example.com/path/to/article
000 points · username · 0 hours ago
example.com485 points · 299 comments · 18 days ago · tatersolid
ethagnawl
Nition
tgsovlerkhgsel
Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.
trollbridge
They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
ChrisMarshallNY
They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).
One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.
The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.
cute_boi
fishfasell
shireboy
rswail
1. You already know who everyone is. By definition identification as an individual is by government.
2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?
3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")?
Governments need to protect the public, not allow businesses open slather on collecting PII.
ChrisMarshallNY
Ars already has a story about the same breach: https://arstechnica.com/security/2026/09/my-drivers-license-...
Is this story being flagged? If so, why?
wolvoleo
But no it's about leaked data. That wasn't very clear from the title.
tgrowazay
Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”
Razengan
duxup
Somewhere in the inane executive brain world there are some folks who seem to see some unspecified value in collecting driver’s license images. They never have given me a sensible justification. They seemed to think it provided some assurance that the providing it is in fact who they really are and they can validate…. something.
I’ve managed to push back on that and told them I didn’t want the legal responsibility of managing such data and tracking all the legal responsibilities for any number of countries and ect.
It doesn’t surprise me that there is a ready made service to bypass this kind of absurd requirement.
trivet
ungreased0675
jakevoytko
grommet_kit
guelo
morkalork
FpUser
htrp
rio517
Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which gets cross-referenced by the legit provider against the id.gov database.
Of course the devil is in the details and I wouldn't trust GrandePelotas and friends to vibe code such a system but it is absolutely possible and is something we should, at the very least, be thinking about.