FBI Probes Service Selling 153M+ Drivers Licenses
krebsonsecurity.com
krebsonsecurity.com
Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which gets cross-referenced by the legit provider against the id.gov database.
Of course the devil is in the details and I wouldn't trust GrandePelotas and friends to vibe code such a system but it is absolutely possible and is something we should, at the very least, be thinking about.
it's stupid easy to setup, the app is not overly bloated and it has different options to authenticate.
Recently I added my passport to my Apple wallet but I’m not sure if that’s used anywhere.
I'd love to read more about what security features US passports are missing and what they have implemented. Just out of curiosity.
The private key itself is locked into the Emirates ID, and need my biometrics to unlock.
Example: When I get delivery that needs my ID, the delivery man just put my Emirates into a card reader, and they need my biometrics to digitally sign the receipt.
It’s often used for important delivery (banks/gov documents), and any related gov services (including telecom, if i want to reload my sim card but forgot my pin, i can just insert my Emirates ID and scan my fingerprint and it retrives my SIM card by magic!)
You can try to read how they are doing the Emirates ID and the UAE Pass app, it’s super interesting to see this so well intergrated and at scale.
> The CERES project (Spanish Certification) headed by the FNMT-RCM consists of establishing a Public Certification Entity that will enable authentication and guarantee the confidentiality of communications between citizens, companies or other institutions and the Public Administrations via the open communication networks.
So far, in my ~decade here, it's been working out great and is so easy to use.
- MiDNI > https://play.google.com/store/apps/details?id=es.gob.interio... - Mi DGT > https://play.google.com/store/apps/details?id=com.dgt.midgt
https://www.e-resident.gov.ee/nomadvisa/
The design standard for US & Canadian driving licenses & ID cards allows for chips on them. Page 27 of
https://www.aamva.org/getmedia/99ac7057-0f4d-4461-b0a2-3a553...
A pet hobby of mine is to get my state to adopt something similar to the Estonian standard. With a card reader, one would be able to vote from home with the election board being confident that the vote was cast by an authorized voter. This would address the fearmongering by one political party that has been going on since some black dude got elected President. Other things could include signing tax returns online.
Since REAL ID, getting a driving license/ID is a lot more controlled.
The next step will be EU-DI, an app based wallet with many more features and hopefully better interoperability between EU countries.
https://en.wikipedia.org/wiki/Electronic_identification#Usag...
https://ec.europa.eu/digital-building-blocks/sites/spaces/EU...
The fact that USA never finished the Real ID thing as the Citizen ID in Europe is kind of mind blowing for me. It is elegant solution to everything what current administration is complaining about - prove of citizenship for ICE, prevention of voting fraud and especially business owners can tell who is citizen and who is not.
Each and every vote is counted!
The people choose and it’s as simple as that!
In fact the people chose with their hard earned votes for Kamala and Trump to run against each other for president didn’t they?
Didn’t they?
And Europe is even freer!
So much global freedom and democracy where we all have a say :D
> It is elegant solution to everything what current administration is complaining about - prove of citizenship for ICE, prevention of voting fraud and especially business owners can tell who is citizen and who is not.
Well there are two things here. We don't in my opinion, have much of an issue with actual voter fraud - as claimed by those on the right. However, we also have a number of folks on the left who are against voter ID requirements because it might disenfranchise some voters who don't have an ID... an ID you need to do the vast majority of important tasks in life. I've always said if you're not responsible enough to get an ID we don't want you voting anyway (no I don't care about the downvotes).
It's sort of funny how these have seemed to change over time. Folks on the right historically were very much against "big government" ID programs. On the left? In favor! Well, until you start using it for checking who is voting or something. It's also amusing and a little bit irritating that our national ID system is basically 50 state ID systems and they are all centered on having a license to drive a car....
Also Americans can get IDs at a younger age too (children over a certain age need a passport to travel outside the US for example) but we don't really as a society require an ID for many things in practice - it's not really the culture here, we prefer a little bit of anonymity, but once you hit 15 1/2 or 16 you can get a state level driver's license which you'll then carry for the rest of your life. For those who don't drive you are also able to get what counts to just a state ID.
