[0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
FBI Probes Service Selling 153M+ Drivers Licenses - https://news.ycombinator.com/item?id=49529621 - Sept 2026 (290 comments)
But it’s also the kind of story that won’t stay down, and will definitely be back.
It appears as if there are folks here that don’t want to talk about this.
Thank you for gifting me a new layer of paranoia I didn't know existed until yesterday. Once you see you can't unsee.
Your government (which already has all your details) generates certificates and you just give those out. The other side can the use simple public/private key verification to ensure the cert is valid. Also government does not get information who you gave the cert to and if you create a bunch and single use them the other side can’t follow you between uses using the certs.
[0] https://github.com/eu-digital-identity-wallet/av-doc-technic...
The alternative is do it offline.
Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem.
Doesn't even need ZKP, the CA can just issue an attestation.
The three times I've needed to provide a scan of my passport were: to enroll in a university course, to buy from an e-commerce site, and to become an app developer. None of those orgs really needed a scan of my passport, which can't be revoked like a cracked password, and will now sit unencrypted somewhere until the end of time or until they are hacked and subsequently shamed into handling their customers data more like radioactive waste.
Unfortunately, IDs are issued 50 different ways by the less competent states.
Combine that with accusations that getting new IDs constitutes systematic racism (a widely held belief on HN), ignoring that the ruralest of India has been able to do this successfully, and you're not getting digital ID any time soon.
Yep that's the only thing you lose, apart from a huge number of literal images of kids in the hands of literal criminals.
> I don't see any other better alternatives
Not doing age verification!
https://www.fourmilab.ch/documents/digital-imprimatur/#SI_an...
Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)
> My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.
Mr Krebs is dealing with all this mayhem and idiocy with remarkable sang froid if I may say so. Good heavens.
‘Just make the encryption secure and so we can read it’
‘Just check everyone’s id but make it totally secure’
DPVCMRA = delivery point is a commercial mail receiving agent. Any sort of location with PO Boxes.
https://developers.usps.com/addressesv3#tag/Resources/operat...
Disclaimer: I used to work for my state's DMV.
Federal law requires state DMVs to supply that data to the car manufacturers. So if you own a Chevy, they have to send your data to Chevy in case there is a recall.
We should have a law which penalizes businesses for leaking other people's private data
Got John's driver license exposed? Write him $1k cheque. Second time this happened? Make it $3k. And another 1% of his assets, since you put them at risk. $10k in the bank? That's extra $100. Guy has property worth 500k? Too bad for you, that's another 5 thou.
And no blaming sub-contractors either. You hired them to do validation and they leaked data? Too bad, must have verified that they are reliable. This is when all of these Hertzies and Targets and Fedexes start thinking twice before storing confidential data. Why do they need to hold on to your driver's license? I know why. They hope to make some extra cash by datamining it. Well, get your checkbook ready then.
You are selling alcohol and wanna make sure I'm older than 21? You don't need to scan ID. You definitely don't need to store it. You CHOOSE to store it, and if you do, be prepared to pay if you expose it.
I wish it worked like that, but yeah, it never will
I suggest you look at who voted for those bills, who lobbied them and who hired those lobbyists.
That's a sarcastic joke. It's how governments demand private companies react, but ...
> Hackers Had A Live Feed Of Every ID __This__ Verification Company Scanned. For Over A Year.
The "This" in the the sentence serves an important role. It currently reads like all ID verification companies were compromised at the same time.
Isn't that weird that the very OBVIOUS AND SELF-EVIDENT ISSUES with requiring id to use the internet were, in fact, OBVIOUS AND SELF-EVIDENT ISSUES that were immediately taken advantage of?
Just so so weird. Who could have seen this coming?
Hackers Had a Live Feed of Every ID Verification Company Scanned
(Huh? How do you scan a company?)
The original title is easier to parse:
Hackers Had A Live Feed Of Every ID This Verification Company Scanned
Yeah just like how the multiple breaches and utter negligence from the incumbent credit bureaus killed the credit file managed by private companies.
These are hardly military grade networks, as long as the driver licence scans make it to the database and can be used to identify and recover damages from accident or theft it's unlikely anybody has cared much past that functionality.
[0] https://www.politico.com/news/2024/09/17/andrew-kingman-data...
It's getting really tiresome
There are zero knowledge proofs
Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy.
Now little Johnny borrows my ID, and uses it to setup some oracle that provides ID validation for every kid and bot in the country. Woops.
To stop that you must compromise the idealized zero knowledge properties of the scheme, and in doing so you create the potential for harm/risk for everyone.
