license at a compatible reader, you're given a notice of what information is being requested and the ability to share it (or not).
It can also request some derived attribute (is this person above the age of 21?) instead of the actual data field itself.
Most of this is from ISO/IEC 18013-5
Ars already has a story about the same breach: https://arstechnica.com/security/2026/09/my-drivers-license-...
Is this story being flagged? If so, why?
Somewhere in the inane executive brain world there are some folks who seem to see some unspecified value in collecting driver’s license images. They never have given me a sensible justification. They seemed to think it provided some assurance that the providing it is in fact who they really are and they can validate…. something.
I’ve managed to push back on that and told them I didn’t want the legal responsibility of managing such data and tracking all the legal responsibilities for any number of countries and ect.
It doesn’t surprise me that there is a ready made service to bypass this kind of absurd requirement.
But no it's about leaked data. That wasn't very clear from the title.
You'd think that 80 million people from a rich first world country would be enough of a market to use this.
No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
Because then that website would get compromised and lose the data on 350 million people instead of 153.
Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.
People throw around terms like "zero trust" like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you'll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.
Using government ID on the internet should simply be banned. 99% of things shouldn't require government ID to begin with and the 1% that do should always be done in person.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
Monetary fines have a tendency to simply be modeled in as a cost of doing business. Going to prison is far more effective when the goal is to concentrate minds.
And because REAL ID requires mailing your DL/ID to you (in order to prove you live at that address), the address will not change (most states require you to get a new DL/ID within 30 days of moving - my state is 15 days). Replacing the driving license will not change any of the data. Only the DL/ID number. For other identity theft, the old data will not change.