this post was submitted on 03 Sep 2026
842 points (99.1% liked)

Technology

87897 readers
4377 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] Darkard@lemmy.world 540 points 4 days ago (102 children)

But don't forget guys, uploading your government IDs to any old fucking website to prove your age is very safe and protects children. There's no way this could go wrong and everyone in the supply chain is very trustworthy

load more comments (102 replies)
[–] sunbytes@lemmy.world 40 points 3 days ago (2 children)

The only way to fix this is to have us upload our IDs online constantly, perhaps to prove we are adults.

It is the only way we can we safe.

[–] MadBits@europe.pub 9 points 3 days ago

But, just think about the children! ~While everyone plastered their children allover social media and they are easily identified with AI~

Woaha. Why didn't anyone think of this before you?

[–] Yaky@slrpnk.net 131 points 4 days ago (3 children)

Also it doesn't help that, for example, at U-Haul, employees just use their personal phone to scan a QR code and take pictures of your ID.

[–] HubertManne@piefed.social 64 points 4 days ago (1 children)

this idea that employees can expect you own and use a personal smartphone as part of the job irks the heck out of me.

[–] ChexMax@lemmy.world 5 points 3 days ago (1 children)

I read that if you use a personal device for anything work related in the US, it means your entire personal device (everything on it) can be considered discovery in a lawsuit against that company. Big risk to take.

load more comments (1 replies)
[–] toynbee@piefed.social 39 points 4 days ago (3 children)

My local hospital apparently requires their employees to use a "secure" app on their personal phone to transmit data on the patients.

Seems like irresponsible handling of PHI (by the administration, not the staff) to me.

load more comments (3 replies)
load more comments (1 replies)
[–] 0x0@lemmy.zip 25 points 3 days ago (3 children)

I bought a domain, configured the webserver in the next 5m.

As soon as it started taking requests (on a domain that i haven't even announced yet) it got flooded by bots.

[–] Brimstone@lemmy.ml 18 points 3 days ago* (last edited 3 days ago) (1 children)

Yeah I worked for company with publicly exposed server, the logs were amazing.

Just bots scanning default ports trying default username and password for services like Microsoft SQL server.

It’s such a waste of energy really

[–] edgesmash@lemmy.world 6 points 3 days ago

That's been happening since forever, though. I helped manage proxy servers for my first job in the mid 00's, and those server logs were mostly automated port scans and failed login attempts, even on the newly commissioned servers.

[–] ddplf@szmer.info 9 points 3 days ago (1 children)

If your browser is based on chromium, you're employing an army of bots yourself that gets enabled each time you enter any domain.

[–] horsesaysweird@feddit.org 11 points 3 days ago

Can you explain what you mean exactly?

[–] dreadbeef@lemmy.dbzer0.com 4 points 3 days ago* (last edited 3 days ago)

Registering SSL is a centralized process with root CAs logging new ones as they come in. Cert transparency logs are a thing, and Google is very involved: https://certificate.transparency.dev/

Once a bad actor hooks up to that, they just get a realtime stream of places to start port scanning and running WHOIS queries for people who didn't get WHOIS protection. If you used letsencrypt your domains you registered certs for got sent there and anyone who wanted to know about it knew about it before you could tell anyone.

You can use something like crt.sh to look up domains

[–] dan1101@lemmy.world 98 points 4 days ago (2 children)

I don't like it when a store scans my driver's license to buy alcohol. I stick to small convenience stores without that tech.

[–] rants_unnecessarily@piefed.social 26 points 4 days ago* (last edited 4 days ago) (12 children)

Why would they do that? What's the use of scanning it?

[–] Steve@startrek.website 59 points 4 days ago (1 children)

It keeps liquor prices down because you get the extra revenue from selling the scans. Try to keep up smh

load more comments (1 replies)
[–] socphoenix@lemmy.world 27 points 4 days ago

It validates against the states license database to confirm it’s a legitimate ID and not a fake.

load more comments (10 replies)
[–] boonhet@sopuli.xyz 18 points 4 days ago* (last edited 4 days ago) (3 children)

Had a fun time visiting the US, clerk didn't understand why she couldn't scan my ID and find it in the database. All that for trying to buy some cigarettes as I was a smoker at the time and didn't bring much with me (stupid mistake, they're way more expensive in the US)

load more comments (3 replies)
[–] Bell@lemmy.world 52 points 4 days ago (4 children)

Annnd this is why a refuse to verify with IDs online and use services like Plaid. And the web of T&C's from multiple 3rd party services like this will mean all of them get shielded from blame.

[–] 7101334@lemmy.world 32 points 4 days ago (3 children)

Did you read the article? They were renting a car. A car rental place isn't going to let you just not show your ID.

[–] ikidd@lemmy.dbzer0.com 24 points 4 days ago (1 children)

So how they did it once upon a time was you showed them your license, they punched the # into the system that would check it. The person at the desk would confirm it was you from the picture. No need to scan the actual ID card, which is where this problem comes from.

load more comments (1 replies)
load more comments (2 replies)
load more comments (3 replies)
[–] Hikermick@lemmy.world 45 points 4 days ago (2 children)

My elderly father recently fell for a Facebook imposter that pretended to be a family member and asked if their friend could contact him. The friend asked him to take a photo of his driver's license and text it to them, fortunately he doesn't know how. I've been wondering ever since what can they do if they had it? It doesn't have his social security number on it. His credit has since been locked and banks notified

[–] GenosseFlosse@feddit.org 27 points 4 days ago* (last edited 4 days ago) (1 children)

They can open bank or crypto accounts in his name, and then either overdraw the account or use it to move money from other scams in and out of this account, so the real scammers name is not attached to this account.

load more comments (1 replies)
[–] historicaldocuments@lemmy.world 17 points 3 days ago

I’ve been wondering ever since what can they do if they had it?

Ask for pictures of all his other paperwork so they can finish onboarding him at his new job.

[–] Horsey@lemmy.world 10 points 3 days ago* (last edited 3 days ago) (3 children)

Wait until non Americans hear that our national social security ID number is only 4/9 digits worth of “random” numbers. (Fun fact, the entire number was procedurally generated based on where you were born and in what order at the hospital for generations until they changed it recently)

load more comments (3 replies)
[–] ilillilillilillililli@lemmy.world 58 points 4 days ago (1 children)

Luckily archive.org saved the idscan.net press release announcing their partnership with Planet13 dispensaries. They have since deleted the post on their site. Nothing shady about that. 😂

load more comments (1 replies)
[–] ftbd@feddit.org 52 points 4 days ago (2 children)

Surely the company must be liable, right guys? Right...?

load more comments (2 replies)
[–] nanometer1625@thelemmy.club 10 points 3 days ago* (last edited 3 days ago) (1 children)

This is yet another reason why virtual ID cards are superior: In the event that the card data is compromised, the old virtual ID can be revoked and a new virtual ID can be issued. Virtual ID cards can also have a much shorter duration, because the cost of rotating it is minimal. For example, California's virtual driver licenses rotate each 30 days.

load more comments (1 replies)
[–] Malica@lemmy.zip 19 points 4 days ago (2 children)
load more comments (2 replies)

I have had to rent cars since 2015. My license has probably been seen by 5000 breach sites by now.

load more comments
view more: next ›