Is your driver’s license on the dark web? | #deepweb


153 million U.S. drivers’ licenses were hacked and put up for sale on the Dark Web. That’s more than half of all licensed drivers. How that happened and what it says about who’s doing what with our data.

Guests

Alan Butler, executive director and president of the Electronic Privacy Information Center.

Edgar Whitley, professor in practice (Information Systems) at the London School of Economics and Political Science.

Also Featured

James Lee, president, Identity Theft Resource Center.


The version of our broadcast available at the top of this page and via podcast apps is a condensed version of the full show. You can listen to the full, unedited broadcast here:

Part I   

MEGHNA CHAKRABARTI: By now, and this is sad to say, most of us are used to hearing about large-scale data breaches of our personal information, and these go way back. Anyone remember back in 2013 when someone hacked three billion Yahoo accounts? Or in 2017, the credit rating agency Equifax discovered a data breach that revealed almost every identifying piece of information for 148 million people, including Social Security numbers, home addresses, dates of birth, driver’s license numbers.

In fact, I still have a credit check freeze in place with Equifax because of that. Or in 2021, more than 500 million Facebook users around the world got hacked. In 2024, a company called National Data, which does background checks, finally disclosed that some 2.9 billion pieces of information, including 900 million Social Security numbers, had been stolen from its servers.

Also in 2024, Change Health, part of United Healthcare Group, discovered that hackers gained access to medical records and other sensitive information for one 197 million people. And those are just a few, and only U.S.-based ones. When you consider global data breaches, the list goes on and on and includes billions of more pieces of stolen information.

Multiple billions. Which is why last month when James Lee, president of the Identity Theft Resource Center, when he learned of the latest major data breach, once again, it’s sad to say, but at first, he didn’t really give it a second thought.

JAMES LEE: When I first saw the post that Brian Krebs put out, I was like, “Oh that’s typical.”

CHAKRABARTI: Brian Krebs is an independent security reporter, and he’d reported some unusual activity on a Russian cybercrime forum called Exploit. Someone was attempting to sell a huge number of North American identity documents, and again, this didn’t really surprise James Lee because he already knew that driver’s license information had been stolen from a company called Assurance America back in July.

But then James took a closer look at Brian Krebs’s report.

LEE: I read it and realized it wasn’t just the data from driver’s licenses and some other kinds of credentials. It was the actual images. Then I went, “Hold on. This is a big deal,” because that fundamentally changes the dynamics of this kind of data breach.

CHAKRABARTI: A dark web group or service was offering to sell actual scans of more than 153 million driver’s licenses from the United States and Canada, as well as more than 10 million ID cards, travel documents, and medical cards. Now, the group is called NEXUS, and it said it had full scans of these documents. That includes copies of the front and back of driver’s licenses, not just the data on the licenses, and the scans included security features intended to deter counterfeiting, things like scatter plots and the barcodes from the back of the driver’s licenses.

James Lee says that means people who buy the scans could conceivably create full replicas of your government-issued ID, replicas that James says will be good enough to fool people and fool machines.

LEE: Now, you’ve got the full image of the driver’s license and these other credentials, and that’s just gonna make it that much easier, especially given the ability of AI to create these kind of documents very quickly and very accurately.

CHAKRABARTI: And James says that obviously that opens the floodgates to massive potential fraud.

LEE: I can use that to open up some kinds of benefits that are automatically available to people at state and local governments. I can apply for things like small business loans. I can apply for unemployment benefits. I can apply for anything online.

That is a very common kind of identity verification today.

CHAKRABARTI: NEXUS went dark after Brian Krebs’s initial post, but that doesn’t mean they’re not going to put that stuff back on the dark web. Krebs had already found his own driver’s license in the database when he wrote his initial report. He also found his mom’s driver’s license and a bunch of friends.

Now, 153 million driver’s licenses were up for sale. That’s more than half of all licensed drivers in this country, which means that really no one was immune. Even Defense Secretary Pete Hegseth’s license was up for grabs. Nexus was selling scans of Hegseth’s license for 100 bucks. So how did this happen?

Is it a new frontier in identity theft? How can people protect themselves? And why do these huge hacks keep happening to third-party companies that most of us know almost nothing about? Let’s turn to Alan Butler. He’s executive director and president of the Electronic Privacy Information Center. He joins us from Washington.

Alan, welcome to On Point.

ALAN BUTLER: Thanks for having me, Meghna.

CHAKRABARTI: So first of all, give us your assessment on what James Lee says, that this was a kind of a categorically different kind of data breach. Do you agree or disagree?

BUTLER: I agree. I think that the breach of the images and like forensic-level detail of identity documents is a fundamentally different thing than most of the breaches that most of us hear about every day.

CHAKRABARTI: Now let’s talk about the forensic-level part, because people might be thinking it’s still not going to be possible for folks to make like a physical plastic replica of a driver’s license from a scan. But that’s not really the issue here, right? Because I was thinking just the other day when I had to verify my identity literally with a car rental company, I just had to send them a picture of the front and back of my driver’s license, and that was good enough.

So that’s the kind of fraud we’re talking about?

BUTLER: That’s right. I think that there’s probably more sophisticated forms of fraud that can be done with the type of data that was obtained here, but I think in the most instances, just like you said, companies are asking for a copy. Sometimes it can just be a simple image that someone could capture from their phone of your driver’s license, and that’s enough to enable a whole bunch of forms of identity theft.

And I think there’s other significant risks of this breach as well.

CHAKRABARTI: Car rental seems to be the most benign of them all. Could you conceivably apply for loans online with this kind of info?

BUTLER: I think there’s major risk of new account fraud, and if you think about combining this data with AI tools, as James mentioned you can synthesize already synthesized voice, synthesized images, or even potentially video, even if there was some form of live verification to go along with the license.

Posting of these pictures and licenses puts so many different folks at risk.

Alan Butler

And I think that another set of risks that goes beyond identity theft is the identification risks to vulnerable communities. The posting of these pictures and licenses puts so many different folks at risk. Think about survivors of domestic abuse who are trying to escape abusive partners or people in witness protection who have had to adopt new identities, but now you have their face images posted with these identity documents.

Another set of risks that goes beyond identity theft is the identification risks to vulnerable communities.

Alan Butler

We already talked about military undercover. There’s I think so much abuse that is enabled by this hack.

CHAKRABARTI: Yeah. And I guess you’re getting to the really critical point here is that short of plastic surgery unlike a password, which you can change, you can’t really change your face.

BUTLER: That’s exactly right. I think the loss of access, and that’s part of what the level of detail in this breach puts at risk, right? Is that these IDs, because of Real ID standards, have facial recognition compatible detailed images in them. And that we’ve already seen instances with companies scraping, for example, facial images to build these databases and doing cross-matching now with this I think really opens it up to abuse.

CHAKRABARTI: Okay. So let’s talk a little bit more, Alan, about exactly how this happened because again, in not in all of the headline grabbing data breaches that I listed at the beginning, not third-party weak points weren’t in all of them, but it’s a recurring feature in these huge large scale breaches.

Now, from what I understand from Krebs’ original reporting that the weak point here was an identity verification platform, a company called IDScan.net. They’re based in Louisiana, and their entire business is to provide ID fraud protection, or excuse me, prevention. They do age and identity verification services, mobile ID scanners, things like that, and they work with fintech, gaming, education, transportation, hospitality, law enforcement, retail security.

They’ve got, what, I’m looking here, 20,000 locations across the United States. 21 million verifications go through this company every month according to the company itself. One would think that given the nature of their business, this would be a place where it would work overtime to keep the data that they’re handling secure, right?

BUTLER: You would certainly think so, but I think the problem is that companies aren’t adequately incentivized under our current legal and regulatory system to not only invest in security to protect the information they collect, but really to limit the amount of information they collect to only what they need and only keep it for as long as they need it.

Companies aren’t adequately incentivized under our current legal and regulatory system to not only invest in security to protect the information they collect.

