• Hikermick@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    6 hours ago

    My elderly father recently fell for a Facebook imposter that pretended to be a family member and asked if their friend could contact him. The friend asked him to take a photo of his driver’s license and text it to them, fortunately he doesn’t know how. I’ve been wondering ever since what can they do if they had it? It doesn’t have his social security number on it. His credit has since been locked and banks notified

    • GenosseFlosse@feddit.org
      link
      fedilink
      English
      arrow-up
      8
      ·
      3 hours ago

      They can open bank or crypto accounts in his name, and then either overdraw the account or use it to move money from other scams in and out of this account, so the real scammers name is not attached to this account.

  • Bell@lemmy.world
    link
    fedilink
    English
    arrow-up
    32
    arrow-down
    2
    ·
    8 hours ago

    Annnd this is why a refuse to verify with IDs online and use services like Plaid. And the web of T&C’s from multiple 3rd party services like this will mean all of them get shielded from blame.

    • 7101334@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      ·
      5 hours ago

      Did you read the article? They were renting a car. A car rental place isn’t going to let you just not show your ID.

      • youmaynotknow@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        58 minutes ago

        Yeah, it was from renting cars, but they are digital copies of your ID, so any online service is just as “at-risk”, if not more.

      • ikidd@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        13
        ·
        4 hours ago

        So how they did it once upon a time was you showed them your license, they punched the # into the system that would check it. The person at the desk would confirm it was you from the picture. No need to scan the actual ID card, which is where this problem comes from.

    • Raiderkev@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 hours ago

      The IRS made me since I used a different service to file my takes this year. It was a pain in the ass. Apparently my existing id.me login wasn’t enough, they wanted a video call or a scan of my face. There was no other option. It was a pain.

  • 7101334@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    5 hours ago

    Most of this seems very serious and concerning, but…

    Nexus also claimed to provide scans of marijuana dispensary cards

    What could anyone possibly do with that? It costs like $50 to get one in California, not sure about other states.

      • 7101334@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 hours ago

        Less taxes in most places if you have a med card. Financially sensible if you buy a certain amount per year.

        • Drusas@fedia.io
          link
          fedilink
          arrow-up
          1
          ·
          1 hour ago

          But then there’s a record of you being a cannabis user, which could lead to your second amendment rights being curtailed.

          • 7101334@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 hour ago

            There is a record, but there’s no central database unless you get an MMIC card which is different than what probably 99.9% of people do (but also larger tax benenfits)

    • hansolo@lemmy.today
      link
      fedilink
      English
      arrow-up
      9
      ·
      5 hours ago

      The data gets sold in blocks usually. Could be for identity theft, or SIM swap attacks or any number of things. A lot of things online want an ID scan now, so this is a huge benefit to scammers.

      • youmaynotknow@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 hour ago

        I still have to see the online service or site asking for my ID. Maybe because I’m mostly off of the bullshit-net for the most part. But the moment any service I use asks for ID, it’s getting cancelled and blocked in my house at the network level. I’m expecting my digital life to be dramatically downsized moving forward.

        Car rentals, well, not many options there when traveling, since I absolutely refuse to use ride-share apps like Uber and such.

    • Talcosis@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 hours ago

      My first thought was “so this is how they got my fake from back in the day to scan”

  • Darkard@lemmy.world
    link
    fedilink
    English
    arrow-up
    379
    ·
    12 hours ago

    But don’t forget guys, uploading your government IDs to any old fucking website to prove your age is very safe and protects children. There’s no way this could go wrong and everyone in the supply chain is very trustworthy

    • Saapas@piefed.zip
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      68
      ·
      10 hours ago

      The QR/one time code way makes a lot more sense and avoids this issue

      • ayyy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        7
        ·
        5 hours ago

        That…doesn’t work. Just because you saw one dumb YouTuber say something doesn’t make it true.