Not to make excuses but the US is a little hard to understand some times with these things because there's so much, especially in the news, emphasis on the federal level of the US government but it really is 50 sovereign states who send representatives to Washington DC. Unlike in, say, Estonia which from my very limited understanding is sort of one people, one country, some divisions. In the US you're from California, or Ohio, or Maine and the state manages most of your lifecycle affairs.
> The fact that USA never finished the Real ID thing as the Citizen ID in Europe is kind of mind blowing for me.
I actually refuse to get a "Real ID". I already have a passport. They can kiss my ass on paying an extra $25 for what amounts to the same ID card I already have. I'll take it for free but I'm not paying for it. I'll just carry my passport when I fly.
But US states are sovereign entities who have, effectively, joined together to delegate some of their sovereign activities to a federal body (which has increased in power over the years) for the common good. They are very tightly bound to the federal government, but these matters don't refute their sovereignty. It's one of the reasons, maybe the primary one, for the US Senate - it's a vote of sovereignty by any individual state so that states with higher populations don't simply dictate rules to states with lower levels of population. Lower population states wouldn't have agreed to delegate some of their sovereign rights without some mechanism to not be run over by populists.
10th/11th Amendment
With the way you’re characterizing the idea of sovereignty, every entity in the world is semi-sovereign. But sovereignty isn’t a spectrum. An entity is either sovereign or it’s not.
See, e.g., Alden v. Maine, 527 U.S. 706 (1999) https://supreme.justia.com/cases/federal/us/527/706/
"Although the Constitution establishes a National Government with broad, often plenary authority over matters within its recognized competence, the founding document "specifically recognizes the States as sovereign entities." Seminole Tribe of Fla. v. Florida, supra, at 71, n. 15; accord, Blatchford v. Native Village of Noatak, 501 U. S. 775, 779 (1991) ("[T]he States entered the federal system with their sovereignty intact"). Various textual provisions of the Constitution assume the States' continued existence and active participation in the fundamental processes of governance. See Printz v. United States, 521 U. S. 898, 919 (1997) (citing Art. III, § 2; Art. IV, §§ 2-4; Art. V). The limited and enumerated powers granted to the Legislative, Executive, and Judicial Branches of the National Government, moreover, underscore the vital role reserved to the States by the constitutional design, see, e. g., Art. I, § 8; Art. II, §§ 2-3; Art. III, § 2. Any doubt regarding the constitutional role of the States as sovereign entities is removed by the Tenth Amendment, which, like the other provisions of the Bill of Rights, was enacted to allay lingering concerns about the extent of the national power. The Amendment confirms the promise implicit in the original document: "The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people." U. S. Const., Amdt. 10; see also Printz, supra, at 919; New York v. United States, 505 U. S. 144, 156159, 177 (1992). The federal system established by our Constitution preserves the sovereign status of the States in two ways. First, it reserves to them a substantial portion of the N ation's primary sovereignty, together with the dignity and essential attributes inhering in that status. The States "form distinct and independent portions of the supremacy, no more subject, within their respective spheres, to the general authority than the general authority is subject to them, within its own sphere." The Federalist No. 39, p. 245 (C. Rossiter ed. 1961) (J. Madison).
"Second, even as to matters within the competence of the National Government, the constitutional design secures the founding generation's rejection of "the concept of a central government that would act upon and through the States" in favor of "a system in which the State and Federal Governments would exercise concurrent authority over the people who were, in Hamilton's words, 'the only proper objects of government.'" Printz, supra, at 919-920 (quoting The Federalist No. 15, at 109); accord, New York, supra, at 166 ("The Framers explicitly chose a Constitution that confers upon Congress the power to regulate individuals, not States"). In this the Founders achieved a deliberate departure from the Articles of Confederation: Experience under the Articles had "exploded on all hands" the "practicality of making laws, with coercive sanctions, for the States as political bodies." 2 Records of the Federal Convention of 1787, p. 9 (M. Farrand ed. 1911) (J. Madison); accord, The Federalist No. 20, at 138 (J. Madison and A. Hamilton); James Iredell: Some Objections to the Constitution Answered, reprinted in 3 Annals of America 249 (1976).
"The States thus retain "a residuary and inviolable sovereignty." The Federalist No. 39, at 245. They are not relegated to the role of mere provinces or political corporations, but retain the dignity, though not the full authority, of sovereignty."
