• 0 Posts
  • 9 Comments
Joined 3 years ago
cake
Cake day: July 23rd, 2023

help-circle

  • This is exactly like the whole Lifetouch story. It beggars belief.

    Rackspace is, and has been, ISO 27001 certified. Part of that means they can’t directly access customer data. You didn’t link any documents covering the contract that “requires” Rackspace hosting; my base assumption is they’re normal contracts that define hosting for regulatory purposes. None of the documents you’ve linked show Apollo had access to Rackspace infrastructure much less encrypted customer data on Rackspace doesn’t have keys for. The pedo employee had CSAM which does not provide Apollo access to Rackspace infrastructure much less encrypted customer data Rackspace doesn’t have keys for.

    Just like with Lifetouch, if you can show that somehow the equity owners Apollo had direct access to the infrastructure of their investments and somehow managed to either hide or justify it during multiple security audits spanning a decade and somehow got access to customer encryption keys, it’s a possibility. I’m not even using Occam’s razor here; there’s genuinely nothing to even consider hanging a hat on here.

    On the other hand, if Leon Black had direct access to the company running the database, all bets are off. Law enforcement shit gets to sidestep audit shit in dumb ways. But if that were the case, we wouldn’t need Rackspace as the incredibly tenuous connection because he would have had direct access.


  • Absolutely valid. In the context of identity verification, I trust ID.me more than random companies that do not have government contracts because government contracts come with security and compliance regulations that require regular audit and make the chances of breach less likely. In either case, it’s a private company and, as any security nut would have told you, when it gets sold all bets are off like 23andme. Even more importantly, in the US, any kind of ID verification is a terrible idea, government or private, because we have no data regulation or privacy constraints. I call out the US here because we have no GDPR equivalent (CCPA wouldn’t hold up to federal data). Even if ID verification were conducted by the government, it can still be used for gnarly shit like we saw with ICE and DOGE.

    On a sliding scale of evil, ID.me is the evil I know will currently fight to continue remaining the only evil which is the only solace I have in the US.


  • The theme of this post is “what things online would I be okay giving my government ID to.” The author did not mention government services in the article, so I brought those up and differentiated which government services I think are reasonable for ID verification. In the US, social security is basically a retirement fund and a huge target for scammers. I’m willing to verify there or for my taxes (although those should just be done for me; different argument). A data portal eg census data is not something I am willing to verify my ID for because it should be public. US trademarks, for example, now require ID verification for an account. An account gives expands some access on the website and allows the ability to file. If I file a trademark, I am fine with verifying my identity. If I make an account, I don’t need to verify my identity until I file.

    I didn’t mention picture sharing websites because I agree with the author’s stance.