Comments

Clive Robinson September 9, 2026 2:12 PM

@ Bruce, ALL,

“A database of 153 million drivers licenses is for sale on the dark web.”

Whilst this is not new, it’s previously required bugs and vulnerabilities be turned into attacks by humans.

Now it appears that “Current AI LLM Systems” can go through the process many many times faster than humans.

Thus we can expect the number of attacks against databases holding ID Documents to rapidly increase.

So we should ask a question,

“Is it wise or even sensible to hold databases of ID documents where attackers either external or internal to the holding organisation can reach them?”

A moment’s thought will show that the answer is “No but with exceptions”.

The exceptions being,

“To those carrying out a task where ID is actually required.”

Which surprising to many is very very few.

There has been a great stupidity in recent times of trying to make,

“ID compulsory for everything”

With any and every excuse used to force access to and storage of copies of ID documents.

The latest being for the faux excuse of the old,

“Think of the children”

Nonsense and “online access” to Web Sites.

Which by the way can not be stopped as I’ve previously pointed out there is always an exploitable gap between tangible physical objects and intangible information objects that always exists at the sensor.

But also children and adolescents are the ones smart enough to hack most systems anyway (as cyber-crime statistics show).

Thus we should “rethink” the continuous push for,

“Requirements for access to primary ID documents”

rather rapidly as the current state of affairs is well beyond a liability for each and every person.

Bob September 9, 2026 3:20 PM

I’m not sure how facilitating identity theft makes children safer. Might need a politician to explain it to me.

KC September 9, 2026 10:58 PM

From Brian’s article:
“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit.

Painful. An incredible real world exhibit on the realities of data collection. I’m sure many are eager to hear about more developments.

‘IDScan.net 🙁

Rontea September 10, 2026 9:16 AM

Until companies and regulators treat ID verification data as crown-jewel assets, breaches like Nexus will continue to compromise privacy and erode trust.

lurker September 10, 2026 2:07 PM

@Rontea, ALL

Data breaches are put in the open frequently because of petty feuds and a failure to recognize the importance of the data. After all, China does not run on private credit, and hence, your identity being stolen there is virtually meaningless, as meaningless as you having next to the biometric ID card data of all of their citizens.

Part of a long rant on the whack-a-mole problem, thanks @r for the heads-up.

https://news.ycombinator.com/item?id=49629221

push up champ September 10, 2026 10:00 PM

@Mexaly

Imagine what could be done with anyone’s record.

You might have heard that certain government officials (including at least one Secretary in the US federal cabinet) may have their IDs in the set of 153 million.

So I would wager that: judges, prosecutors, prison guards, law enforcement officers, and family members of all of these people, are also in the data set. Even if only because they went on vacation, rented a car, checked into a hotel, or did something else trivial that caused a clerk to scan their ID.

Security by obscurity only works when there isn’t a giant database already operating.

If James Bond was going to steal someone’s identity, he would steal from (as you say) small fishes and guppies. To put it another way, real life James Bonds blend in and look very boring. They drink beer rather than martinis. They don’t have sex lives that attract attention. They drive base model Chevrolets … at or below the speed limit.

Bob September 11, 2026 10:51 AM

As a general rule, when American Christians claim “discrimination,” they’re actually the ones discriminating.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.