TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

ID verification service for TikTok, Uber, X exposed driver licenses

432 pointsby brw11 months ago

33 comments

brw11 months ago
<a href="https:&#x2F;&#x2F;archive.is&#x2F;9ywDK" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;9ywDK</a>
alwa11 months ago
It says the company claimed that the credential leak was discovered and remediated 18 months ago, meanwhile the leaked credentials were still working as of a month ago.<p>Is this level of governance and sophistication really typical of vendors in this space? Sprawling enterprises I can imagine losing track of the odd place or two where the credentials are used, but a vendor who only does one thing, specifically a high-trust thing like this?<p>Even if they don’t have the wherewithal to be thorough in-house, am I confused to imagine that such a firm would have to carry insurance, which would tend to bring in specialists to make sure this kind of remediation is done right?
评论 #40816997 未加载
评论 #40813215 未加载
评论 #40817182 未加载
评论 #40815825 未加载
评论 #40818032 未加载
joshribakoff11 months ago
Uber wouldn’t delete my data when I demanded them to, they just hung up on me rudely. I escalated to the CEO and they sent me this message explaining why and assuring my fears of a data leak were “unfounded”:<p>Maribel again with Uber Support. Thank you for your patience while I took a further look at the deletion request. Unfortunately, we are unable to delete all of your information on the account due to security measures. Please visit our Privacy Notice for more details, specifically the sections titled E. Data retention and deletion. As of May 12, 2024, your account was marked for deletion. Keep in mind that deleting your driver account is permanent and will automatically delete your rider account as well. Any credits associated with your accounts will be lost. Additionally, I want to emphasize that we have strict security measures on the platform to ensure that your personal information and your safety are secured. Your understanding is appreciated.
评论 #40821732 未加载
评论 #40821181 未加载
neilv11 months ago
Of course they leaked the data. Any seasoned techie could&#x27;ve seen that coming from the start.<p>One of these days, some seasoned and principled lawyer, who knows a bit about tech, is going to get ticked off, and decide to make one of these companies truly pay for their gross negligence.<p>Then, gazing at the obliterated company, other companies will try to get legislation to let them let them off the hook, but some of those companies will decide the party of recklessness is probably over, and that they need to start acting responsibly and competently.
评论 #40814822 未加载
评论 #40815078 未加载
评论 #40815861 未加载
评论 #40815072 未加载
评论 #40815035 未加载
评论 #40816943 未加载
评论 #40816968 未加载
评论 #40820444 未加载
评论 #40814629 未加载
charles_f11 months ago
Security theater cycle at this is stage:<p>1. Develop features at any cost, over-collect data, neglect security<p>2. Hacker gets in, pick the entirety of the data made readily available, credit card numbers, social security numbers, prod credentials, sexual orientation predictions that the company made on their customers for some reason, all of the pay history of the company, instagram creds of the ceo&#x27;s girlfriend, and takes a dump in their bathroom<p>3. Try to shush the story<p>4. It gets exposed by an independent journalist in Kazakhstan who just reads &#x2F;r&#x2F;leaks<p>5. &quot;we recently discovered that a malicious individual got access to a few logs on a random test server. Oops! So far we didn&#x27;t find proof that it was used. Rest assured that security is our utmost priority. We love security here at ACME corp. Our teams have matching &#x27;security&#x27; shirts, and every thursday we pray to Glombo, the security god. As a gesture to our customers we offer everyone a free 2 week trial of our &#x27;security+&#x27; package ($15.99&#x2F;M after trial, don&#x27;t forget to cancel). Once again, sleep well knowing your data is safe with us!&quot;.<p>6. 6 months later the security gap is half plugged by an intern developing a novel password management system that encrypts passwords in base64<p>7. Go to 1. because no-one cares
评论 #40825195 未加载
JumpCrisscross11 months ago
Wow, look at that list of clients: eToro, Coinbase, Payoneer [1].<p>Is there any way to determine if your information was leaked? The driver&#x27;s license picture should qualify as biometric information under some states&#x27; laws [2].<p>[1] <a href="https:&#x2F;&#x2F;www.au10tix.com" rel="nofollow">https:&#x2F;&#x2F;www.au10tix.com</a><p>[2] <a href="https:&#x2F;&#x2F;www.huschblackwell.com&#x2F;2023-state-biometric-privacy-law-tracker" rel="nofollow">https:&#x2F;&#x2F;www.huschblackwell.com&#x2F;2023-state-biometric-privacy-...</a>
评论 #40813514 未加载
derbOac11 months ago
This all feels like some Orwellian nightmare to me. Things like TikTok and X shouldn&#x27;t require any ID verification in my mind; the rest of this fiasco just underscores all the other reasons why this is a bad idea.
