Hackers had a live feed of every ID verification company scanned for over a year

2 days ago (techdirt.com)

Brian Krebs' article is, in my opinion, a much better read for this story[0].

[0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proofs for particular properties (e.g. if the person has a driver license or not) without de-anonymizing the account. In the rare even of root key leak you should be able to physically go to the authority and make a new one, while revoking the old key. I don't see any other better alternatives than this.

  • This is effectively the EU age verification system.

    Your government (which already has all your details) generates certificates and you just give those out. The other side can the use simple public/private key verification to ensure the cert is valid. Also government does not get information who you gave the cert to and if you create a bunch and single use them the other side can’t follow you between uses using the certs.

    • The problem in the US is that the government doesn't necessarily have all of your details. Most people's ID is a driver's license, but you're not mandated to have one of those. The federal government doesn't control those databases (hi, REAL ID), and few people actually have passports. Your citizenship documents are just a birth certificate that is an image on file with a particular state's health department. A centralized identification system on that scale in the US would take generations to get up and running

      14 replies →

  • I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through.

    The alternative is do it offline.

    • eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs.

      Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem.

      Doesn't even need ZKP, the CA can just issue an attestation.

      12 replies →

    • or just not ask for it at all.

      The three times I've needed to provide a scan of my passport were: to enroll in a university course, to buy from an e-commerce site, and to become an app developer. None of those orgs really needed a scan of my passport, which can't be revoked like a cracked password, and will now sit unencrypted somewhere until the end of time or until they are hacked and subsequently shamed into handling their customers data more like radioactive waste.

      3 replies →

    • The US Government is one of the reference implementations of PKI.

      Unfortunately, IDs are issued 50 different ways by the less competent states.

      Combine that with accusations that getting new IDs constitutes systematic racism (a widely held belief on HN), ignoring that the ruralest of India has been able to do this successfully, and you're not getting digital ID any time soon.

      23 replies →

    • While that can certainly be true it is still generally safer than username/password for authentication.

  • > the most you lose

    Yep that's the only thing you lose, apart from a huge number of literal images of kids in the hands of literal criminals.

    > I don't see any other better alternatives

    Not doing age verification!

If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)

  • This comment is worrisome:

    > My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.

    • I feel like that should require an in-person visit, as troublesome as that might be. A picture of an ID is not the same thing as presenting the actual ID

      4 replies →

    • Sometimes I feel it's a blessing that for even a minor change my banks make me visit the branch and ask for my real Govt issued IDs (often more than one) while also make me do the online auth (Govt ID; needs OTP and biometric) and still make me submit self-attested print-outs and then add a delay to it (and even reject once in a while if they feel the signature didn't match..and then the cycle restarts :D). I know, I know - there is a solution of this on hn and it will even scale handsomely. But I'd rather have my hard earned savings safe.

    • Wouldn't this also mean Gmail, Facebook, etc are no longer safe? The person can simply provide this documentation as proof they own the accounts and claim they were hacked.

      1 reply →

  • > "The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit."

    Mr Krebs is dealing with all this mayhem and idiocy with remarkable sang froid if I may say so. Good heavens.

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible.

‘Just make the encryption secure and so we can read it’

‘Just check everyone’s id but make it totally secure’

  • They do not care about 'secure' part at all.

    • This is the answer. The more failures, the more justification for more draconian restrictions of civil liberties.

      I can hear the defense now: "Oh, yeah, you blame the honest, good, handsome people trying their best to protect you and you let the hackers off scot-free! We must make sure that hackers don't have access to the tools that aid them to commit these crimes, like books and computers. Anyone could be a hacker."

      1 reply →

  • That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain.

    The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know.

    I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"?

    • As Ops person, massive doubt. I've been at companies that have gotten hacked twice now, neither my department though. Both times, security vulnerabilities that hackers got into were well known, the tickets were in the backlog and deprioritized over feature requests.

      I've also seen cases where it's like, maybe we shouldn't share S3 Root Creds or put it on the VPC so we can monitor outgoing traffic but too many applications would need to be redeployed for that so skip it. Those 2 year old tickets were still sitting in the backlog when I left.

