If you are anything like me: First off, you have my deepest sympathies. But what I meant to say was that if you are anything like me you probably get a letter in the mail about once a year explaining that your health insurance provider, health care provider, vehicle loan provider, mortgage provider, video game distribution platform, coffee machine manufacturer or buy-12-get-1-free french toast rewards program overseer has accidentally let all your personal data be stolen, whoopsies, our bad.
The letter will go on to say that they're fairly sure that none of your medical files or financial data has appeared on the so called "dark web," the criminal marketplace for such records, at least not yet, and to be honest the company hasn't looked into it too much because what you don't know can't hurt you. And while there's not a damn thing that you can do about that, to make it up you're now going to get 12-18 months of "free credit monitoring" so that if anyone does try to take out a new car loan or mortgage in your name, you might get an email warning you about that, maybe.
And that's how I've had "free credit monitoring" for the past five years and counting, despite never once signing up for it. Right around the time each 12-to-18 month offer expires, a new letter arrives from Whoops County, Delaware, explaining that due to a new boo-boo from another company I've never heard of every hacker from Chengdu to Dubrovnik now knows I'm a member in good standing of the Potato Of The Month Club, which for some reason also keeps my complete medical history on file because apparently that's just how things work now.
Boom, another year of "free credit monitoring," always with fine print saying of course we all realize you can't actually sue us for this, not when we've got the legal and legislative resources of both the potato shipping and for-profit health insurance industries backing us up, but we're going to throw you this bone to make it seem like we give a crap.
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.
Security researcher Brian Krebs reports that his initial investigation suggests the hackers infiltrated identity verification company idscan.net, plus others, and that the crime syndicate responsible claims to have been "continuously" stealing these drivers licenses and other information for "over a year," apparently undetected by anyone tasked with making sure that couldn't happen.
There are somewhere in the neighborhood of 240 million licensed drivers in the United States, so if you're asking how many of those are now in the hands of hackers the answer is "most of them." Or, rather, most of us.
So here we go. Again. If you've rented a car, shipped a package, or done anything else that required you to hand your drivers license over to be scanned in the past year, or if you had to photograph your license and upload it to an internet site as "proof of age" or "proof of identity," the odds are high that it's now for sale in some corner of the internet for the low low price of $100 or so. (A commenter on Krebs' site reports that their bank account was hacked earlier this year by someone who had a copy of their drivers license, because when you have a full scanned copy of someone's drivers license that is something you can do.)
Among the drivers licenses for sale: that of current Secretary of Defense Pete Hegseth. So if anyone wants to waltz into a government building claiming to be the belligerent twitchy-eyed Secretary of War, you can do it for 100 bucks and however much alcohol it takes to make you smell throughly sloshed.
There are several lessons to be learned here, none of which will be learned because hello, I haven't gotten 5 years of "free credit monitoring" out of corporate America due to anybody involved learning any lessons, but one of the more important ones we might learn from the current moment might be this:
Online "identity verification" and "age verification" is just identity theft with an extra step.
And no, nobody knows quite what to do about that.
That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, itâs worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification.
So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned. [...]
At this point, anyone still supporting age verification requirements, especially claiming itâs for âchild safety,â should have to answer for all the millions of people put needlessly at risk due to data breaches like this.
You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. Thatâs what happened here. And itâs what will happen with any such systems.
There has been a big recent push for so-called "child safety" laws restricting the internet, a push that has coincided rather coincidentally with the new anti-trans panic and with the revelation that the President of the United States was not only best buds with a child sex trafficker but has staffed a big chunk of his administration based on his estimates of who will best block investigations into that.
Nobody can be against child safety, right? That's what everybody with even a glancing mention in Jeffrey Epstein's personal files can all agree on. Gotta protect those kids.
The conclusion that each lawmaking body keeps coming to, thanks in large part to the corporate takeover of every little detail of law-writing, is that everyone needs to upload their most sensitive identification documents to the internet where our corporate overlords will keep them super-safe and become the final arbiter of whether or not you're you.
