My point was that computers are as secure as human(s) who programmed them were careful and competent. Computer security is ultimately human knowledge and reasoning competence (plus time/money tradeoffs, if made willingly)
That's overhead that businesses really hate paying as it's diverts software devs away from making new features.
Who do you think employs the top-level criminals?
It also requires actually caring about security and putting effort into it. These data breaches are usually systems where little attention was paid to security in the first place, and e.g. getting ahold of one user's password is enough to lose the game. Getting companies to care about security is really hard, but it does happen.
outside of english class "secure" is relative and context-dependent, not binary.
Ironically in case of breach they just sell you another of their product where you put your personal information again
How many people actually sign up for your "free credit monitoring for a year" following a breach?
When you do, you typically do so by signing up for the highest tier (sometimes $30 or even $50 a month) product with a redemption code for one year free. You have to enter a credit card to do so, and to no-one's surprise, if you don't cancel in time, it automatically converts to a paid subscription "for your convenience".
There are many consumer protection farces in the US, but right up there has to be the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen. You're considered liable until you prove innocence, even though you did nothing wrong.
This very nearly burned me when buying my home - having been an AT&T customer in the PNW for nearly two decades, "I" apparently decided to hit up a Walmart on the outskirts of El Paso, sign up for a Verizon service, run up two months of international calls and bail out.
Despite a police report, my utility statements, AT&T bills, etc. (all of which were, to be blunt, none of VZWs business), VZW stood by it initially, "On review of your documentation, we remain satisfied that this debt belongs to you based on the documents used to open your account".
I asked to see them, since they were, in VZW's own words, "mine". "We can't, for customer privacy reasons." Oh, so "mine when the bill needs paid, may not be mine for privacy purposes".
Somehow a few hours before our court hearing they by some miracle decided to settle the debt with no fee to me.
You may enjoy/find-useful this Mitchell & Webb radio-skit [0] of a conversation between a banker and a visiting customer.
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.
I’m not sure how we start over but this data plus LLMs is gonna make it a full time job to keep your parents from sending every penny to a scammer.
The 2nd factor is the phone number on file, which offloads liability for errors in that mechanism to the phone company.
The goal is to reduce the amount of decisions the teller makes, so as to reduce the amount of errors they can make, which also reduces the amount of training they need, all of which reduces costs.
It’s really interesting how the lack of US federal government stepping in to provide an official electronic identity verification API has resulted in the mobile phone networks becoming the de facto arbiters of identity. Even for government services.
I don’t even think I could trust having my phone number on someone else’s mobile phone plan, as I would want to ensure I have as much control over it as possible.
With the benefit of hindsight, we'd have all been better off if SSNs had been so obviously flagrantly public that nobody would ever consider them a trust-factor.
"I know! We'll use this number that its issuing agency says is most definitely not to be used for identification purposes for identification purposes!" is real PHB thinking.
For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.
Insurance is not a solution for everything.
More critically, just because a company buys insurance, it should not be a get-out-of-jail-free card for the executives and management to feel free to manage data irresponsibly.
It is really simple:
If they can not handle properly the risks of their business, they should be in another business.
Any data stored anywhere can be exfiltrated through either social engineering, or computer hacking.
Make it illegal to have this data, and if they really want it, then you hit them with jail when it leaks, not fines that can be paid by the board in the form of a golden parachute.
Only those that absolutely need data like this should store it. Like, I dunno, the government? Everyone else can rely on zero knowledge proofs or literally anything else than forever storing a scan of someone's entire fucking identity.
We need people to stop internalizing that the government and the rich somehow deserve access to private data just because they want to use it. Seeing a way to make money using enough to make you entitled to it.
Force businesses to add value if they want to exist instead of extraction or rent seeking.
I specified it in the last sentence: >>If they can not handle properly the risks of their business, they should be in another business.
The same way it is handled in any other business or trade with risk.
Make sure the risks are also PERSONALLY CONSEQUENTIAL TO THEM.
If they fail to handle the business with state-of-the-art advanced knowledge, intelligence, diligence, and resources, then they will face serious personal consequences. If they do not want to take that risk, they are free to go work in any other business.
