posted in Technology
I rented a car, and within hours, my driver's license was for sale
arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/posted in Technology
I rented a car, and within hours, my driver's license was for sale
arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/Replying to @return2ozma@lemmy.world
But don’t forget guys, uploading your government IDs to any old fucking website to prove your age is very safe and protects children. There’s no way this could go wrong and everyone in the supply chain is very trustworthy
The QR/one time code way makes a lot more sense and avoids this issue
How about we just don’t suck the dicks of authoritarian wannabe dipshits that have proven they can’t secure any information properly and can’t run any institution properly?
I don’t know exactly what you mean, I just think for age gating there’s ways that are a lot better
Replying to @Saapas@piefed.zip
That’s the issue. We don’t need nanny’s to age gate us on the internet. All it does is create a very short path to removing anonymity on the internet
Don’t mind some age gating tbh. It would have to be pretty convenient and anonymous though.
Replying to @Saapas@piefed.zip
How do you imagine it will be anonymous? Or convenient, for that matter.
Replying to @maccentric@sh.itjust.works
Easy. You set the age in the os (or age range) per system account.
Apps can then request this and allow/ deny based on it. Requires admin / sudo to update age range.
No need for 3rd parties, id or anything else.
If parents are concerned about it they can implement it easily. If not, they can ignore it.
Replying to @Dnb@lemmy.dbzer0.com
But it needs to be verified there first in some way, and then services will need to somehow verify that your device properly verified it.
And which of those systems are secure themselves, oses and their manufacturers - the answer is none. None are secure enough to trust that private information on mandatory verification systems. Not the base systems nor any systems that would share any approval tokens.
Replying to @testaccount789@sh.itjust.works
Why does it need to be verified? If the parents set it up as an adult they can’t be mad when its treated as an adult?
Replying to @Dnb@lemmy.dbzer0.com
that’s how we get to the point that the parents need to be made accountable. the only correct answer.
Replying to @Dnb@lemmy.dbzer0.com
So any unchecked web/app developer can see if a child is visiting their site? No thanks. This will make children less safe.
I will VPN to mars before I upload my ID, or that of my child for that matter. Not a chance in hell.
Replying to @genzboomer@lemmy.zip
They already want this, but in a worse way 😆
Replying to @Dnb@lemmy.dbzer0.com
Government: we want to kill all women!
People: this is unacceptable
Government: we can compromise: we want to kill all black and trans women!
People: yay, deal! lets accept this, this is much better!
Well the implementation is going to be that you prove your age to the id app that only saves the info that you’re over 18. Then the id app just tells that info to the website (or app or whatever I guess). So the site doesn’t know who is trying to prove their age or even what their age is, just that they’re over 18.
It would be nice to have that sort of quick and easy app for verifying your personal information too. I don’t think we have one where I live. We always use a bank for that and that’s more hassle than I’d like
And how would that app verify you’ve given your actual age? Now you need to deanonymize yourself to that app and while random sites might not know who you are the app does and the app also knows every site you visit (that requests your age).
So no, that’s no longer anonymous. In practice that’s just your government (as that’s the most likely source of authority to verify your age) tracking what you’re doing on the web. Is that really preferable to parents parenting their children?
Replying to @Goodeye8@piefed.social
The app is from the government and open source at every endpoint. You can see for yourself that it doesn’t track activity.
Replying to @Aatube@lemmy.dbzer0.com
the government would never do that
I’d be more worried if the apps were closed source but the ones I’ve heard about that are making an actual implementation of the protocol are open source so you can see everything it is doing, who it is contacting etc
Replying to @jumping_redditor@sh.itjust.works
They already have. github.com/orgs/…/repositories
Replying to @Aatube@lemmy.dbzer0.com
if you can even verify it, unlike the proposed EU identity app that adds in all the obfuscation, and anti-debugging DRM of the world, also denying operation on any device and operating system not directly made by one of the two tech monopolies in the field.
but that is not only what you should worry about. even with an actually auditable app, they just change it one day and practically nobody bats an eye. the common person can not and will not check anything, it updates automatically and thry know nothing. if they don’t comply, they are immediately excluded from half the world. the thing is auditability is a nice plus, but doesn’t actually matter, because it requires a fully benevolent government. if they want to push through a change, they can roll it out in 5 minutes across the whole country and no businesses can defy it.