Sure, it's better than sending an ID card live feed to the dark web, but the risks of ID card theft are at least somewhat easy to understand.
Some of the threats to human rights don't even require the departure from the 'idealized' model-- as even the idealized model requires an ID issuer to issue the of-age person an ID. And so if the ID ZKP is widely required then the issuer can unperson you by simply declining to issue you an ID.
I’ve often thought that replacing the US social security number with a more robust root key makes for a fun thought experiment. Hard to imagine how such a system could securely serve so many people but passports with embedded chips seem to be doing okay.
As for the passport, the key/PIN you need to authenticate to the chip are printed on the page with the photo. Otherwise "hackers" can only determine nationality of passport. The standard is ICAO 9303.
https://www.icao.int/publications/doc-series/doc-9303
SSN was never intended for identification. My original card, issued in the 1970s was clearly marked "not for identification". In the original numbering system, the first 3 digits identified the office/area where the card/number was issued and the next 2 digits identified the filing cabinet. 700s were set aside for railroad workers (until 1963) because the legislators did not want railroad workers to be included in social security.
I can hear the defense now: "Oh, yeah, you blame the honest, good, handsome people trying their best to protect you and you let the hackers off scot-free! We must make sure that hackers don't have access to the tools that aid them to commit these crimes, like books and computers. Anyone could be a hacker."
The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know.
I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"?
I've also seen cases where it's like, maybe we shouldn't share S3 Root Creds or put it on the VPC so we can monitor outgoing traffic but too many applications would need to be redeployed for that so skip it. Those 2 year old tickets were still sitting in the backlog when I left.
If we ever get report, it's extremely likely going to be massive failure and only way to change this is fines for company that are bankrupting.
EDIT: Oh yea, SOC2 needs to go away. It's security theater that's just giving cover to companies.
It's been released and in production since summer. Since then, several social networks have apparently started A/B testing age verification for their EU users, but how many of them actually integrate with the anonymous solution that is now available and in production? To my knowledge: 0. They all use Persona.
This highlights one of my main criticisms of EU's naive approach to regulation of tech companies. They fail to realize that any regulation that they impose will be complied with in the most malicious way possible, which is how we got cookie banners with dark patterns instead of a simple HTTP header saying no thanks to cookies.
Here in the US, we have login.gov, but many government services use the private ID.me instead.
Any time the government says it needs to “cut spending”, it instead sells off critical infrastructure to friends of government who then permanently extract a private tax on the public.
Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which of course impact quality of deliveries (not shaming the people who do the hard job without the relevant means). And while more distributed governmental topologies would have their own caveats, at least it would less likely offer opportunities for single point of failure.
During the totalitarian communist rule in Czechoslovakia, the state would regularly interfere with passports of people considered not loyal enough - withholding them outright or inventing extra paperwork that was necessary for the border police to let you out of the country. They also controlled all supply of foreign currency, both in an out.
Then if someone was actually allowed to travel outside the country but failed to return, their family and relatives would be punished, including demotion at work & prohibition of higher education.
So if your government goes bad, this is what will happen - the form of the ID takes at that point does not make much difference.
What's going on in France?
Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place.
I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue.
Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so. Which means that the only way for it to actually be secure is for the implementation to also required locked down computing devices. Hence why the EU scheme insists on proprietary Apple/Google devices, and why Google research has written nerd sniping blog posts to market it.
There, now you know!
I dunno if I agree but I think that's the thrust of it.
There's a EU initiative https://digital-strategy.ec.europa.eu/en/news/commission-mak.... The direction is generally good, but I'm not very positive about the implementation (as with everything comes from the govs).
Collecting images of people’s ID is outdated and really shouldn’t be done.
But it's still the type of story that should have had a much longer tenure, especially as it was Krebs.
I am now thinking that the access may have been through a backdoor. It certainly seems to have operated like a direct intravenous link.
BTW: Thanks for this link: https://securitywall.co/tools/ipa-analyzer
Looks interesting.
[1] A credit monitoring service that will give the institution that "free 12 months" at a vastly reduced bulk rate because it knows that in order to sign up for free credit monitoring you actually sign up, with a card, for their top tier product (which might otherwise be $50+ a month) on what is effectively a 12 month trial after which they switch you over to a paid subscription (hell, there may even be commissions paid to the institution for anyone who neglects to cancel quickly enough). The incentives are so perverse.
Ended up moving my mail and info from Google away, just not to deal with it.
- get a VISA to be allowed to cross the border
- send to the airline for my flight that will cross the border
- show the real passport at the border
I have another ID for authentication inside my country, which by the way, is not a driving license (which is used only for car driving usage).KYC & AML is poison.