Some people are fine taking the risks of subsea welding or windmill maintenance. Others are not, and are free to pursue other work. The risks for fuking-up there include sudden death and life-changing injury.
It should be the same for people risking the livelihoods of every person who's data they handle — if they fuk-up badly enough, their risk should be financial bankruptcy and prison.
Instead, white-collar work is typically organized so those who fckup get a promotion or just find a new higher-paying job, while the people they screwed over are left to deal with the consequences.
What amount per person is acceptable for a thing that simply should never happen?
I don't think "this will ruin my and my bosses life"-levels are over the top at all. Don't wanna risk it, then don't store the data. Usually for most purposes it would be e ough to store that yes, someone has a legit drivers license, which types of vehicles it is for and how long it is valid (if there is a limit).
We don't get to this kind of data reduction if people don't see data as the liability it sometimes is for their customers.
Holding actual humans liable (with appropriate levels of harshness) would make actual humans more likely to take preventative steps. Holding shareholders somewhat liable (maybe extra taxes on sales of a companies stock) might be useful also.
And why the hell would anyone want a job where a mistake results in personal ruin? Sure, there are a lot of shitty companies and people running them, but mistakes also happen when people are trying to do a good job. It’s not possible to completely prevent a data breach even with an unlimited budget.
I think the best solution is to weed out the people who behave irresponsibly and have an environment where we learn from the ones who are responsible and fail anyway.
People will do nearly anything if the price is right.
This sort of personal liability OP is proposing would just ensure the security industry is dominated by highly compensated compulsive gamblers because nobody else is insane enough to take the risk. It's an absolutely ridiculous idea.
Corporations evolved the liability structure they have today so that large undertakings, where many people have to work together and where the bad deeds of a small number of those people could sink the undertaking, were something that regular -- people who can't self insure -- could be a part of, as investors, managers, staff, &c, &c.
Limited liability may make accountability too narrow; but blanket personal liability makes it far too broad. It's not a solution for running a large, complex economy in a more accountable way.
It seems like the handful of people you're talking about are totally different people.
We are talking about the sort of job where you are paid ludicrous amounts of money. The sort of jobs that usually come with massive golden parachutes
People earning more money in a year than most people earn their whole lives should be accepting a much higher burden of risk
I guess you think pilots, doctors, air traffic controllers, etc. are all made up?
What do you think their incentives should be?
Sure there can be good arguments for having insurance. Insurance companies are part of the financial sector and will be working to make more money. That is a fine incentive for the insurance industry but for the insurance consumer it is a reason to be skeptical and careful.
Does wonders for how c-level treats compliance work, now if only middle management followed...
It's why you can't legally drive without insurance. It's not for you or your car, nobody cares about that. It's for the other people and their property.
We're talking about assurances that you're going to be able to cover damages if you rear-end a sedan and cause $8,000 in repairs. That's why you're required to drive with insurance coverage.
what's the point of liability insurance if youll never be held liable?
There is literally no way to have the broad base of investment in markets by members of the public that we see today if investors incur personal liability. It was and remains one of cornerstones of any commercial society.
Let's say the investor part doesn't apply to public companies, to make it simple.
The liability shield is too strong though so I do agree it’s causing problems.
We should also make it much easier for company employees to whistle-blow or even initiate stringent audits of security and privacy.
https://en.wikipedia.org/wiki/Carrie_Tolstedt
> In response to the report, Wells Fargo retroactively fired Tolstedt for cause and revoked $47.3 million that they had previously paid her. This brought the total amount of money she had given up to $67 million, or about 54% of her $125 million pay package she initially received when she retired.
How cute, you think the engineers who failed to properly develop and maintain a system that can securely store sensitive information flawlessly won't (or shouldn't) be held accountable.
Every time this topic comes up it makes me wonder how many people on here who go "wow how in this day and age is it possible to have a data breach???" aren't just extraordinarily lucky that no one is really trying to attack the service they created or are fortunate enough to work in the few places that can legitimately say they're nigh-impenetrable.
If they deleted the IDs within a week of getting them surely the leak would be much smaller.
