Also it doesn’t help that, for example, at U-Haul, employees just use their personal phone to scan a QR code and take pictures of your ID.
this idea that employees can expect you own and use a personal smartphone as part of the job irks the heck out of me.
I read that if you use a personal device for anything work related in the US, it means your entire personal device (everything on it) can be considered discovery in a lawsuit against that company. Big risk to take.
most companies want you to put on this software than can wipe your device. its nuts.
My local hospital apparently requires their employees to use a “secure” app on their personal phone to transmit data on the patients.
Seems like irresponsible handling of PHI (by the administration, not the staff) to me.
Work in IT, alongside info security. Nah.
A secured app environment on a phone is plenty well secure for medical data. It is preferred strongly over a web based solution. Having a personal device running a company profile of security compliance monitoring and conditional access is as good as a company device provided by the hospital. They would do literally the same thing.
I think you’re making a lot of assumptions on how the setup is. It could be fine IF they configured everything correctly and are enforcing things on the work profile. Or, it could be terrible IF they just said “install this app, that’s it”.
Having a company provided device with poor guardrails would at least mean it’s not a device that the staff would do their personal stuff on, installing random apps. Having a company provided device with strong guardrails and fully locked down for this purpose would avoid most of the risk of an undiscovered vulnerability being abused. However well the work profile stuff is now separated in mobile OSs today, there can always be day 0s, and people will install any random apps on their phones or fall for plain social engineering.
Maybe technically right now they’re comparable for security, but their risk profile is different I think.
Imagine just targeting this place for phishing and creating a similar looking app with the same name, then sending fake communication to staff to say there is a new version and install it. They can just install it on their personal profile even if the work one doesn’t allow it and start putting data in it. In the case of a locked down work device they could just not install it. Also, there’s no reason for these devices to leave the grounds whereas personal devices will need to go out into the wild.
Maybe if you consider it a personal device if the staff has to relinquish all control of their entire personal device to the work provided security controls they can achieve a similar risk profile, but at that point it’s just a work device the staff had to pay for, not their personal device.
Sigh
Please show me your masters in computer science and your decade of working with the devices. No? Then let me help you out.
It could be fine IF they configured everything correctly and are enforcing things on the work profile. Or, it could be terrible IF they just said “install this app, that’s it”.
That is true of ANY solution. If they violate this, then they are federally liable. Nothing about who owns the device changes this so it is a non-starter.
Having a company provided device with poor guardrails would at least mean it’s not a device that the staff would do their personal stuff on, installing random apps.
First, applications concerning healthcare data are going to operate in both encryption at rest and encryption in flight. They will isolate all data flow to just that app and its external managed connections. So what other things you have on the device from an App Store are irrelevant.
Having a company provided device with strong guardrails and fully locked down for this purpose would avoid most of the risk of an undiscovered vulnerability being abused.
I don’t think you understand ANYTHING about how security profiles are loaded onto a device. I will keep this to an explain like I am 5 level. None of what you just said is true. It does not matter who owns the device. If they are using it , for work, and work manages conditional access policies on the device, with security policies loaded, it will enforce ALL of the same things for monitoring data flows inside apps relevant to the workplace. It will enforce OS versions or kick your ability to authenticate. There is NOTHING that device ownership will change. Repeating this makes it very clear you have no idea what the fuck you are talking about.
However well the work profile stuff is now separated in mobile OSs today, there can always be day 0s, and people will install any random apps on their phones or fall for plain social engineering. Maybe technically right now they’re comparable for security, but their risk profile is different I think.
You think. Yes, you think, because you don’t do this for a living nor have the slightest clue what you are discussing. Again. Zero day exploits are going to be the same no matter who owns the device. They impact software under the same managed rules that exist regardless. It doesn’t change if it is a company device. Holy shit.
Imagine just targeting this place for phishing and creating a similar looking app with the same name, then sending fake communication to staff to say there is a new version and install it. They can just install it on their personal profile even if the work one doesn’t allow it and start putting data in it. In the case of a locked down work device they could just not install it. Also, there’s no reason for these devices to leave the grounds whereas personal devices will need to go out into the wild.
The reverberation speaking this much out of your ass must be immense. The whole point with a security profile is it limits these actions, and the security profile on the device is THE FUCKING SAME whether it is a device owned by you or the company. Once the employee has it configured correctly, the same in tune, same defender policies, the same OS management, the same everything could be used.