You can use a driver’s license or your bank. Different methods to verify it to the app. After verification, the app won’t save the info, just the knowledge that you’re over 18.
the app also knows every site you visit (that requests your age)
Not much of a worry locally. Disabling history is probably included in this (sort of porn mode/incognito, same as your browser). The info isn’t much use locally anyway
In practice that’s just your government (as that’s the most likely source of authority to verify your age) tracking what you’re doing on the web.
Government knows you’ve verified the app but they don’t know what you’re using the app for, it doesn’t have phone home. Your app is giving the site a generated cryptographic key, the site compares that to see if it is a valid key and then accepts it. The key doesn’t carry your personal info with it, so the central db doesn’t know who is being asked about, just whether the key is valid (so someone is 18+)
Now you’ve got a system without oversight. A child just needs an adult key and everything gets bypassed. And before you think it won’t be done, I know from my childhood friends who used their older sibling identification to buy alcohol without the older sibling even knowing it was being done. Kids are creative and they will find a way to bypass something without oversight. That arguably will put them in even greater danger because while kids are creative they’re not that great at assessing dangers. For example a bad actor could give keys to kids and then use that same key as blackmail to control them.
The child would need to get the app and have it verified (id and face scan, bank logins).
I know kids steal or fake ids but yeah not a reason imo to not card people hah
a bad actor could give keys to kids and then use that same key as blackmail to control them.
How would that work, be around to verify with the app or something?
I know kids steal or fake ids but yeah not a reason imo to not card people hah
This whole post exists because the need to card people and then use that card to verify that person and how it opens up the door for your identifiable information getting stolen.
The child would need to get the app and have it verified (id and face scan, bank logins).
How would that work, be around to verify with the app or something?
The way your proposed solution works is that the verification process is asynchronous. The government verifies the identity in the app and then the app is used to verify identity elsewhere. Those are two separate steps that don’t happen in succession. There’s bound to be some time between the two steps if for no other reason than for the government to push the new key into third party databases (because if it uses the pull method then you’ve reintroduced government tracking. That means there’s a timeframe where person A verifies themselves, gives the key to person B and then person B uses the key until it expires. Now you need to start building in safeguards to prevent keys from leaking from within the app.
I’ll ask a counter-question since my point was is it really preferable to parents parenting. How complex (which increases how costly the development will be) and how inconvenient does it have to get for you to consider that perhaps parenting is a better solution? Because I’ll also add this, this solution doesn’t prevent “bad parenting” because a bad parent can just identify themselves and let children use their identification to bypass whatever the kids want to bypass.
I’m against sending pictures of your card. Just showing your card to a shopkeeper, that’s fine imo.
I don’t think there being a delay once you originally setup the app is a big issue or takes more than a few minutes max. You do that first time and then your phone is generating the key based on the master key, the site confirms the key with the central server. That sort of handshake or what it is called happens almost instantly.
Replying to @Saapas@piefed.zip
we all know all of that, you did not respond to any questions Goodeye asked from you
I didn’t realize there was some question at the end, thanks mentioning it
E: Answered it now
I think it’s supposed to be additional to parenting, like carding at stores
Replying to @Saapas@piefed.zip
So lets just take kids off the internet. Sounds pretty great to me.
Man, that would be fun. Probably healthier for them too haha
Like parents actually parenting and activating the built in restrictions for their children’s devices?
It’s probably more effective done at the other end. It’s not like you can make parents parent
You actually can, it’s called regulations, policies and enforcement. Don’t vaccinate your crotch fruit? Cool, they can’t go to public school, and you just won a visit from child welfare
It’s not like we don’t have regulations, policies and (some) enforcement. But there’s still dogshit parents. And for this kind of thing, how would you even enforce it?