        • Saapas@piefed.zip
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          1
          ·
          5 hours ago

          I’m not sure if there’s some popular video you’re talking about but I’m talking about the EU ID proposal. Haven’t seen any videos about it

        • Saapas@piefed.zip
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          13
          ·
          6 hours ago

          They’re already doing the verification and it’s not going away. I definitely prefer a better way to do it

          • Kangae_Hishiryo@scribe.disroot.org
            link
            fedilink
            English
            arrow-up
            19
            ·
            6 hours ago

            That “it’s not going away” attitude is the fucking problem…

            We should fucking fight it, either by good or by bad, because that defeatism is what they want, they want us to think that TINA, then, little by little, force ourselves to do things that at first would seem unacceptable to us.

      • BooBees@fedinsfw.app
        link
        fedilink
        English
        arrow-up
        103
        arrow-down
        2
        ·
        10 hours ago

        How about we just don’t suck the dicks of authoritarian wannabe dipshits that have proven they can’t secure any information properly and can’t run any institution properly?

        • Saapas@piefed.zip
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          34
          ·
          9 hours ago

          I don’t know exactly what you mean, I just think for age gating there’s ways that are a lot better

              • lightnsfw@reddthat.com
                link
                fedilink
                English
                arrow-up
                2
                ·
                4 hours ago

                Yeah, that’s why you monitor what the kids you’re responsible for are doing on the internet. It’s trivial to setup parental controls on a network.

              • Kangae_Hishiryo@scribe.disroot.org
                link
                fedilink
                English
                arrow-up
                6
                ·
                5 hours ago

                Hell naw, that’s an arbitrary take. There’s no “child things” or “adult things”, nor “male things” or “female things”, just things, and the “male”/“female”/“child”/“adult” is an arbitary tag we put on them.

                And even if there are some things that aren’t so good for the child to see, the only correct way to address that is educating them, guiding them, listening to them and, over all, treating them as humans, the “we need to block this to children” is totally adultist.

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  4
                  ·
                  5 hours ago

                  And even if there are some things that aren’t so good for the child to see

                  That’s what people mean by “not all stuff is for kids”

          • Sturgist@piefed.ca
            link
            fedilink
            English
            arrow-up
            47
            arrow-down
            2
            ·
            9 hours ago

            Like parents actually parenting and activating the built in restrictions for their children’s devices?

            • Saapas@piefed.zip
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              35
              ·
              9 hours ago

              It’s probably more effective done at the other end. It’s not like you can make parents parent

              • BooBees@fedinsfw.app
                link
                fedilink
                English
                arrow-up
                12
                arrow-down
                1
                ·
                7 hours ago

                You actually can, it’s called regulations, policies and enforcement. Don’t vaccinate your crotch fruit? Cool, they can’t go to public school, and you just won a visit from child welfare

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  8
                  ·
                  6 hours ago

                  It’s not like we don’t have regulations, policies and (some) enforcement. But there’s still dogshit parents. And for this kind of thing, how would you even enforce it?

          • ramble81@lemmy.zip
            link
            fedilink
            English
            arrow-up
            26
            ·
            9 hours ago

            That’s the issue. We don’t need nanny’s to age gate us on the internet. All it does is create a very short path to removing anonymity on the internet

            • Saapas@piefed.zip
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              25
              ·
              9 hours ago

              Don’t mind some age gating tbh. It would have to be pretty convenient and anonymous though.

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  arrow-down
                  13
                  ·
                  8 hours ago

                  Well the implementation is going to be that you prove your age to the id app that only saves the info that you’re over 18. Then the id app just tells that info to the website (or app or whatever I guess). So the site doesn’t know who is trying to prove their age or even what their age is, just that they’re over 18.

                  It would be nice to have that sort of quick and easy app for verifying your personal information too. I don’t think we have one where I live. We always use a bank for that and that’s more hassle than I’d like

                • Dnb@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  4
                  arrow-down
                  10
                  ·
                  8 hours ago

                  Easy. You set the age in the os (or age range) per system account.

                  Apps can then request this and allow/ deny based on it. Requires admin / sudo to update age range.

                  No need for 3rd parties, id or anything else.

                  If parents are concerned about it they can implement it easily. If not, they can ignore it.

          • Doomsider@lemmy.world
            link
            fedilink
            English
            arrow-up
            5
            ·
            8 hours ago

            I think no ASL covers it for the Internet. Going against the most basic rule is kind of ridiculous.

