Hacker downloads close to 300k personal ID photos from Estonian gov database
news.err.ee
news.err.ee
We need to replace IDs with chips that do not give away their secret key but only sign stuff you throw at them.
So when a website or hotel wants to know "Hey, are you really Joe Doe?" it sends this message to the "ID" and the "ID" sends it back with "yes" and signed.
This way we can identify ourselfes without giving the other party the ability to identify as us from now on.
Unfortunately most places still check these type of cards visually, but I hope that electronic verification will become more common in a few years.
For example these cards can be checked very easily simply using an NFC Android phone and the right app.
In US for something similar you can look at ICAO passports and Enhanced driver's license,
It's infuriating. Governments still use a 100 year old system of stamping each others documents in overseas missions to confirm the authenticity of a document that is based in an era where there was neither telephone nor internet. The whole world runs on a bad joke.
The thing that's different about the three baltics is that their crypto is open source and has had many iterations. They even sued Gemalto for an insecure revision IIRC. All of the signing code is open source on top of that.
The way Germany works is that they design something in a committee for 20 years in private, then they push it out to public. Then the CCC finds security issues in there, then the government ignores it and changes the law to force you to use it anyway. One thing I will give the Germans is that in legal interaction with their official institutions they will allow you to blacken out PII from the identity card. But no private institution does that so it's kinda pointless.
But you can put it another way: if someone commit am identity fraud using a picture of your ID, you can defend yourself showing that you were required by many different entities to send a copy of your ID. So there are many parties that could have leaked your ID and a picture of you ID cannot be considered a prove that you authorized or allowed anything.
Case dismissed :)
If creditors want to get a judgement to garnish wages or seize assets they have to go to court. I wonder if the burden of proof is any different there, or if the parent's defence (everybody has a copy of my identification!) could work at that point?
Garnished wages are pretty rare from what I've heard, and yes it rarely gets to that point. It's still a nightmare for many people with real world consequences if it happens to you.
Over the years I've been trying to minimize my dependence on credit reports. It's been frozen for most of a couple decades, and I'd like to keep it that way. I've paid cash for vehicles, use secured credit cards, put down a deposit for my utility service, have a pay as you go phone, rent from people I know, and hope to remain self-employed, or work for people who know me enough to know that I can be trusted. I'd rather not deal with BigCorp. I realize that not everyone wants to or can do these things.
But that left me wondering about what would happen in a trial to get a judgement if someone was able to fraudulently open a line of credit in my name. I'm hoping that a judge would require more than a forged signature to seize my wages/assets. Personally this is what I worry about, not so much my credit report.
You need to file a police report and send a copy to the credit reporting companies with enough specifics to indicate which entries are not yours.
New fancy integration, digital signatures, etc are still protecting a process that’s unreliable fundamentally. It’s all anchored to your birth certificate, and in the US that’s controlled by thousands of jurisdictions with varying competence.
The most secure scenarios (cleared employees), tie your credentials to biometrics, and vet your origin as a control for fraud. Everything else increases the risk of fraud as a trade off for convenience or privacy. (Your cellphone carrier doesn’t need to vet where you went to elementary school)
The differentiator is that when an incompetent jurisdiction gives away your ID, it's your loss, not theirs. When hackers spoof a business with your credentials to perform industrial espionage or plant ransomware, it's the business that loses, not you. An incompetent jurisdiction can continue operation indefinitely, they just have unhappy, powerless citizens. An incompetent business will suffer financial losses and fail.
The village clerk in some Indian reservation in South Dakota probably doesn’t have a process that looks like the NYC department of Health for vital records. But people live for a long time, and errors and omissions do too.
The point is, you can establish identity, but it’s a pain in the ass. I need to provide a drivers license to open a savings account, but anyone with my SSN can open a credit card.
Other organisations (especially banks) will collect far more information than is legally required for KYC because they can use it for marketing.
But why does a 50 cent SIM card need a security deposit?
https://www.ccc.de/de/updates/2010/sicherheitsprobleme-bei-s...
It's sad that this myth that "eID is insecure" has stuck around, because it's just not true. Their problems have all been with auxiliary devices or software, not the eID itself.