Replying to @Saapas@piefed.zip
by denying childcare benefits, and giving a visit from child welfare.
the school should start the procedure when they see the kid scrolling social media regularly, or if the kid regularly says they want their phone (when somehow taken away) as that means they are already kinda addicted to it. child welfare investigates whether the suspicions are true, initiates denying benefits, and communicates directly with the parents being willing to support them improving the situation, including offering free assistance from child’s psychologist. then, the point becomes not denying benefits, but recognizing that they have little time to figure it out themselves, and giving all the help they need.
That sounds a lot more involved, expensive and burdensome to people than just having the site ask you to verify with the app
Replying to @Saapas@piefed.zip
Why do we need to? What’s the risk, some unsupervised kid with neglectful parents might see porn? Oh man, just imagine the world-ending consequences if that happened!
I was thinking gambling but porn is illegal to buy for under 18-yo in some places so they might use the age gating for that too
Replying to @Saapas@piefed.zip
That feels an even sillier concern; what is a child going to do on a gambling site without some adult payment method to access services? And if you say “well they can steal their parent’s credit card,” how would that not equally apply to a parent’s photo ID or anything else necessary for age-verification?
Where I live a lot of kids have bank accounts, but of course it would be silly to put a lot of money there. But can’t you deposit cash into bitcoin things and use them for payments or gift cards? I’ve seen those on some gambling sites.
And if you say “well they can steal their parent’s credit card,” how would that not equally apply to a parent’s photo ID or anything else necessary for age-verification?
Photo ID apparently needs a face scan too, it’s not enough to just have the ID. Then you get into what if they steal the ID, fool their parents and whatnot which… I don’t think that’s as much of a concern tbh
Replying to @Sturgist@piefed.ca
The whole credit card system worked until pron websites gave you stuff for free. The average kid couldn’t acquire a credit card without being caught.
Replying to @Saapas@piefed.zip
I think no ASL covers it for the Internet. Going against the most basic rule is kind of ridiculous.
If it’s going to be implemented imo it’s better to do with a privacy respecting centralized fashion than sending your id pics all over the place
Replying to @Saapas@piefed.zip
You can’t violate and protect privacy at the same time.
You can protect the identity and all other info of the person than if they’re over 18 or not. I think that’s a lot better than the other ways sites are now using.
Unless you think it of just as bad because a site knowing if you’re 18+ is a violation of privacy, so might as well give them everything haha
Replying to @Saapas@piefed.zip
Your arguing for the elimination of privacy as a solution to privacy.
You are naive if you think this is anything other than a demand from advertisers to ensure it is human being advertised to and not a bot.
I don’t think you understand the situation. They’re already doing the id verification. They’re not going to stop with that. I’d much prefer telling a site I’m 18+ than having to send in photos of my id to every random website out there. 🤷♂️
Replying to @Saapas@piefed.zip
They are not going to stop it with people like you rolling over. Pathetic, but I guess you can pretend there is a silver lining.
Oh wait, that silver lining is apparently you bending over, dropping trow, spreading those cheeks and shouting, “is that wide enough!”
That’s very nice but you could still have your fight about the thing while having a much better system in place. Then you get your fight against it and everyone gets less of their info out there.
It’s just a horrid system, sending pictures of your id with all your info on it, to random sites
Replying to @Saapas@piefed.zip
I have already said I won’t be using any site requiring this unless there is a work around. I will not make advertisers lives easier. Fuck them.
While I am generally inclined to pick the lesser of two evils, not in this case. So while you are not wrong about a centralized system being less problematic, I personally cannot accept it. I gave up Meta, Zombie Twitter, Reddit, etc already.
I think even without sending pics of you id to random sites you can see the benefit of a system where the only info being shared is “18+ yes/no”. As many people won’t be fucked over by data leaks at least
Replying to @Saapas@piefed.zip
As many people won’t be fucked over by data leaks at least
oh, yes, they will
How? Now people are sending their photo ids to many sites. With the app you’d be sending a cryptographic key that tells the site nothing else than the person who has this, is 18+
Have the app you use to verify scan it so it can sanitize it
Replying to @Saapas@piefed.zip
No. Fuck off
They’re already doing the verification and it’s not going away. I definitely prefer a better way to do it
Replying to @Saapas@piefed.zip
That…doesn’t work. Just because you saw one dumb YouTuber say something doesn’t make it true.