            • Saapas@piefed.zip
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              13
              ·
              8 hours ago

              If it’s going to be implemented imo it’s better to do with a privacy respecting centralized fashion than sending your id pics all over the place

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  11
                  ·
                  8 hours ago

                  You can protect the identity and all other info of the person than if they’re over 18 or not. I think that’s a lot better than the other ways sites are now using.

                  Unless you think it of just as bad because a site knowing if you’re 18+ is a violation of privacy, so might as well give them everything haha

  • Yaky@slrpnk.net
    link
    fedilink
    English
    arrow-up
    88
    ·
    11 hours ago

    Also it doesn’t help that, for example, at U-Haul, employees just use their personal phone to scan a QR code and take pictures of your ID.

    • toynbee@piefed.social
      link
      fedilink
      English
      arrow-up
      17
      ·
      7 hours ago

      My local hospital apparently requires their employees to use a “secure” app on their personal phone to transmit data on the patients.

      Seems like irresponsible handling of PHI (by the administration, not the staff) to me.

    • HubertManne@piefed.social
      link
      fedilink
      English
      arrow-up
      27
      ·
      8 hours ago

      this idea that employees can expect you own and use a personal smartphone as part of the job irks the heck out of me.

  • dan1101@lemmy.world
    link
    fedilink
    English
    arrow-up
    76
    ·
    11 hours ago

    I don’t like it when a store scans my driver’s license to buy alcohol. I stick to small convenience stores without that tech.

    • boonhet@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      15
      ·
      9 hours ago

      Had a fun time visiting the US, clerk didn’t understand why she couldn’t scan my ID and find it in the database. All that for trying to buy some cigarettes as I was a smoker at the time and didn’t bring much with me (stupid mistake, they’re way more expensive in the US)

      • ayyy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        5 hours ago

        The stated justification is that it somehow catches forgeries that altered the front of an ID but didn’t make the barcode information match. That might have been justifiable in like 1980 or something, but it’s reaaaaaaally not hard to generate the correct barcode these days if you’re forging an ID.

        The real reason is to track and sell more data about you.

      • Steve@startrek.website
        link
        fedilink
        English
        arrow-up
        39
        ·
        10 hours ago

        It keeps liquor prices down because you get the extra revenue from selling the scans. Try to keep up smh

      • socphoenix@lemmy.world
        link
        fedilink
        English
        arrow-up
        20
        arrow-down
        1
        ·
        10 hours ago

        It validates against the states license database to confirm it’s a legitimate ID and not a fake.

        • dan1101@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          8 hours ago

          At best they are keeping an audit trail to be sure the clerk didn’t sell alcohol to an underage person. But even if they aren’t already I figure it will get retained and used in some manner. Marketing, insurance, who knows? Lots of data brokers would buy information on who buys alcohol.

        • partofthevoice@lemmy.zip
          link
          fedilink
          English
          arrow-up
          9
          ·
          9 hours ago

          Is that really what’s going on? I always thought the barcode just contained the ID number and your information. Can probably be validated that the format is correct very easily, but you can use the correct format with incorrect data easily.

          I assumed the scan was still offline validation. Because if the database isn’t networkable from their store, I imagine they aren’t causing any issues in the sales process. So you would only need to precompile and print a valid barcode with correct-looking data.

          Probably won’t work for a police dispatch, who I’m sure are going to use online validation when they run the ID. But I’d swear that level of sophistication isn’t in gas stations yet.

            • partofthevoice@lemmy.zip
              link
              fedilink
              English
              arrow-up
              2
              ·
              6 hours ago

              Yeah, it could be digitally signed for offline verification. But I’m doubtful there’s enough standardization going on that corporations are integrating signature verification right there in the POS system. They’d need the public keys from the government, presumably. That doesn’t sound too difficult but also, setting up a process to get that info for all 50 states would probably be a mess. Do the states even sign the info to start — that’s another question.

              I think the infrastructure can be deployed. Though, I get the impression it would take more coordination than we actually see here in the wild.

  • tigeruppercut@lemmy.zip
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    10 hours ago

    Jeez, Daniel Gooooooch must be pretty pissed about this article revealing his name as an example pic.