However the cards were simply rolled out: essentially the only practical difference for anyone between the old cards and the new was that there was a chip in it. But there was no surrounding infrastructure: government didn't take it, banks didn't take it -- there was no practical benefit. There were no mandates for use, no examples or or incentives. The country made greater provision for spelling reform than they did for the E-ID. There was a lot of unease about the idea of all that tracking...yet the card itself already leaks lots of unnecessary personal info (e.g. address) to anyone who glances at it.
Compare this to countries like Estonia who made a point of using the card as the easiest way to unlock government services and made it easy for companies to do the same.
This is touched on in English in this recent article: https://www.theguardian.com/world/2021/may/22/new-id-law-aim...
I'm not sure what you mean be "Enhanced driver's license", but my RealId driver's license doesn't seem to have a chip in it, just an excess of holographic overlays.
https://blog.americansafetycouncil.com/enhanced-drivers-lice...
Real IDs are only for Domestic Travel, from May 2023. Is available to anybody with a legal status.
If we use safely stored finger print hash in ID cards/Passports/Phones (Iris is better but expensive), the stolen IDs from server have less value to hackers. ICAO standard already includes secure storage of the biometrics data long time ago but not many countries implement yet. Finger print sensor is widely adopted in mobile phones. Anyway the technology exists. Maybe some identity theft incidents will push the government and the industry to implement the solutions
A number of governments already use eIDs, and have elaborate databases for citizens, such as Croatia. See: https://gov.hr/en
There are also other forms of government facilitated authentication (e.g. electronic signatures or citizen services), and depending on the level of security needed.
It’s amazing that the United States does not have this functionality, which would be useful moving from state to state.
I guess the US passport card is the closest example, but it is useless except as identification.
The US does have it, used in both passports and “Enhanced Driver's Licenses” meeting the federal requirements for that label. I think only a couple states currently issue EDLs.
> I guess the US passport card is the closest example, but it is useless except as identification.
Almost any place that requires government ID, IME, accepts passports; they aren't at all useless as ID.
The eIDs also require a biometric picture of your face and 2 fingerprints, which are encoded into the card, as required by European Union regulation.
When I am ready to I can even apply for my European Engineer license online on that portal, with my eID using a Smartcard reader on PC (highest level of security for authentication of credentials).
As far as I know there's a deadline for it and we just passed it.
So far, it seems like a "mini passport" and an enormous risk to carry around literally everything someone needs to know to rob and/or impersonate me, but yet we're legally required to do so.
As to how to use the smart features: not knowing how to use them is really what makes you German. Welcome onboard!
There is an online portal where you can read more about it:
https://learn.e-resident.gov.ee/hc/en-us/articles/3600006244...
Their ID cards can cryptographically sign documents/anything using a PIN that only the user should know, so even if the ID card is stolen, it still can't be used to sign documents/messages.
The problem is, the certificate (public key) purposely contains the full-name/public personal ID code, so that people can prove who (and which ID card) signed the message.
I'm unsure if making the photograph public was purposeful;, the Wikipedia article is quite vague (it says that "personal data" is publicly associated with your certificate, but I can't find whether photos are included under "personal data" on the English language government site).
These days, you also have the option of signing with Mobile-ID (using a secure SIM application provided by your phone carrier) or SmartID (a regular Android/iPhone app) are probably more convenient since you don't need the smart card reader.
I can't remember the last time I had to physically sign something in Estonia, only when dealing with foreign companies, where you need to pretend to print, sign & scan the document. They don't seem to mind copy-pasted PDF signatures though...
It's also used for things like tracking of tax liabilities - so if someone has your SSN, with some minor fudging of other data there have been historic issues like claiming tax overpayments and getting checks from the government.
It's incredibly dumb, but it is what it is (mostly still).
At least most of the big players aren't quite as dumb about it as they used to be.
Over subsequent years, politics fucked it up bad. They made it "compulsory". Then people started asking for photocopies. Then scans. Then people would keep and then buy and sell these scans in bulk. Then people started putting phones with multiple cards, like entire villages would be one computer operator who would keep his own phone for "otp". That operator would then sell access which would be bought for buying Sim cards, shit and frauds.
Then you have the political appiontees who run this Aadhar system, those pompous assholes claim they are unhackable. Come on.
Sadly they built a Pandoras box now with 1.3 billion almost demographic data, biometric data and that is scary.
However, having a smart chip on your ID card does not do away with requirements for good operational security.