I’m not sure if there’s some popular video you’re talking about but I’m talking about the EU ID proposal. Haven’t seen any videos about it
Replying to @Saapas@piefed.zip
Fuck all that noise.
Replying to @return2ozma@lemmy.world
I don’t like it when a store scans my driver’s license to buy alcohol. I stick to small convenience stores without that tech.
Why would they do that? What’s the use of scanning out?
Prevents fake IDs. Or, makes them much harder really.
Replying to @rants_unnecessarily@piefed.social
It validates against the states license database to confirm it’s a legitimate ID and not a fake.
Replying to @rants_unnecessarily@piefed.social
It keeps liquor prices down because you get the extra revenue from selling the scans. Try to keep up smh
You’re the product. The alcohol is just the lure.
It’s hooked up to a database to make sure it’s not a fake ID.
Replying to @walden@wetshav.ing
Is that really what’s going on? I always thought the barcode just contained the ID number and your information. Can probably be validated that the format is correct very easily, but you can use the correct format with incorrect data easily.
I assumed the scan was still offline validation. Because if the database isn’t networkable from their store, I imagine they aren’t causing any issues in the sales process. So you would only need to precompile and print a valid barcode with correct-looking data.
Replying to @partofthevoice@lemmy.zip
I don’t know what kind of cards you have over there, but couldn’t it just contain all required information including photo, digitally signed by the government?
Wouldn’t need the internet.
Replying to @testaccount789@sh.itjust.works
Yeah, it could be digitally signed for offline verification. But I’m doubtful there’s enough standardization going on that corporations are integrating signature verification right there in the POS system. They’d need the public keys from the government, presumably. That doesn’t sound too difficult but also, setting up a process to get that info for all 50 states would probably be a mess. Do the states even sign the info to start — that’s another question.
I think the infrastructure can be deployed. Though, I get the impression it would take more coordination than we actually see here in the wild.
I highly doubt that
Replying to @walden@wetshav.ing
At best they are keeping an audit trail to be sure the clerk didn’t sell alcohol to an underage person. But even if they aren’t already I figure it will get retained and used in some manner. Marketing, insurance, who knows? Lots of data brokers would buy information on who buys alcohol.
Replying to @rants_unnecessarily@piefed.social
I think some states might literally require it
Replying to @rants_unnecessarily@piefed.social
It’s for the children’s safety, like age verification
Replying to @rants_unnecessarily@piefed.social
The stated justification is that it somehow catches forgeries that altered the front of an ID but didn’t make the barcode information match. That might have been justifiable in like 1980 or something, but it’s reaaaaaaally not hard to generate the correct barcode these days if you’re forging an ID.
The real reason is to track and sell more data about you.
Replying to @dan1101@lemmy.world
Had a fun time visiting the US, clerk didn’t understand why she couldn’t scan my ID and find it in the database.
Replying to @boonhet@sopuli.xyz
UNSCANNABLE! youtu.be/Gg--VIL2I6Y
YouTubeUNSCANNABLE!Replying to @boonhet@sopuli.xyz
Depends on the state. In Missouri I can easily find cigarettes under 5 dollars.
Replying to @boonhet@sopuli.xyz
I couldn’t find my wallet one day when buying some vapes and the store always requires ID, so I brought my passport guy was like I can’t scan this, and I said it’s a freaking passport so he scanned some random ID they had.
Replying to @return2ozma@lemmy.world
I got arrested this past Saturday… They called my mom to try and scam her.
Replying to @blindbunny@lemmy.ml
what did you do?! oh wait I guess it probably wouldnt be a good idea to admit guilt on the internet so quickly after being arrested
Replying to @thisbenzingring@lemmy.today
Feed people 🤷♂️
Replying to @blindbunny@lemmy.ml
I am proud of you, sorry the state is arresting you for that. hopefully you do not get prosecuted.
Replying to @thisbenzingring@lemmy.today
Yeah. You gotta ask “what did you allegedly do?”