Edit: to be clear, this lawyer also represented me when I bought said property.
Also learned “know your customer” laws require US people to give passport + SSN to a foreign bank who then reports it back to the US. Given that such bank’s website involves disabling right-click for “security”, the only glimmer of hope is that the data is catastrophically lost due to stupidity before it can be compromised.
One such platform used to be called Vigilant Systems. They'd sell details of where a car has passed a police/Flock ALPR camera, mostly to repo companies, but also bail/bounty hunters. Using details of license plate scans are more up-to-date than the DMV registration. People on the run from courts are extremely unlikely to keep their vehicle registration or driving licenses up to date.
https://www.youtube.com/watch?v=AKxkokoQdkc&t=238
The governing law is Driver's Privacy Protection Act.
https://en.wikipedia.org/wiki/Driver%27s_Privacy_Protection_...
https://www.nytimes.com/2026/05/05/us/pope-leo-xiv-bank-cust...
As do physical IDs, as somebody who's bought his younger brother beers growing up.
Proxying the credential means something like letting your brother use your ID. But note there are still avenues of accountability here - for your brother if he would have gotten caught, and possibly for you for loaning him your ID.
These dynamics don't translate to Internet scale, where all it takes is literally one person to go "I disagree with this age check scheme on principle, and I will proxy my credential to anyone who asks".
At any rate, you had started off saying you didn't understand why there was criticism and now you know why, regardless of whether you accept that criticism.
The principle reason why the Netherlands joined the EU was to sabotage the French-German alliance- all the alarm bells went off in the 1950s.
Case in point; I can't tell if you're being sarcastic or not! :D
Think about it, how many kids will get a gun just because some of the kids have access to guns through their negligent parents? If it's banned the path to getting it won't be straightforward.
Sure, your parents can give you access, but your parents could also give you booze, porn and guns if they feel so inclined.
Cultural pushback has so far prevented such a system from being created. I hope that continues but am not optimistic.
In functioning ID systems (and not having or wanting one is a valid political position which both the US and the UK took) this is not an issue.
I live in Poland, and we force rotating IDs on a (staggered) 10-year schedule, just so we can slowly upgrade them and introduce new features like these.
Also on the rotating schedule thing, driver's licenses expire in the US, usually on a 5-10 year cadence. Replacing the physical cards was not even remotely close to the issue we had with getting REAL ID implemented, the cards themselves aren't special they just have an extra indicator on them. It was about putting in requirements around new documentation and proof of identity, citizenship, and residence and most states not being ready to handle that
For example my home state of Alabama issues licenses through the state department of public safety. That's who does the initial test to see if you're fit to drive, etc. But, once you have it you can then renew your license at a city or county office. These offices take a HUGE burden off the state, but they're not qualified to do the verification needed under federal law for REAL ID. So, to get a compliant ID you'd need to go to one of the very few state offices and they were overwhelmed
This is the type of issue with the system in the US, not the physical card, not the big scary illegal immigrant problem
It was explained right there in the comment. Illegal immigrants are often able to get services because the ID system is such a patchwork that they can manage to slip through the cracks.
And attempting to implement any sort of widespread centralized ID is going to be met with resistance not just from people such as myself but also from those who attempt to shield illegal aliens on the basis of opposing those who want to reduce immigration.
Standard Arizona drivers licenses only expire when the licensee turns 65 years of age, and must be renewed every 5 years thereafter.
i see your other comment about guns, so just to preempt that a little bit: the internet is far more ubiquitously available than guns are.
Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky, but it doesn't mean that it shouldn't be banned.
Theres no avoiding this, structurally. So the best thing you can do is not to introduce any additional points of failure.
I am so much more afraid of monopolies invading my privacy than roving hackers, or my corner store. Governments are the ultimate monopoly.
And clearly, the alternative is not the corner store. It's private monopolies building databases of 153M IDs.
With ZKP, you specifically don't have to do that. That's precisely what the Zero Knowledge in Zero Knowledge Proof means. Those are good for stuff like age checks.
But for the other stuff, of course you need to tell the government who you are??? How else are you gonna pay your taxes? Just send them some money anonymously and hope that settles it? Of course they need to know who's paying their taxes?
So the whole "eID/CAs/ZKP/PKI" mumbo jumbo can be easily fooled by a gif file.
My national ID card supposedly has some of it, the 17-year olds who want to pass as 18-year olds usually show a doctored gif file of their ID card, with a year of birth one or two years before the actual one; this works in ~98% of the cases.