      If we ever get report, it's extremely likely going to be massive failure and only way to change this is fines for company that are bankrupting.

      EDIT: Oh yea, SOC2 needs to go away. It's security theater that's just giving cover to companies.

    • I'd say it's not so much "as secure as we know how" and a lot more "as secure as we're willing to pay for". I'm sure this company has competent sysadmins and devs who'd be happy to lock things down. Usually management doesn't want the expense or the hassle.

    • This is kinda my point though - just don’t do it in the first place is the answer. Nothing is unhackable. So don’t create a massive honeypot in the first place.

    • Those aren’t the people in charge. People like 93 year old Senator Chuck Grassley are calling the shots.

Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

  • We also have a Danish wallet now, AltID, which implements an anonymized (assuming no collusion between issuer and eavesdropper or service provider) age verification protocol based on batches of single-use tokens which contain no personal information (except that they can be traced back to you by the issuer).

    It's been released and in production since summer. Since then, several social networks have apparently started A/B testing age verification for their EU users, but how many of them actually integrate with the anonymous solution that is now available and in production? To my knowledge: 0. They all use Persona.

    This highlights one of my main criticisms of EU's naive approach to regulation of tech companies. They fail to realize that any regulation that they impose will be complied with in the most malicious way possible, which is how we got cookie banners with dark patterns instead of a simple HTTP header saying no thanks to cookies.

    • The problem in much of the west is that even if verification is initially government funded/run and secure, the neoliberal ratchet (underfunding>degraded service>privatize) ensures that it will eventually be privatized and enshittified.

      Here in the US, we have login.gov, but many government services use the private ID.me instead.

      Any time the government says it needs to “cut spending”, it instead sells off critical infrastructure to friends of government who then permanently extract a private tax on the public.

  • But usually gov't will outsource to random 3rd parties, no?

    • One third party, managed by a public contract, seems much better than a parade of third parties for every service you interact with though right?

    • In Finland they outsource the system to banks and telephone operators. Its a very strange system. As far as I know, its not possible to access government services just by being a citizen. You also have to have an account with one of these third parties to get in.

      3 replies →

    • probably gov will outsource to 3rd party for gov to build system to track and manage ID. Sometimes though also to manage, as in Denmark's MitID mainly managed by NETS under government set rules.

  • As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions.

    Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which of course impact quality of deliveries (not shaming the people who do the hard job without the relevant means). And while more distributed governmental topologies would have their own caveats, at least it would less likely offer opportunities for single point of failure.

    [1] https://francepassoire.com/

    • I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.

      13 replies →

    • On the end of the day, it is the state that issues these ID documents. So if you let the government go bad, IMHO the form of the documents does not matter that much.

      During the totalitarian communist rule in Czechoslovakia, the state would regularly interfere with passports of people considered not loyal enough - withholding them outright or inventing extra paperwork that was necessary for the border police to let you out of the country. They also controlled all supply of foreign currency, both in an out.

      Then if someone was actually allowed to travel outside the country but failed to return, their family and relatives would be punished, including demotion at work & prohibition of higher education.

      So if your government goes bad, this is what will happen - the form of the ID takes at that point does not make much difference.

      1 reply →

If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.

  • CADMV claims on their web site that they cannot accept a P.O. box as a residence address. I have yet to find anything in California state law supporting this policy, though IANAL. Their enforcement seems to be quite lax.

  • Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?

    • I used to work for my state's DMV. They'd sell vehicle registration data to various companies, which is how and why you get those "we've been trying to reach you about your car warranty" phone calls. I don't know about CA, but KY had a problem with tracking who ordered and who paid for that data. When I worked there, we found a number of "purchasers" who only paid for Year 1 but stopped paying afterwards.

      Federal law requires state DMVs to supply that data to the car manufacturers. So if you own a Chevy, they have to send your data to Chevy in case there is a recall.

