logoalt Hacker News

Nitiontoday at 3:51 AM4 repliesview on HN

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.


Replies

analog31today at 4:12 AM

I believe we need to criminalize possession of the data, with statutory damages per violation.

show 4 replies
maccam912today at 3:58 AM

It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.

show 1 reply
Aurornistoday at 4:55 AM

The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.

Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through

samlinnfertoday at 3:55 AM

The whole point is they keep it forever. You think any id verification services actually delete the data?

show 1 reply