If you’re genuinely interested, look into things like OpenID credentials systems, and similar standards like w3c verifiable credentials.
If you think cryptography can solve your problem, you don’t understand your problem and you don’t understand cryptography.
(Bruce Schneier dug into origins of this here: https://www.schneier.com/blog/archives/2026/05/laurie-anders...)Sorry. Wrong.
https://www.google.com/search?client=firefox-b-d&q=MEPS+assh...
But more serious and non joking answer, the new thing from the "department of war" is testosterone level lab exams for existing servicemembers.
https://news.google.com/search?q=US%20military%20testosteron...
The bunghole inspection was to see if you were the receptive partner in anal intercourse because being a gay man was a criminal offense.
Allegedly, lesbianism was never outlawed because Queen Victoria was so offended by the idea of it that she prohibited the legislation from even being heard in Parliament.
I mean if a poo can get out, something of its size can also go in, and quality toilet paper was not that available at all historically.
It's definitely worth doing infinite security in order to avoid regulating social network algorithms, because
The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway.
Your system effectively collects exactly the data ZKP is intended to protect.
Which is a long way of saying "ZKP" isn't an answer to this problem because you can't actually have zero knowledge in a system where people have little incentive to keep their key a secret.
That's also assuming you can get all the documents you need for the initial ID. If you don't already have all the essential documents you'll need multiple appointments at government facilities. The local social security office usually has just one location. Mine required time off from work because they were open from 10 till 4 four days a week. This was just part of the process to get an ID for a child when we only had a copy of a couple documents instead of the originals.
Getting an ID for my grandma who made the mistake of being born black in the rural South during Jim Crow was a year long process, since she didn't even have originals of most of the documents. It took that long and was handled by one of her children that was a lawyer. For her we were getting an ID so the family could take her traveling, years before it was turned into a political issue to disenfranchise people.
Nobody arguing for the ID laws ever argues for raising their taxes for an ID that all citizens are guaranteed with the supporting infrastructure. They're arguing for it because they know people they don't want to vote will have trouble getting one
"The right of citizens of the United States to vote in any primary or other election for President or Vice President, for electors for President or Vice President, or for Senator or Representative in Congress, shall not be denied or abridged by the United States or any State by reason of failure to lay pill tax or other tax" - 24th amendment to the United States Constitution
Every time national ID gets moderately serious discussion it is revealed very clearly that yes, the people are against it.
RealID—which was simply national standardization of state issued ID (when used for a variety of important purposes) had intense resistance, too—and its the closest policy to national ID that has passed.
Social Security identifiers are not ID for the person, and anyway were adopted nearly a century ago at a moment of higher-than-current trust in the federal government.
I know people who don't have a social security number because their parents didn't want them to be tracked by the system.
The minimum size of this population, people who are adamant that the world is 10k years old, that god created everything as it currently is within those past 10k years, and therefore that all of science is a conspiracy in league with satan to deceive you from god, is about 30 million people. That's the percentage of Americans that willingly state such a belief when an alternative survey option is "Earth is old but god is still real and meaningful and doing everything" ie the current Catholic Dogma.
That exact same cohort is the singular reason for the Satanic Panic back in the 80s, for every child that "wasn't allowed" to participate in Halloween, for kids that weren't allowed to read Harry Potter because it "promoted witchcraft". These people insist we are in a constant and active war against actual physical demons that have infiltrated much of society. They believe they are losing this "war". They believe they are following God's orders. They believe anything is permissible in this war
Systemic racism is very much a thing, and while perhaps not foundational in this particular issue, we see still see political fuckery that definitely targets by race: https://www.nbcnews.com/politics/2026-election/tarrant-count...
For multiple reasons.
The fact that the things that require me to identify myself for functional reasons already do is exactly why it's ridiculous to propose that I do it in order to use the internet at all.
Something having downsides but being worthwhile for certain purposes doesn't mean that it's reasonable to require it in all circumstances. Pumping your body with radiation is not something you want to do in most circumstances, but it's worthwhile sometimes as a way to try to kill cancer cells before they kill you. Transmitting information that can be used to impersonate you is useful if you want to pay taxes, but that's no reason to think that it would be better to do literally every time you open a browser.
If Apple (or another large international company) suffers from decreasing margins, gets a new CEO and decides to turn the data it sits on into money there is absolutely nothing you can do, and you might in fact still stay a "forced" customer because of network effects (=> just consider whatsapp being an important communication channel in many places worldwide).
I think this attitude in general is often harmful; if your government sucks, fix the government instead of making yourself dependent on some quasi-monopolist private company.