A legal term of art is often a bit different than the basic word itself. From a legal term of art perspective, I’m essentially referencing “absolute sovereignty”, which would more closely mirror the actual dictionary definition of sovereignty, as a basic, contextless word.
Related to your point about absolute sovereignty I wouldn't disagree with you at all, but I would say that, and I'm not accusing you of doing this by any means, we should be mindful not to shift the goalposts and attempt to depress the meaning and significance of sovereignty just because an entity isn't also absolutely sovereign.
I agree with this, I'm thinking more along the line of debate mistake. I make them, I always invite corrections and I think the willingness to speak on terms of your debate opponent smooths the debate process. Sometimes it does get a bit impractical, heh debating libertarians often involves learning whole new versions of english lol
Still I think you will be more successful if you put forward your caveat on definitions ahead of time, nothing is to be gained during a debate by preemptively declaring your victory, so if I were to suggest improvements to rhetoric, I'd examine my own use of "the fact is that" type things and make sure that what I describe during these uses are indeed facts agreed upon by the debate participants.
Like if I were a libertarian, instead of declaring taxation is theft, I would offer a "wouldn't you agree" and this way we debate participants share a goal of honing in to the fundamental disagreement at stake and I can tell you in my experiences it often comes down to a lack of shared values instead of facts in dispute.
it was a small load of text easily digested, and the word "sovereign" is right there in it very early on. Your argument would be better accepted if you tossed in that you disagree with the characterization and have an opinion what YOU think sovereign entities are. Declarations of fact should only be used when what you are declaring is indeed a fact.
>In practical terms, there is no such thing as a semi-sovereign entity.
According to the text you're replying to, this is also untrue. In the future, I would recommend something like "while the 10th amendment talks about states being sovereign entities, in practical terms the federal government has jurisdiction over some matters involving states" or something like that. Its fine to voice opinions, but declaring your opinions "fact", well good luck with that hehehe
Sovereign states in the latter sense can delegate their powers to external entities (as they do in the EU), but they can also unilaterally choose to take that power back (as the UK did).
The USSR was an interesting case when it comes to sovereignty. Legally its member republics were sovereign states, but that sovereignty meant little in practice. As a result of a weird compromise, Ukraine and Belarus were founding members of the UN, despite not being sovereign in the generally understood sense. There was a legal mechanism for secession, but in the end, the member republics ignored it and dissolved the union.
Just to be clear for our international friends, this is basically as unheard of. "In some cases" you could say well in some cases of murder someone is a cannibal too. It's a big country with over 340 million people under one roof. Shit happens.
Stop fear-mongering. One person doing something wrong one time does not constitute any sort of noticeable or wide-scale practice and the fact that if such an event occurs it makes national news and is fixed goes to show that the public is opposed to these practices, they are exceptionally rare.
Or perhaps there are "some cases" of voter fraud too ;)
Somehow this wasn't a problem for them, while whites-only water fountains still live rent-free in your mind.
Following your logic, no problem is solvable until you have eliminated all potential issues and outliers. No startups would ever get off the ground with that attitude.
> People who want to just ram through voter ID laws without solving the problem of undocumented citizens can't be treated as serious members of society.
Maybe we want to be more like Europe with IDs from birth and to use them for all government activities.
Who are you to be the arbiter of who is a serious member of society?
Sure, because the documentation required used to be less.
When I was first getting my driver's license, you could establish your identity by having a birth certificate or some sort of vouching process. These days, you need a birth certificate.
It would be hard to immigrate today without a birth certificate, in part because it would be hard to get a passport without it, and it's hard to enter the country without a passport. Countries where record keeping was historically poor tend to have more accessible ways to obtain a passport without a birth certificate... A passport is sufficient proof of birth in an immigration file, and a certificate of naturalization is sufficient proof of citizenship, so a birth certificate isn't explicitly necessary.
I believe it's more rare than citizens without documentation of birth.
If you want to tie a 'universal' ID to a birth document when birth documentation is not universal, you need to lead with a proposal for how to actually make it universally accessible, including to those without documentation of birth.
It’s a lot harder these days given the 60 years of progress
If one or both of the two who just got married wants to change their name? The process is downright bizarre. There is no central name database you go update. You just send off forms to a bunch of places saying “this is my name now,” some with a copy of your marriage license.