Replying to @thisbenzingring@lemmy.today
“i got arrested” is not an admission of guilt
Replying to @return2ozma@lemmy.world
Luckily archive.org saved the idscan.net press release announcing their partnership with Planet13 dispensaries. They have since deleted the post on their site. Nothing shady about that. 😂
Replying to @ilillilillilillililli@lemmy.world
In addition to scanning and verification, VeriScan performs ID parsing to collect, separate, and classify information from the various fields on IDs. This allows Planet 13 to seamlessly harvest the names and demographic/geographic information of its guests. This data is providing insights into customer profiles, which is especially valuable as Planet 13 expands its footprint into other states, including supplementing its SuperStores with smaller, neighborhood retail shops.
I have no words.
Replying to @return2ozma@lemmy.world
Jeez, Daniel Gooooooch must be pretty pissed about this article revealing his name as an example pic.
wait. the gooch!
Replying to @return2ozma@lemmy.world
Surely the company must be liable, right guys? Right…?
Replying to @ftbd@feddit.org
The company MUST be Held accountable and liable for this
Replying to @GolfFoxtrotLima@sh.itjust.works
I’m sure in the hour long to read rental agreement you don’t have time energy, or the law degree it takes to understand, you waive your right to any lawsuit and have already agreed to settle out of court.
Replying to @return2ozma@lemmy.world
Also it doesn’t help that, for example, at U-Haul, employees just use their personal phone to scan a QR code and take pictures of your ID.
Replying to @Yaky@slrpnk.net
Totally secure system!
this idea that employees can expect you own and use a personal smartphone as part of the job irks the heck out of me.
Replying to @HubertManne@piefed.social
I read that if you use a personal device for anything work related in the US, it means your entire personal device (everything on it) can be considered discovery in a lawsuit against that company. Big risk to take.
most companies want you to put on this software than can wipe your device. its nuts.
My local hospital apparently requires their employees to use a “secure” app on their personal phone to transmit data on the patients.
Seems like irresponsible handling of PHI (by the administration, not the staff) to me.
Replying to @toynbee@piefed.social
Work in IT, alongside info security. Nah.
A secured app environment on a phone is plenty well secure for medical data. It is preferred strongly over a web based solution. Having a personal device running a company profile of security compliance monitoring and conditional access is as good as a company device provided by the hospital. They would do literally the same thing.
I think you’re making a lot of assumptions on how the setup is. It could be fine IF they configured everything correctly and are enforcing things on the work profile. Or, it could be terrible IF they just said “install this app, that’s it”.
Having a company provided device with poor guardrails would at least mean it’s not a device that the staff would do their personal stuff on, installing random apps. Having a company provided device with strong guardrails and fully locked down for this purpose would avoid most of the risk of an undiscovered vulnerability being abused. However well the work profile stuff is now separated in mobile OSs today, there can always be day 0s, and people will install any random apps on their phones or fall for plain social engineering.
Maybe technically right now they’re comparable for security, but their risk profile is different I think.
Imagine just targeting this place for phishing and creating a similar looking app with the same name, then sending fake communication to staff to say there is a new version and install it. They can just install it on their personal profile even if the work one doesn’t allow it and start putting data in it. In the case of a locked down work device they could just not install it. Also, there’s no reason for these devices to leave the grounds whereas personal devices will need to go out into the wild.
Maybe if you consider it a personal device if the staff has to relinquish all control of their entire personal device to the work provided security controls they can achieve a similar risk profile, but at that point it’s just a work device the staff had to pay for, not their personal device.
Replying to @toebert@piefed.social
Sigh
Please show me your masters in computer science and your decade of working with the devices. No? Then let me help you out.
It could be fine IF they configured everything correctly and are enforcing things on the work profile. Or, it could be terrible IF they just said “install this app, that’s it”.
That is true of ANY solution. If they violate this, then they are federally liable. Nothing about who owns the device changes this so it is a non-starter.
Having a company provided device with poor guardrails would at least mean it’s not a device that the staff would do their personal stuff on, installing random apps.
First, applications concerning healthcare data are going to operate in both encryption at rest and encryption in flight. They will isolate all data flow to just that app and its external managed connections. So what other things you have on the device from an App Store are irrelevant.
Having a company provided device with strong guardrails and fully locked down for this purpose would avoid most of the risk of an undiscovered vulnerability being abused.