Indirectly only. This is typically also always too late; instead of doing "the right thing" in the first place, companies are disincentivized by regulation from doing "bad things" again.
Regulations are like scar tissue, they don't help against getting burnt in the first place.
Preemptive regulation typically sucks, and is admittedly extremely difficult to get right; most governments don't even bother trying.
Corporation know this and exploit it ruthlessly-- there are almost never consequences as long as they keep to the letter of the law, even when acting with intent, against better knowledge and causing astronomical damage to society (just consider the whole leaded gas disaster for an extremely clear example).
If anyone has to have this type of control, better it be a local national government that you can in at least some small way influence.
For those unfamiliar, you are, of course, allowed to peacefully protest in support of Palestine in the UK.
Palestine Action is a specific group that was controversially labelled as a terrorist group after they broke onto a runway and spray painted military planes.
im mostly on board with that.
>Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky
alcohol bans are way easier to enforce.
the internet is invisibly broadcast everywhere. most of my downtown & surrounding area has free wifi access. devices that can connect to the internet are also everywhere. phones, tablets, tvs, fridges, etc.
on the other hand, alcohol comes from licensed stores and requires a physical transaction to take place.
There are all kinds of restrictions on alcohol now. They haven't been there since the invention of alcohol, though.
No third part would know how often you use your ID.
Why do people make up problems that are already solved?
OTP and biometrics aren’t new security features and people don’t assume the government gets informed every time they use it.
But also, this on-device fingerprint MFA would presumably be fairly bypassable. E.g. just glitch the device to extract the private key. ... and of course all the power hungry / extra complex ZKP machinery means less resources spent on preventing glitch attacks.
https://www.google.com/search?num=10&client=firefox-b-d&hs=Y...
We are all supposed to be pro-perversion now too?
When the guy was trying to get a passport, he asked if anyone could show a picture of him from our high school yearbook.
So what happens if you just don't show up?
I don’t see how we could develop a national ID in an environment of such low trust (bidirectionally). You need a government that’s responsive to citizens and obeys constitutional guardrails, and citizens who trust the government to protect their best interests. We haven’t had that since the prior century (and last century the government was still breaking our trust, it just didn’t make the news).
People are against requiring certain types of IDs to vote as racism or other forms of voter suppression because it may cost money to get those IDs or be very very hard to do so, when there are other methods to authenticate a person for voting
Those are two separate issues and complaints.
When I lived near the ghetto in a different state I had roughly 2 choices, one 30 minutes out and the other over an hour (by car without traffic). Bus? Hah! Have fun. Arriving at the nearer of the two within an hour or so of opening in the morning there was already a multi-hour line for service.
Don't worry though, there's definitely not any sort of institutional racism behind the various efforts to require certain forms of ID to vote. /s
give people a moderate benefit to do it, like a tax credit, and I think you'll find the majority of people hold their beliefs not so rigidly
Most operating systems and browsers come with a sync mechanism that many people default to, but it's no more than that: the default.
As for account recovery, most websites have a way to recover your account when you lose your password, there's no reason why that wouldn't work for passkeys. Every website with passkey access I've used so far makes passkeys optional and forces you to set a password already. If they switch their default to passkeys and add a password as an optional step, nothing would change.
Assuming the FIDO Consortium approves. Otherwise you might be like KeePass, being unceremoniously threatened with revocation of attestation, for offering to do what the big players are able to do.
When I'm on non-Apple I can scan a QR code on my phone and it will validate it the same way, using bluetooth to send enough info to the target computer to get me logged on.
It is not true. You can move passkeys between OSs if you have a password manager or an OS that has this ability. For example, I store my Passkeys in iCloud Keychain and I have them synced on all my Apple devices.
There are cases though, where the website can force the requirement of a device bound passkey, but that is something it is not very likely you will encounter.
And I suspect that most geeks, hereabouts, could set up their own signing system.
It's not all sunshine and roses, though. Despite having Bitwarden set as the only passkey provider in my Android setup, the phone persistently only offers me Google. Which is empty, because as I said, I won't use one tied to things I can't control. Works great on desktops, though.
Passkeys can theoretically require you to be on hardware, I haven't found anything yet that requires that.
They work fairly well. I use a login ID/PW to set up the passkey, then the passkey, for everything else.
Passkeys work well, but I feel as if they are still a bit too “fiddly” for your average mensch.
I’m pretty sure the private key is transferable, but Apple keeps them in the Keychain, so they seem locked into the OS. On my machine, I can also keep passkeys in 1Password.
A while back, I wrote up a series on implementing passkeys in iOS/MacOS: https://littlegreenviper.com/series/passkeys/