Very strange system IMO.
Why go through some centralized, hackable database, wait in line, and maybe get told to go away by some nameless official making minimum wage to update your last name when you can just decide to start using it and that's your prerogative? "I go by this, you don't get to decide". "My gender is this: it's not up to you to decide". I think it's something worth debating whether or not these kinds of things should even have anything to do with the government. I think there are good reasons, but I can certainly see very well-reasoned and principled arguments against the government being involved in some affairs like this.
Also, it should be noted, parents can opt out of enumeration at birth. The child certainly doesn't have input into that decision.
Medical professionals are generally legally obligated to report births, but not all births happen with medical supervision.
I was in college around 2000. Some of my fellow students had no way to obtain an official birth certificate as the county records had been lost in a flood or a fire or something.
Older generations also have the legacy of Jim Crow. Birth registration rates in 1940 in some states was close to 80%. [1].
If you're born today and don't have a birth certificate, it's a giant PITA and your parents will likely end up getting your birth retroactively documented. Maybe when they want to claim you for taxes; maybe to enroll you in school.
If you were born in 1940 and didn't have one, you probably just made do... When 24% of the children in Arkansas didn't get a birth certificate, everybody is going to be fine with you not having one.
[1] https://pmc.ncbi.nlm.nih.gov/articles/PMC1527492/?page=3 (paper from 1943)
S Korea has had government issued digital IDs for all online transactions, although it was originally implemented as an Internet Explorer 5.5 plug-in (eww). I haven't heard anything about how it works these days.
Japan has new digital IDs cards and a standard little device available at every corner store to use it to digitally sign legal documents.
It's worth pointing out that the point of contact for state IDs is the DMV, which is the butt of every government inefficiency complaint. If, instead, it was done at USPS offices or even by postal workers on their routes, no one would complain.
It's entirely about whether the burden is placed on the citizen to maintain their Constitutionally guaranteed rights or whether political agents can use the state to selectively burden neighborhoods, especially ones with no / badly performing DMV offices.
I always find DMV (or whatever your state's equivalent) inefficiency arguments to be hilarious. They're run extremely efficiently for the government. They suck use because of that (long wait times, most important stuff gets shipped by mail weeks later).
The point of the government doing it is that it has to be able to service those people who live maximally far from a DMV (say 60 minutes each way by car), who can't drive there, who have to weigh losing pay to take the time to travel there, who have below average intelligence, who are functionally illiterate (because Mississippi created A LOT of those before their recent education reforms), who "can't use technology", who forgot to bring whatever specific document qualifies for Real ID, etc.
There is a huge difference between a guaranteed Constitutional right that this country fought a Civil War for... and a privilege such as getting on a plane or driving a car.
Assume that I know everything you know about this topic and still arrived at a different conclusion.
It's real funny until they pass a law that says you need an ID to vote and then immediately close the only DMV anywhere near where you live specifically because they want to keep you and your neighbors from voting (https://www.yahoo.com/news/feds-called-investigate-alabama-d...)
Earlier this year, my license was expiring and I decided to get a Real ID. I was able to create an appointment on the Oregon DMV website. It was set for 10 AM. I got there at 9:50 and checked in. My name was called up at only a couple minutes after my appointment time. I gave my documents and paid, then was instructed to wait by the camera area for my picture. I had barely sat down when my name was called. They took my picture, and I was all set. I was out the door by 10:15. Pretty sure my ID then came in the mail only about a week later.
So when people talk about long waits, I don't know what they're talking about. Maybe their state just sucks.
When I lived in Colorado the smart move in Denver was to start lining up about an hour before the DMV opened (for driver licenses, car registration never had much of a line). Out in the mountains, I was able to just walk in just about anytime. The longest wait I had in the small mountain town I lived in was when the one lady working there was doing a driving test, and I had to wait 10 minutes for her to get back.
Living in Washington, they allow private businesses to register vehicles, so transferring a car was normally a 5 minute job. Never did bother to switch my DL, so can't comment on that.
Now I'm up in BC where vehicle and driver licensing is handled by the state owned insurance monopoly. Any agent, private or public, can register your car. You can get the licensing done at public insurance offices, or at provincial service centres that handle all sorts of business by appointment or walk in. It all works pretty well.
