The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.

So most businesses are not permitted to just delete the data.

Regulatory retention is a valid reason for some of this data to exist. It isn't a blanket justification for every intermediary in the verification chain to retain its own permanent copy. If anything, that makes minimizing the number of copies even more important.

Back In The Day, if somewhere like a car hire agency wanted to record proof of identity they'd photocopy your driver's license on paper, and store it in a filing cabinet. The computer record of a customer's account would just say "driving license checked, on file at branch #1234"

Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.

A system abandoned decades ago? https://en.wikipedia.org/wiki/Gold_standard

Storing personal data should require insurance that increases per data point.

I believe we need to criminalize possession of the data, with statutory damages per violation.

Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.

Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.

Not quite the same, but the GDPR gives you a right to erasure.

And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.

Maybe the bureaucracy is there for a reason some times?

Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses?

Hm.

Negligence is already illegal.

Just locate a prosecutor.

I'll sleep so much better at night when the company that'll leak my Social Security Number on the internet due to hosting a backup of a database that's assessible publicly gets fined $0.30 per SSN leaked.

Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.

Yeah, this is the part I don't get either. Verification should produce a yes/no result, not a permanent archive of everyone's identity documents

It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.

Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.

It's obvious they are keeping them all. 150 million didn't get all re-scanned at once.

It's actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker's claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned.

Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.

The whole point is they keep it forever. You think any id verification services actually delete the data?

I mean, just because all your friends are jumping off a cliff...

It feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...

If you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.

The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.

Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through

Which is why you need GDPR equivalent in the US…