I don’t think you understand ANYTHING about how security profiles are loaded onto a device. I will keep this to an explain like I am 5 level. None of what you just said is true. It does not matter who owns the device. If they are using it , for work, and work manages conditional access policies on the device, with security policies loaded, it will enforce ALL of the same things for monitoring data flows inside apps relevant to the workplace. It will enforce OS versions or kick your ability to authenticate. There is NOTHING that device ownership will change. Repeating this makes it very clear you have no idea what the fuck you are talking about.
However well the work profile stuff is now separated in mobile OSs today, there can always be day 0s, and people will install any random apps on their phones or fall for plain social engineering. Maybe technically right now they’re comparable for security, but their risk profile is different I think.
You think. Yes, you think, because you don’t do this for a living nor have the slightest clue what you are discussing. Again. Zero day exploits are going to be the same no matter who owns the device. They impact software under the same managed rules that exist regardless. It doesn’t change if it is a company device. Holy shit.
Imagine just targeting this place for phishing and creating a similar looking app with the same name, then sending fake communication to staff to say there is a new version and install it. They can just install it on their personal profile even if the work one doesn’t allow it and start putting data in it. In the case of a locked down work device they could just not install it. Also, there’s no reason for these devices to leave the grounds whereas personal devices will need to go out into the wild.
The reverberation speaking this much out of your ass must be immense. The whole point with a security profile is it limits these actions, and the security profile on the device is THE FUCKING SAME whether it is a device owned by you or the company. Once the employee has it configured correctly, the same in tune, same defender policies, the same OS management, the same everything could be used.
Maybe if you consider it a personal device if the staff has to relinquish all control of their entire personal device to the work provided security controls they can achieve a similar risk profile, but at that point it’s just a work device the staff had to pay for, not their personal device.
Jesus wept. You don’t relinquish control of he whole device. Unless you are working in a SCIF, your physical device is not going to have the type of controls on it that need to prevent any access to Bluetooth or WiFi. It will be only managed insofar as the profile for security requires it to be. That means you selectively block actions and abilities related only to the data within the app context and surrounding risk vectors. I’m typing this on a phone with a security profile on it for work. It serves as my Authenticator, has work application data, and doesn’t have to interfere with other personal use. You have a fundamental misunderstanding of how ANY of this works.
If you walked into Palo Alto today and sat down at the table with their engineering team, would you be telling them their firewall solution is flawed without knowing anything about it? I hope not. So why do that here?
Replying to @return2ozma@lemmy.world
Annnd this is why a refuse to verify with IDs online and use services like Plaid. And the web of T&C’s from multiple 3rd party services like this will mean all of them get shielded from blame.
Replying to @Bell@lemmy.world
Did you read the article? They were renting a car. A car rental place isn’t going to let you just not show your ID.
Replying to @7101334@lemmy.world
So how they did it once upon a time was you showed them your license, they punched the # into the system that would check it. The person at the desk would confirm it was you from the picture. No need to scan the actual ID card, which is where this problem comes from.
Replying to @ikidd@lemmy.dbzer0.com
That is true, but now they rather have a digital proof for insurance reasons.
Replying to @7101334@lemmy.world
Yeah, it was from renting cars, but they are digital copies of your ID, so any online service is just as “at-risk”, if not more.
Replying to @7101334@lemmy.world
it wasn’t just Hertz. it was the ID verification service they used.
Replying to @Bell@lemmy.world
The IRS made me since I used a different service to file my takes this year. It was a pain in the ass. Apparently my existing id.me login wasn’t enough, they wanted a video call or a scan of my face. There was no other option. It was a pain.
Replying to @Raiderkev@lemmy.world
they tried that with me. I just told em to fuck off.
if you make it impossible to identify myself through standard means, you don’t get my tax dollars. 🤷 fuck em.
Replying to @GreenKnight23@lemmy.world
I would have, but they owed me money, so I needed to get my money.
Replying to @return2ozma@lemmy.world
My elderly father recently fell for a Facebook imposter that pretended to be a family member and asked if their friend could contact him. The friend asked him to take a photo of his driver’s license and text it to them, fortunately he doesn’t know how. I’ve been wondering ever since what can they do if they had it? It doesn’t have his social security number on it. His credit has since been locked and banks notified
Replying to @Hikermick@lemmy.world
They can open bank or crypto accounts in his name, and then either overdraw the account or use it to move money from other scams in and out of this account, so the real scammers name is not attached to this account.