      2 replies →

    • You fill out a form. The government sells the data on the form to someone who pays them money for it. There is no nuance here.

I wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!

  • You know, it always bugged me that the NSA (and more directly Google, and my phone company, and so on) know where I was at exactly this time a year ago, but that I do not.

And again, there will be no monetary consequences for the companies that failed to secure our private data.

  • I can't agree more strongly with this statement. It is mind-blowing how can it be socially acceptable to treat other people's confidential data so mindlessly

    We should have a law which penalizes businesses for leaking other people's private data

    Got John's driver license exposed? Write him $1k cheque. Second time this happened? Make it $3k. And another 1% of his assets, since you put them at risk. $10k in the bank? That's extra $100. Guy has property worth 500k? Too bad for you, that's another 5 thou.

    And no blaming sub-contractors either. You hired them to do validation and they leaked data? Too bad, must have verified that they are reliable. This is when all of these Hertzies and Targets and Fedexes start thinking twice before storing confidential data. Why do they need to hold on to your driver's license? I know why. They hope to make some extra cash by datamining it. Well, get your checkbook ready then.

    You are selling alcohol and wanna make sure I'm older than 21? You don't need to scan ID. You definitely don't need to store it. You CHOOSE to store it, and if you do, be prepared to pay if you expose it.

    I wish it worked like that, but yeah, it never will

  • And governments will continue to force citizens to use these shitty companies for whenever they need id verification.

    • And create new requirements normalizing id verification for increasingly mundane things assuring citizens are exposed to ever more breaches.

    • That's why I say "Our lobbyists have more money than your lobbyists". Every state has sunshine laws to show who the lobbyists are, what they lobbied on, and to whom. Some states separate those lobbyists into legislative & executive branch lobbying.

      I suggest you look at who voted for those bills, who lobbied them and who hired those lobbyists.

      1 reply →

  • More like class action lawsuit, $500m settlement, $300m for lawyers and $0.50 for every victim.

No worries! Governments who used this company are taking responsibility and now have a plan to, at the very least, replace all IDs they forced people to expose and to make sure the old ones are unusable!

That's a sarcastic joke. It's how governments demand private companies react, but ...

The HN title is misleading.

> Hackers Had A Live Feed Of Every ID __This__ Verification Company Scanned. For Over A Year.

The "This" in the the sentence serves an important role. It currently reads like all ID verification companies were compromised at the same time.

  • There are only two types of scanned ID documents, those that are known to be compromised and those that are not

I cannot get over the volume of techies calling for more centralized systems, in response to an obvious corruption of a mass scale of a crucial centralized system

The HN submission title is a garden-path sentence:

Hackers Had a Live Feed of Every ID Verification Company Scanned

(Huh? How do you scan a company?)

The original title is easier to parse:

Hackers Had A Live Feed Of Every ID This Verification Company Scanned

> This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe.

Yeah just like how the multiple breaches and utter negligence from the incumbent credit bureaus killed the credit file managed by private companies.

How exactly does that work? How can you sneak a live feed past detection systems? It is incomprehensible to me, considering this is highly regulated and sensitive data. It is just open ports sending what they shouldn't be sending all the way out or what?

  • Brian Krebs' article makes a good case for the ID source being a harvester on the internal Hertz Car Rental network, and likely other similar consumer services that log ID for asset security and recovery.

    These are hardly military grade networks, as long as the driver licence scans make it to the database and can be used to identify and recover damages from accident or theft it's unlikely anybody has cared much past that functionality.

“Prove you are Alice by sending us enough information to impersonate Alice.”

Isn't it weird that every opponent to ID verification screamed at the top of their lungs the whole time that this would cause a massive privacy breach and would be used by bad actors to defraud the public, steal their identity, and by the private sector to track their every web search and activity Big brother style, and they passed it anyway?

Isn't that weird that the very OBVIOUS AND SELF-EVIDENT ISSUES with requiring id to use the internet were, in fact, OBVIOUS AND SELF-EVIDENT ISSUES that were immediately taken advantage of?

Just so so weird. Who could have seen this coming?

