Senators Urge FTC to Probe ID.me over Selfie Data
krebsonsecurity.com
krebsonsecurity.com
I tried to help set a relative up a while back to receive his payments, which required authenticating with ID.me. Over and over again, the facial recognition feature would fail and prompt to take a new video. It took reaching out to a support line to assist, but they weren't particularly fast or helpful. I couldn't imagine being his age and trying to set this stuff up alone.
For every beautiful, artisinal website experience out there that takes UX seriously, there's an equally horrible one that stands between you and something you need and it's pretty clear that the people behind that system don't give a damn about you the user.
In some cases, perhaps he's right.
I bought HP 61s
Plus, I imagine everyone made more effort to be civil when interacting because everything was face-to-face.
In New Zealand, which is similar population to say Oregon, the modern systems absolutely spank the old systems.
Tax: the majority of people don’t need to file a tax return, instead it is all automatic. You only file if you have income from uncommon sources, such as foreign investments. Any questions, and I can call my tax department, and I get a person who answers the phone call, and answers the difficult questions correctly. They don’t treat you like a criminal: 10 years ago I personally did five years of unfiled tax returns simultaneously . . . I rang and asked questions of the tax department, and got my refunds without any trouble. I believe you can trust the tax department (YMMV).
Local government: I can walk in to their help desk and ask questions for free about the council rules and processes. I admit the help desk does not provide legally binding opinions, instead you need to go through formal processes. The local council may be slow and difficult for some things, but the process is fairly transparent and you can get closure on questions if you persist. The local council has restrictions on what it can do. There are automatic rights to house development, so if you follow the planning rules (setbacks, recession planes, etcetera), then it is unlikely for neighbours or local government to be able to chuck a spanner into your plans to build on your own property.
Passport renewal: last time I did it over the internet.
Mostly the government interactions New Zealand at least functional, and sometimes they are even pleasant.
The exception is our legal system, which is still mostly paper based, and archaic. Although anecdotally it works better than the US system.
(Paper file navigation is so easy my Gram can do it faster than me!)
Computers added:
-Hardware abstraction -Software abstraction -Storage abstraction -Search abstraction -Indexing abstraction -Networking abstraction -Legislative abstraction (When you have a computer to program once instead of a workforce to train, people are more willing to complicate things instead of leaving well enough alone)
Honestly, I can totally believe it worked better.
Can't find it now but one of my all-time favorite engineering memes goes something like, "modern engineer, cries when Matlab crashes; Roman engineer, built aqueducts by eyeballing them."
> In 1935, the first group of female human computers were hired. Before electronic computers, all mathematical equations and computations would be done by hand by people, often known as human computers. With the advent of World War II, many male employees at NACA left to fight overseas. More and more women were needed to fill their roles, and soon African American women were hired to help with the shortfall.
> These African American women were sent to a segregated computing section known as the West Area Computing Unit, which was the center of the 2016 movie Hidden Figures. In April 1942, a memo was passed around stating that, “The engineers admit themselves that the girl computers do the work more rapidly and accurately than they could.” The women computers were becoming increasingly more valuable and doing incredible work along the way.
Isn't it weird for the US to rely on public services that are managed on the TLD (.me) of a foreign country?
I see the same stupidity with my own country's government where they use independent domain names for every service rather than a single, high value namespace (ex: gov.TLD). I guess I should just be happy they use our country's TLD. Lol.
Imagine if the service was called who.ru. What could possibly go wrong?
It was always funny seeing news about the instability of government in Libya and then also see a bunch of projects come out using the TLD (.ly)
Unfortunately I had to do this just to PAY MY TAXES since I had received some unemployment benefits and the relevant form was gated behind my Dept of Labor acct that had, of course, been long since locked due to scam attempts.
Or at least, the people buying the system don't have the technical ability to create it, and the contractors who won the lowest bid to create it don't care about anything other than having the project's completion signed off on.
more like 10 equally horrible ones
[1]: https://www.irs.gov/newsroom/new-online-identity-verificatio...
[1] https://www.fool.com/taxes/2019/04/13/heres-what-happens-whe...
I gave them thousands of dollars (hoping to get some of it back as credit card points). I immediately got an email saying "Thanks for your payment at 1:30 AM (not my timezone, tomorrow)." I was livid, and I had no recourse.
I don't even know how to check for the fine and pay it. I'm just waiting for an IRS nastygram at this point, so I can contest their "processing fee" on my credit card.
(I'm sure there are people who legitimately have to do it at the last moment for some reason. But I don't believe that's the common case.)
