Home Technology Hackers Had a Live Feed of Every ID Verification Company...
Technology

Hackers Had a Live Feed of Every ID Verification Company Scanned for over a Year

Key Points

From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening.

From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening. This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. 153 million scans of drivers licenses easily available based on this breach, with more being added all the time. Literally on the day it was revealed (and right before the site was taken down) it added another 400,000 records to its available database. There is no safe age verification. There is no age verification that doesn’t put people at risk. Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. This is despite the numerous examples we’ve had in just the past few years of verification providers and their customers having massive data breaches. The latest comes to us via Brian Krebs, who reports on a massive breach of scanned IDs — more than 153 million drivers licenses from people across the US and Canada, now for sale on the dark web: A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of theFederal Bureau of Investigation(FBI) today launched an official inquiry into the source of the images. Krebs traces the breach back to an ID verifier that appears to be used by many companies, including Hertz, the rental car company. It appears to not be limited to them either, as he checked with a number of people who were in the database, and by looking at the date they were added alongside their calendars, found examples of other people who shared their ID at places like a pot dispensary. That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, it’s worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification. So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned. Yiiiiiikes. And, of course, like all age and identity verification providers, IDScan has spent years talking up how secure it keeps all this data, even as every single record appeared to be leaking in realtime. Here’s their “Trust Center” page which is still up days after the hack was revealed: That’s the company that spent over a year leaking 150 million drivers licenses in real time, explaining “how we protect data, maintain system reliability, and earn the confidence of our customers and their users.” Might be time to update that page. But also, this should be a massive warning to everyone pushing for age verification laws. You can have a “trusted” company in the space who brags about all the certifications it has. It’s in “compliance” with the GDPR, the CCPA, and every other law. It is “transparent” about its “privacy practices” and how its “sensitive identity data is handled responsibly” and…. for over a year it’s been leaking all of those sensitive records. And it appears no one internally at the company noticed. As Krebs makes clear, the breach included many, many millions of records and ID scans that were being swiped in real time by the hackers who breached the system: The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies. “We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.” Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this serviceon a semi-regular basis. And the exposed records aren’t just random members of the public. Krebs found the driver’s license of the sitting Secretary of Defense sitting in there for sale: A bargain! Only $100 to get a scan of the Secretary of Defense’s driver’s license. Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. Yet here’s one of the largest identity verification companies in the country, with a pipeline so wide open that hackers had a real-time feed of every government ID it scanned, for over a year, without anyone at the company noticing. Krebs spoke to a security researcher at Cybera, named Larry Baldwin, who talks about how this kind of data can do real damage: Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools). This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities. “Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said. At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this. You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. That’s what happened here. And it’s what will happen with any such systems. Am I the only person left in the entire world who’s old enough to remember the 1990s? Way back, every so oft, some idiot would announce an urgent need for an Internet Driver’s License for the Information Superhighway kind of online identity scheme to stop crime, protect children, etc., etc., blah, blah, blah. If they were a clueless offline politician, the Internet laughed at them. If they were online, the Internet flamed them to a cinder—and then laughed at them. Maybe the Internet had good reasons? Lots of good reasons? Like, I dunno, it’s stupid and inherently doomed to disaster? (/me checks news…) Among other reasons, like maybe freedom? “Age verification” is only an Internet Driver’s License repackaged with ageist propaganda, just like “app-store” locked-down “devices” connected to the “cloud” are only 1990s failed “thin-client” and 1960s failed “utility computing”. 🄯 impurify. Anonymous Cowardsays: Regular readers of Techdirt aren’t surprised by this revelation. You predicted exactly this… Every politician behind KOSA and other age verification schemes/scams needs to have their IDs publicly shown like Heg****’s above. Otherwise it’s just something that happens to someone else. Anonymous Cowardsays: “Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit.” In my state, they’re also used as (one form of) proof of identity to register to vote. This is particularly helpful to people who aren’t sure which district they live in, partly because the boundaries are so gerrymandered, and partly because the boundaries have been occasionally redrawn. The local registration process uses (local) accurate and updated maps to assign people to the right district, and they use a crosscheck to verify it. So this leak — if it’s a leak and not intentional — comes at a critical time, when efforts to shut down the November mid-term elections and suppress the vote are in full gear. Watch