Hackers had a live feed of every ID verification company scanned for over a year
Hackers reportedly gained a live feed of every ID document processed by a major verification company for over a year, renewing fears that large-scale identity checks on the internet are fundamentally unsafe. Commenters connect this breach to broader concerns about mandatory age and identity verification, arguing that both government and private systems routinely leak highly sensitive data while facing few real consequences. Many advocate for cryptographic or government-backed digital ID schemes with minimal data exposure, while others contend the only reliable protection is to avoid collecting and centralizing such data in the first place.
Meta-discussion about coverage
- Several commenters prefer the earlier, more detailed security-journalist writeup and note it briefly hit HN’s front page then dropped quickly, which some find suspicious given its importance.
- Some users discover that journalist’s broader archive and describe it as both compelling and anxiety-inducing.
Risk of ID / age verification in general
- Many see this breach as confirming long-standing warnings: collecting ID scans for online verification is inherently dangerous and will be abused.
- Multiple comments stress that “prove you are X by sending us enough to impersonate X” is a fundamentally broken pattern.
- Skeptics doubt the incident will “kill” ID verification, comparing it to credit bureaus: repeated failures but the system persists.
Kids, age checks, and the internet
- Heavy sarcasm around “sacrifices” required to protect children online; some argue age verification helps no one and mostly serves political control.
- Alternatives proposed:
- Ban or strongly discourage unsupervised internet use for young children.
- Put responsibility on parents and existing negligence systems, not on ID infrastructure.
- Others counter that peer pressure and negligent parents make purely home-based controls insufficient.
Government vs private digital identity
- One camp prefers government-run digital wallets / eID (EU examples, national PKI) since the state already issues IDs and adding third parties just multiplies failure points.
- Another camp distrusts central governments (esp. in countries sliding authoritarian), fears single points of failure, and worries about “unpersoning” if an issuer withholds credentials.
- Strong concern that even EU-style schemes end up practically tied to Apple/Google ecosystems and proprietary devices.
Zero-knowledge proofs, PKI, and technical schemes
- Advocates highlight ZKP and verifiable credentials as ways to prove attributes (e.g., age) without disclosing full ID, and note working prototypes and some national deployments.
- Critics argue:
- Real-world ZK age schemes are not truly “zero knowledge” once you add anti-sharing / MFA requirements.
- Anyone can proxy their credential, e.g., one adult fronting for many minors, which pushes designs toward device lock-in and issuer tracking.
- Cryptography can’t fix underlying social incentives and usability problems.
Regulation, liability, and data reuse
- Anger that companies and governments repeatedly leak or sell highly sensitive data (DMV records, license scans, ALPR hits) with little consequence.
- Suggestions:
- Strict statutory damages per leaked ID, escalating for repeat offenses and tied to victim’s at-risk assets.
- Ban or heavily penalize storing ID images when not strictly necessary.
- Cynicism that current norms (class actions, cheap credit monitoring) create perverse incentives rather than real accountability.
Security practice and systemic failure
- Some emphasize how hard it is to secure complex systems and supply chains; others argue many breaches stem from known, unfixed issues deprioritized for features.
- There is frustration with compliance regimes (e.g., SOC2) seen as “security theater.”
- Several criticize calls for more centralization in response to a failure of a large centralized ID pipeline, arguing this just enlarges the honeypot.