I've outsourced this clown show of an obligation to an accounting firm for the past 6 years or so, but for some that's simply not a feasible option. Nor should it be required -- an additional cost for the privilege of knowing how much you need to pay in to the government (who pretty much already knows this amount, in many/most instances, mind you) is beyond absurdity.
Tax filing in the US is archaic and like I've mentioned previously (but I'll say it again because it's a constant source of frustration for me) a needlessly complex process.
Square Cash took over Credit Karma Tax this year, and their CA state form was atrocious.
What the system lacks in technical security is (supposedly) made up for by legal protections/processes--yeah, it's incredibly easy to take money out of an account, but that transaction _will_ get reversed if it was fraudulent.
To pay them with wire is extremely complicated and requires setting up an EFTPS account.
If you have the money to pay your taxes, less hassle for the government for you to not pay with debt. If you don't have the money better to just pay late.
You realize the IRS accepts check right? You could also just easily put a stop payment on a check or write a bad check. There would be no point in doing that of course just like there would be no point in in issuing a chargeback for a card payment.
All to be a) spammed with 'deals' I did not sign up for the next day from id.me, and b) to access an IRS page that really isn't very useful.
It's a really stupid partnership which of course exists to avoid the government giving you a digital ID themselves and something something private enterprise something something, but of course ID.me has a monopoly so those points are moot.
Plus, if we go to all of this effort to have a secure, authenticated portal, it would make sense to then be able to actually use the portal to do things. Once logged in I can't change my address (send us a paper form!), I can't see the status of paper-submitted returns (received/processing/etc), nor can I see a digital record of communications from the IRS... they show 'some versions of IRS notices' but I still get paper letters from the IRS that are not on the portal (despite signing up for paperless communications).
(That's the ideological cover. The reality is that the public-private partnership funnels money from the state to the shareholders to the party donor class. Both parties.)
This is also part of the reason for the ~$60B in aide to Ukraine and why all of a sudden senators are making "surprise visits" to Ukraine.
Would you like details and a history lesson on how vile cheney and all his PNAC buds have been?
https://en.wikipedia.org/wiki/Keating_Five
https://www.upi.com/Archives/1991/10/22/FBI-knew-BCCI-financ...
Guess which Khoshoggi's dad was involved...
https://en.wikipedia.org/wiki/Jamal_Khashoggi
and who did donald trump buy his yacht from
Adnan... "the worlds largest Arms trader"
yeah, it gets super weird after that...
According to that company's 'About Us' page, "PrintScan’s certified fingerprint technicians undergo extensive background checks before being cleared with the FBI, NYS Department of Criminal Justice Services, Florida Department of Law Enforcement, and Homeland Security."
I looked up on the FBI website to see if they provide similar background check service, and sure they do for $18! I have a hard time figuring out why FL board of medicine uses a third party service instead of FBI to do background checks, and also wondered why shouldn't FBI background check be enough/sufficient for criminal activity (i.e. don't states share their criminal records with FBI?). All of this is to say that the existence of companies like PrintScan--and the fact that one of the state governments uses it--is definitely concerning to me.
It was a very complete system at the time and used in many situations for background checks for everything from LEOs to day care centers for cheap. We also had hard requirements around 99% of responses had to come back within 10 minutes.
Anyway, that's changed quite a bit the last few years..
More and more State & Local stopped participating in the system - https://www.washingtonpost.com/crime-law/2021/12/09/fbi-poli... - so huge swathes of data just isn't available anymore. Then more DAs are choosing to prosecute fewer crimes and negotiating down serious crimes that would trigger alerts (usually felonies) to lesser crimes so the data that is there may not be representative of the situation. And finally, the overall crime statistics are being characterized as "racist" so the FBI is getting more cautious about what they release and how.
So.. less data, incomplete/wrong data, and less access to the data.
All of those mean "competitors" have room to operate.
This is false. I've had my background checked at least a dozen times. Most recently, just this past October, and I have never given my fingerprints to anyone.
Any fingerprints submitted as a background check were required by law to be deleted pretty quickly (within hours, iirc). Fingerprints submitted as part of an arrest were different.
Unfortunately, that may have changed as many gun control advocates have pushed to keep fingerprints from background checks on file indefinitely. I don't know if they've been successful.
See https://www.fbi.gov/services/cjis/compact-council/privacy-ac...
those are not the ONLY ones with that interest !
> Then more DAs are choosing to prosecute fewer crimes and negotiating down serious crimes that would trigger alerts (usually felonies) to lesser crimes so the data that is there may not be representative of the situation.
Isn’t this representative of the situation? They didn’t get a felony and the background check shows they didn’t get a felony? Are background checks supposed to be extra punishment on top of what the judicial system determines?