Alan Butler

CHAKRABARTI: Do we know … I don’t know if you know any more about IDscan.net?

BUTLER: Not more than what was collected in Krebs’ initial reporting. But I think it’s unfortunately, as you noted, a trend that is all too common, where there’s a weak point in the chain of custody of our data, and hackers will find the weakest point and try to exploit it.

And that’s why we really need a much more robust and strong, both legal and technical protections for data that’s collected and, in most instances, for the most sensitive data to not store that data whenever possible.

CHAKRABARTI: Okay. We’re gonna get to the point that you made about if companies aren’t, in your view, adequately incentivized to really do everything they can to, keep one step ahead of hackers in the cybersecurity arms race.

But I do wanna note that the FBI is actually investigating this data breach. They have an official investigation going on. Also, sidebar, some of the driver’s licenses in the hack apparently belong to FBI agents. Do you think that an FBI investigation can bear fruit, Alan, or is it too little too late?

BUTLER: I think that it’s really hard to put the genie back in the bottle. When you have 150 million driver’s licenses posted on the dark web, probably already purchased or obtained by other folks, chasing that down is immeasurably harder than trying to prevent it in the first place.

And I think that one thing that really struck me in the reporting was the note at the end of the reporting about the response from IDscan.net, which is that they’re offering credit protection services, right? Credit protection services do not in any way compensate individuals from the loss of their driver’s license, given the nature of the risks that they face.

Credit protection services do not in any way compensate individuals from the loss of their driver’s license.

Alan Butler

Credit protection services only address a small sliver of the problems that are created by this breach.

Part II

CHAKRABARTI: By the way just as a side note, Alan, I’m just looking back at Brian Krebs’s report here. IDScan.net’s own documentation shows that it’s not just a sort of a visual image that their machines scan.

They also scan in infrared and ultraviolet light. And I think that’s one of the things that captures then all the sort of anti-counterfeiting technology, right?

BUTLER: Exactly.

CHAKRABARTI: Okay. So tell me, what are the justifications that these third-party companies give for not just doing sort of an instantaneous scan, verifying the document and then deleting the information?

Why do they keep them in these databases which turn out to repeatedly be the kind of weak points in, in the cybersecurity networks around the world?

BUTLER: I think you really rarely hear any meaningful justification for retaining that sort of data that can, as far as we can see, only do harm in keeping it other than a cost, right?

Like maybe it feels slightly more expensive to them upfront to build the system in a different way, but that’s why you need to impose costs on the back end if when these things happen. But I think also there’s a risk that a lot of companies see data as value to them, right? And they’re thinking to themselves down the line, “Oh, maybe we’ll … maybe this data will be something we can train on and use on, to do more research or to potentially sell down the line as a valuable asset.” And I think that’s really, showing an inadequacy in the legal restrictions and protections on this data.

CHAKRABARTI: Can you tell me more about that, Alan?

Because right now sticking with driver’s licenses, even though there was actually also other kinds of IDs that were in part of this hack, but driver’s license images, I’m gonna presume that right now, legally, you are not allowed to sell them.

BUTLER: I certainly hope not, but I think it depends unfortunately on exactly how the law is written in terms of what data these companies have.

And one trend that we’ve seen alarmingly in a number of other sectors is when a company, let’s say, goes bankrupt, one of their most valuable assets is their data. And bankruptcy sales can create ways to essentially extract the value from data even if technically the law prohibits, would prohibit its sale to a third party.

But I think there’s just too many instances nowadays where companies, again, see data as value and don’t see their main necessarily even business model as being selling, a service that incorporates security and privacy, but part of their business model is amassing more and more data.

CHAKRABARTI: Okay. So I wanna hold onto that thought and come back to it, because if we’re talking about incentives and how to use sort of the lever of the law to incentivize companies in the right direction, we’ll keep that in mind. But right now, you said a little earlier that there’s no incentive to really be as vigilant as possible.

Now, and I’m sure that companies in the industry would say, “That’s just not true. If we cannot be trustworthy with the information or the IDs that are given to us, then we will simply have no business model that any other company would want to engage with.” What’s your response to that?

BUTLER: I think that the proof is in the pudding here, in that if you were properly incentivized, then you wouldn’t let this happen, right?

And whatever mechanism it takes for you to not let this happen, whether it’s to impose additional technical and procedural safeguards, physical safeguards on your data systems, or whether it is to collect and store less of the data, you would find a way if you were adequately incentivized.

The amount of harm that’s done by allowing 150 million digital ID scans like this to be breached is so massively out of proportion to the cost of engineering a better system that there’s just no way that these companies are adequately incentivized if this is happening.

CHAKRABARTI: But so tell me more, though, because I think one thing that I’ve heard a lot in the public discourse around major hacks like this is that … and I used this phrase actually myself earlier in the show, which is, it’s just a hacker’s arms race right now. That every time cybersecurity, the white hats they take a step forward and they make systems more secure, the black hats come in and they’re like, “Nope, we found a way around this,” and that because it’s this constant arms race, that it’s just a matter of time before any one particular company falls prey to a major data breach like this.

Your thoughts on that?

BUTLER: I think when you get into the details of how companies incorporate best cybersecurity practices I think that there are, yes, a company could be breached. I think the question is, if a company is breached, what happens, right? Does the breach immediately give access to their most sensitive troves of data?

How are those data segmented? How are they limiting access of different roles? Not all breaches are created alike, and not all companies that suffer a breach are turning over access to the most sensitive data that they hold.

Not all breaches are created alike, and not all companies that suffer a breach are turning over access to the most sensitive data that they hold.

Alan Butler

CHAKRABARTI: By the way, with IDscan.net I think at this point in time they still haven’t actually … I’m looking back at their public releases for this month. They still haven’t said how this happened, and maybe they never will because I suppose that would just invite other hackers to try again. They just have said that they have determined that an unauthorized third party may have accessed and/or copied certain customer information, quote, “Stored within their accounts on the IDscan.net cloud.”

Does the cloud part bear special scrutiny, or is that kinda irrelevant these days, Alan?

BUTLER: I think it is relevant but common, right? So storing data in cloud services is pretty routine for all many different types of vendors right now, and the question is how is it stored and, again, what are you storing?

Because back to your earlier question, why in the world is this company storing these highly detailed images when all they’re doing is doing, supposedly is doing an upfront, verification step? I think that really undercuts any future claims they make about how reasonable this was.

CHAKRABARTI: Okay, one last question about the status quo right now around incentives and regulation, Alan. Because as I mentioned earlier, the FBI is doing an investigation. IDscan.net’s doing their own internal investigation. But are there any, I was gonna say sort of criminal punishments or charges that could be levied against a company if they are found that their security systems simply were inadequate to prevent a breach?

BUTLER: Yeah, that’s a great question. I’m not sure. Offhand I can’t think of specific criminal charges that the FBI has brought against a company that is breached, but I do think it really depends on exactly what happened and whether something could rise to the level of criminal negligence.

But I think that they’re frequently in discussing, future potential what the law should look like question of accountability and remedies is really central.

CHAKRABARTI: And this is getting to an interesting question. What does negligence look like? What does criminal negligence look like in these cases?

Because, I very much believe the line of thinking that a company like IDscan.net is the victim, right? It’s one of the victims of this data breach, of this hack. But on the other hand, there is a certain minimal level of vigilance that we would expect from a company that’s handling such sensitive data.

So maybe we can talk about better ways to define what negligence is in cases of data breaches a little later in the show.

CHAKRABARTI: But Alan, hang on here for a second because I want to now bring Edgar Whitley into the conversation. He’s a professor in practice of information systems at the London School of Economics and Political Science, and he’s spent decades examining how governments and societies navigate these complexities of digital identity, data, and trust.

Professor Whitley, welcome to On Point.

CHAKRABARTI: Thank you. Can you first give me just your broad thoughts on this specific hack that happened with IDscan.net?

