Nearly 28M licensed Texas drivers hit by data breach
fox26houston.com
fox26houston.com
I appreciate that the Texas DMV wasn't the direct cause of this breach, but they can't completely pass the buck to Vertafore. At the very least, I would think they need to issue 28 million new licenses with new license numbers and invalidate the old ones. And, since this is likely to be an expensive and time consuming process, they should probably sue Vertafore to make them pay for it.
And while they're at it, they should probably make sure that Vertafore is never allowed to access this data again.
Realistically, none of this will happen, the compromised DL #s will remain valid in perpetuity (I just had someone tell me they moved out of Texas for 5 years and were issued the same DL # when they moved back), and Vertafore won't even be fined.
This isn't some far-fetched premise, either. "Third Party Risk Management" is a basic part of pretty much every cyber security framework I can think of. It is even part of the NIST CSF, which every government entity in the US is supposed to be following.
Vertafore's failure is the DMV's failure, and heads should roll at the DMV.
DMV can't afford the kind of external auditing that would've caught this. Not with their current budget. Setting aside taxes etc, what do you propose a public service organization should do in these situations other than trust a company to do what they're saying?
edit: removed a statement distracting from the two questions.
It wasn't intended politically, but rather to say the tax situation is a known quantity already which is why the second question asked to set that aside before answering.
Usually, the prevailing wisdom of HN will respond to such a statement with "if you can't afford to do it properly, you shouldn't be doing it at all".
So you have to consider if you really care about the privacy that auditing would bring. If you do, then increase the budget.
Maybe the real service provided by the credit data sharing is how data is used almost everywhere in reality: marketing?
If each lender does their own due diligence and risk ranking, any lender that has an above average failure rate will take a lot of flack from their investors and regulators.
If they say "We use the same scoring formulas and credit files as everyone else", they can push the blame back to the bureaus.
Around that same time the credit card companies were also getting a lot of flack for issuing cards to newborns, pets, and the deceased. That also took an act of congress to stop.
The US credit agencies themselves are only a few decades old, people have been borrowing and lending for a bit longer then that - you can read about it in the Old Testament.
So long as just knowing some of these details has value like getting fraudulent credit cards the problem will exist, and criminals will find ways of accessing the data.
Now granted, stuff like the home address is always going to be valuable, but less so if its not as useful for identity theft.
That’s not necessarily a good example of doing it well. Unless something changed since I last looked, after the Estonian certs were all found vulnerable, allowing impersonation and forged signatures on official government documents, the government refused to reissue new certs to citizens.
In other words, they were effectively in the same place as Texas.
Sending 3rd parties perfect copies of private data of your citizens to run a credit scheme is a different place.
Eventual fines will also be shared by them, and the ratio will depend on how diligent the controller was in selecting and auditing their data processor(s). Exactly because it's too easy to outsource your exposure risk along with your customers' data.
California too, one keeps the same number for whole life, all between ID, License, Commercial & anything in between. The only way to change it by religious objection to the number like 666 or 999 or such; or if somehow DMV issued same number to two persons; which has happened in past long ago.
Texas is by far the worst state I've lived in for getting your drivers license and vehicle registrations.
As in, all 28 million drivers?
28 million people dealing with this level of inconvenience is astounding, and a clear-cut example of why the penalties for data leaks need to... well, at least start existing, by one means or another. Also worth noting I don't see SSNs, CC info, or any passwords included, so this just seems to be a standard thing people say regardless.
All it takes is one junior employee to make a mistake one day copying a file.
It’s our mission to provide exceptional service and powerful insurance technology so you can focus on what matters to you – people.
Every single SS# needs to be made public, along with the assigned name. Not just known-breached, but somewhere where it's obvious that anyone could look it up as easily as looking up a phone number or mailing address. Somewhere so public that everyone else knows that they're no longer "secret."
Using Social Security numbers as some sort of proof you're who you say you are is batshit crazy these days. But we all pretend that it's still secure somehow. If there was an embarrassingly public list of all SS#s, then banks would be forced to improve their vetting of applicants.
At the same time, the onus needs to be on a financial institution to prove that I opened an account. If I discover a line of credit in my name, all I should need to do is disavow it, and make the lender prove that I was the one who authorized it.
