美国驾驶证信息泄露是一场国家安全灾难
America's Driver's License Breach Is a National Security Disaster

原始链接: https://www.lawfaremedia.org/article/america%27s-drivers-licence-breach-is-a-national-security-disaster

以下是《Risky Business》报告重点摘要的中文翻译: **重大数据泄露:** 一个名为“Nexus”的暗网服务近期提供了1.53亿份美国和加拿大驾照数据,这些数据极有可能从身份验证公司IDScan窃取。除了助长常规网络犯罪外,此次大规模窃密还构成了严重的国家安全威胁;外国情报机构(尤其是中国和俄罗斯)可以通过交叉比对这些详细的个人数据,挖掘秘密行动并追踪政府人员。 **军事安全疏漏:** 美国军方终于开始禁用政府设备上的广告标识符,以防止军方人员被追踪。虽然这对行动安全而言是积极的一步,但专家警告称这并非彻底的补救措施,因为它未能解决个人设备带来的风险,也未能解决多年前就已识别出的全面追踪漏洞。 **“白帽”黑客私刑:** “先盗后付”式的黑客攻击趋势仍在继续,近期的作案者在退还被盗加密货币的同时,会私自截留一笔“赏金”。当局警告称,无论窃贼如何自我辩解或受害者是否配合,此类行为依然违法。 **其他新闻:** 其他更新包括谷歌为防御者推出AI驱动的网络安全工具、国际社会对长期存在的Sality僵尸网络的打击,以及乌克兰涉及诈骗呼叫中心的高层腐败丑闻。

这份 Hacker News 讨论贴探讨了一篇《法律战》(*Lawfare*)文章,该文将近期美国驾照数据泄露事件定性为一场国家安全灾难。 评论者对现代网络安全现状持有一种愤世嫉俗的共识,一位用户指出“计算机安全是一个自相矛盾的词”。讨论强调了大规模数据泄露的常态化;尽管驾照泄露令人担忧,但参与者指出,私人医疗记录被泄露的频率要高得多——通常每周涉及数百万条记录——却并未引发公众的强烈抗议。 讨论贴总结认为,只要企业在未能保护敏感用户数据时只需承担微不足道的后果,这种系统性失败就不可避免。总体而言,这种情绪反映了人们对数据窃取频发以及责任方缺乏实质性问责的疲惫与无奈。
相关文章

原文

America's Driver's License Breach is a National Security Disaster

Last week, Krebs on Security broke the story of a newly launched dark web service calling itself Nexus that was selling access to identity documents, including 3 million travel documents and 153 million driver's licenses from U.S. and Canadian citizens. This is a huge breach that not only will be used for run-of-the-mill cybercrime but also will feed the intelligence machines of America's adversaries.

Nexus claimed that it had gained unauthorized access to a major identity verification company and had spent more than a year "continuously" exfiltrating new data into a private database. Krebs on Security noted that in a single day the number of licenses in the database increased by nearly 400,000, suggesting regular ingestion of new data.

Krebs on Security was able to verify that the driver's licenses held by the service were genuine. In addition to Krebs’s own, it contained licenses from nine of his friends and family members. Secretary of War Pete Hegseth, an assistant director at the FBI and other high-ranking U.S. government officials also had licenses in the mix.

Based on a variety of circumstantial evidence, Krebs linked the incident to identity verification service IDScan. The service's website says it helps to reduce fraud by confirming that an ID is authentic and being presented by its legitimate owner and by detecting fraudulent documents.

The FBI is looking into the incident, and IDScan has confirmed it is investigating a data breach. The Nexus service also disappeared from the dark web shortly after Krebs published his story, although the people responsible for the hack do not claim to have deleted the data. Presumably they are lying low till the publicity dies down. 

Licenses and identity documents can be used to facilitate identity theft and phishing attacks, but because the data can be used to inform intelligence operations, an incident like this also has national security implications.

For the intelligence world, licenses are particularly valuable because they're key identity documents and license numbers are often used in other databases. These databases, whether hacked or purchased, become much more valuable when records can be linked directly to a particular person with home address and photo included.

And it's not a theoretical threat.

In the mid-2010s, Chinese cyber espionage actors stole complementary data from a variety of sources that, together, would be useful for analyzing the U.S. intelligence apparatus. Various Chinese APT groups stole information from the health insurance company Anthem, credit reporting company Equifax, Marriott hotels, United Airlines, and, perhaps most significantly, security clearance information from the Office of Personnel Management.