When I got my license they told me that if I had time it would be faster to drive down to the springs than to wait at the Denver office.
In Washington the DMV is split between licensing people and licensing cars/etc (2 locations), plus separate emissions testing locations. It's all contracted out with private companies providing staff and services. Last cycle, it took me over 3 hours to update my ID and registration.
Later, one of these places overcharged me on registration of a new car bought out of state. One near my last apartment in Seattle was running a credit card fraud scheme. Some may not have staff when you need them.
Turns out that when you support and fund the program, the government can do a pretty good job. You can, in fact, pay someone to care.
The government is efficient without qualification.
People just like to complain and Reagan was charismatic so we’re cursed with this government inefficiency meme. We’re programmed to repeat it even when providing counter examples.
The overwhelming majority of the waiting I do in life is at the hands of private organizations who are unwilling to invest in proper staffing.
There will no doubt be replies to the contrary but to them I say they have identified corruption, not inefficiency. When the government doesn’t work it is by choice.
The government has to (and should have to) provide the same service to everyone, everywhere. Businesses would never bother putting a DMV office in a small remote county because of cost, even if it was unfair and inconvenient to people living there. Government does do that, and it doesn't look great on a balance sheet.
Like I said, the USPS is in a much better position to be able to scale identity to the national scale.
That's because ours are all done by third party companies on contracts :P
You must have had better luck with post offices than I have. Having lived in a dozen states and used many different post offices, the vast majority is an utter nightmare. Between the rudeness and the apathy, I would much prefer the DMV (depending on the state)
Sure, you can get an ID cheap. Most of the time. But if all of your ID is lost (which can easily happen to the victim of a purse snatching) it's going to take time and money to fix the problem. And voter registrations are not supposed to be permitted to be challenged too close to the election. Not supposed to be doesn't mean it doesn't happen repeatedly, though. This scales much, much better than sending in fraudulent ballots. We find a handful of fraudulent ballots, often by Republicans trying to prove fraud is easy. 2016 and 2024 both had more people denied access by ID laws, challenges and the like than the margin of victory. And those missing votes would have skewed heavily Democrat.
Almost forgot: SAVE puts a very onerous paper trail on divorced women. They'll need copies of the paperwork changing back to their maiden name--something an awful lot of them don't have. I've already seen a variation on this with RealID. A mistake was made at my wife's naturalization, a hyphen crept into her name that didn't belong, went unnoticed for years. Even when it was discovered it was a so-what. Social security had an errant hyphen, everything else was as intended. No problem. Then RealID came along--and she had to do a legal name change in order to change her name to what her ID and passport said. Weeks and hundreds of dollars.
Denying legitimate voters is just as much fraud as permitting fraudulent ones. A system in which the the former happens at least 10,000x as often as the latter is not a good system.
Estonia wasn't even the first, Belgium was.
I think the problem that lots of people, including all the people involved in those companies, don't think that's a problem but a feature. Adds "jobs", GDP, filling their own pockets and a whole host of other "benefits" they're willing to look past any drawbacks in order to get.
Not for government services. The only problem is if the government makes it overly easy for private companies to integrate with and make use of the system. Pretty much no website except perhaps my bank or health care provider have any business collecting my PII.
Effectively this allows the keypair issuing government (and thus whoever collects breach data) the ability to impersonate you. Seems like a terrible idea.
i also have 0 trust in the USG's ability to not lose those, either through hacking or through blatent corruption a la DOGE, et al
You're right. Since a few others have said as much, I was sketching an outline and not suggesting handing people literal RSA keypairs. Any practical, _usable_ solution would involve a physical card, mobile app, web app, etc.
I'm not saying the gov is competent in general btw, but they are actually far better about this area than private industry, in my direct experience.
[0] due to constant undermining by said surveillance industry, which has now basically become "too big to fail"
Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.
Just locate a prosecutor.
Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.
18 U.S.C. § 1028 makes certain transfers involving identification documents criminal. It specifically covers a driver's license or personal identification card and provides enhanced penalties for transferring such documents.
1028 expressly recognizes electronic transfer as satisfying its interstate-commerce requirement.
What are you talking about?
Correct, like being criminally negligent of a child, if you leak data through long-known vectors (for argument’s sake), one could argue you are criminally negligent in securing the private data.