Your thoughts of it. Is it categorically different from others? You heard what Alan Butler had to say.

EDGAR WHITLEY: Yeah, I think the kind of distinguishing feature of this particular breach is the inclusion of the images.

So this is not just your email address, your date of birth, your Social Security number, but I think the really interesting additional element is the image and also the fact that in a large number of cases, these were images of Real ID approved driving driver’s licenses.

So the photograph that would be on, that was being stored and that’s then been leaked is a really high-quality photograph. So in the UK when you apply for a passport, you have to have a clear background for your photo. You’re not allowed to smile. There’s a whole load of things that make the image as high a quality as possible.

And the breach now reveals that the hackers and anybody who’s bought the data from them has a database of really high-quality, government-standard approved images of millions and millions of U.S. and Canadian drivers.

Anybody who’s bought the data from them has a database of really high-quality … images of millions and millions of U.S. and Canadian drivers.

Edgar Whitley

CHAKRABARTI: Okay. So in the UK, Professor Whitley you have been active.

You’ve given evidence to the Home Affairs Committee on, I think it’s the current government’s plan to roll out a digital identity system. Can you tell us a little bit about that?

WHITLEY: Yeah. So it’s the current government, but the plans have changed … because we’ve just got a new prime minister. … So in the UK, like in the U.S., we don’t currently have a national ID card, as is common in many European countries.

We still obviously have to do a lot of things online, and there had been proposals a year and a half ago, two years ago now to have a government-issued ID and to make it mandatory for everybody to have one. And so the parliamentary inquiry was exploring what the issues around the way that the government was making those particular proposals.

Then after Keir Starmer stepped down and Andy Burnham took over as Prime Minister, and I know he’s in New York at the UN today, one of the first things he said was to scrap that current plan for a government issued ID essentially because there was so many other things that the government wanted to do, that something that was unpopular, that would be a longer term change, that would be relatively costly for different government departments to implement and to adjust their systems to.

He decided that was one fight that he wasn’t prepared to have right now, so he scrapped that version of the proposals.

CHAKRABARTI: Actually, Professor may I just jump in here for a second? Because this is a very important point. In the government’s attempt to come up with a new ID system that would ostensibly be more secure, it was supposed to be a government issued digital ID.

I’m seeing here, this is reporting from the Electronic Frontier Foundation that some 3 million Britons signed a petition calling for an end to those plans. That’s the debate, that’s the controversy you’re talking about, and civil society organizations also rallied against the plan. Obviously, the deep concern was regarding that would allow the government to possibly intrude on civil liberties of people in the UK, and that seems like actually quite a justifiable concern.

WHITLEY: Yeah. As I say, there was a large number of that petition with nearly 3 million. The government inquiry that I gave evidence to had a very large number of written submissions just from citizens concerned about the proposal.

Apparently it wasn’t the largest number of submissions. The assisted dying bill in the UK got more submissions  because even more people were worried about that, but it was number two in terms of issues that were of concern. And the big issue with many of those concerns was, okay, government issuing you a credential rather than a private company issuing you a credential is a political choice.

But it was also a question, if you’re gonna put a photo on there, where is that photo going to be stored? How is that photo going to be used? Can you be sure that the government can keep the photographs of all of the people who’ve been issued with one of these IDs secure? And then there were reports that possibly some of the software developers who were onboarded to help develop that system hadn’t necessarily done the full security checking, and they potentially had access to all of the systems and et cetera, et cetera.

So there’s unease at various levels across society about the proposals.

CHAKRABARTI: Tell me if I’m using this British idiom incorrectly, but it seems like everything went pear-shaped.

WHITLEY: Yes.

CHAKRABARTI: But so you actually, you anticipated the question I was gonna ask, which is, okay, if just the civil liberties question aside, that’s for another show, which we’ll come back to, I’m sure, sometime in the future. But the data security side, it seems like the concern was there’s no guarantee that just because it was a government-issued, a federal nationally issued government ID for every person in the UK, even though this isn’t happening, that they would manage to keep that data any more secure than, here in the United States ID, the company, IDScan.net was able to keep things secure. That seems like a very fair and kind of cogent criticism.

WHITLEY: There’s an argument that public sector is lots of government systems are effectively parts of the critical national infrastructure. We, like the U.S., have a national cybersecurity center who spend a lot of time worrying about these kinds of things.

And so key systems, tax records, health records, are pretty, pretty secure. Nobody’s going to say that they are perfectly secure. But to be fair, there is an argument that says governments should have the capability of keeping that data pretty secure. I think the really interesting thing, case for this one was, okay, you get a private company to do the checking.

This is not the issuing of the cards. This is the checking of the cards. But as Alan was saying, why do they need to keep a record … of every card that they check? And that’s the possibility of seeing all of that data … that you could then sell, particularly if you go bust.

I like the metaphor of, don’t see data as oil, but see data as asbestos, and we have good processes in organizations. If you’ve got a whole load of asbestos in your organization, you really manage it and keep it carefully clean and stuff like that. And so the really big question is why were they … so you get a private company to do your ID checks, to check that this person is who they claim to be, et cetera, et cetera, but why are they storing all of the data? And why are they storing all of the data, it would seem, in essentially one system? Which, once you’ve hacked, you’ve got access to all of them.

Part III

CHAKRABARTI: Alan, I just wanted to hear your thoughts on what Professor Whitley was saying a little bit earlier about the UK government had considered doing some kind of national ID, but in a sense, some of the very same security concerns popped up there that do with private companies here.

How would we plausibly move forward?

BUTLER: Sure, yeah. I think that the experience in the UK really underscores the fact that when it comes to identification, we really need to think bigger and differently, right? We can’t just simply carry forward systems designed for old sort of like physical federated IDs issued by state or municipal governments and say, “We’ll just turn these things digital,” with all their existing flaws, right?

I think if we’re going to do ID and identification in a digital context, we need to take advantage of the advances in privacy and security technology that have been made over the last decades and really make those systems work better for both privacy and security, which I really do think go hand-in-hand.

And I think that it is possible to have safer, more secure and private identity systems.

CHAKRABARTI: Okay. Before we get to further solutions, I want to ask you both, because we keep coming back to this, why were the question of why was this data stored? Why did why did IDscan.net keep those driver’s licenses for an indefinite amount of time?

I’m just trying to think of plausible explanations for it. Maybe they need to go back and occasionally do audits of their own systems, and it’s very hard, if not impossible, to audit accounts if they don’t have the original the scans. Or maybe they need to do evaluations of how good their scanning system is, and using data they already have is a helpful way to improve those systems.

Professor Whitley your thoughts on that?

WHITLEY: Yeah. So it’s clear that organizations will need to do some form of audit, but realistically, you’re not going to audit all 150 million records that you have. And even if you do have to have a large sample for your auditing processes as Alan was saying, we do have technological solutions that allow you to store that data in a much more secure way, and ideally not on your main system.

It may be complete, once you’ve done the check, if you are keeping it, and I still have a big concern about whether you should be keeping it at all. But if you are keeping a record, because you could have a record that just says, “We checked Edgar’s driving license on the 22nd of September, and we got the confirmation that it was all legit.”

That doesn’t mean that we need to keep a copy of the image that we’ve got. So there’s a big kind of process question, but it’s also an architecture question about how, what are you collecting, where are you storing it? Even if you acknowledge that you need to have an audit, you can still do much more privacy-friendly audits for those rare occasions when you do need to do that.

CHAKRABARTI: Okay. Hang on, professor. Let’s backtrack to something you said just a second ago. There are much better technologies to keep this kind of data secure that these technologies exist right now?

WHITLEY: Yeah. They’re not necessarily mass scale. They’re not necessarily things that you would want to explain to your grandma how to use because they do get a little bit complicated and a little bit sophisticated.