Maybe if you consider it a personal device if the staff has to relinquish all control of their entire personal device to the work provided security controls they can achieve a similar risk profile, but at that point it’s just a work device the staff had to pay for, not their personal device.
Jesus wept. You don’t relinquish control of he whole device. Unless you are working in a SCIF, your physical device is not going to have the type of controls on it that need to prevent any access to Bluetooth or WiFi. It will be only managed insofar as the profile for security requires it to be. That means you selectively block actions and abilities related only to the data within the app context and surrounding risk vectors. I’m typing this on a phone with a security profile on it for work. It serves as my Authenticator, has work application data, and doesn’t have to interfere with other personal use. You have a fundamental misunderstanding of how ANY of this works.
If you walked into Palo Alto today and sat down at the table with their engineering team, would you be telling them their firewall solution is flawed without knowing anything about it? I hope not. So why do that here?
Totally secure system!
The only way to fix this is to have us upload our IDs online constantly, perhaps to prove we are adults.
It is the only way we can we safe.
But, just think about the children! ~While everyone plastered their children allover social media and they are easily identified with AI~
Woaha. Why didn’t anyone think of this before you?
I bought a domain, configured the webserver in the next 5m.
As soon as it started taking requests (on a domain that i haven’t even announced yet) it got flooded by bots.
Yeah I worked for company with publicly exposed server, the logs were amazing.
Just bots scanning default ports trying default username and password for services like Microsoft SQL server.
It’s such a waste of energy really
That’s been happening since forever, though. I helped manage proxy servers for my first job in the mid 00’s, and those server logs were mostly automated port scans and failed login attempts, even on the newly commissioned servers.
If your browser is based on chromium, you’re employing an army of bots yourself that gets enabled each time you enter any domain.
Can you explain what you mean exactly?
Registering SSL is a centralized process with root CAs logging new ones as they come in. Cert transparency logs are a thing, and Google is very involved: https://certificate.transparency.dev/
Once a bad actor hooks up to that, they just get a realtime stream of places to start port scanning and running WHOIS queries for people who didn’t get WHOIS protection. If you used letsencrypt your domains you registered certs for got sent there and anyone who wanted to know about it knew about it before you could tell anyone.
You can use something like crt.sh to look up domains
Luckily archive.org saved the idscan.net press release announcing their partnership with Planet13 dispensaries. They have since deleted the post on their site. Nothing shady about that. 😂
In addition to scanning and verification, VeriScan performs ID parsing to collect, separate, and classify information from the various fields on IDs. This allows Planet 13 to seamlessly harvest the names and demographic/geographic information of its guests. This data is providing insights into customer profiles, which is especially valuable as Planet 13 expands its footprint into other states, including supplementing its SuperStores with smaller, neighborhood retail shops.
I have no words.
Annnd this is why a refuse to verify with IDs online and use services like Plaid. And the web of T&C’s from multiple 3rd party services like this will mean all of them get shielded from blame.
Did you read the article? They were renting a car. A car rental place isn’t going to let you just not show your ID.
So how they did it once upon a time was you showed them your license, they punched the # into the system that would check it. The person at the desk would confirm it was you from the picture. No need to scan the actual ID card, which is where this problem comes from.
That is true, but now they rather have a digital proof for insurance reasons.
Yeah, it was from renting cars, but they are digital copies of your ID, so any online service is just as “at-risk”, if not more.
it wasn’t just Hertz. it was the ID verification service they used.
The IRS made me since I used a different service to file my takes this year. It was a pain in the ass. Apparently my existing id.me login wasn’t enough, they wanted a video call or a scan of my face. There was no other option. It was a pain.
they tried that with me. I just told em to fuck off.
if you make it impossible to identify myself through standard means, you don’t get my tax dollars. 🤷 fuck em.
I would have, but they owed me money, so I needed to get my money.
My elderly father recently fell for a Facebook imposter that pretended to be a family member and asked if their friend could contact him. The friend asked him to take a photo of his driver’s license and text it to them, fortunately he doesn’t know how. I’ve been wondering ever since what can they do if they had it? It doesn’t have his social security number on it. His credit has since been locked and banks notified
They can open bank or crypto accounts in his name, and then either overdraw the account or use it to move money from other scams in and out of this account, so the real scammers name is not attached to this account.