评论 #40817048 未加载
评论 #40817355 未加载
评论 #40817108 未加载
评论 #40818308 未加载
评论 #40816745 未加载
astroid11 months ago
Didn&#x27;t X switch to Stripe already? There was a huge uproar over people protesting Palestine being concerned about having their ID (with home address), biometrics (which they admitted to collecting), and other info to a company with such direct ties to Israel.<p>I don&#x27;t know about this company specifically, but I know it&#x27;s common for the government to essentially act as an incubator for tech companies, so the concerns probably weren&#x27;t unwarranted.<p>I guess even with the switch, some people probably verified prior so it likely has some impact on X still -- and maybe this is actually what moved the needle internally, since the users were calling it out as a concern for quite some time.<p>I had no clue uber and tiktok used them though, so that&#x27;s good to know - thankfully I haven&#x27;t given them my biometrics as of yet.
评论 #40813409 未加载
treeFall11 months ago
Why are US citizens biometric identities being sent to Israel? Aren&#x27;t there laws about sensitive information like this leaving US data centers?
评论 #40817005 未加载
评论 #40815503 未加载
评论 #40815290 未加载
评论 #40816442 未加载
qchris11 months ago
I sometimes think that situations like this are eventually going to lead to legally-required professional licensing for certain tasks in software development.<p>Obviously, not everyone who writes code needs a development license (what, I&#x27;m going to get licensed to write a blog or put up a site with fruit jokes?&quot;), but if your business is going to involve personally-identifiable information, then you need actual engineering, and the folks that do that engineering need certification. This is a similar mechanism to how engineering licensing even started (in the US anyway), where Wyoming basically got tired of water infrastructure being built by people who didn&#x27;t know what they were doing.<p>Licensing could also help provide individual engineers with leverage against managers or C-suite folks who want to move fast &amp; break things. When you&#x27;re in a professional class with exclusive sign-off capabilities, it&#x27;s easier to be say &quot;we have to do this right or it&#x27;s my ass, back off&quot; and should the company says &quot;fine, you&#x27;re fired&quot;, goes ahead with managing the PII, and a leak like this happens, the company&#x27;s liability goes way way up. That situation overall tends to improve the leverage that skilled workers (like those who know how about database management for PII and endpoint configuration) have to do things right. There&#x27;s a number of pitfalls that can happen with licensing as well, but I&#x27;d be curious to see if a push for something like this emerges over the next few years.
评论 #40816068 未加载
评论 #40816560 未加载
评论 #40820393 未加载
评论 #40816767 未加载
评论 #40820019 未加载
评论 #40816478 未加载
评论 #40816368 未加载
评论 #40816771 未加载
bux9311 months ago
LinkedIn is badgering me to &quot;verify&quot; my identity using some app I&#x27;ve never heard every time I log on. I won&#x27;t, because this will inevitably happen, and Microsoft will shrug and blame the outside company.
steelframe11 months ago
I had to use one of these services once after I lost the MFA app for a domain registrar when switching phones. I wouldn&#x27;t be at all surprised if my driver&#x27;s license has been compromised from that company&#x27;s S3 bucket (or wherever they&#x27;re stuffing the images) since then. Regardless I was super-annoyed to have to jump through that hoop. The subsequent emails from them pleading with me to re-enable MFA have since gone straight to the bit bucket.
评论 #40820130 未加载
diebeforei48511 months ago
I&#x27;ve noticed that companies are generally happy to say they use (for example) Plaid to handle your bank account details, but often bury or hide who is handling your passport details.<p>This is unacceptable. If you want my ID, you&#x27;d better disclose who you&#x27;re sharing my ID with. And ideally give me a choice of providers.
评论 #40815318 未加载
gurchik11 months ago
&gt; While PII data was potentially accessible, based on our current findings, we see no evidence that such data has been exploited.<p>How is this possible, when the journalist accessed the data to confirm it contained PII?<p>Each day I am more and more interpreting &quot;we see no evidence&quot; as &quot;we didn&#x27;t really look.&quot; That way their statement can be technically correct, without divulging any evidence that might be used against them when users sue for damages.
评论 #40814178 未加载
评论 #40814543 未加载
mrweasel11 months ago
While we complain about it a lot, more and more I have come to appreciate the Danish governments online ID solution (MitID). It&#x27;s certainly not perfect, but it does allow you to do ID verification, without exposing PII to companies.<p>Understandably not everyone who needs to verify your identity is going to implement MitID, I can understand X not wanting to do that for the limited amount of users they have in Denmark. It&#x27;s simply not worth the cost. What I don&#x27;t get is why more countries doesn&#x27;t have this. The US sure seem like it would benefit greatly from having a standardized, safe and secure online ID (MitID may or may not be as secure as it could be).
