IDScan.net is an identity-verification vendor in Louisiana. Its customers include Hertz, FedEx, Target, thousands of cannabis dispensaries, and a roster of tech platforms doing age checks. This week Brian Krebs reported that a dark-web service called Nexus is selling scans of more than 153 million driver's licenses, and that the images appear to be coming out of IDScan's systems in real time. The FBI's New Orleans field office has opened an inquiry. Techdirt's read is that there is no safe age verification. That's true, and it's the smaller point.

The larger one: an age-verification mandate doesn't add a thousand small risks at the margin. It routes a thousand businesses through one pipe. Then it hands out the badges that decide which pipe.

Look at the shape of the breach. A rental counter, a dispensary, a social login, and a shipping account have nothing in common except that each was told to check an ID. None of them wanted to build a scanner. So they bought one, and the market for scanners, like every compliance market, consolidated around whoever had the certifications. IDScan's Trust Center page, still up days after the disclosure, advertises GDPR and CCPA compliance and explains "how we protect data, maintain system reliability, and earn the confidence of our customers." That page is the sales pitch and the selection criterion. It is how a dispensary in Denver and a car rental in Newark end up feeding the same database in Louisiana.

We have been continuously exfiltrating new data for over a year into our private database. Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.
KrebsOnSecurity

Over a year. Nobody inside noticed. In the 24 hours after Krebs's story ran, the listing grew by nearly 400,000 records, which means the tap was still open while the press release was being drafted. Individual records went for $100. One of them was the sitting Secretary of Defense's license. Every one of those 153 million people did the responsible thing: they showed a government ID to a company that had the paperwork.

The mandate didn't create the risk at the margin. It picked the pipe.

The skeptic's answer is fair. Driver's licenses have been leaking for decades. DMVs, Equifax, the federal government's own personnel files. Hertz needed your license before any age-verification bill existed. If your ID is already in thirty dumps, the thirty-first changes little. Concede all of it. Those were breaches of records at rest, one institution at a time, each with its own reason to hold the document. This one is a breach of a pipeline, and the pipeline exists because a growing list of laws requires businesses that never needed your ID to collect it and outsource the collecting. Every new statute is a new feed into the same vendor. The marginal scan in Nexus's database isn't a rental car. It's a login.

There's a version of this where the pipe gets narrower rather than wider: a verifier that returns a yes and discards the image, audited on the discarding rather than on the certificates. No law on the books today requires that. They require the check. The market supplies the archive, because an archive is what the customer's lawyers want and what the vendor's investors call a moat.

Techdirt says you can't do this safely. The plumb line says something narrower and harder to argue with. The laws didn't fail to anticipate a breach. They specified one: a single, credentialed, continuously fed target, chosen by the badge on its trust page. IDScan wasn't the exception to the system. It was the system, working.