Is there a way to block that? Ie: freezing your credit means no one can take a loan, but that doesn’t remove the scenario you described.
I’ve been wondering ever since what can they do if they had it?
Ask for pictures of all his other paperwork so they can finish onboarding him at his new job.
Surely the company must be liable, right guys? Right…?
The company MUST be Held accountable and liable for this
I’m sure in the hour long to read rental agreement you don’t have time energy, or the law degree it takes to understand, you waive your right to any lawsuit and have already agreed to settle out of court.
Wait until non Americans hear that our national social security ID number is only 4/9 digits worth of “random” numbers. (Fun fact, the entire number was procedurally generated based on where you were born and in what order at the hospital for generations until they changed it recently)
The numbers aren’t random. They are sequential. The early digits are assigned geographically, but the rest are in sequence. If you know a valid social security number, adding or subtracting 1 will be another valid social security number, most likely someone born in the same hospital on the same day.
They did change it somewhat recently, but they don’t re-assign the numbers when making that change, so most of the numbers are completely insecure.
Yeah, we know. We just can’t believe that you actually use it for anything important.
That stupid ass number is used as one of the identifying factors when financing anything. Yes, a house is bought and mortgaged with that number next to 2 other forms of ID lmao.
This is yet another reason why virtual ID cards are superior: In the event that the card data is compromised, the old virtual ID can be revoked and a new virtual ID can be issued. Virtual ID cards can also have a much shorter duration, because the cost of rotating it is minimal. For example, California’s virtual driver licenses rotate each 30 days.
We honestly should be using virtual vouchers for everything. The question then becomes “whats one level up from the voucher i can steal” and we’re very frustratingly (for my mental exercise) back at square 1
Just rented a car. Fuck.
Yeah, there’s like 150 million IDs and licenses. I guess the company that handles like every major businesses ID verification has online security designed by Grom. Should arrest the top 15 people hands down.
I’m literally picking one up in an hour 😬
I got arrested this past Saturday… They called my mom to try and scam her.
what did you do?! oh wait I guess it probably wouldnt be a good idea to admit guilt on the internet so quickly after being arrested
Feed people 🤷♂️
I am proud of you, sorry the state is arresting you for that. hopefully you do not get prosecuted.
“i got arrested” is not an admission of guilt
Yeah. You gotta ask “what did you allegedly do?”
I have had to rent cars since 2015. My license has probably been seen by 5000 breach sites by now.
At this rate, a new ID type will have to be used. I dont have a clue what, but a new one…
Welcome to Rent-a-car. Please sign into your vehicle with Facebook, Google or AppleID.
Most of this seems very serious and concerning, but…
Nexus also claimed to provide scans of marijuana dispensary cards
What could anyone possibly do with that? It costs like $50 to get one in California, not sure about other states.
The data gets sold in blocks usually. Could be for identity theft, or SIM swap attacks or any number of things. A lot of things online want an ID scan now, so this is a huge benefit to scammers.
I still have to see the online service or site asking for my ID. Maybe because I’m mostly off of the bullshit-net for the most part. But the moment any service I use asks for ID, it’s getting cancelled and blocked in my house at the network level. I’m expecting my digital life to be dramatically downsized moving forward.
Car rentals, well, not many options there when traveling, since I absolutely refuse to use ride-share apps like Uber and such.
Legal weed in CA now dawg. No dispensary card needed
Less taxes in most places if you have a med card. Financially sensible if you buy a certain amount per year.
But then there’s a record of you being a cannabis user, which could lead to your second amendment rights being curtailed.
There is a record, but there’s no central database unless you get an MMIC card which is different than what probably 99.9% of people do (but also larger tax benenfits)
Huh, I just assumed they got rid of them when legalization happened. TIL
Under 21 still requires a medical card
My first thought was “so this is how they got my fake from back in the day to scan”
Nineteen Brazilian Nationals Charged in Nationwide Conspiracy to Open Fraudulent Driver Accounts at Leading Rideshare and Delivery Service Companies
Jeez, Daniel Gooooooch must be pretty pissed about this article revealing his name as an example pic.
wait. the gooch!