Lawyers, doctors, and engineers to name a few.
like why your driver license or even id should enable someone to do damage to your life?
especially that it isnt difficult to lose it and even needs to be shared with someone (e.g hotel)?
Companies definitely respond to fines or liability. They just need to be big enough.
For example, I recently heard an interview from an environmentalist who expected to be outraged touring a Chevron drilling location but was surprised by how much precaution is taken these days. Basically, liability for oil spills is massive. We could just make data leak liability massive too.
In the ID company case, there simply aren't enormous assets available, despite enormous damage being possible. As such, we really need to re-think just how much we limit liability.
Perhaps it's time to stop allowing degenerate gamblers to freeroll their risks... perhaps it's time to start zeroing out investors, so that they have to start behaving responsibly.
No large undertaking could ever function with such broad exposure to liability, anyways.
And if "No large undertaking could ever function with such broad exposure to liability" - that would be great, i think we would prefer that such firms doesn't exists.
They would still exist, just not in any country insane enough to pass a ridiculous law like this.
They stop existing within your jurisdiction. Also, the idea that the public would go along with any of this for this issue is silly. Let's start with crimes that actually cost lives.
https://spectrumlocalnews.com/tx/south-texas-el-paso/news/20...
"According to the Identity Theft Resource Center’s 2023 Consumer Impact Report, 16% of identity theft victims are experiencing suicidal thoughts."
Holding all managers personally accountable for actions of a corporation runs up against the legal structure of a corporation -- a legal structure that is definitely not one of joint and several liability. That is what I mean when I say there is no legal basis for it. The whole point of a corporation is that the corporation is liable (which is a great convenience in many respects).
Restitution is not about who is liable but about making a wrong right. It's a different layer.
That has nothing to do with changing the whole approach to -- really undermining the whole idea of -- corporations. Limited liability is the only way they can work. It's a cornerstone of every developed economy.
I don't think this is at all similar to jsrozner's solution, which is to assign liability to "...every person who has ever worked for IDScan at any level of management...".
The IRM is describing officers with culpability as individuals whereas jsrozner is really proposing to do without any individuate consideration of wrongdoing at all.
Neither does imprisoning murderers for life, but it's one heck of a deterrent.
We'll probably never get there.
I hate to think how many people would kill if it were not illegal. Think about that. Then tell me its not a deterrent.
Unless you have a requirement to also use domestic ID-verification services, this just means you shut that sector down in the U.S. and all our scans go to a country that doesn't extradite.
The solution is simpler: you're not allowed to hold certain special categories of data. ID scans, until we get proper identity verification in America, being one of them.
Snark aside, I agree with you, it’s messed up and there is a better a way.
What's stopping IDScan from "delegating" the storage to another company so they're no longer liable for stolen data? If Company A uses IDScan and the storage of the ID info is handled by Company B, do I have standing to demand compensation for damages from Company B when my data is stolen after I agree to let Company A verify my ID?
BTW this is how accountability is being avoided today.
Or are you referring to the practice of using shell companies to obfuscate responsibility? In that case, I think there’s history that says IDScan would still be responsible, questionable legal business nonsense be damned.
If someone steals my identity, and puts me in a position where "I" owe money that I didn't borrow, NONE of that money paid back will come from my pocket.
The government can figure out who should owe it, but it sure as hell isn't me.
I think in the same way part of our paycheck goes to federal taxes, part of our paycheck should go towards funding an insurance for the financial impacts these sorts of events, commensurate with the total compensation of a person, and adjusted each year for the growth of any stocks granted to that person.
I'm sure there are edge cases and operational details that need to be figured out with that idea, but at the end of the day if a company is directly or indirectly responsible for awful things, the executive and senior leadership should feel the impact more than others, financially and/or criminally.
I think the best way to prison reform is to start jailing execs who inflict mass suffering via process decisions en masse. maybe then Sergey Brin will decide to drop a quarter billion in something other than opposing a wealth tax
two birds, one stone as they say
You can't really delegate the liability to a vendor. Of course in current world it means nothing since there is effectively no liability anyway, but if we're dreaming of a world where there is liability, you can't delegate it. You can delegate the operation, but not the liability.