This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet

  • I think there's a number of people reading this who clearly didn't detect the satirical nature of this single sentence. It's blunt and obvious, but even so...

    • Yeah, I thought it was obvious enough, but then again, I also seem to get a lot of disagreement every time I directly express the opinion that ID verification for internet use is a terrible idea, so I have no confidence which side the downvotes came from (maybe both!)

  • The politicians really want to know who to prosecute if someone on the internet says bad things (about them).

  • This is precisely why the authority doing these checks needs to be the government that already issues the IDs.

    Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place.

    I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue.

    • > I don't know why HN rails against it [ZKP for age verification] constantly

      Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so. Which means that the only way for it to actually be secure is for the implementation to also required locked down computing devices. Hence why the EU scheme insists on proprietary Apple/Google devices, and why Google research has written nerd sniping blog posts to market it.

      There, now you know!

      2 replies →

    • Government systems leak information all the time. The type of institution managing the data makes little difference. Its how the institution manages the data that matters.

      6 replies →

    • It is European which means that it is both anti-capitalist and communist and therefore must be spit upon.

  • I still don't understand why the simplest approach isn't used: ban kids from using the Internet unsupervised. There's really no good reason why a six year old should have internet access.

    • The argument is that there are parents who are too stupid/lazy to enable parental controls on kids devices and society has a duty to protect kids even if their parents are negligent. Also, kids interact with other kids, so even if you do everything right your kids wind up with access/peer pressure through the kids with bad parents.

      I dunno if I agree but I think that's the thrust of it.

      4 replies →

> There is no safe age verification. There is no age verification that doesn’t put people at risk.

There are zero knowledge proofs

  • Concrete ZKP age verification schemes are hardly zero knowledge.

    Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy.

    Now little Johnny borrows my ID, and uses it to setup some oracle that provides ID validation for every kid and bot in the country. Woops.

    To stop that you must compromise the idealized zero knowledge properties of the scheme, and in doing so you create the potential for harm/risk for everyone.

    Sure, it's better than sending an ID card live feed to the dark web, but the risks of ID card theft are at least somewhat easy to understand.

    Some of the threats to human rights don't even require the departure from the 'idealized' model-- as even the idealized model requires an ID issuer to issue the of-age person an ID. And so if the ID ZKP is widely required then the issuer can unperson you by simply declining to issue you an ID.

  • True. I built a ZK age verification based on Polish digital identity https://x.com/maciejlotkowski/status/1899896737688436844, but I didn't find a business case for it at the time.

    There's a EU initiative https://digital-strategy.ec.europa.eu/en/news/commission-mak.... The direction is generally good, but I'm not very positive about the implementation (as with everything comes from the govs).

  • Yep, and there are a variety of other schemes like OpenID Verifiable Credentials which allow you to prove things like age without giving away everything, too.

    Collecting images of people’s ID is outdated and really shouldn’t be done.

I’ve been following the development of the drivers license sharing system from Apple where different fields can be selected; are there any implementations of PKI based identification systems where multiple certificates can be generated and revoked when compromised?

I’ve often thought that replacing the US social security number with a more robust root key makes for a fun thought experiment. Hard to imagine how such a system could securely serve so many people but passports with embedded chips seem to be doing okay.

  • Not in the US. Several EU countries have PKI systems integrated with identity documents that let the requester to ask for age (for example) and then only age is supplied. But their PKI systems are for the whole ID document.

    As for the passport, the key/PIN you need to authenticate to the chip are printed on the page with the photo. Otherwise "hackers" can only determine nationality of passport. The standard is ICAO 9303.

    https://www.icao.int/publications/doc-series/doc-9303

    SSN was never intended for identification. My original card, issued in the 1970s was clearly marked "not for identification". In the original numbering system, the first 3 digits identified the office/area where the card/number was issued and the next 2 digits identified the filing cabinet. 700s were set aside for railroad workers (until 1963) because the legislators did not want railroad workers to be included in social security.

    https://secure.ssa.gov/poms.nsf/lnx/0110225045