Replying to @GenosseFlosse@feddit.org
Is there a way to block that? Ie: freezing your credit means no one can take a loan, but that doesn’t remove the scenario you described.
Replying to @Hikermick@lemmy.world
I’ve been wondering ever since what can they do if they had it?
Ask for pictures of all his other paperwork so they can finish onboarding him at his new job.
Replying to @return2ozma@lemmy.world
Just rented a car. Fuck.
Replying to @Malica@lemmy.zip
I’m literally picking one up in an hour 😬
Replying to @Malica@lemmy.zip
Yeah, there’s like 150 million IDs and licenses. I guess the company that handles like every major businesses ID verification has online security designed by Grom. Should arrest the top 15 people hands down.
Replying to @return2ozma@lemmy.world
Most of this seems very serious and concerning, but…
Nexus also claimed to provide scans of marijuana dispensary cards
What could anyone possibly do with that? It costs like $50 to get one in California, not sure about other states.
Replying to @7101334@lemmy.world
My first thought was “so this is how they got my fake from back in the day to scan”
Replying to @7101334@lemmy.world
The data gets sold in blocks usually. Could be for identity theft, or SIM swap attacks or any number of things. A lot of things online want an ID scan now, so this is a huge benefit to scammers.
Replying to @hansolo@lemmy.today
I still have to see the online service or site asking for my ID. Maybe because I’m mostly off of the bullshit-net for the most part. But the moment any service I use asks for ID, it’s getting cancelled and blocked in my house at the network level. I’m expecting my digital life to be dramatically downsized moving forward.
Car rentals, well, not many options there when traveling, since I absolutely refuse to use ride-share apps like Uber and such.
Replying to @7101334@lemmy.world
Legal weed in CA now dawg. No dispensary card needed
Replying to @Raiderkev@lemmy.world
Less taxes in most places if you have a med card. Financially sensible if you buy a certain amount per year.
Replying to @7101334@lemmy.world
Huh, I just assumed they got rid of them when legalization happened. TIL
Replying to @7101334@lemmy.world
But then there's a record of you being a cannabis user, which could lead to your second amendment rights being curtailed.
Replying to @Drusas@fedia.io
There is a record, but there’s no central database unless you get an MMIC card which is different than what probably 99.9% of people do (but also larger tax benenfits)
Replying to @Raiderkev@lemmy.world
Under 21 still requires a medical card
Replying to @7101334@lemmy.world
Replying to @return2ozma@lemmy.world
ever wonder how those food delivery app drivers seem to maybe be from another country and it’s questionable of whether or not they are working legally? there are a lot of fake driver accounts that use real drivers licenses and spoofed SSNs to create them.
Replying to @ellopete22@lemmy.zip
Nineteen brazillian? Wow, that’s a lot.
Replying to @merc@sh.itjust.works
Definitely more than a billion lol.
they did create thousands of fake accounts though and advertised heavily in Brasil, offering housing and vehicles to work using these accounts while securing huge referral bonuses from creating so many accounts once they hit a certain amount of deliveries.
I had roommates involved in that in the bay area at the time, they were making anywhere between 15-50k per month off of the referral bonuses doordash was offering at the time.
Replying to @return2ozma@lemmy.world
I don’t understand what is the point to upload all these IDs to dark web. Everything is traceable! Every transaction ect. If it would not be traceable many would just get another ID for identification on web or similar- like Sim card, because government is tracking everything, so they could track "Indiana Jones " and not me. Later just get another Sim with other iD. So, that data is available, I don’t think it’s possible to buy it without being connected to it.
Replying to @Newhere@lemmy.ml
Do you think a Bulgarian cares if the US authorities tracks a transaction?
Replying to @Newhere@lemmy.ml
I recommend listening to the podcast Darknet Diaries. It’s about sketchy things online, and very often has real accounts from real criminals talking about what they did and how they got caught.