The company is responsible for vetting their vendors so they meet their requirements. Today that is done with a silly dance of exchanging SOC2 reports and such, which means nothing. But if there was actual personal liability for the board and executives, that would change in a millisecond.
NIST creates the standards that businesses must follow when doing business with the Federal Government. Without those standards, the government's operations would be even more unreliable and haphazard than they are today.
A long time ago they mandated a single password policy, because having thousands of agencies all with different password policies was crazy. At the time, they (and the industry) thought it was a good policy. Some people suspected otherwise, but there was no proof to show that a change was necessary. So academic research was undertaken to find whether the policy was helping. The research showed that it was more harmful than helpful.
Academia proposed a solution, NIST considered it, and then adopted it, in 2017. The language they used in 2017 was "flexible", so nobody really had to change. Finally in 2025 they made the language mandatory. Now the affected companies will be forced to abandon their crappy password policies, specifically because they aren't allowed to keep them anymore, if they want those lucrative contracts.
This should not just apply to the Federal Government. The same reasons FedGov needs these standards applies to every single one of us. The tech lobby has successfully fought this for years, and politicians are scared of introducing something that might negatively impact public citizens (and thus risk the politician's job). But they can't deny that FedGov needs these standards.
This is a pretty normal process. The electrical code, building code, fire code, etc, all take time to change. But the changes do happen, and we all reap the benefits. With no code at all, we would be experiencing a lot more death, injury, financial loss, and inconvenience.
And btw, there is a lot of technology that has not evolved much in 40 years. We don't need to make everything absolutely perfect, and every aspect 100% set in stone, in order to have a code. Every other code is updated regularly. Software code can change too. (Or are software people too incompetent to figure it out? I might agree with that...)
I don't mind if government software has to use Dual_EC_DRBG - let the government hack itself. I do care if you get prison time for using a secure random number generator.
They end up pay some class action lawyers $8 million dollars and we get a letter offering FREE CREDIT MONITORING!!1!
Downstream of that, people need to stop accepting knowledge of the basic public metadata fields or possession of images containing them as evidence of identity verification. Do actual public key cryptography on the internet or check biometrics and the document’s physical security measures in person.
Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo.
(Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.)
In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.
My ex had access to Lexis Nexis and I was always shocked how much information about people they have.
- license number
- license class
- license issue date
- license expiration date (birth day and month in my state)
- birth date
- eye color
- sex
- height
Are any of these very difficult to find?I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious.
I think IDScan should set something up so we can check if our data was compromised, at the least.
There are a number of companies (e.g. Delete Me) that offer that service. They wouldn't have caught the subject of this post since it was a breach.
The problem here arose from ID verification where you need to show your ID to an entity that then has the opportunity to store it.
Seems crazy until you realize politicians write the laws
Car dealerships. Heck, even the DMV. Sign up for Credit Karma? Enjoy credit card offers arriving to your house. It seems everyone is "in" on selling/sharing our data. If you ever read the terms of services, you'll usually see a "third party partners", or something like that, which mentions how they "share" your data.
Opt out should be the default, but it isn't.
[0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger.
AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out.
These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked.
The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.
Check out Estonia
The system is only as strong as its weakest link. ID cards can be faked and mobile devices can be stolen. Biometrics can't be easily faked, but they're horrible to have leaked because you can't change your fingerprints or eyeballs if compromised.
Yes, they do. Fundamentally this is because they don't spend enough money on security (like basically everybody else).
Some form of personal liability for executives is one (relatively simple) way to ensure that this becomes a priority, like SOX did for financial reporting.
There are other ways, but I do like the personal liability approach as its targeted, and has been used successfully in the past.
I suspect the reason for that (nothing other than a "gut feeling" that I get, seeing the story pushed off the front page so quickly, every time), is that the breach was through a backdoor that was deliberately coded into the system, for TLA use, and what happened, is exactly what people keep warning about; it got breached, and is now a "front door," and The Powers That Be don't want that examined too closely.
Also: many US states allow you to use a PO Box on your license (e.g: Calif., Tenn., Texas)
If we fix that, then having your ID stolen is a much, much smaller problem.
Personally, data security is the AI Doom I’m concerned about, not being turned into paperclips.