What neither lawmakers nor the companies lobbying for online identity tracking are willing to grapple with, however, is the plain truth that so far, the most reliable outcome of every online tracking effort has been that the companies involved accidentally spill everything they've tracked into the big bucket of Online Identity Theft. Medical records, drivers licenses, the answer to the "what was the name of your first pet" security question that companies are absolutely certain nobody but you would know; all of it gets hacked and put up for sale with, apparently, such regularity that it's easier for companies to dole out "free credit reporting" in yearly chunks than it is to actually secure the data in the first place.
And it is not keeping anybody terribly safe, because nobody wants to Calmly Observe that the people most able to get a copy of someone's drivers license, other than that person themselves, is their live-in offspring. Not that any rebellious 16 year old would go through their parent's purse or wallet, oh heavens no. Never.
The main problem with every current online verification push, however, goes even deeper. It can be best summed up as Every Product Is A Camera Now.
The company calls it iKairos, and its modular design lets it learn about the userâs life from different perspectives. At a desk, it will observe and interact with users like any other desktop AI robot. However, users can pop it out of its robot body and slot it into a necklace to take it with them on the go.
As a result, iKairos can capture contextual data about the user across multiple environments. It will then feed this data into LifeOS â Lingverseâs AI operating system â which will use it to surface relevant and (hopefully) useful suggestions for the user.
Aw, it's so cute. It has cute little eyes, that's how you know it's a good omnipresent recording device and not an evil omnipresent recording device.
There's no point in picking on this particular product. It's not much different from any of the other hopeful world-changers being announced right now: All of them, and it really does seem to be all of them, are new knickknacks designed to record everything you see, hear, and do, uploading all of it to global data centers, which allegedly will be good for you because it will stop you from having to think very hard or remember how many children you have.
This really is the only product being developed right now. It's this and nothing else. It's the exact same selling point that Mark Zuckerberg's world-crushing company is pushing to convince you to wear glasses that record everything that goes on around you.
Meta has filed a patent for new AI glasses that use facial recognition to capture moments without a command from the user - building up a searchable memory bank. [...]
This means the glasses could record events without the wearer commanding them to, focusing on 'interesting' events based on facial expressions, conversations, behaviors and where the user is looking.
The AI assistant would also build up a profile of relationships, based on facial recognition - pulling up certain records associated with each person the wearer interacts with.
The patent says that the glasses could then "access a plurality of episodic memories associated with the user."
The sales pitch here is that the Zuckerglasses will track the faces of everyone you meet, upload them to The All-Knowing Cloud, identify them via their facial characteristics, and spit back to you its "records" of that person. All of this would happen without you telling your glasses to do that, and more importantly all of this would happen without any of the people now being tracked in Meta data centers having a damn thing to say about it. Meta gets to build, according to their own patent, a database of "interesting" moments it's collected about everybody that so much as walks through the camera's field of vision, focusing on "relationships," creating a giant enormous database of photos of every American going about their lives, what stores they go to, what makes them laugh, what made them angry, what their children look like, what their children's favorite animals and games and hobbies are ...
What you get, in trade for collecting all of that data on the company's behalf, is an onscreen or in-ear description of how you know this person. Maybe. Unless it's wrong, of course. Wouldn't that be a hoot.
"Hello, my dear spouse who I have been married to 15 years. It's nice to see you again."
"Who the f--- are you?"
This is all of tech. The whole industry is just this. Nothing else, just this. There are glasses to do this, and pendants to do this, and crib monitors that do this, and your gaming console wants to do this, and your f--king refrigerator wants to do this while flashing advertisements at you whenever you go into the kitchen.
It wasn't all that long ago that the tech industry was at least marginally premised on bringing us A More Useful Future. A company finally invented a robot vacuum, one that scuttled around sweeping your floors so you didn't have to, and people liked that because this is what we were promised, in all those past visions of the future. They said there would be robots that would do annoying chores, things like sweeping, mopping, and window-washing; we could hand those tasks off to the robots and instead focus on learning our children's names or finding out which dinosaurs they liked.
But then Silicon Valley decided they didn't want to make robots that swept floors. There wasn't enough money in it. There wasn't enough money in anything, they all agreed, except for data collection for data collection's sake. So the new products became cameras that tracked your every move. They wanted to put microphones on every street corner and in every living room, so that they could comb through the data of what people said and where they said it, and if you asked them what benefit this would bring to, you know, the average schlubs being monitored every moment of each day they would get suspiciously and sniffingly mad at you while ranting that you just didn't understand.