It doesn’t really go that way, often, now.
It could, as more e.g. water treatment and energy providing facilities get pwnd.
Good luck arguing against their conviction rate.
Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses?
Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model?
Hm.
But it has to be freely given. "Give permission or you can't use this service" is not ok for data that isn't required to provide the service.
If the purpose wasn't "we keep to resell it later" it's likely illegal.
Well, "illegal" given that this type of criminality is pretty much ignored (I've been fobbed off by the regulator after pointing a systematic law-breaking by a $company many many many times. Still better than not having this).
That suddenly means a data leak doesn't matter - nobody can make new signatures.
Verifying someone's ID would be as simple as asking them to sign your company name and today's date.
[1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...
If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed).
We'll get there eventually, but not before we try everything else first.
"They can already send a drone to watch you and track your cell location and, and, and, why does it matter if they also slap up a million AI powered cameras?"
The comprehensiveness of the system matters.
This is Chesterton’s Fence.
https://en.wikipedia.org/wiki/G._K._Chesterton#Chesterton's_...
What attributes should require proof? Where do you draw the line?
Age?
Gender?
Race?
Religion?
Political party?
Citizenship?
> We'll get there eventually, but not before we try everything else first.
We got here by trying everything else first.
The “good old days” are now. Thousands of years of progress and blood delivered our liberal societies. Don’t give it up so easily.
Really, the broader point is I'm tired of giving away massive chunks of my PII (SSN, DL copies, etc) instead of just having something from the government that will say "Yep. He is who he claims."
If we, collectively, decide we need age-gated websites, then let's enable that properly. I shouldn't have to give NYT a scan of my DL and my SSN to gain access.
We haven’t decided this.
> having something from the government that will say "Yep. He is who he claims."
You’re literally trading liberty for convenience.
I understand your position. I just fundamentally disagree that the tradeoff you are so eager to make is worthwhile.
Meaning, I can’t buy food; rent or buy a home; or hold any sort of job and earn and save.
What we have today isn’t better, but until recently I was hard pressed to see how such fears were even warranted.
What would happen today if your government revokes a SSN which is your de facto "personal identification number" today? Can you still rent/buy a home? Can you have a job?
But while cash is printed (physical currency): Not having an SSN becomes a major impediment but not impossible to make transactions and survive.
Our migrant workers—who are basically carrying white collar workers like me—are proof of this.
Point is, the US already basically have a de facto "ID card", they just don't call it as such (yet?), so claiming somehow correctly labeling this thing would make things worse or more difficult, doesn't make much sense.
That can be a military id, passport, NEXUS card, DL, state ID.
Things are already bad enough as it is, but at least it’s still possible to get by even if the system takes a dislike to you.
If you're within the borders of the US, this ability already exists, they have a monopoly on violence in the country, something the government is very eager to demonstrate this year.
And again, as long as backchannels exists in the system to accommodate those without a Government ID, it is possible to get by even if the system tries to cut you off.
Don't you see and understand you already have government ID? You're just calling it by another name...
Do you seriously not get it yet? You have IDs now, and you claim those backchannels exists now, and haven't been cut off. Why would calling something something else suddenly make those backchannels be cut off? How come they exists today in the first place then?
I have not seen a definition of this that is simultaneously true and useful
The sole provider of violence in the U.S. is not the government.
Of course many engage in "violence", or "provide it", that is not in doubt.
In the U.S. I can lawfully use violence in many ways under many circumstances. I.E. if you’re in my house and I didn’t invite you there, I can slay you lawfully.
In the U.S. the federal government is not the only institution responsible for law making or law enforcement. It is not only entity that can lawfully use violence. Etc.
Yes, and you can do so, because the government and state says it's OK to do so. If they didn't, it wouldn't. This is the core idea.
> In the U.S. the federal government is not the only institution responsible for law making or law enforcement. It is not only entity that can lawfully use violence. Etc.
Hence the whole "sole arbiter of" and last paragraph in my last comment. All those entities are "allowed to use violence" because your government says it's OK.
There are clear counter examples to your statement in the U.S.
States are not “allowed” to use violence because the Federal government says it’s okay. States have a right to create and enforce laws.