The U.S. intelligence community is certain that stolen data was used to counter American intelligence efforts against China, as described in this series of Foreign Policy articles by Zach Dorfman.

Of course, China itself isn't known for releasing detailed reports describing how it exploits its stolen data, but investigative research outfit Bellingcat has shown exactly how similar data can be used to uncover covert government activity.

In 2022, a hacked database provided a key piece of travel information that helped Bellingcat identify a deep cover GRU agent (Russian military intelligence) trying to infiltrate a NATO command post in Naples, Italy. And in another striking example, these three Bellingcat reports from 2018 identified suspects in the attempted assassination of Sergei Skripal with the Novichok nerve agent.

Clearly, leaked and hacked databases are incredibly useful for Bellingcat's Russia-related investigations. In 2020, it said it had "acquired dozens of leaked databases over the past few years, giving us a large number of data points to cross-reference and verify any new data we acquire."

If a small investigative outfit is hoovering up Russian data when it is leaked, you can bet your bottom yuan that China's intelligence services are doing the same for any American data that pops up.

The IDScan breach is big. The number of U.S. licenses in the database is roughly 63 percent of the country's total licenses. But breaches from identity verification companies occur depressingly frequently. In the past two years, breaches have occurred at AU10TIX, at Discord's age verification service provider 5CA, and at National Public Data.

Identity verification services are necessary to help to prevent fraud but are also a point of vulnerability when security is poorly done. The sheer volume of sensitive data these services handle means they should be subject to strict regulation and oversight.

We're realists here at Seriously Risky Business, though, and recognize that there is no chance of swift government action. In the short term, we can only hope that significant financial consequences will help encourage these firms to shore up their security. Law firms are already lining up class-action suits against IDScan, but a little federal government attention from the Federal Trade Commission wouldn't be unwelcome either.

The U.S. Military's Ad-Tracking Fig Leaf

Back in June, Reuters reported that commercial location data was being used to target U.S. military personnel in the Middle East. At the time, we wrote that the Department of Defense's existing policies regarding the issue, which already included disabling advertising identifiers on military-owned devices, did "not fill us with confidence." They simply weren't comprehensive enough.

It turns out that these policies weren't even being well implemented.

This week, Reuters reported that some branches of the U.S. military have finally gotten around to disabling some advertising identifiers on military-owned devices.

The U.S. Air Force said it disabled Windows and Android advertising identifiers in late July, although they were already disabled on Apple devices. The Army told Reuters it disabled advertising identifiers on Android and Apple devices by default in February. And U.S. Special Operations Command said that identifiers on Windows computers were "recently" disabled. 

Turning off these advertising identifiers is a fundamental mitigation that should have been implemented years ago. The U.S. military was first briefed in 2016 about the potential for commercial location data to be used to track its people to sensitive locations. In a striking 2018 example, an Australian Twitter user pointed out that Strava's global heat map could be used to identify U.S. military bases and even service members' jogging routes.

Disabling advertising identifiers on military devices is also an incomplete solution. It makes it harder to track them, but not impossible. And as it happens, many U.S. service members also use personal devices. Having a locked-down work phone is step one, but having good policies for personal devices is equally important.

Disabling advertising identifiers by default is the simplest short-term measure that might improve operational security (OPSEC), but it is impossible to know if it will make much of a difference without assessing the U.S. military's OPSEC posture holistically. Does disabling advertising identifiers on government devices reduce risk to an acceptable level? Probably not.

It's good that the U.S. military is finally disabling advertising identifiers by default. But we’re concerned the military has no idea how effective it will be.

"White Hats" Are Kidding Themselves

Over the weekend, self-proclaimed white-hat hackers stole $320 million worth of Bitcoin from the Liquid Network cryptocurrency platform. By Wednesday, the hackers had returned 85 percent of the funds, but kept around $47 million.

In recent years, there has been a regular drumbeat of steal-first-claim-reward-later hacks. We begrudgingly categorize several of these as successes as the perpetrators have not (yet) been arrested or jailed.

In 2021, a hacker stole $610 million worth of cryptocurrency from Poly Network. This was eventually returned in full, minus the  company's offer of $500,000 for the attacker it referred to as Mr White Hat.