Very often, people only get caught because 1) they get huge and greedy enough that many governments are actively trying to hunt them down, 2) they make a stupid mistake that tracks back to them personally.
There is no “the government can trace everything!” In reality, it’s more like “if someone does something egregious, a few people will spend months or years trying to find them. And maybe they’ll catch a lucky break.” Hacker OpSec is typically more than enough to frustrate the FBI for years. If they even care to look for attackers. The FBI can’t just show up in Romania and arrest people, either, so it takes international government cooperation. Which is slooooooow to move.
Replying to @return2ozma@lemmy.world
Where can I find this nexus?
Replying to @Magnum@infosec.pub
Fortunately, Nexus went dark within hours of the KrebsOnSecurity scoop,
Replying to @return2ozma@lemmy.world
I bought a domain, configured the webserver in the next 5m.
As soon as it started taking requests (on a domain that i haven’t even announced yet) it got flooded by bots.
If your browser is based on chromium, you’re employing an army of bots yourself that gets enabled each time you enter any domain.
Replying to @ddplf@szmer.info
Can you explain what you mean exactly?
Yeah I worked for company with publicly exposed server, the logs were amazing.
Just bots scanning default ports trying default username and password for services like Microsoft SQL server.
Replying to @Brimstone@lemmy.ml
That’s been happening since forever, though. I helped manage proxy servers for my first job in the mid 00’s, and those server logs were mostly automated port scans and failed login attempts, even on the newly commissioned servers.
Registering SSL is a centralized process with root CAs logging new ones as they come in. Cert transparency logs are a thing, and Google is very involved: certificate.transparency.dev
Once a bad actor hooks up to that, they just get a realtime stream of places to start port scanning and running WHOIS queries for people who didn’t get WHOIS protection. If you used letsencrypt your domains you registered certs for got sent there and anyone who wanted to know about it knew about it before you could tell anyone.
You can use something like crt.sh to look up domains
Replying to @return2ozma@lemmy.world
The only way to fix this is to have us upload our IDs online constantly, perhaps to prove we are adults.
It is the only way we can we safe.
Replying to @sunbytes@lemmy.world
But, just think about the children! ~While everyone plastered their children allover social media and they are easily identified with AI~
Replying to @sunbytes@lemmy.world
Woaha. Why didn’t anyone think of this before you?
Replying to @return2ozma@lemmy.world
At this rate, a new ID type will have to be used. I dont have a clue what, but a new one…
Replying to @Bluedragon012@lemmy.world
Welcome to Rent-a-car. Please sign into your vehicle with Facebook, Google or AppleID.
Replying to @return2ozma@lemmy.world
This is yet another reason why virtual ID cards are superior: In the event that the card data is compromised, the old virtual ID can be revoked and a new virtual ID can be issued. Virtual ID cards can also have a much shorter duration, because the cost of rotating it is minimal. For example, California’s virtual driver licenses rotate each 30 days.
Replying to @nanometer1625@thelemmy.club
We honestly should be using virtual vouchers for everything. The question then becomes “whats one level up from the voucher i can steal” and we’re very frustratingly (for my mental exercise) back at square 1
Replying to @return2ozma@lemmy.world
Wait until non Americans hear that our national social security ID number is only 4/9 digits worth of “random” numbers. (Fun fact, the entire number was procedurally generated based on where you were born and in what order at the hospital for generations until they changed it recently)
Replying to @Horsey@lemmy.world
The numbers aren’t random. They are sequential. The early digits are assigned geographically, but the rest are in sequence. If you know a valid social security number, adding or subtracting 1 will be another valid social security number, most likely someone born in the same hospital on the same day.
They did change it somewhat recently, but they don’t re-assign the numbers when making that change, so most of the numbers are completely insecure.
Replying to @Horsey@lemmy.world
Yeah, we know. We just can’t believe that you actually use it for anything important.
Replying to @Blackmist@feddit.uk
That stupid ass number is used as one of the identifying factors when financing anything. Yes, a house is bought and mortgaged with that number next to 2 other forms of ID lmao.
Replying to @return2ozma@lemmy.world
I have had to rent cars since 2015. My license has probably been seen by 5000 breach sites by now.