评论 #40818583 未加载
评论 #40818507 未加载
评论 #40818518 未加载
dinglestepup11 months ago
&quot;Our customers’ security is of the utmost importance&quot;<p>They don&#x27;t even have 2FA enabled for logging into such a sensitive portal?
评论 #40815250 未加载
heavyset_go11 months ago
It&#x27;s going to be fun when there&#x27;s repeated incidents like this each week because every site will require your driver&#x27;s license to prove you&#x27;re 18 so you&#x27;re allowed to post on the internet.
leni53611 months ago
Does the ID verification service retain personal information after verification? If so, why?
评论 #40817116 未加载
评论 #40820108 未加载
评论 #40820827 未加载
frugalmail11 months ago
Recently there was mass infringement by the Democrat politicians or government reps of our 1st Amendment rights indirectly through social media as proven by the #TwitterFiles.<p>The fact that these sites are now forcing users to submit to these identity disclosures simply because of some potentially fabricated rationale is really concerning.<p>All of that with the nonchalant attitude of these data service providers, I&#x27;m deeply concerned.
hanniabu11 months ago
High-profile fintech partners: Mercury, Stripe, Affirm, Airwallex, Alloy, Bond (now part of FIS), Branch, Dave, EarnIn, TabaPay, and previously worked with Wise and Rho, though both have since migrated to other bank partners<p>Leaked account holder info: name &amp; address, email, phone, unencrypted SSN&#x2F;TIN, DOB, fintech platform<p>Leaked account info: status, type, balance, last activity, opened date, account number, daily limits
callalex11 months ago
What are the chances that anyone goes to prison for this? If the answer is “none” this will just keep happening.
stefan_11 months ago
Why on earth are these identity verification companies storing this data? Once the verification is done, the data must surely be promptly deleted?
评论 #40814649 未加载
miki12321111 months ago
I&#x27;m surprised identity verification by logging into your bank and&#x2F;or carrier isn&#x27;t more common in the US.<p>They have your data anyway, it&#x27;s much harder to impersonate somebody this way, it doesn&#x27;t require the verifying company to hire any workers to do the verification, you could even do it without the site you&#x27;re verifying yourself at learning anything about you.
评论 #40816387 未加载
评论 #40813674 未加载
评论 #40813815 未加载
评论 #40813609 未加载
lizardking11 months ago
My understanding is that X has moved on from AU10TIX to using stripe.
classified11 months ago
What better cracking target than the place where everyone stores their ID info?
matrix8711 months ago
I wonder if companies like coinbase use these authenticators as some kind of liability shield
1oooqooq11 months ago
can&#x27;t wait for id.me<p>if you don&#x27;t know id.me, it&#x27;s the new gatekeeper to your ID for any interaction with the USA govt in the near future. If you still don&#x27;t have one, you are just not poor enough. But the time will come. enjoy.
totorovirus11 months ago
this is why we need zero knowledge proof
neilv11 months ago
dupe: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40812118">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40812118</a>
评论 #40814530 未加载
StiffFreeze911 months ago
Beyond any ID theft - Oppress homeless who lost papers and can&#x27;t navigate replacing them. Under pay and abuse hard-working immigrant families.<p>_Papers, Please_ by Lucas Pope. _Engage and Evade_ by Asad L. Asad.
AzzyHN11 months ago
Shocker.
ryandrake11 months ago
It&#x27;s gotten to the point where if a company requires you to upload something to verify your identity, you should treat it as if that something is being posted visibly to the public internet, and decide based on that whether it is worth providing. Companies repeatedly demonstrate their inability to secure personal data that they obtain and store, while always issuing press releases about how &quot;we take security very seriously.&quot;
评论 #40814492 未加载
评论 #40815058 未加载
评论 #40813730 未加载
评论 #40815066 未加载
评论 #40815604 未加载
评论 #40814624 未加载
评论 #40816773 未加载
benreesman11 months ago
Jesus, let’s skip the foreplay and let the under-endowed cousins of someone important off with a warning and get tough on crime with some normal people.<p>inb4 the usual chorus of people who are rabid originalists when it’s a tech titan but concerned with the budget when it’s a kid who hasn’t invented Reardon Steel yet.<p>edit: I apologize for the low value comment. as someone who had their community devastated by synthetic opioids and spent all day reading people defend the Sackler family I was just lashing out at rich evil people and I apologize for the negative-signal comment.