But we’ve known for kind of 20-odd years that there are what are known as cryptographic techniques that allow you to prove things about yourself without disclosing almost anything about you. The particular challenge in this case is it seems that some of these checks are not just the data about you, but somebody either explicitly or potentially looks at your face and looks at your document and says, “Yeah, it’s probably the same person,” even if your photo is 10 years old, et cetera.

And of course, if you did that electronically with a digital camera as you get at passport gates at airports, then you’ve got that real check. But again, you don’t need to store the data. So yeah, there are things available that allow you to prove things about yourself without having to share lots of data and therefore not storing lots of data and therefore not running the risk of that data being leaked in the future.

CHAKRABARTI: Okay so just to clarify, these cryptographic techniques you’re talking about are for ID verification or verifying who you are. The cryptographic techniques are not necessarily for keeping stored data more secure.

WHITLEY: But the underlying technology can also store whatever you have ended up keeping so that, again … so if you have an audit trail of Edgar, 22nd of September, et cetera, you can store that in a way that doesn’t reveal that it was Edgar Whitley on the 22nd of September, et cetera, et cetera. So the technologies apply at multiple levels through the process.

CHAKRABARTI: So Alan Butler, let me just briefly turn back to you here, because I gotta ask the obvious question. If better technologies are available, why aren’t they in wider use? Or am I being unfair and we’re just … since we talk about this every time there’s a single huge data breach, we’re ignoring the fact that most of the time maybe our data is more secure than this conversation would let people, would lead people to believe?

BUTLER: I’m going to start by going back to your previous question, which is why did this company specifically store these images? Even though I think in this conversation we all come to the conclusion that that doesn’t seem to make any sense and makes everything, puts everything at risk. And I think the simplest answer has to be because no one told them not to.

And I think it’s the same answer to the question of why don’t we have implement implemented more secure technologies more often? And I think it’s because many companies are not required to implement them, right? And the best-case scenario is that the company feels obligated, as you indicated earlier, through their social perception of their business or maybe their vendor agreements upstream to implement stronger standards to meet a certain, security certification level.

But I think when it comes to identity verification Processes specifically, right? Which is where this data is coming from. I think there to the professor’s point we need to have more privacy protective processes and identity verification in order to avoid this data really ever existing at all.

I think at this point we look back and we say, “No one should have 150 million copies of driver’s licenses.” That is by, I think, indication, not a secure practice and not a privacy preserving practice. So how do we get digital verification to work without that happening?

CHAKRABARTI: Yeah, the elegant simplicity of it is undeniable, right?

You can’t breach data that doesn’t exist on, or stored somewhere on the cloud or on servers. Okay, so Alan and Edgar, hang on here for a second, because I wanna turn back to James Lee, who we heard at the very top of the show. He is the president of the Identity Theft Resource Center, and he had some more thoughts to share with us, particularly that this nation, the United States, is in dire need of new laws around how data breaches are disclosed.

LEE: We built the data breach notification system 20-plus years ago when we were talking about essentially paper documents and information on paper documents.

CHAKRABARTI: Okay, so that old notification system was designed for its time, to notify people if a data file, a physical disc, or something like a laptop went missing.

20 years later, who carries around a disc? Our data vulnerability extends everywhere, as we’ve been talking about, and flows through companies we may not even know have access to our sensitive identifying information.

LEE: The individual whose driver’s license was scanned, they don’t even know this company exists.

And that company has so many images that when it was breached, the state law there says if it’s more than 100,000 individuals or it costs more than $100,000 to notify everybody, you don’t have to notify them individually. All you have to do is put a notice on your website, which nobody knows to go to, and send a news release to the media in your state.

CHAKRABARTI: And by the way, the company IDscan.net is based in Louisiana. The original data breach laws were … pieced together state by state. That’s why the state law issue here is really important. And James Lee says they need to be restructured on a national scale.

LEE: So where you live does not determine if you are notified, and if you are notified, what you find about the breach, what was done to protect you. What’s done to make sure it doesn’t happen again, and then what resources are available to you to protect yourself.

It shouldn’t matter where you live for those kind of issues to be addressed.

CHAKRABARTI: And just like Alan Butler said earlier, James Lee also believes that companies are still reluctant to disclose in a timely manner when they have been compromised. So he’d like to see rules that push companies to inform people quickly and clearly if they’re victims of a data breach.

LEE: We also need to revisit in a way that we don’t have to wait for somebody to find this information on the dark web, or we don’t have to wait for a company to necessarily go through a months-long, or in some cases years-long forensic investigation before we find out. We’ve got to have a different way of looking at this.

CHAKRABARTI: And once again, we’re living in a world where so much of our lives are online, whether we like it or not. And so for James, that makes this a national security issue, which requires national security level protection.

LEE: Everybody’s got to get involved in this and have a very different kind of discussion, or we’re going to keep seeing what we have seen for the last several years, and that is the slow but steady escalation every year of more and more data breaches that impact more and more people.

CHAKRABARTI: That’s James Lee. He’s president of the Identity Theft Resource Center. So Alan Butler, you’ve said this a couple of times, and now finally I’m going to let you elaborate. What sort of legal levers or new legal systems could be created to, as you said, incentivize companies to do a much better job to protect our data?

BUTLER: My organization, the Electronic Privacy Information Center, has been advocating for a number of years for a strong privacy and security standard. We commonly refer to these rules as data minimization rules, meaning not only that companies should limit the data they collect, to what is actually necessary to provide the goods and services that they offer, but should also ensure that data is only retained as long as it is needed and that it is secured in the most robust way.

And that, for example, in this context would, I think, go directly to this question of why was it necessary for this company to store copies of these images and technical details of these driver’s licenses whereas currently, for example, state attorneys general might have to, or the FBI or the United States might have to investigate whether that was an unfair or deceptive business practice, which is a much, you know, vaguer and less clearly applicable standard, or might have to rely on some of the weaker privacy laws, for example, that require companies to notify users of the data that they collect and the standards that they impose, which really doesn’t provide protection.

CHAKRABARTI: So just to be clear about this, would you advocate for, let’s say a federal law that would say, “No matter what company you are out there in the United States, you can scan or, process identifying information in order to do your business, but you cannot store things like driver’s licenses, Social Security numbers, address, et cetera”?

You just simply cannot store them.

BUTLER: I think that there’s the two answers to that question. I think first I think we do need more specific regulations in place on impermissibly dangerous data collection and storage practices, and it I think probably would be the case that, for example, storing copies of identity documents, absent very narrow set of circumstances, just shouldn’t be permitted.

But we also need to have a flexible standard that can address future data collection practices that either don’t exist or maybe we don’t know about.

CHAKRABARTI: Okay. But creating standards for something that doesn’t yet exist seems to be a mighty big ask.

BUTLER: It’s a challenging thing in the law, and it’s not unique to privacy, but I think it is very clearly present every time we’re talking about creating or updating a privacy law, is how is this gonna work in five years or 10 years when the world looks very different?

CHAKRABARTI: Okay. I would also say that in the United States, the federal government issuing such a broad new rule or law that would prevent companies from storing certain kinds of data would be met with a great deal of corporate pushback, as they’d see it as the federal government interfering with the process of doing business.

But Edgar Whitley, we only have about 30 seconds left, I’m afraid. What’s the one next step that you would recommend to keep data more secure?

WHITLEY: So another way of looking at that problem that doesn’t involve states versus the central government is to change or to educate the procurement practices of the companies that are buying these services.

So a smart procurer, a smart a car rental firm might go along and say, “Are you storing images of the driving licenses that we are asking you to check? If you are, walk away. We’re not going to use you as a service.” So that’s another way of changing those kinds of dynamics. But that requires people to understand what the risks are and what the potential solutions and options are as well.

The first draft of this transcript was created by Descript, an AI transcription tool. An On Point producer then thoroughly reviewed, corrected, and reformatted the transcript before publication. The use of this AI tool creates the capacity to provide these transcripts.