I don't know if you're in the US, but that's simply not how our Constitution works. "Monopoly on violence" is just something some people made up. It's meaningless, just some empty words on paper.
(Which is also true for the Constitution itself, of course. But if you're talking about the theoretical and philosophical basis for lawmaking in the US, that's what determines both. Theoretically.)
In any case all the old gods are dead or dying, including old ideas of statehood, so enjoy the ride, everyone.
This is because the US made a critical flaw by tying the authentication and authorization tokens into one single token - your driving license/ID. They should be separate things. Your authentication token (who are you?) should have your picture and be forgery resistant. Your authorization token (what can you do?) should be a piece of plastic with zero pictures (like your insurance card). Did you get stopped for DUI? The officer takes your authorization token, instead, the officer confiscates both tokens and hands you a paper receipt.
The FAA does it the smart way, your authorization token (pilot's license) has no photo. You do something stupid, the ATC tells you to "call this number" and if it is really badly stupid, then the local FAA person confiscates your authorization token.
There is no reason a digital equivalent can’t be made using the passport system, and it can be left optional, just like passports are optional.
"Border controls aren’t supposed to exist between EU member states – that’s the promise of the 1985 Schengen treaty. Yet today, travelers routinely face checks when crossing borders within the [European] union"
https://euobserver.com/198454/law-professor-sues-germany-for...
EU did border checks without digital IDs being a thing, so why couldn’t US states do a border check without digital IDs?
Digital IDs are not a causal factor for these concerns, seeing as how those government abuses already happen without digital IDs.
AFAICS from the other side of the pond, United States Government can track people well enough even without a national ID card. They have successfully worked around that problem.
So, it's a moot point now. No?
The EU/EEA is rolling out a digital identity mechanism with interoperable wallets that can hold any range of identity documents and other credentials. You don't need to pick a single wallet provider - several EU countries are approving multiple, including private providers. You don't need to standardise on a single ID.
This is already the case for many already in-use ID solutions in Europe. E.g. in Norway, there are at least 3 signing providers, and only one provider is government issued - the by far most popular (BankID) is private. You identify yourself to the provider when requesting issuance, not to the government (unless you sign up with a government provider).
The GDPR in a nutshell......
Unnecessary personal data is a liability.
In the US, courts have ruled that the compiler of data owns all that data - you have no control about data about yourself (except in a few legal categories like credit reporting). Some of these old court rulings covered telephone books and business directories.
> Unnecessary personal data is a liability.
Absolutely.
I wish it would be more enforced and controlled tho.
Everyone just gets away with everything.
Recently a bit dutch ISP was hacked and it turned out they kept millions of former customers' details way way beyond any normal lifecycle term. People were still in there that hadn't had anything to do with that company for a decade. This is illegal in the EU but even after this practice was exposed by the leak, the personal data authority just let it all slide.
They also sent out a press release pooh-poohing the consequences for affected (ex-)customers and all they did in compensation was to give a "free" antimalware subscription that was basically advertising just like the few months of mcafee crap you get with a new computer. But all we get from regulators and politicians alike is crickets.
This means the police don't get involved. The only thing you need is a tort lawyer willing to take a share of the damages. Also, a data breach is proof that you possessed the data.
A business wouldn't be able to reduce their liability exposure to zero, but to an acceptably low level, for instance by actively erasing the data before a breach can occur.
Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
So most businesses are not permitted to just delete the data.
Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.
There can be a discussion about retention periods and the like but too short a retention period amounts to "trust us bro" in the eyes of some un-feeling government agency who is trying to screw you either at the behest of the law or at the behest of whoever hates you and has their ear.
Something needs to be done but "just delete it after you've verified it" is not workable at scale. Yes I know it worked fine for brick and mortar forever. Maybe some acceptable technical solution could be reached, idk.
Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in reality the attackers had card-sniffing malware installed on every single cash register at every single store across the country.
How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type dir or ls at a command prompt, it says something like "X files using Y bytes, Z bytes free". How do you know those numbers are true/correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out).
Heartland - #19, Target - #20 at:
https://www.upguard.com/blog/biggest-data-breaches-us
You may notice that the poster of the comment you are responding to is mentioned a lot on that page.