What your describing sounds like it should stay out of government hands just on an ethical basis
The purpose of running a background check is to predict if someone will be a problem. But they work by measuring interactions with the legal system (probably convictions in particular?). And if suddenly most of the behavior you care about stops generating records of interactions, well background checks just got a loss less useful.
Uh huh. Just like these guys, right?
"NSA staff used spy tools on spouses, ex-lovers: watchdog" https://www.reuters.com/article/us-usa-surveillance-watchdog...
If they want us to hand over our facial recognition data (something that has never been needed before and isn't actually needed now) the government should create their own service where any data collected is never used for anything else.
I think it's just pure laziness and a total lack of concern for the public that government websites are full of Google trackers, but when I see a company like ID.me being used I assume somebody is getting a nice kickback somewhere for handing over the American public's data to a private company to exploit and enrich themselves with and all at the tax payers expense.
I have a lot of notes around this whole dustup; it's my opinion that:
- The IRS acted in good faith trying to secure its website in the best way possible
- It's very unfortunate that the US government at the same time promotes a particular standard, but does not provide a service matching that standard and seems to currently have no plans to do so
[1]: https://pages.nist.gov/800-63-3/sp800-63a.html
[2]: login.gov is IAL1 but not IAL2 compliant; IAL2 compliance requires biometric verification and login.gov does not do this. I also think the IRS had concerns around scaling login.gov, but that the lack of biometric verification was decisive[3]
[3]: https://twitter.com/llimllib/status/1490802056256532480
id.gov could be a great project for the US Digital Service [4] and 18F [5] who are the ones that delivered login.gov [6].
[5]: https://18f.gsa.gov/
[6]: https://digital.gov/2017/08/28/government-launches-login-gov...
[1] https://www.nbcsandiego.com/news/local/ca-dmv-makes-50m-sell...
I love what I do, I really do. But stories like this make me want to get a "boring" tech job that I am just maintaining something. Not innovating anymore and at the mercy of not technical people telling me to make horrible decisions.
I just find it disheartening. I am just curious if others ever feel this way?
I personally don't but I think the issue here is that things like ClearView AI and ID.me and the related controversies were inevitable. Just as we're seeing with the development of DeepFakes. An astute observer can probably pretty accurately pick out the differences but will that be true in five to ten years? Audio faking is already fairly good.
Once any technology is close, there will be people telling you it's solved. Look at self-driving cars. All these "we've solved it, autopilot is the greatest thing since sliced bread" takes are pushed as marketing, meanwhile the capabilities are substantially lower than human drivers. The bar for these kinds of things should be, at minimum better than a human.
The issue isn't with the tech itself but the actors involved. It's a tool, and like any others it can be abused. What makes it dangerous is that the limitations of these tools don't appear to be investigated at all, which is a failure of something or someone, I'm just not sure what or who (probably government).
Coupling a "not quite ready" tech with some snazzy marketing and shady practices seems to have been par for the course for a lot of technologies that emerged from the post-industrial revolution era, and in some cases even before then. Just chemical examples: Leaded gasoline, CFCs, DDT, Thalidomide, etc. You could look to something like cryptomining and its environmental and social impact as another more modern tech example.
But I imagine many of us have been on the side of being told that marketing/user retention wants a dark pattern introduced. "User Research" wants all kinds of tracking introduced. Finance wants ads. Management wants something quicker so we cut corners (or worse they tell us to release something even though we say its not ready and very buggy but marketing was making a big deal about it... which I have personally been involved in. Will give one guess how that one went and then who was blamed). Or any other decision made by someone non technical that is a bad decision and is another controversy waiting to happen.
I still see technology as a great force. I still believe in it. I am lucky that my current job, I don't have to deal with any of these things. But we are not a consumer facing operation. But when I look to the future, I find myself asking myself. Where is the industry going and it feels like it's just constantly getting worse. I worry about being in a position of needing to be involved in that again.
I really think what you're saying is just something engineers tell themselves to feel better about what they do. I hear it more often from people at FAANG, defense contractors, and other morally ambiguous places than anywhere else.
Also, if you're the guy building a tool that's oppressing someone, you are the guy building the means to oppress someone. There's nothing neutral about that.
But that aside, I do mostly agree. It's nonsense to help produce something that you know will be misused and then absolve yourself of responsibility.
The problem is not that people like this crap, it's that building and selling it is absurdly profitable and people like money. I don't know how you address such a thing other than to have government step in and block it (see GDPR, tracking cookies etc)
Using a gun on another human to defend my family from immediate threat. Moral.
Using a gun on another human to inflict harm on an innocent. Immoral.
Thus "tech is neutral, usage determines morality".