Source link


153 million U.S. drivers’ licenses were hacked and put up for sale on the Dark Web. That’s more than half of all licensed drivers. How that happened and what it says about who’s doing what with our data.

Guests

Alan Butler, executive director and president of the Electronic Privacy Information Center.

Edgar Whitley, professor in practice (Information Systems) at the London School of Economics and Political Science.

Also Featured

James Lee, president, Identity Theft Resource Center.


The version of our broadcast available at the top of this page and via podcast apps is a condensed version of the full show. You can listen to the full, unedited broadcast here:

Part I   

MEGHNA CHAKRABARTI: By now, and this is sad to say, most of us are used to hearing about large-scale data breaches of our personal information, and these go way back. Anyone remember back in 2013 when someone hacked three billion Yahoo accounts? Or in 2017, the credit rating agency Equifax discovered a data breach that revealed almost every identifying piece of information for 148 million people, including Social Security numbers, home addresses, dates of birth, driver’s license numbers.

In fact, I still have a credit check freeze in place with Equifax because of that. Or in 2021, more than 500 million Facebook users around the world got hacked. In 2024, a company called National Data, which does background checks, finally disclosed that some 2.9 billion pieces of information, including 900 million Social Security numbers, had been stolen from its servers.

Also in 2024, Change Health, part of United Healthcare Group, discovered that hackers gained access to medical records and other sensitive information for one 197 million people. And those are just a few, and only U.S.-based ones. When you consider global data breaches, the list goes on and on and includes billions of more pieces of stolen information.

Multiple billions. Which is why last month when James Lee, president of the Identity Theft Resource Center, when he learned of the latest major data breach, once again, it’s sad to say, but at first, he didn’t really give it a second thought.

JAMES LEE: When I first saw the post that Brian Krebs put out, I was like, “Oh that’s typical.”

CHAKRABARTI: Brian Krebs is an independent security reporter, and he’d reported some unusual activity on a Russian cybercrime forum called Exploit. Someone was attempting to sell a huge number of North American identity documents, and again, this didn’t really surprise James Lee because he already knew that driver’s license information had been stolen from a company called Assurance America back in July.

But then James took a closer look at Brian Krebs’s report.

LEE: I read it and realized it wasn’t just the data from driver’s licenses and some other kinds of credentials. It was the actual images. Then I went, “Hold on. This is a big deal,” because that fundamentally changes the dynamics of this kind of data breach.

CHAKRABARTI: A dark web group or service was offering to sell actual scans of more than 153 million driver’s licenses from the United States and Canada, as well as more than 10 million ID cards, travel documents, and medical cards. Now, the group is called NEXUS, and it said it had full scans of these documents. That includes copies of the front and back of driver’s licenses, not just the data on the licenses, and the scans included security features intended to deter counterfeiting, things like scatter plots and the barcodes from the back of the driver’s licenses.

James Lee says that means people who buy the scans could conceivably create full replicas of your government-issued ID, replicas that James says will be good enough to fool people and fool machines.

LEE: Now, you’ve got the full image of the driver’s license and these other credentials, and that’s just gonna make it that much easier, especially given the ability of AI to create these kind of documents very quickly and very accurately.

CHAKRABARTI: And James says that obviously that opens the floodgates to massive potential fraud.

LEE: I can use that to open up some kinds of benefits that are automatically available to people at state and local governments. I can apply for things like small business loans. I can apply for unemployment benefits. I can apply for anything online.

That is a very common kind of identity verification today.

CHAKRABARTI: NEXUS went dark after Brian Krebs’s initial post, but that doesn’t mean they’re not going to put that stuff back on the dark web. Krebs had already found his own driver’s license in the database when he wrote his initial report. He also found his mom’s driver’s license and a bunch of friends.

Now, 153 million driver’s licenses were up for sale. That’s more than half of all licensed drivers in this country, which means that really no one was immune. Even Defense Secretary Pete Hegseth’s license was up for grabs. Nexus was selling scans of Hegseth’s license for 100 bucks. So how did this happen?

Is it a new frontier in identity theft? How can people protect themselves? And why do these huge hacks keep happening to third-party companies that most of us know almost nothing about? Let’s turn to Alan Butler. He’s executive director and president of the Electronic Privacy Information Center. He joins us from Washington.

Alan, welcome to On Point.

ALAN BUTLER: Thanks for having me, Meghna.

CHAKRABARTI: So first of all, give us your assessment on what James Lee says, that this was a kind of a categorically different kind of data breach. Do you agree or disagree?

BUTLER: I agree. I think that the breach of the images and like forensic-level detail of identity documents is a fundamentally different thing than most of the breaches that most of us hear about every day.

CHAKRABARTI: Now let’s talk about the forensic-level part, because people might be thinking it’s still not going to be possible for folks to make like a physical plastic replica of a driver’s license from a scan. But that’s not really the issue here, right? Because I was thinking just the other day when I had to verify my identity literally with a car rental company, I just had to send them a picture of the front and back of my driver’s license, and that was good enough.

So that’s the kind of fraud we’re talking about?

BUTLER: That’s right. I think that there’s probably more sophisticated forms of fraud that can be done with the type of data that was obtained here, but I think in the most instances, just like you said, companies are asking for a copy. Sometimes it can just be a simple image that someone could capture from their phone of your driver’s license, and that’s enough to enable a whole bunch of forms of identity theft.

And I think there’s other significant risks of this breach as well.

CHAKRABARTI: Car rental seems to be the most benign of them all. Could you conceivably apply for loans online with this kind of info?

BUTLER: I think there’s major risk of new account fraud, and if you think about combining this data with AI tools, as James mentioned you can synthesize already synthesized voice, synthesized images, or even potentially video, even if there was some form of live verification to go along with the license.

Posting of these pictures and licenses puts so many different folks at risk.

Alan Butler

And I think that another set of risks that goes beyond identity theft is the identification risks to vulnerable communities. The posting of these pictures and licenses puts so many different folks at risk. Think about survivors of domestic abuse who are trying to escape abusive partners or people in witness protection who have had to adopt new identities, but now you have their face images posted with these identity documents.

Another set of risks that goes beyond identity theft is the identification risks to vulnerable communities.

Alan Butler

We already talked about military undercover. There’s I think so much abuse that is enabled by this hack.

CHAKRABARTI: Yeah. And I guess you’re getting to the really critical point here is that short of plastic surgery unlike a password, which you can change, you can’t really change your face.

BUTLER: That’s exactly right. I think the loss of access, and that’s part of what the level of detail in this breach puts at risk, right? Is that these IDs, because of Real ID standards, have facial recognition compatible detailed images in them. And that we’ve already seen instances with companies scraping, for example, facial images to build these databases and doing cross-matching now with this I think really opens it up to abuse.

CHAKRABARTI: Okay. So let’s talk a little bit more, Alan, about exactly how this happened because again, in not in all of the headline grabbing data breaches that I listed at the beginning, not third-party weak points weren’t in all of them, but it’s a recurring feature in these huge large scale breaches.

Now, from what I understand from Krebs’ original reporting that the weak point here was an identity verification platform, a company called IDScan.net. They’re based in Louisiana, and their entire business is to provide ID fraud protection, or excuse me, prevention. They do age and identity verification services, mobile ID scanners, things like that, and they work with fintech, gaming, education, transportation, hospitality, law enforcement, retail security.

They’ve got, what, I’m looking here, 20,000 locations across the United States. 21 million verifications go through this company every month according to the company itself. One would think that given the nature of their business, this would be a place where it would work overtime to keep the data that they’re handling secure, right?

BUTLER: You would certainly think so, but I think the problem is that companies aren’t adequately incentivized under our current legal and regulatory system to not only invest in security to protect the information they collect, but really to limit the amount of information they collect to only what they need and only keep it for as long as they need it.

Companies aren’t adequately incentivized under our current legal and regulatory system to not only invest in security to protect the information they collect.

