America's Driver's License Breach Is a National Security Disaster
hn_acker
286 points
170 comments
September 15, 2026
Related Discussions
Found 5 related stories in 73.2ms across 6,718 title embeddings via pgvector HNSW
- FBI Probes Service Selling 153M+ Drivers Licenses tatersolid · 123 pts · September 01, 2026 · 57% similar
- DHS demands AAMVA's national commercial driver database iamnothere · 13 pts · August 15, 2026 · 55% similar
- I rented a car, and within hours my driver's license was for sale chha · 30 pts · September 02, 2026 · 53% similar
- America's Military Is Dangerously Exposed petethomas · 16 pts · August 10, 2026 · 52% similar
- DHS Program Analyzes Americans' Finances to Flag Drivers for Traffic Stops randycupertino · 32 pts · September 09, 2026 · 50% similar
Discussion Highlights (20 comments)
exabrial
I really want these people handling my healthcare and other details about my life.
curuinor
Near the beginning of my career, I talked to a greybeard who harrumphed at me discussing something-or-other and said "computer security is an oxymoron". I thought he was being too pessimistic, nowadays I realize he was right.
maxrev17
Slackers are always behind this shit
anxman
Glad to see someone talking about this
sandeepkd
Its unfortunate that the security requirements are expected from the for-profit businesses when the cost of paying penalties for breach of security is way lower than actually implementing the security. Ironically in case of breach they just sell you another of their product where you put your personal information again
er4hn
Will anything be different _this time around_? https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.
shireboy
When this first landed I asked what the fix could even be. Everyone needs a new ID at a minimum. But then I got to thinking: 1) is that the point? Conspiratorial thinking I know but “hey all Our ids got hacked I guess we need a national id”. And related 2) the current id system from a security standpoint was a band aid fix for outdated world to be shoehorned into a modern one. IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN” but bottom line, at least in US there is no cryptographically secure identity system that proves you are the citizen you say. And that fact bleeds into all sorts of patchwork solutions, fraud, etc. Moreover there are serious philosophical hurdles to getting to one. I’m not even positive I want one. But unless there is some zero-trust way to do this, I’m not sure what the fix would be.
jsrozner
There's a solution: personal liability for the executives and managers at the company, and for the investors. For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth... )
charcircuit
Hundreds of millions of American's names, addresses, social security numbers, etc were in the NPD leak which has been publicly downloadable. The idea that any of this information should be considered private, only knowable by the person themself is wrong.
nullc
The breach is bad no doubt-- but this information was already readily available to bad actors e.g. via Lexis Nexis. Practically all states sell DL and registration information to information brokers, and the remaining ones require you to obtain auto insurance, and the insurers all sell the information. Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo. (Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.) In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.
0xmattf
Is there any way to check if your ID was compromised without going on some onion site? I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious. I think IDScan should set something up so we can check if our data was compromised, at the least.
robinsoncrusue
American national security apparatus do not care about the actual Americans. They are too worried about foreign entanglements, and protecting a specific foreign country than their own country.
O3marchnative
I'm reminded of the OPM breach back in 2015 [0]. Practically everyone that even applied for a security clearance was compromised. In addition, millions of sets of fingerprints were recovered by the entity that carried out the hack. [0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
deepsquirrelnet
Wow, how could this have happened right before the election? Surely this will not be used as a pretext for anything.
klaff
Does anyone know what "disabling advertising identifiers" actually means?
JumpCrisscross
Is there anything comparable going on to the data of Chinese citizens? Or Chinese public servants?
joshfraser
KYC = kill your customer It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger. AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out. These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked. The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.
ChrisMarshallNY
I'm glad to see this keep popping up. It gets pushed down, very quickly, when it does. I suspect the reason for that (nothing other than a "gut feeling" that I get, seeing the story pushed off the front page so quickly, every time), is that the breach was through a backdoor that was deliberately coded into the system, for TLA use, and what happened, is exactly what people keep warning about; it got breached, and is now a "front door," and The Powers That Be don't want that examined too closely.
classified
There were times when the words “national security” made rules and laws magically evaporate. Now that total surveillance is already here, companies and agencies can have it for close to free, and nobody gives a rat's ass for rules and laws anyway, national security is no longer needed.
ProllyInfamous
ProTip: US Passport Cards are official identification documents which don't have your home address listed on them . Also: many US states allow you to use a PO Box on your license (e.g: Calif., Tenn., Texas)