HOWEVER
what if we are in a society where using guns is the normal way to resolve conflict? Where everyone is required to carry a gun at all times and be prepared to use it to defend their family? Is the tech still neutral when it becomes a cornerstone of every interaction?
Not a fanciful example. Think: dueling.
Some questions I ask myself
Certain technologies force a certain world view. If that world view is not moral, then the technology is not moral.
If a technology is inherently dehumanizing, how is it moral?
Does the technology have room for forgiveness, repentance, and redemption? If not, how is it moral?
The counter-counter arguments is to move up the stack. "computers are neutral, but a computerized system which does X is immoral. So we can only have computerized systems which do Y". But what if the problem is that computerizing something inherently makes it immoral?
A toy example: When something becomes a metric, it loses its value as a metric ("lines of code", "rankings of universities", ...). Computerizing things makes them standardized metrics.
To work for a company is to support their mission (unless you're a corporate spy or saboteur). The morality of your work should be partly decided by how much it improves or worsens the morality of the company's actions. Not "guilt by association," but "guilt by participation."
Personally, I think this logic also applies when the outcome of the technology is obvious. If you devote your life to making a mind control helmet, you can't play the "technology is morally neutral" card.
Philosophical disclaimer: None of this is meant to be black and white rules. There are always murky situations involving trollies and stolen loaves of bread.
I don't see a reason to call out tech as being worse than other industries I could name. It is uniquely awful in a number of ways, but so are others.
I generally do not get disheartened by this sort of thing but you also probably will not ever see me working for Facebook for example.....
Just an hour ago I was thinking to myself, "I wish I was good with my hands. I wish I could do anything but this."
Computers are the only talent I have, and changing careers would mean going back to entry-level pay, which I can't do at this point in my life.
It used to be that when you got fed up with your profession, you could go teach. But that doesn't pay jack squat anymore.
Most people I talk with in the industry disagree with me on this but I firmly believe that most product/service updates are net negative for the user. They get done for the benefit of a company, with a lot of spin and marketing on top to make it sound like it's actually a good thing.
https://www.techdirt.com/2022/02/01/idme-finally-admits-it-r...
https://www.techdirt.com/2022/02/15/idme-doesnt-have-enough-...
In another case, he released the names and details of the people he believed were running the Coinhive cryptomining scam. He also compiled and released information on three people who he thought were connected to the Shadow Brokers group, although he has since unpublished that post (some analysis at [2]). There's even an urban dictionary term: 'krebbed' [3]. There's been discussion here, and elsewhere, although it's mainly back-and-forths on Twitter.
The issue I take with it is separate from whether or not he was correct, but that he is taking it upon himself to act as the judge, jury and executioner of potentially innocent people by releasing names and personal details of people on his blog and on Twitter.
Edit to add: He's even posted someone's passport before, which is kind of wild to think about [4].
[1] https://twitter.com/StarFire2258/status/1283892893539635200
[2] https://www.emptywheel.net/2017/11/28/the-russian-metadata-i...
[3] https://www.urbandictionary.com/define.php?term=krebbed
[4] See his blog post "Meet the World’s Biggest ‘Bulletproof’ Hoster", where he still has the dudes passport picture (with all info, no redactions) up.
It's an expression that I thought most people would understand, but to make it abundantly clear: I do not think that Krebs is executing people. Nor do I think he has the legal training to be a judge. He might have been on a jury before, I'm not sure.
I am using it as an expression to state that he is taking upon himself the task that is normally reserved for either LEA and/or the court system, which is ascribing guilt.
If you have enough information to release a bunch of personal information on someone and tell thousands of people that they are guilty of something, you should go to the appropriate LEA and either take some care writing your story or wait until an actual investigation has happened, reporting on those results.
Edit to add: At least in this case, regarding Krebs, it would seem that at least one senior editor and journalist agrees with me that Krebs acted unethically (see the first comment for a link to a tweet by a senior editor at The Verge). Other major news organizations (e.g. CBC) have policies not to named those only accused of a crime, except in extenuating circumstances or after a charge is laid/legal proceedings have begun. They must also report on the outcome of the criminal investigation.
"Costing an arm and a leg" is an idiom. "The disease cost her an arm and a leg" might be using the idiom to refer to the costs of medical treatment, or could refer to the literal amputation of limbs. Most people use context to understand this. For example, what was the disease?
Disapproval of doxxing is often specifically because of the danger it can pose to the life and well-being of the victim. In this context, a reference to execution does not seem like an innocent expression.
hopefully we all on HN recognize that we know an infinitesimally small fraction of a percentage of all there is to know – at least, I do :)
Or at worst there were big kickbacks involved and something nefarious is going on here.