Alan Butler

CHAKRABARTI: Do we know … I don’t know if you know any more about IDscan.net?

BUTLER: Not more than what was collected in Krebs’ initial reporting. But I think it’s unfortunately, as you noted, a trend that is all too common, where there’s a weak point in the chain of custody of our data, and hackers will find the weakest point and try to exploit it.

And that’s why we really need a much more robust and strong, both legal and technical protections for data that’s collected and, in most instances, for the most sensitive data to not store that data whenever possible.

CHAKRABARTI: Okay. We’re gonna get to the point that you made about if companies aren’t, in your view, adequately incentivized to really do everything they can to, keep one step ahead of hackers in the cybersecurity arms race.

But I do wanna note that the FBI is actually investigating this data breach. They have an official investigation going on. Also, sidebar, some of the driver’s licenses in the hack apparently belong to FBI agents. Do you think that an FBI investigation can bear fruit, Alan, or is it too little too late?

BUTLER: I think that it’s really hard to put the genie back in the bottle. When you have 150 million driver’s licenses posted on the dark web, probably already purchased or obtained by other folks, chasing that down is immeasurably harder than trying to prevent it in the first place.

And I think that one thing that really struck me in the reporting was the note at the end of the reporting about the response from IDscan.net, which is that they’re offering credit protection services, right? Credit protection services do not in any way compensate individuals from the loss of their driver’s license, given the nature of the risks that they face.

Credit protection services do not in any way compensate individuals from the loss of their driver’s license.

Alan Butler

Credit protection services only address a small sliver of the problems that are created by this breach.

Part II

CHAKRABARTI: By the way just as a side note, Alan, I’m just looking back at Brian Krebs’s report here. IDScan.net’s own documentation shows that it’s not just a sort of a visual image that their machines scan.

They also scan in infrared and ultraviolet light. And I think that’s one of the things that captures then all the sort of anti-counterfeiting technology, right?

BUTLER: Exactly.

CHAKRABARTI: Okay. So tell me, what are the justifications that these third-party companies give for not just doing sort of an instantaneous scan, verifying the document and then deleting the information?

Why do they keep them in these databases which turn out to repeatedly be the kind of weak points in, in the cybersecurity networks around the world?

BUTLER: I think you really rarely hear any meaningful justification for retaining that sort of data that can, as far as we can see, only do harm in keeping it other than a cost, right?

Like maybe it feels slightly more expensive to them upfront to build the system in a different way, but that’s why you need to impose costs on the back end if when these things happen. But I think also there’s a risk that a lot of companies see data as value to them, right? And they’re thinking to themselves down the line, “Oh, maybe we’ll … maybe this data will be something we can train on and use on, to do more research or to potentially sell down the line as a valuable asset.” And I think that’s really, showing an inadequacy in the legal restrictions and protections on this data.

CHAKRABARTI: Can you tell me more about that, Alan?

Because right now sticking with driver’s licenses, even though there was actually also other kinds of IDs that were in part of this hack, but driver’s license images, I’m gonna presume that right now, legally, you are not allowed to sell them.

BUTLER: I certainly hope not, but I think it depends unfortunately on exactly how the law is written in terms of what data these companies have.

And one trend that we’ve seen alarmingly in a number of other sectors is when a company, let’s say, goes bankrupt, one of their most valuable assets is their data. And bankruptcy sales can create ways to essentially extract the value from data even if technically the law prohibits, would prohibit its sale to a third party.

But I think there’s just too many instances nowadays where companies, again, see data as value and don’t see their main necessarily even business model as being selling, a service that incorporates security and privacy, but part of their business model is amassing more and more data.

CHAKRABARTI: Okay. So I wanna hold onto that thought and come back to it, because if we’re talking about incentives and how to use sort of the lever of the law to incentivize companies in the right direction, we’ll keep that in mind. But right now, you said a little earlier that there’s no incentive to really be as vigilant as possible.

Now, and I’m sure that companies in the industry would say, “That’s just not true. If we cannot be trustworthy with the information or the IDs that are given to us, then we will simply have no business model that any other company would want to engage with.” What’s your response to that?

BUTLER: I think that the proof is in the pudding here, in that if you were properly incentivized, then you wouldn’t let this happen, right?

And whatever mechanism it takes for you to not let this happen, whether it’s to impose additional technical and procedural safeguards, physical safeguards on your data systems, or whether it is to collect and store less of the data, you would find a way if you were adequately incentivized.

The amount of harm that’s done by allowing 150 million digital ID scans like this to be breached is so massively out of proportion to the cost of engineering a better system that there’s just no way that these companies are adequately incentivized if this is happening.

CHAKRABARTI: But so tell me more, though, because I think one thing that I’ve heard a lot in the public discourse around major hacks like this is that … and I used this phrase actually myself earlier in the show, which is, it’s just a hacker’s arms race right now. That every time cybersecurity, the white hats they take a step forward and they make systems more secure, the black hats come in and they’re like, “Nope, we found a way around this,” and that because it’s this constant arms race, that it’s just a matter of time before any one particular company falls prey to a major data breach like this.

Your thoughts on that?

BUTLER: I think when you get into the details of how companies incorporate best cybersecurity practices I think that there are, yes, a company could be breached. I think the question is, if a company is breached, what happens, right? Does the breach immediately give access to their most sensitive troves of data?

How are those data segmented? How are they limiting access of different roles? Not all breaches are created alike, and not all companies that suffer a breach are turning over access to the most sensitive data that they hold.

Not all breaches are created alike, and not all companies that suffer a breach are turning over access to the most sensitive data that they hold.

Alan Butler

CHAKRABARTI: By the way, with IDscan.net I think at this point in time they still haven’t actually … I’m looking back at their public releases for this month. They still haven’t said how this happened, and maybe they never will because I suppose that would just invite other hackers to try again. They just have said that they have determined that an unauthorized third party may have accessed and/or copied certain customer information, quote, “Stored within their accounts on the IDscan.net cloud.”

Does the cloud part bear special scrutiny, or is that kinda irrelevant these days, Alan?

BUTLER: I think it is relevant but common, right? So storing data in cloud services is pretty routine for all many different types of vendors right now, and the question is how is it stored and, again, what are you storing?

Because back to your earlier question, why in the world is this company storing these highly detailed images when all they’re doing is doing, supposedly is doing an upfront, verification step? I think that really undercuts any future claims they make about how reasonable this was.

CHAKRABARTI: Okay, one last question about the status quo right now around incentives and regulation, Alan. Because as I mentioned earlier, the FBI is doing an investigation. IDscan.net’s doing their own internal investigation. But are there any, I was gonna say sort of criminal punishments or charges that could be levied against a company if they are found that their security systems simply were inadequate to prevent a breach?

BUTLER: Yeah, that’s a great question. I’m not sure. Offhand I can’t think of specific criminal charges that the FBI has brought against a company that is breached, but I do think it really depends on exactly what happened and whether something could rise to the level of criminal negligence.

But I think that they’re frequently in discussing, future potential what the law should look like question of accountability and remedies is really central.

CHAKRABARTI: And this is getting to an interesting question. What does negligence look like? What does criminal negligence look like in these cases?

Because, I very much believe the line of thinking that a company like IDscan.net is the victim, right? It’s one of the victims of this data breach, of this hack. But on the other hand, there is a certain minimal level of vigilance that we would expect from a company that’s handling such sensitive data.

So maybe we can talk about better ways to define what negligence is in cases of data breaches a little later in the show.

CHAKRABARTI: But Alan, hang on here for a second because I want to now bring Edgar Whitley into the conversation. He’s a professor in practice of information systems at the London School of Economics and Political Science, and he’s spent decades examining how governments and societies navigate these complexities of digital identity, data, and trust.

Professor Whitley, welcome to On Point.

CHAKRABARTI: Thank you. Can you first give me just your broad thoughts on this specific hack that happened with IDscan.net?