Fwiw some countries, including Japan, require the hotel to keep a record of a copy of your passport/residence card (for non citizens at least) to meet regulatory requirements. It's not up to the hotel to choose to collect it or not.
I seem to recall I had a similar experience in Canada.
Stolen pictures were not forwarded, so they even got the leaked data back.
Dunno, not a big deal.
Only thing was he was downloading pictures en masse. Names and ID codes got from elsewhere beforehand. ID code is not a secret here either, you can reconstruct it with high accuracy just by knowing persons birthday and city he lives.
Tho I think this triggered a fast lane for upgrading some legacy stuff that was to be updated soon. So good scare I think.
Can we be certain that the hacker didn’t make any copies?
Estonia's government is exceptionally forward-thinking when it comes to embracing technology (they've had internet voting since 2005, for example), but ultimately they're still a smaller nation and it sucks to see them get burned.
Some more info: https://www.newyorker.com/magazine/2017/12/18/estonia-the-di...
Also, such leaks can be dangerous. If someone is hiding from authoritarian government then the stolen data can be used to track and assasinate them.
So he took it upon himself and called the specific government branch…
… and within an hour the whole portal was offline and the deadlines ended up being extended. This year was the earliest time I needed to submit said paperwork.
Handling stuff online is not easy and sometimes goes very wrong. That being said, for most general company admin things you need to do here you can buy a hardware cert and avoid this entire risk and they’re supposed to be rolling out IDs with similar features and a similar promise in August. Though as to how that will function, I have no idea as I couldn’t find any info on it.
(Estonia has a similar population to Maine or New Hampshire, 1.3 million people.)
But wouldn't that mean your friend no longer had a valid drivers license ?
That’s strange. Where I live, if you get a new ID you have to turn in your old one. You can keep a passport if you want (some people like to if they have a ot of stamps from their travels) but in that case they punch a couple of big holes through the entire booklet before returning it to you (basically, it removes the chip and some other security measures).
I looked it up for my state and they said you only must file a police report if you believe your license has been stolen, not lost, and you desire a new number. I’m sure policies differ among states.
I picked Michigan at random. Their website merely warns that the old license will be invalidated electronically and cannot be used for border crossing while encouraging use of online replacement services.
https://www.michigan.gov/sos/0,4670,7-127-1627_8669_53328---...
The Netherlands.
> rendering your license invalid because you lost a physical license
If you lost it, you can't drive anyway. Why would you not invalidate a lost license ? To clarify: the physical license is invalidated, and since you need to have a physical license on you to be allowed to drive, you can not drive until you get a new physical license.
If you fraudulently report your license as stolen, it is invalidated and you can no longer drive using that physical license. If you get a new one with someone else's photo on it, that basically means you can no longer drive a car.
I noted this earlier: " Almost nobody you presented the license to would know that another one has been issued, besides possibly a police officer." So the usefulness is for situations that are not driving and don't involve police. One could still definitely use the 'lost' license to get into bars or concerts, start accounts, and purchase alcohol or cigarettes.
If he looks it up in his computer, wouldn't it show the wrong photo ?
Also, if you don't have a valid license your insurance may not pay out in case you are in an accident.
As for the example of the fraudulent license holder, yes, the officer would probably be able to tell, which is what I've been saying this whole time - one would not want to present the old or the new license to the police.
Sure, an illegal license holder presumably either doesn't care or isn't prepared to deal with an auto accident, in which they would have to pretend to be the person on the license and it would go on that other person's record.
https://www.consilium.europa.eu/en/press/press-releases/2019...
These are from 2019,but the documents have always existed. And each country is using this guideline for their countries.
In Germany for instance most data is held by the municipality and centralization happens slowly and centralizing pictures is only a recent proposal.
https://www.golem.de/news/trotz-kritik-smartphone-ausweis-un...
They also compared my old ID photo with the new photo I was submitting when I renewed it recently for the same reason.
Though I've never had this particular problem, I believe the police will also do the same thing to verify they're arresting or ticketing the right person.
Also keep in mind that Estonia is the size of a (quite) small state in the US, so they're storing things like a driver's license photo just like your state would. You actually don't need a physical driver's license with you in Estonia as long as it's linked to your ID card, so it's really an "all your eggs in one basket" kind of system.