Part of the attack was physical, aka skimmers. I still remember the relatively elegant inspection tool blogged by Target Tech on HN 3 years ago:
Target's EasySweep – Simplifying Skimmer Detection: https://news.ycombinator.com/item?id=36788831
Not in the US, but in Spain, police gets this data real time when you rent a car or check in to a hotel.
This is of course important for protecting you.
Well, that's very kind of them. I am constantly impressed at the kindness of our governments, and the recent growth of that kindness. I guess that, with all of the power that modern technology is giving them, they're finally getting to live out their heart's desires of being very, very kind.
Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.
They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.
Basically swaps the LED illum with an UV LED instead. Makes all the security features pop right out.
They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).
One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.
The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.
Some Interrail travellers told to cancel passports as hacked data posted online
https://www.theguardian.com/technology/2026/apr/23/some-inte...
I just don’t hear about it anywhere near as much.
Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is.
And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We're talking a $5 billion company handing 15 million people's credit reports to hackers, and getting fined $15 million.
As an EU citizen and resident I strongly recommend you not take EU privacy controls seriously. The GDPR functions well as a means of tax collection, but it really doesn't work all that well as something that actually protects people's privacy.
The theory that local government is more accountable and responsive seems to be pretty deeply broken, what actually seems to happen is that localities lack a critical mass of attention and focus for real responsiveness and accountability.
Or the American character in general does.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
You'd think that 80 million people from a rich first world country would be enough of a market to use this.
No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
Because then that website would get compromised and lose the data on 350 million people instead of 153.
Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.
People throw around terms like "zero trust" like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you'll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.
Using government ID on the internet should simply be banned. 99% of things shouldn't require government ID to begin with and the 1% that do should always be done in person.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
What does an "identity verification" company even do?
Handles the multitude of ID document standards around the world while providing a simple Boolean flag to websites that are required to check if you're an adult.
I didn’t go through with that part of my application and didn’t keep the job.
Count the number of Americans who would have an ID worth scanning (aka ages 18 or over): 269M [1].
Or the number of Americans with a driver’s license: 212M (2013) [2].
1: https://www2.census.gov/programs-surveys/popest/tables/2020-...
1. You already know who everyone is. By definition identification as an individual is by government.
2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?
3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")?
Governments need to protect the public, not allow businesses open slather on collecting PII.
European Digital Identity Wallet (EUDI Wallet) framework established under the eIDAS 2.0 regulation (Regulation (EU) 2024/1183)
When you scan your driver's license at a compatible reader, you're given a notice of what information is being requested and the ability to share it (or not).
It can also request some derived attribute (is this person above the age of 21?) instead of the actual data field itself.
Most of this is from ISO/IEC 18013-5
Generally speaking, it's the narrative of a pushback on a "national id".
Many countries already have this place. Estonia has the Digital ID provided by government[0]. Nordic countries use BankID, which is a form of KYC that is backed by banks (you prove your identity to the bank, the bank issues a bank id - usually back by certificate[s], and you login with this to services[1][2]). Finland is the outlier, here, with their own service[3].
0 - https://e-estonia.com/service/estonian-e-identity/id-card/
1 - https://www.bankid.com/en/individuals/get-bankid
2 - https://bankid.no/en/how-to-get-bankid
3 - https://www.suomi.fi/instructions-and-support/identification...
Ars already has a story about the same breach: https://arstechnica.com/security/2026/09/my-drivers-license-...
Is this story being flagged? If so, why?
But no it's about leaked data. That wasn't very clear from the title.
Somewhere in the inane executive brain world there are some folks who seem to see some unspecified value in collecting driver’s license images. They never have given me a sensible justification. They seemed to think it provided some assurance that the providing it is in fact who they really are and they can validate…. something.
I’ve managed to push back on that and told them I didn’t want the legal responsibility of managing such data and tracking all the legal responsibilities for any number of countries and ect.
It doesn’t surprise me that there is a ready made service to bypass this kind of absurd requirement.
Monetary fines have a tendency to simply be modeled in as a cost of doing business. Going to prison is far more effective when the goal is to concentrate minds.
And because REAL ID requires mailing your DL/ID to you (in order to prove you live at that address), the address will not change (most states require you to get a new DL/ID within 30 days of moving - my state is 15 days). Replacing the driving license will not change any of the data. Only the DL/ID number. For other identity theft, the old data will not change.