Your thoughts of it. Is it categorically different from others? You heard what Alan Butler had to say.

EDGAR WHITLEY: Yeah, I think the kind of distinguishing feature of this particular breach is the inclusion of the images.

So this is not just your email address, your date of birth, your Social Security number, but I think the really interesting additional element is the image and also the fact that in a large number of cases, these were images of Real ID approved driving driver’s licenses.

So the photograph that would be on, that was being stored and that’s then been leaked is a really high-quality photograph. So in the UK when you apply for a passport, you have to have a clear background for your photo. You’re not allowed to smile. There’s a whole load of things that make the image as high a quality as possible.

And the breach now reveals that the hackers and anybody who’s bought the data from them has a database of really high-quality, government-standard approved images of millions and millions of U.S. and Canadian drivers.

Anybody who’s bought the data from them has a database of really high-quality … images of millions and millions of U.S. and Canadian drivers.

Edgar Whitley

CHAKRABARTI: Okay. So in the UK, Professor Whitley you have been active.

You’ve given evidence to the Home Affairs Committee on, I think it’s the current government’s plan to roll out a digital identity system. Can you tell us a little bit about that?

WHITLEY: Yeah. So it’s the current government, but the plans have changed … because we’ve just got a new prime minister. … So in the UK, like in the U.S., we don’t currently have a national ID card, as is common in many European countries.

We still obviously have to do a lot of things online, and there had been proposals a year and a half ago, two years ago now to have a government-issued ID and to make it mandatory for everybody to have one. And so the parliamentary inquiry was exploring what the issues around the way that the government was making those particular proposals.

Then after Keir Starmer stepped down and Andy Burnham took over as Prime Minister, and I know he’s in New York at the UN today, one of the first things he said was to scrap that current plan for a government issued ID essentially because there was so many other things that the government wanted to do, that something that was unpopular, that would be a longer term change, that would be relatively costly for different government departments to implement and to adjust their systems to.

He decided that was one fight that he wasn’t prepared to have right now, so he scrapped that version of the proposals.

CHAKRABARTI: Actually, Professor may I just jump in here for a second? Because this is a very important point. In the government’s attempt to come up with a new ID system that would ostensibly be more secure, it was supposed to be a government issued digital ID.

I’m seeing here, this is reporting from the Electronic Frontier Foundation that some 3 million Britons signed a petition calling for an end to those plans. That’s the debate, that’s the controversy you’re talking about, and civil society organizations also rallied against the plan. Obviously, the deep concern was regarding that would allow the government to possibly intrude on civil liberties of people in the UK, and that seems like actually quite a justifiable concern.

WHITLEY: Yeah. As I say, there was a large number of that petition with nearly 3 million. The government inquiry that I gave evidence to had a very large number of written submissions just from citizens concerned about the proposal.

Apparently it wasn’t the largest number of submissions. The assisted dying bill in the UK got more submissions  because even more people were worried about that, but it was number two in terms of issues that were of concern. And the big issue with many of those concerns was, okay, government issuing you a credential rather than a private company issuing you a credential is a political choice.

But it was also a question, if you’re gonna put a photo on there, where is that photo going to be stored? How is that photo going to be used? Can you be sure that the government can keep the photographs of all of the people who’ve been issued with one of these IDs secure? And then there were reports that possibly some of the software developers who were onboarded to help develop that system hadn’t necessarily done the full security checking, and they potentially had access to all of the systems and et cetera, et cetera.

So there’s unease at various levels across society about the proposals.

CHAKRABARTI: Tell me if I’m using this British idiom incorrectly, but it seems like everything went pear-shaped.

WHITLEY: Yes.

CHAKRABARTI: But so you actually, you anticipated the question I was gonna ask, which is, okay, if just the civil liberties question aside, that’s for another show, which we’ll come back to, I’m sure, sometime in the future. But the data security side, it seems like the concern was there’s no guarantee that just because it was a government-issued, a federal nationally issued government ID for every person in the UK, even though this isn’t happening, that they would manage to keep that data any more secure than, here in the United States ID, the company, IDScan.net was able to keep things secure. That seems like a very fair and kind of cogent criticism.

WHITLEY: There’s an argument that public sector is lots of government systems are effectively parts of the critical national infrastructure. We, like the U.S., have a national cybersecurity center who spend a lot of time worrying about these kinds of things.

And so key systems, tax records, health records, are pretty, pretty secure. Nobody’s going to say that they are perfectly secure. But to be fair, there is an argument that says governments should have the capability of keeping that data pretty secure. I think the really interesting thing, case for this one was, okay, you get a private company to do the checking.

This is not the issuing of the cards. This is the checking of the cards. But as Alan was saying, why do they need to keep a record … of every card that they check? And that’s the possibility of seeing all of that data … that you could then sell, particularly if you go bust.

I like the metaphor of, don’t see data as oil, but see data as asbestos, and we have good processes in organizations. If you’ve got a whole load of asbestos in your organization, you really manage it and keep it carefully clean and stuff like that. And so the really big question is why were they … so you get a private company to do your ID checks, to check that this person is who they claim to be, et cetera, et cetera, but why are they storing all of the data? And why are they storing all of the data, it would seem, in essentially one system? Which, once you’ve hacked, you’ve got access to all of them.

Part III

CHAKRABARTI: Alan, I just wanted to hear your thoughts on what Professor Whitley was saying a little bit earlier about the UK government had considered doing some kind of national ID, but in a sense, some of the very same security concerns popped up there that do with private companies here.

How would we plausibly move forward?

BUTLER: Sure, yeah. I think that the experience in the UK really underscores the fact that when it comes to identification, we really need to think bigger and differently, right? We can’t just simply carry forward systems designed for old sort of like physical federated IDs issued by state or municipal governments and say, “We’ll just turn these things digital,” with all their existing flaws, right?

I think if we’re going to do ID and identification in a digital context, we need to take advantage of the advances in privacy and security technology that have been made over the last decades and really make those systems work better for both privacy and security, which I really do think go hand-in-hand.

And I think that it is possible to have safer, more secure and private identity systems.

CHAKRABARTI: Okay. Before we get to further solutions, I want to ask you both, because we keep coming back to this, why were the question of why was this data stored? Why did why did IDscan.net keep those driver’s licenses for an indefinite amount of time?

I’m just trying to think of plausible explanations for it. Maybe they need to go back and occasionally do audits of their own systems, and it’s very hard, if not impossible, to audit accounts if they don’t have the original the scans. Or maybe they need to do evaluations of how good their scanning system is, and using data they already have is a helpful way to improve those systems.

Professor Whitley your thoughts on that?

WHITLEY: Yeah. So it’s clear that organizations will need to do some form of audit, but realistically, you’re not going to audit all 150 million records that you have. And even if you do have to have a large sample for your auditing processes as Alan was saying, we do have technological solutions that allow you to store that data in a much more secure way, and ideally not on your main system.

It may be complete, once you’ve done the check, if you are keeping it, and I still have a big concern about whether you should be keeping it at all. But if you are keeping a record, because you could have a record that just says, “We checked Edgar’s driving license on the 22nd of September, and we got the confirmation that it was all legit.”

That doesn’t mean that we need to keep a copy of the image that we’ve got. So there’s a big kind of process question, but it’s also an architecture question about how, what are you collecting, where are you storing it? Even if you acknowledge that you need to have an audit, you can still do much more privacy-friendly audits for those rare occasions when you do need to do that.

CHAKRABARTI: Okay. Hang on, professor. Let’s backtrack to something you said just a second ago. There are much better technologies to keep this kind of data secure that these technologies exist right now?

WHITLEY: Yeah. They’re not necessarily mass scale. They’re not necessarily things that you would want to explain to your grandma how to use because they do get a little bit complicated and a little bit sophisticated.

