The only way to fix this is to have us upload our IDs online constantly, perhaps to prove we are adults.
It is the only way we can we safe.
This is a most excellent place for technology news and articles.
The only way to fix this is to have us upload our IDs online constantly, perhaps to prove we are adults.
It is the only way we can we safe.
Woaha. Why didn't anyone think of this before you?
But, just think about the children! ~While everyone plastered their children allover social media and they are easily identified with AI~
Wait until non Americans hear that our national social security ID number is only 4/9 digits worth of “random” numbers. (Fun fact, the entire number was procedurally generated based on where you were born and in what order at the hospital for generations until they changed it recently)
The numbers aren't random. They are sequential. The early digits are assigned geographically, but the rest are in sequence. If you know a valid social security number, adding or subtracting 1 will be another valid social security number, most likely someone born in the same hospital on the same day.
They did change it somewhat recently, but they don't re-assign the numbers when making that change, so most of the numbers are completely insecure.
Yeah, we know. We just can't believe that you actually use it for anything important.
That stupid ass number is used as one of the identifying factors when financing anything. Yes, a house is bought and mortgaged with that number next to 2 other forms of ID lmao.
This is yet another reason why virtual ID cards are superior: In the event that the card data is compromised, the old virtual ID can be revoked and a new virtual ID can be issued. Virtual ID cards can also have a much shorter duration, because the cost of rotating it is minimal. For example, California's virtual driver licenses rotate each 30 days.
We honestly should be using virtual vouchers for everything. The question then becomes "whats one level up from the voucher i can steal" and we're very frustratingly (for my mental exercise) back at square 1
I bought a domain, configured the webserver in the next 5m.
As soon as it started taking requests (on a domain that i haven't even announced yet) it got flooded by bots.
Registering SSL is a centralized process with root CAs logging new ones as they come in. Cert transparency logs are a thing, and Google is very involved: https://certificate.transparency.dev/
Once a bad actor hooks up to that, they just get a realtime stream of places to start port scanning and running WHOIS queries for people who didn't get WHOIS protection. If you used letsencrypt your domains you registered certs for got sent there and anyone who wanted to know about it knew about it before you could tell anyone.
You can use something like crt.sh to look up domains
If your browser is based on chromium, you're employing an army of bots yourself that gets enabled each time you enter any domain.
Can you explain what you mean exactly?
I have had to rent cars since 2015. My license has probably been seen by 5000 breach sites by now.
At this rate, a new ID type will have to be used. I dont have a clue what, but a new one..
Welcome to Rent-a-car. Please sign into your vehicle with Facebook, Google or AppleID.
But don't forget guys, uploading your government IDs to any old fucking website to prove your age is very safe and protects children. There's no way this could go wrong and everyone in the supply chain is very trustworthy
Also it doesn't help that, for example, at U-Haul, employees just use their personal phone to scan a QR code and take pictures of your ID.
this idea that employees can expect you own and use a personal smartphone as part of the job irks the heck out of me.
I read that if you use a personal device for anything work related in the US, it means your entire personal device (everything on it) can be considered discovery in a lawsuit against that company. Big risk to take.
most companies want you to put on this software than can wipe your device. its nuts.
My local hospital apparently requires their employees to use a "secure" app on their personal phone to transmit data on the patients.
Seems like irresponsible handling of PHI (by the administration, not the staff) to me.
My elderly father recently fell for a Facebook imposter that pretended to be a family member and asked if their friend could contact him. The friend asked him to take a photo of his driver's license and text it to them, fortunately he doesn't know how. I've been wondering ever since what can they do if they had it? It doesn't have his social security number on it. His credit has since been locked and banks notified
I’ve been wondering ever since what can they do if they had it?
Ask for pictures of all his other paperwork so they can finish onboarding him at his new job.
They can open bank or crypto accounts in his name, and then either overdraw the account or use it to move money from other scams in and out of this account, so the real scammers name is not attached to this account.
Is there a way to block that? Ie: freezing your credit means no one can take a loan, but that doesn’t remove the scenario you described.
I don't like it when a store scans my driver's license to buy alcohol. I stick to small convenience stores without that tech.
Annnd this is why a refuse to verify with IDs online and use services like Plaid. And the web of T&C's from multiple 3rd party services like this will mean all of them get shielded from blame.
Did you read the article? They were renting a car. A car rental place isn't going to let you just not show your ID.
So how they did it once upon a time was you showed them your license, they punched the # into the system that would check it. The person at the desk would confirm it was you from the picture. No need to scan the actual ID card, which is where this problem comes from.
Luckily archive.org saved the idscan.net press release announcing their partnership with Planet13 dispensaries. They have since deleted the post on their site. Nothing shady about that. 😂
In addition to scanning and verification, VeriScan performs ID parsing to collect, separate, and classify information from the various fields on IDs. This allows Planet 13 to seamlessly harvest the names and demographic/geographic information of its guests. This data is providing insights into customer profiles, which is especially valuable as Planet 13 expands its footprint into other states, including supplementing its SuperStores with smaller, neighborhood retail shops.
I have no words.