So now every last g--damn product is a recording device that sucks up every possible thing it can know about you, and in this latest, 2026 version sucks up every possible thing it can learn about everyone you meet and interact with. The new commercial vision of tomorrow is that you will sweep the floors, which you'll have plenty of time to do if you'd shut up and let the see-all, hear-all glasses you're wearing remember your kid's favorite dinosaur instead of doing it yourself.
So maybe now the company that makes vacuum cleaners doesn't want to make vacuum cleaners anymore. Instead, they want to make $500 AI-powered toothbrushes that take pictures of your teeth when you brush.
When the toothbrush's software detects a gap between your teeth, the device shoots a jet of water into it within 100 milliseconds. This allows for precision flossing as you brush your teeth. [...]
"The Dyson CameraJet⢠is Wi-Fi connected at 2.4GHz and Bluetooth connected," the press release states. "Its integrated camera is a high-quality endoscope, allowing users to see what their dentist sees through the live-viewing feature in the MyDysonT⢠app."
Oh thank god, I've been trying to find the gaps between my teeth on my own, like a sucker. Like a chump. Like some sort of primordial ooze-creature that's barely scuttled onto land and just now learned it even had teeth.
It's not the first Wi-Fi connected toothbrush, of course. Nor is it the only bodily orifice that A.I. companies have been itching to point cameras at.
Yeah, you probably don't want to click that link. I don't blame you. Oh, and it goes without saying that after putting an "A.I."-enchanced camera in, ahem, your toilet, you will have to pay a monthly subscription fee if you want it to tell you what it learned from the pictures it took.
Here's a question: Will you have to upload your drivers license to prove you're you, when subscribing to the camera feed that uploads the goings-on of your butt every toilet-time? Or do you not have to verify your identity when subscribing to the pay-by-the-month My Toilet Highlight Reel? Is it a bluetooth thing, where any guest who enters your bathroom can wave your phone at your Toilet Camera, go sign up for a subscription to your Toilet Camera, and then watch everything that happens on your Toilet Camera for as many months as they're willing to pay for?
Do we think the "A.I." toothbrush-collected data is going to be kept more secure or less secure than the identity verification companies are keeping your drivers license data?
Do we think the "A.I." toilet camera footage is going to be kept more or less safe than the toothbrush footage, the medical records, or the drivers licenses?
Do we think the glasses or pendant learning who you meet with, what foods that person likes, where they can be found at various points of the day, what their children's names are, where their children go to school, and what "relationships" they have with other people you've recordedâas all of that data gets uploaded to The All-Knowing Cloud for processing, is the premise still going to be well you can count on the good people of [insert gigantic company that every world government bows down to] to make sure none of this gets misused?
That's a more nuanced question than it looks, because so far the primary purpose of collecting all of this information has been to sell it to other companies, either for advertising or for A.I. training. The difference between your data getting hacked and your data being safe is not a matter of who has it, but whether that person or company paid for it.
If a company pays $1 for your drivers license scan, that's synergy. That's Innovation. Our entire economy will die if you don't let companies do that.
If a company gets your drivers license without paying the company selling it to others, then that's just theft. You're not respecting their copyrights on what they've collected on you. Knowing whether you like hot dogs is their intellectual property, not yours.
This is what's so maddening about the current Silicon Valley and legislative versions of "the future." They're almost gleefully dystopian. The point of every new product is to record you, your family, and everyone else you meet. All the time. Either from devices attached to you, or to cars, or to lamp posts. Companies desperately wantâno, they say they needâthis information in order to bring you their latest Inventions, which are universally products that dully repeat about 0.5% of the data they've sucked in, often riddled with errors, while the company doesn't just keep the rest of the data but cross-references and indexes and analyzes it with all the other data it's sucked in from everybody else.
Even 20 years ago, the premise of "innovation" was to create new products that people wanted because they were useful. Because they solved a genuine problem, even if a fairly niche one. Robots to vacuum your floors. Smartphone applications to identify birds and their songs, just in case you noticed a bird and were curious about it. Apps to identify the song you were listening to, if it was on the radio and you wanted to buy it for yourself. Well, lease it. Well, temporarily rent it until a new system update bricked whatever piece of electronics you loaded it into.