But we’ve known for kind of 20-odd years that there are what are known as cryptographic techniques that allow you to prove things about yourself without disclosing almost anything about you. The particular challenge in this case is it seems that some of these checks are not just the data about you, but somebody either explicitly or potentially looks at your face and looks at your document and says, “Yeah, it’s probably the same person,” even if your photo is 10 years old, et cetera.

And of course, if you did that electronically with a digital camera as you get at passport gates at airports, then you’ve got that real check. But again, you don’t need to store the data. So yeah, there are things available that allow you to prove things about yourself without having to share lots of data and therefore not storing lots of data and therefore not running the risk of that data being leaked in the future.

CHAKRABARTI: Okay so just to clarify, these cryptographic techniques you’re talking about are for ID verification or verifying who you are. The cryptographic techniques are not necessarily for keeping stored data more secure.

WHITLEY: But the underlying technology can also store whatever you have ended up keeping so that, again … so if you have an audit trail of Edgar, 22nd of September, et cetera, you can store that in a way that doesn’t reveal that it was Edgar Whitley on the 22nd of September, et cetera, et cetera. So the technologies apply at multiple levels through the process.

CHAKRABARTI: So Alan Butler, let me just briefly turn back to you here, because I gotta ask the obvious question. If better technologies are available, why aren’t they in wider use? Or am I being unfair and we’re just … since we talk about this every time there’s a single huge data breach, we’re ignoring the fact that most of the time maybe our data is more secure than this conversation would let people, would lead people to believe?

BUTLER: I’m going to start by going back to your previous question, which is why did this company specifically store these images? Even though I think in this conversation we all come to the conclusion that that doesn’t seem to make any sense and makes everything, puts everything at risk. And I think the simplest answer has to be because no one told them not to.

And I think it’s the same answer to the question of why don’t we have implement implemented more secure technologies more often? And I think it’s because many companies are not required to implement them, right? And the best-case scenario is that the company feels obligated, as you indicated earlier, through their social perception of their business or maybe their vendor agreements upstream to implement stronger standards to meet a certain, security certification level.

But I think when it comes to identity verification Processes specifically, right? Which is where this data is coming from. I think there to the professor’s point we need to have more privacy protective processes and identity verification in order to avoid this data really ever existing at all.

I think at this point we look back and we say, “No one should have 150 million copies of driver’s licenses.” That is by, I think, indication, not a secure practice and not a privacy preserving practice. So how do we get digital verification to work without that happening?

CHAKRABARTI: Yeah, the elegant simplicity of it is undeniable, right?

You can’t breach data that doesn’t exist on, or stored somewhere on the cloud or on servers. Okay, so Alan and Edgar, hang on here for a second, because I wanna turn back to James Lee, who we heard at the very top of the show. He is the president of the Identity Theft Resource Center, and he had some more thoughts to share with us, particularly that this nation, the United States, is in dire need of new laws around how data breaches are disclosed.

LEE: We built the data breach notification system 20-plus years ago when we were talking about essentially paper documents and information on paper documents.

CHAKRABARTI: Okay, so that old notification system was designed for its time, to notify people if a data file, a physical disc, or something like a laptop went missing.

20 years later, who carries around a disc? Our data vulnerability extends everywhere, as we’ve been talking about, and flows through companies we may not even know have access to our sensitive identifying information.

LEE: The individual whose driver’s license was scanned, they don’t even know this company exists.

And that company has so many images that when it was breached, the state law there says if it’s more than 100,000 individuals or it costs more than $100,000 to notify everybody, you don’t have to notify them individually. All you have to do is put a notice on your website, which nobody knows to go to, and send a news release to the media in your state.

CHAKRABARTI: And by the way, the company IDscan.net is based in Louisiana. The original data breach laws were … pieced together state by state. That’s why the state law issue here is really important. And James Lee says they need to be restructured on a national scale.

LEE: So where you live does not determine if you are notified, and if you are notified, what you find about the breach, what was done to protect you. What’s done to make sure it doesn’t happen again, and then what resources are available to you to protect yourself.

It shouldn’t matter where you live for those kind of issues to be addressed.

CHAKRABARTI: And just like Alan Butler said earlier, James Lee also believes that companies are still reluctant to disclose in a timely manner when they have been compromised. So he’d like to see rules that push companies to inform people quickly and clearly if they’re victims of a data breach.

LEE: We also need to revisit in a way that we don’t have to wait for somebody to find this information on the dark web, or we don’t have to wait for a company to necessarily go through a months-long, or in some cases years-long forensic investigation before we find out. We’ve got to have a different way of looking at this.

CHAKRABARTI: And once again, we’re living in a world where so much of our lives are online, whether we like it or not. And so for James, that makes this a national security issue, which requires national security level protection.

LEE: Everybody’s got to get involved in this and have a very different kind of discussion, or we’re going to keep seeing what we have seen for the last several years, and that is the slow but steady escalation every year of more and more data breaches that impact more and more people.

CHAKRABARTI: That’s James Lee. He’s president of the Identity Theft Resource Center. So Alan Butler, you’ve said this a couple of times, and now finally I’m going to let you elaborate. What sort of legal levers or new legal systems could be created to, as you said, incentivize companies to do a much better job to protect our data?

BUTLER: My organization, the Electronic Privacy Information Center, has been advocating for a number of years for a strong privacy and security standard. We commonly refer to these rules as data minimization rules, meaning not only that companies should limit the data they collect, to what is actually necessary to provide the goods and services that they offer, but should also ensure that data is only retained as long as it is needed and that it is secured in the most robust way.

And that, for example, in this context would, I think, go directly to this question of why was it necessary for this company to store copies of these images and technical details of these driver’s licenses whereas currently, for example, state attorneys general might have to, or the FBI or the United States might have to investigate whether that was an unfair or deceptive business practice, which is a much, you know, vaguer and less clearly applicable standard, or might have to rely on some of the weaker privacy laws, for example, that require companies to notify users of the data that they collect and the standards that they impose, which really doesn’t provide protection.

CHAKRABARTI: So just to be clear about this, would you advocate for, let’s say a federal law that would say, “No matter what company you are out there in the United States, you can scan or, process identifying information in order to do your business, but you cannot store things like driver’s licenses, Social Security numbers, address, et cetera”?

You just simply cannot store them.

BUTLER: I think that there’s the two answers to that question. I think first I think we do need more specific regulations in place on impermissibly dangerous data collection and storage practices, and it I think probably would be the case that, for example, storing copies of identity documents, absent very narrow set of circumstances, just shouldn’t be permitted.

But we also need to have a flexible standard that can address future data collection practices that either don’t exist or maybe we don’t know about.

CHAKRABARTI: Okay. But creating standards for something that doesn’t yet exist seems to be a mighty big ask.

BUTLER: It’s a challenging thing in the law, and it’s not unique to privacy, but I think it is very clearly present every time we’re talking about creating or updating a privacy law, is how is this gonna work in five years or 10 years when the world looks very different?

CHAKRABARTI: Okay. I would also say that in the United States, the federal government issuing such a broad new rule or law that would prevent companies from storing certain kinds of data would be met with a great deal of corporate pushback, as they’d see it as the federal government interfering with the process of doing business.

But Edgar Whitley, we only have about 30 seconds left, I’m afraid. What’s the one next step that you would recommend to keep data more secure?

WHITLEY: So another way of looking at that problem that doesn’t involve states versus the central government is to change or to educate the procurement practices of the companies that are buying these services.

So a smart procurer, a smart a car rental firm might go along and say, “Are you storing images of the driving licenses that we are asking you to check? If you are, walk away. We’re not going to use you as a service.” So that’s another way of changing those kinds of dynamics. But that requires people to understand what the risks are and what the potential solutions and options are as well.

The first draft of this transcript was created by Descript, an AI transcription tool. An On Point producer then thoroughly reviewed, corrected, and reformatted the transcript before publication. The use of this AI tool creates the capacity to provide these transcripts.



Source link

——————————————————–


Click Here For The Original Source.

..........

.

.