Yes, this will increase the cost of doing business. But that increased cost is already here, just born randomly and disproportionately by the victims of "identity theft."
Want to issue a credit card with a $15,000 limit? Have the applicant walk into a branch, provide a thumbprint take their picture. Or get them on a video call standing in front of their house, attesting that they're the person they say they are. Or if you think that's too inconvenient you can take on all the risk if the borrow later disavows the debt.
A piece of paper or online form with the magic numbers is just not enough.
I admit that I think that was 100% unnecessary, expecially in this situation, to put the kibosh on the conversation. But it made me realize how insane it is that something that is a common "get to know you" type question (tell me about where you grew up? (street, school etc) Tell me about your parents? (maiden name)) are also a common "security" questions.
Also, side note. I NEVER use real answers to those questions. I treat it as an extra password and store it securely that way. No way I'm going to turn my mother's maiden name (easily searchable if you know my full name) into a password!
They are already required by law to assume the risk for fraudulent charges. It's just a mess and hassle for consumers.
It's like leaving packages on doorsteps without signatures. Apparently they just make more money eating the occasional fraud losses than the price of doing something safer.
We have to call you to find out if you leaked our information? That's some idiotic logic right there. I didn't call you to put my information in your systems, I shouldn't have to call you to find out if you lost it.
> "The department only allows outside use of information for reasons found in Transportation Code Chapter 730 and the Federal Drivers Privacy Protection Act. These laws permit, and at times require, the release of motor vehicle records to authorized parties."
Texas should pass a law requiring any companies who become 'authorized parties' to proactively respond in case of a breach by sending registered letters to everyone affected, telling them how to sign up for the credit monitoring they're entitled to.
DMVs sell just about everything, using fairly standardized contract models that the association of DMVs coordinates,
In some states, it’s illegal for DMV to give other agencies, say a tax department, most information, so the other entity buys the data from a broker. Similar to the contracts with companies like LexisNexis and Thompson where the government needs to pay for a subscription to access its own laws.
They also didn't release anything that wasn't already available by a variety of other means. This is all non-sensitive public data.
So many comments in this thread are an ad hoc emotional (crying) response to the phrase leaked data without any thought as to actual harms.
>Driver's license numbers, names, birthdates, addresses, and vehicle registration information were stolen for nearly 28 million Texas drivers who received a license before February of 2019.
"There's a lot an identity thief can do with this information. They can try to create a new account and they can try to prove they are you when they're logging in to an existing account," said James Lee with the Identity Theft Resource Center.<
No idea about you, but I don't make any of that info public.
Did you say the same for the equifax breach?
You thinking the information being public, complete and in a searchable format is nothing big doesn't lessen the very real impacton literally millions of people.
It has everything to do with it because you are imagining a harm that doesn’t exist. Then you complaining about it with your head in the sand. I say this as somebody who lives in Texas, a supposed victim.
> The company says they reported it to the Texas Office of the Attorney General, the Texas Department of Motor Vehicles, and the Texas Department of Public Safety and wrote, "Vertafore’s notice was delayed at law enforcement’s request."
Hard not to see this as purposefully delayed until after the election.
Whether the assignment on existing representation is logical is a fair question. But this would be far from the most irrational sentiment from voting people these days.
I’ll stake out this was purposefully repressed for political reasons. On surface it suggests weakness in oversight by the state. And lack of privacy protection oversight posture by prevailing party doesn’t help either.
Why would I want to change passwords? Either he doesn't know what he's talking about, or breach is worse than reported, e.g. DMV website passwords were stolen and they were stored without salting/hashing.
So if you signup, an example identity question might be what are the color of your eyes, or weight, or your zip code, and so on.
They deliver these files on a ftp server with a zip file.
On top of that you have to create identity questions out of the cars the person owns but it is not a downloadable file you have to scrape the contents of an online site you buy access to which gives you access to every car the person owns.
Lastly, to complete clearing their ticket in Texas they have to have a certified copy of the driving record from the DMV. I would login as them using a script, purchase, then mark-up from $15 to $25, a pdf.
Wait a minute. Isn't this all public data? In fact you have been able to pay to access all of that data through a company called Public Data since the 90s. So what exactly is the new risk here? https://login.publicdata.com/
It's also a bit absurd that the victim count is 28M. The total population of Texas is 28M, which includes small children who aren't drivers.
