Hackers had a live feed of every ID verification company scanned for over a year

beardyw 539 points 235 comments September 04, 2026
www.techdirt.com · View on Hacker News

Discussion Highlights (20 comments)

piva00

Brian Krebs' article is, in my opinion, a much better read for this story[0]. [0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

pelagicAustral

I wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!

saghm

This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet

lrvick

If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.

jwilk

The HN submission title is a garden-path sentence: Hackers Had a Live Feed of Every ID Verification Company Scanned (Huh? How do you scan a company?) The original title is easier to parse: Hackers Had A Live Feed Of Every ID This Verification Company Scanned

padjo

Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

spwa4

No worries! Governments who used this company are taking responsibility and now have a plan to, at the very least, replace all IDs they forced people to expose and to make sure the old ones are unusable! That's a sarcastic joke. It's how governments demand private companies react, but ...

xvilka

The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proofs for particular properties (e.g. if the person has a driver license or not) without de-anonymizing the account. In the rare even of root key leak you should be able to physically go to the authority and make a new one, while revoking the old key. I don't see any other better alternatives than this.

croes

> There is no safe age verification. There is no age verification that doesn’t put people at risk. There are zero knowledge proofs

addag

Crazy hack considering the order of magnitude...

kleiba2

And again, there will be no monetary consequences for the companies that failed to secure our private data.

jonplackett

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’

khalic

"Nobody could have predicted this" It's getting really tiresome

bnj

I’ve been following the development of the drivers license sharing system from Apple where different fields can be selected; are there any implementations of PKI based identification systems where multiple certificates can be generated and revoked when compromised? I’ve often thought that replacing the US social security number with a more robust root key makes for a fun thought experiment. Hard to imagine how such a system could securely serve so many people but passports with embedded chips seem to be doing okay.

mawadev

How exactly does that work? How can you sneak a live feed past detection systems? It is incomprehensible to me, considering this is highly regulated and sensitive data. It is just open ports sending what they shouldn't be sending all the way out or what?

ornornor

> This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. Yeah just like how the multiple breaches and utter negligence from the incumbent credit bureaus killed the credit file managed by private companies.

zero_k

If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli... Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)

mistrial9

I cannot get over the volume of techies calling for more centralized systems, in response to an obvious corruption of a mass scale of a crucial centralized system

hobofan

The HN title is misleading. > Hackers Had A Live Feed Of Every ID __This__ Verification Company Scanned. For Over A Year. The "This" in the the sentence serves an important role. It currently reads like all ID verification companies were compromised at the same time.

Yhippa

“Prove you are Alice by sending us enough information to impersonate Alice.”

Semantic search powered by Rivestack pgvector
5,564 stories · 50,257 chunks indexed