rental cars and dispensaries
Nobody ever voted for a national identity database. We built one anyway, by accident, one rental counter at a time.
On 31 August a source told Brian Krebs about a listing on Exploit, a Russian-language cybercrime forum, advertising scans of identity documents belonging to more than 170 million people in North America. The goods surfaced on a marketplace called Nexus: more than 153 million scanned driver’s licenses from the U.S. and Canada, plus about 10 million ID cards, 3 million travel documents, and 579,000 medical cards.
IDScan.net, a Louisiana identity-verification company, said it received information around 1 September that data on its cloud platform may have been accessed without authorization, secured its systems, and brought in outside specialists. The FBI’s New Orleans field office opened an investigation. The company has confirmed a breach; the precise relationship between what IDScan lost and what is listed on Nexus is what the investigation is for, and I am not going to assert it is one-to-one before the investigation says so.
What is not in dispute is the shape of the thing. Somewhere there was a pile of nine-figure scale, and it was a pile of photographs of people’s licenses.
Here is the part worth sitting with. IDScan processes ID checks for car rental companies, retailers, and cannabis dispensaries.
That is the whole essay in one line. You have never heard of this company. You never agreed to anything with this company. And there is a decent chance it is holding a photograph of your driver’s license, because at some point you rented a car.
No legislature ever passed a law creating a centralized archive of North American identity documents. What legislatures passed, over about thirty years, were a great many rules that say some version of check. Check that this person is twenty-one. Check that this renter is licensed. Check that this buyer is who they claim. Every one of those rules is defensible on its own terms and most of them are good.
But “check” is a verb about a moment, and the systems we built to satisfy it do not implement a moment. They implement a record.
The reason is mundane and it is not villainous. If a regulator can ask you in two years whether you checked, then checking is worthless unless you can prove you checked, and the cheapest proof is the artifact itself. So the scanner does not compute over twenty-one, yes. It captures an image, parses the barcode, writes a row, keeps the image. The compliance requirement is about the past, so the implementation is a memory.
We legislated verification and we deployed retention, and nobody wrote the second part down as policy — it arrived as a vendor default.
Arendt drew a distinction in The Human Condition that I keep finding useful and that I think is exactly load-bearing here: the difference between who somebody is and what they are.
Her argument is that what you are is a set of attributes — qualities, traits, characteristics, the things you could put on a list. Who you are is disclosed only in acting and speaking among other people, over time, and it is not a property you possess. It cannot be inventoried, because it is not the sort of thing that sits still. Her point was about politics and appearance: the who shows up in the space between people and nowhere else.
A driver’s license scan is the pure limit case of the what. A name, a birthdate, a height, an address, a number, a photograph, a barcode. It is a list of attributes and it is nothing else, which is precisely why it is useful for verification and precisely why it is trivially transferable.
And this is not a philosophical flourish. It is the operational fact that makes the breach matter, because a stolen scan does not impersonate you in any meaningful sense. It does not need to. The system on the other end was never looking for a who. It was looking for a what, and the thief has the what, complete and unmodified.
There is no degradation in the copy. A forged signature is worse than a real one. A stolen photograph of a license is exactly as good as yours, because it is yours.
The steelman deserves better than it usually gets, so: the check is not the problem.
A dispensary that does not verify age loses its license and should. A rental company handing a car to someone with no valid license is a genuine hazard to other people. Fraud against retailers is real, expensive, and falls hardest on the smallest of them. The people who built ID-scanning products did not set out to assemble a shadow registry; they set out to let a clerk at 11 p.m. do a thing correctly in four seconds, and they succeeded at that.
I would also rather a bored twenty-two-year-old behind a counter not be the sole arbiter of whether a hologram looks right. Automating that judgment is a real improvement in a real process.
None of that requires keeping the image.
Which is the uncomfortable engineering fact underneath all of this: the retention is not technically necessary, and it has not been for a long time.
You can answer is this person over twenty-one without storing a photograph. You can answer is this license valid without storing the license. You can keep a signed, timestamped attestation that a check was performed and passed — enough to satisfy an auditor — without keeping the material that makes the check re-performable by anyone who steals the database. The cryptography for proving a predicate without disclosing the underlying value is not exotic, is not new, and is not the hard part.
The hard part is that nobody is the customer for it. The dispensary wants to not get fined. The vendor wants to win the dispensary. The person whose license is in the pile is not party to the transaction, has no contract with the vendor, cannot enumerate which vendors hold their documents, and has no mechanism to ask any of them to delete anything. The externality has no counterparty. So the default persists, and the default is keep it, because keeping it is free until the day it isn’t, and on that day the cost lands somewhere else entirely.
The thing about a password is that it is an arbitrary token, and the entire reason it works is that it is arbitrary: when it leaks you throw it away and mint another one. The whole system is built on the assumption of disposability.
An identity document is the opposite by design. Its value comes from being stable, singular, and hard to change — that is the property that makes it worth checking. Your birthdate does not rotate. Your face does not rotate. The number is yours for years, and the photograph is yours for as long as you look like it.
We took the class of data specifically engineered to be permanent and unforgeable, made a hundred and fifty million copies of it, and handed the copies to companies chosen by whoever was selling ID scanners to dispensaries.
The ‘what’ was always supposed to be the stable part. That is what made it useful. That is what makes it, now, impossible to recall.
Sources: Krebs on Security ↗ · Help Net Security ↗ · Time ↗ · SecurityWeek ↗ · Malwarebytes Labs ↗ · Arendt, The Human Condition (1958) ↗