Regardless seems like a good thing to investigate
Drizly had a massive databreach as well.
The way it was explained to me, (apologies if there's anything factually inaccurate in here, this is my recollection from a while ago, just before the IRS very notably decided to cancel their contract for the 2021 tax year?) they had an army of people whose job was literally to visually compare the person's selfie to the ID they presented, and if I understood correctly, they also had some facility for verifying the presented ID was genuine. And that was it.
(Edit: I see from clicking through to the CyberScoop article "ID.me CEO backtracks ... on 1:many recognition use claims" that it may not be the case that's all they do with each selfie, and that in reality they do store the selfies, based on a regulatory requirement that they must do so for 7 years.)
I think based on that conversation (and sure, call me biased) the "invasion of privacy" concerns were way overblown. If you think the best way to implement an ID verification system is to hire more permanent government employees and have them do the job in-house, ... I'm on Hacker News, so I'm going to assume that nobody thought that.
If you have concerns about the truthfulness of this scheme (does it really happen without permanently storing any selfies?) I think those are fair concerns, and we should know the answer.
But is there anything to be really concerned about, if there's no permanent storage? I don't understand. Can someone explain it to me? I think that the "invasion of privacy" ship must have already sailed, the government has your photo ID in a database, and it's already on record there forever.
What does it matter if the verification is outsourced to a private company? Is there the capacity to do this already inside of our government? (Would you trust them to implement such a system efficiently and correctly without private help?)
What level of oversight would make this scheme appropriate, I guess is my question? Is there any ID verification system that people who are up in arms would accept here? I'm in favor of probing the questions but I am not surprised that wait times are longer and support staffing was evidently reduced, after the IRS cancelled their contract. "You reap what you sow."
I mean, that's why this calls for a probe, right? I also suspect they were overblown - but that's why you look into something.
> I think that the "invasion of privacy" ship must have already sailed, the government has your photo ID in a database, and it's already on record there forever.
I absolutely disagree with this framing of the question. It's false equivalence to suggest that once something exists somewhere "unprivate" that any other system would also be fine. We are going to need to dig into systems and understand if the reduction in privacy fulfills a necessary function and push back on all the systems where that isn't true.
There's no magic in "public" v.s. "private" companies - but each new layer introduces new potential for mismanagement and so you need to ask everyone to "get to the bottom" of what happened.
What data was available? Where they live? Who their parents are? What school they went to? What car they drive? Or even creepier, like hobbies?
There is no scenario where walking up to a stranger and starting a conversation about their personal information is going to come across as normal.
(Such scenes are in probably 75% of all movies. It is an old device for introducing characters.)
What you mention is any random person identifying any other random person (ignoring the creepiness of taking a picture of someone without their consent). And using that to track down identifying information about them.
Just because it may be legal, doesn't mean it isn't creepy for someone to take a picture of a random other person.
Big agencies have entire dossiers on their clients for the sole purpose of brushing up on your info before a meeting so they can come across as super friendly and high touch. Even your hairdresser probably does this.
Main difference being that it isn’t creepy to keep track of things you can’t remember when being friends with hundreds of people is part of your job.
And his personal assistant is a person which is a building block that innately fits into society. Any given person has some level of morals and integrity which would limit what they were willing to do with their knowledge. And even if they don't, people can be brought to justice if they abuse their knowledge/skills or otherwise have some kind of public pressure used against them. An algorithm cannot be imprisoned or even really destroyed and doesn't care one bit what it's used for because it doesn't care about anything at all.
Some of these things seem inevitable, but that doesn't mean they aren't creepy!
There is a flip side to this in places like Russia. If you are at a party and want to talk to someone, you might want to lookup whether she is the wife/girlfriend of the local crime boss/politician/general first.
A private company is accountable to nobody, trusted by nobody, and likely accessing "public" information that was publicized by an entity other than the individual. They are collecting the information purely to make a profit, not to (again in theory) increase public safety. Their entire purpose is to abuse the information for purposes it was not intended for.
In order to legally drive we basically enter into a contract with the state agreeing to the terms it set. Keeping a current license, registration, insurance etc. During a traffic stop, it is a requirement to hand over the documents, if asked, so they can verify you are within the law. Atleast in the parts of the US that I am familiar with. Same for travel and other government documents, if you want to legally move between borders, you agree to their terms or stay put.
Having random creep take a pic of someone and get their address so they can visit later on, would be a very big problem.
Most people travelling in private conveyance are not engaging in commerce.
Have you researched USSC rulings about private travel?
You'd just need a picture.. and it would auto suggest who they are.
That's what got them into trouble with the IL Biometric privacy law.