Category is unsecured storage service, you have available to you one consonant and a digit. Your 30 seconds start now.
If a bank or whoever gets defrauded by someone claiming they are someone else, that should be the bank’s problem. Everyone has a smartphone today with a video camera and data. Why is a video of you giving a thumbs up and announcing your authorization for entity X to borrrow or purchase with Y dollars not the standard?
It's a running joke whenever I have to wire money: "Make sure Madge is working today!"
I liked that quaint feel, but I suppose Steally McThief would also appreciate it...
Video is not 100% safe, it can be faked.
No they don't.
It could get complicated, like mandatory checking of centralized revocation lists, which the creditor would also need proof of, etc. But it could be worked out by smart people, and even run by the government gasp. If a hacker gets the information, wow, they've got your public keys, and then upon discovering the breach, all the certs get revoked.
But we'll keep using dumb magic numbers forever.
Yup, now nobody is going to use the thing. People use social security numbers because they’re convenient, not because they’re good.
It's not a big deal, and the proposal you're dismissing has an identical user experience.
With 99% of pockets containing an NFC chipped phone these days, it could be even easier than that.
I don't think we're close to being able to pull it off at anything approaching scale. It's not just a technical problem, hard as that is by itself, it's also a political problem, and a public trust problem. Right now, half the country would reject it based simply on which party is in power. "It could get complicated" indeed. I think we are a decade at least, maybe a generation away.
Zilch.
You can't have a globally connected society, data storage in the billions of records, and a 'right to privacy' at the same time. It's not possible, these breaches just reaffirm that.
How long before the next data leak pops up on HN again?
Privacy died after 2001, and there's nothing to prove otherwise.
Am I wrong?
And since people will probably do the unethical thing again, and the system which enabled people to do the unethical thing isn't perfect, we don't even really need to worry about whether using that to our benefit is unethical.
In fact, it's been years since we really needed to worry about that sort of thing anyway.
Isn't it just easier to ignore our personal responsibility to try to do the right thing in this situation?"
In this case, you cannot choose to opt out, not if you wish to drive. Further, this isn't just ID, but a whole range of info around that ID.
As example, by law in my jurisdiction, I am legally obliged to keep medical info, address, and other info up to date for my license.
I believe breaches of government ID must be held to a far higher standard than a lost credit card. IMO equifax goes into that slot, for it falls into the "cannot escape" category.
As an example, I have never used airbnb, due to their mandatory ID requirements, regardless of their claims uploaded ID is deleted after vetting. After all, Equifax's compromise went on for almost a year, and in such a case each upload, waiting to be vetted, could be copied before deletion.
So I use alternative services, like VRBO, or Craigslist even. I have choice, options, and am not compelled by law to use any of these services.
As soon as I am compelled, by the threat of violence (arrest, etc) to do a thing, you'd better perform the utmost in due diligence.
And maybe, not give entire databases to others, for profit?
They aren’t breaking any laws unfortunately.
What is meant by this? Is the distinction between "word" and "phrase?" As in "don't have 'horse' have 'correct-horse-battery-staple'" because that's a "phrase?"
Delicious dark chocolate
Are you going 2 the cinema?
H3r3’s l00k1ng at y0u, k1d!
2019 estimated Texas population 28,995,881.
Remove non-adult driving population.
U.S. Census data from 2010 indicate that .. 27.3% is under 18.
Roughly say 75% of the population has a license. An overestimate, I'd say. So roughly 21.5 million.
So this sounds to me like it would be a breach of all digitized Texas license records for all time, living and deceased.
Tip to anyone reading this: Use HN/search and find other examples of data breaches to know exactly how these comments will play out, we can even use an AI to simulate this exact situation!
"We're weally sowwy about this, have free credit reporting on us! (P.S we don't care, nothing bad will actually happen to us so sucks to be you! bye!)"
(source: Experian/Equifax leaks or any data leak ever)
Meanwhile nothing ever changes, nobody is imprisoned or even mildly inconvenienced whilst those affected have to deal with the fallout...
To be honest, it'd be better to stop calling them "breaches" and just call it "already public data was made public, again".
This data is not, was not, and can not be considered 'private' at this point. Your data is always leaking; consider your name/address/SSN/DOB and anything else part of the immutable public record.
You could call it...
A permanent record.