But this vision of the future, the one trafficked by Elon, by Zuckerberg, by a hundred less-known fabulists and their ten thousand lobbyists and lawyers, has contempt for such things. In this new version of the future, the robots aren't there to help you. The robots are there to be you.
You don't need to remember what your friends like or don't like. Let the robot do it for you.
You don't need to remember what your kids want or need. The robot knows; let the robot decide.
Why are you trying to do a good job at work? The robot can half-ass it while you do nothing. Nobody will know, because your boss uses the same robot to read what you send him. Nobody will ever know, not until the day your half-assed company goes belly up and you have to ask a robot to half-ass a new resume on your behalf.
Why do you have hobbies? Leave the hobbies to the robot. Why do you read books? Ask the robot what's in them. Ask the robot whether you liked them. Tell the robot to brag to your friends that you almost read a book and know the general summary of what happens.
The new vision is that the robots will make your music, and the robots will care for your children, and the robots will make friends so you don't have to, and you will be left with so, so much time to do the things robots aren't as good at, like sweeping floors and screwing in tiny screws.
But this future will only come to pass, warn the Innovators, if we upload everything about who we are and who we meet to the big computers so that the computers can process it, and share it with other computers, and know you. The only way to ensure your glasses know what your child's favorite dinosaur might be is if you let the glasses record everything your child says and does. Put this stuffed animal in your child's bed, and let it record your child sleeping. Try this new robot vacuum: It doesn't work any better than the last one, but if this one gets stuck it has a little camera on it, and it can connect to an Indonesian labor camp where a worker can look through the lens, observe what's happening in your house, and make adjustments, and maybe upload the footage to The Cloud so that The Cloud knows what furniture you might want to shop for next.
There is a monthly vacuum fee, of course. It's a different monthly fee from the toilet fee and the toothbrush fee. And you should pay it, because a half century ago nobody could hand off the task of raising children to a cloud of interconnected toilets and toothbrushes and vacuums, but you can, and if you don't want to be investigated for neglect you'd do well to share all of those feeds with Meta and with Grok so they can check your work. They will check your work.
This is the future we're uploading our drivers licenses to the internet to get?
So far, the only thing everyone can agree on is that it mostly sucks. And while all of these ketamine addicts are quite certain we will let their robots run our lives and remember our memories, not a damn one of these same people and companies has shown an interest in keeping all of what they've sucked up truly safe from being spit back out into criminal parts of the web.
It might be that it's simply impossible, at least with the internet's current cobbled-together architecture. It might be that it is impossible in all cases, because there is no version of electronic security that can't be defeated by an electronic countermeasure.
Or it could be that none of the companies sucking up this data give a particular damn whether or not it is stolen, because collecting the data is very, very lucrative but protecting the data is not. There's a lot of money in pretending that you can secure millions of people's private dataâas marketing gimmick.
But none of these companies have created truly secure systems for doing it. Not even now, after this many breaches and breaches that keep getting larger and larger. There's no reason they should. The worst that can happen, if millions of health records or identification documents are leaked into organized identity theft rings, is that you will have to offer 12 to 18 months of "free credit protection." In bulk, "free credit protection" costs almost nothing.
And, in the meantime, all those same companies can keep gorging on the data brought in by the traffic cameras, the camera-glasses, the pendants that record everything anyone says, and they can keep combining it all together to sell it to the other companies that do the same, and there doesn't seem to be any point to it other than the visceral resentment every tech CEO seems to have when they're asked to act somewhat human.
This is the future, they say. A robot will pretend to be you, and other companies will buy access to the robot that pretends to be you so that they can sell it things a robot pretending to be you might like, and you will do a half-assed job at work and stop paying attention to your friends and your kids because why the hell bother. If there's a problem your toothbrush will talk it out with your toilet. They'll figure it out.
And you will sweep your own damn floors, because there's no money in making a robot for that.
Comments
We want Uncharted Blue to be a welcoming and progressive space.
Before commenting, make sure you've read our Community Guidelines.