Comment by Nition

3 hours ago

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.

So most businesses are not permitted to just delete the data.

  • Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234"

    Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.

I believe we need to criminalize possession of the data, with statutory damages per violation.

  • Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.

  • Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.

  • Not quite the same, but the GDPR gives you a right to erasure.

    • And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.

It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.

  • Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.

The whole point is they keep it forever. You think any id verification services actually delete the data?

  • I mean, just because all your friends are jumping off a cliff...

    • It feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...

    • If you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.

The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.

Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through