for this to be used as a rationale to postpone elections until everyone is forced to get a new driver’s license or something along those lines, because the GOP is increasingly desperate and determined to end representative democracy — or any semblance of it — in the United States. Beyond that: it’s not just this data. It’s how this data can be correlated with other data/metadata that’s out there and used to build alarmingly comprehensive and dangerous databases on people. This doesn’t require AI, only routine data science techniques, sufficient storage, memory, and CPU, and some time. You can download the tools to do this, the tutorials and books on how to use them, and so even if you’re new to the field, you can probably do something productive — and dangerous — without too much trouble. Okay, sure, there’s great harm to the public, but have you considered that there’s a lot of lobbying money to be made by supporting spinning up a new industry out of legislation? Without it, the congresscritters will have to settle for having their second gold plated yacht built without platinum highlights. They’ll be the laughingstock of the club! I think it’s worth keeping in mind that this happened because identity data is a high value target, and not just that the system breached was setup by boneheads (though there’s a solid chance that in the coming days and weeks, we’ll find out that they are in fact boneheads). Look at the amounts that the hackers wanted: $100 per ID probably meant that they were making enough money for the juice to be worth a really difficult squeeze. Keep that in mind during the next push for identification laws, when you see claims that “the next company will do better next time” Anonymous Cowardsays: Re: not just that the system breached was setup by boneheads (though there’s a solid chance that in the coming days and weeks, we’ll find out that they are in fact boneheads) If it wasn’t in Louisiana, I might consider this for a minute. But the entire Fifth Circuit, as a region, exists to cut corners and blame others for it. Anonymous Cowardsays: Re: I’d argue something differently. It happened because it is not profitable to give a shit about security. Any fine or punishment will be much smaller than the cost of doing it well. When someone, Some company, Some TV Evangelist, ANY Person of Company says TRUST. My cellphone company has suggested 2 apps to HELP kill Spam calls. I was upto 50 per day. After 2 months it went down, and at 5 months its at about 20. At 12:25PM, My phone(on do not disturb) had gotten 10 Calls. Anonymous Cowardsays: Re: When someone, Some company, Some TV Evangelist, ANY Person of Company says TRUST. A trusted system is one whose failure will fuck you over. I don’t know what it’s like elsewhere, but up here in Canada, age verification software is sold as having “industry standard” protection of people’s personal information. This is what that industry standard delivers. I’d say to those talking up “industry standard” privacy, “not good enough.” Anonymous Cowardsays: Can we all agree that Clarence Thomas is an idiot for claiming in Free Speech Coalition v. Paxton that ID verification is just an “incidental” burden for accessing speech?? I wonder how the justices behind that ruling would feel about their data being in one of these leaks… Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. We’ve been living with data breaches of various organizations (DMVs, credit companies, the federal government etc) for well over the past decade. I don’t think people are in denial. They’ve just accepted that’s part of modern life. And the examples here prove it, with stuff like Hertz. This isn’t the first breach, it won’t be the last. Stuff like age verification for social media is new, but needing an ID to rent a car (in their ancient systems) has been a thing since forever. And comes with the same risks. Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. The problem is the other direction, I think. As long as things like driver’s licenses exist, you’re going to be at risk. To be honest, personally the fact that my driver’s license (and social security, etc) is already out there from 30 other breaches is certainly a factor in muting my alarm. What’s one more marginal vector? I’ve never even given Equifax anything to begin with. Anyone claiming it’s perfectly safe, is perfectly safe to ignore. There’s no such thing as perfect safety (and even if age verification didn’t exist, it still wouldn’t be perfectly safe, either). It’s all just gradients of more risk or less risk. At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this. The problem is, you’ll have people who think it’s not needless, and that the risk is worth it. It’s not premised entirely on being perfectly safe. And then you’re back to square one of the underlying argument. You are entirely missing the point which is why make it easier for criminals to acquire PII while only providing downsides for people? I’m not missing that point, I’m literally saying the article should make that point more directly instead of trying to contrast it with perfect safety/denial. Anonymous Cowardsays: Re: The problem is, you’ll have people who think it’s not needless, and that the risk is worth it. Those people are sociopaths and need to be thrown out, not caved to. Right, but if we want to throw them out, that means convincing enough voters to throw them out. It’s not enough to not cave, you have to actually beat them. I don’t think voters are voting for these sociopaths because they’re in denial that privacy risks exist or because they’re falling for the perfectly safe PR, given that one of these breaches happens every few months. At this point pretty much literally all of them have personally had their data leaked and privacy violated at some point.
Live Feed of Every ID Verification Company Scanned (ORG) Eric Goldman (PERSON) Brian Krebs (PERSON) US (LOCATION) Canada (LOCATION) the United States (LOCATION) Louisiana (LOCATION) New Orleans (LOCATION) theFederal Bureau of Investigation(FBI (ORG) Krebs (PERSON) Hertz (ORG) FedEx (LOCATION) Target (ORG) the Kids Online Safety Act (ORG)
Originally published by Hacker News Read original →