Hacks of Multichain (2022), Huobi (2023), and Tender.fi (2023) had similar outcomes: Millions were stolen and returned, with the hackers taking a cut of tens or hundreds of thousands in cryptocurrency as a "reward" or "bug bounty."

The standout example is the 2022 hack of Mango Markets, in which a hacker extracted $110 million from the decentralized exchange. The individual responsible, Avraham Eisenberg, described his actions at the time as a "highly profitable trading strategy." He claimed all his actions were legal and he used the protocol as designed, "even if the development team did not fully anticipate all the consequences of setting parameters the way they are." 

Eisenberg returned $67 million to Mango Markets to recapitalize it, and the Mango community voted to give him a cool $47 million for his time. Eisenberg was convicted of fraud in a 2024 jury trial, but those convictions were overturned by a U.S. judge last year.

In our view, the perpetrators of these hacks are deceiving themselves. By returning most of the money, they're deluding themselves into thinking they're acting responsibly. As for consequences, the law won't chase me down if I return the majority and the victim says it's fine … right?

In Eisenberg's case, it did turn out to be right. But the FBI has been clear that victims cannot guarantee that perpetrators will not be prosecuted.

One wrinkle in the Liquid Network case is, as far as we can tell, the company never agreed to allow the hacker to keep a 15 percent cut.

It feels possible that this self-proclaimed good guy might have to spend some of that $47 million on a good lawyer.

Three Reasons to Be Cheerful This Week:

  1. More options for trusted defenders: Last week, Google launched the Fairwind Program, its version of equivalent Anthropic's Project Glasswing and OpenAI's Trusted Access initiatives to limit more advanced AI cyber capabilities to vetted cyber defenders. On the same day, it launched Gemini 3.8 Flash Cyber, a cyber-specific version of its latest model that will be available through its Fairwind Program. Google says the model delivers "frontier-level" performance in vulnerability detection and patching but is far cheaper than competitor models. 
  2. Sality botnet takedown: Last week, the U.S. Department of Justice and Europol announced that an international operation had disrupted the Sality botnet. The botnet was first detected way back in 2003, and its peer-to-peer architecture meant there was no single point of failure that authorities could attack. CrowdStrike's blog on the takedown says that for the past eight years the botnet's primary payload, known as EggJagger, monitored the compromised host's clipboard for cryptocurrency wallet addresses and replaced them with addresses controlled by the malware operator.
  3. U.S., U.K. to collaborate on scam networks: British and American authorities have signed a memorandum of understanding to collaborate on efforts to tackle scam compounds.

Risky Biz Talks

In our latest "Between Two Nerds" discussion, Tom Uren and The Grugq talk about whether AI will help cyber defense in critical infrastructure and organizations that are below the cyber poverty line.

From Risky Bulletin:

Ukraine's top prosecutor resigns amid scam call center scandal: Ukraine's top prosecutor, Ruslan Kravchenko, resigned on Monday over allegations that individuals in his office were taking bribes to protect scam call centers operating across the country.

His resignation comes after investigators from Ukraine's main anti-corruption body, the National Anti-Corruption Bureau (NABU), arrested Serhiy Kropyva, the deputy head of the Department of International Cooperation, a top lieutenant in Kravchenko's Office of the Prosecutor General.

In a report last week, NABU claimed it uncovered a major scheme in Kravchenko's office, where one of his department heads was taking bribes to look the other way when it came to a network of call centers that was calling Ukrainians and foreigners and luring them into fake investment platforms that stole their money.

[more on Risky Bulletin]

BEC campaign steals 35 million euros from French notaries: Hackers have stolen more than 35 million euro from French notaries in a massive business email compromise campaign over the past four years.

The attackers breached companies via phishing, took over their networks, and slowly and silently modified transaction details to hijack wired payments.

According to French newspaper Le Monde, the campaign hit more than 500 victims, or about 7 percent of all French notary offices.

[more on Risky Bulletin]

Russia tells data centers to deploy drone defenses: The Russian government has instructed data center operators to deploy protections against drone strikes and other physical threats as part of a national effort to boost defenses at critical infrastructure organizations.

Companies that fail to follow the Kremlin's instructions risk having their operations put under the state's administration.

Russian President Vladimir Putin signed a presidential decree last month allowing the state to temporarily take over the operations of critical infrastructure operators who fail to protect against Ukrainian hacks and drone strikes, or who take too long to repair damage.

[more on Risky Bulletin]

联系我们 contact @ memedata.com