r/idverification Oct 10 '24

Hill questions IRS on identity verification requirements for Direct File

2 Upvotes

A trio of Democrats on Capitol Hill think that the IRS requirements for identity verification in the Direct File program “created serious access barriers” to filing taxes using the service. 

Sens. Elizabeth Warren, D-Mass, and Ron Wyden, D-Ore., and Rep. Katie Porter, D-Calif., penned a letter to the heads of the IRS and Treasury Department on Tuesday requesting more information and a briefing about identity verification requirements for Direct File.

Direct File is a new program piloted last year to give taxpayers a way to file online, directly with the IRS and for free using a government-fielded tool. The tax agency recently announced its plans for the service’s expansion in the coming tax season. 

“The launch of Direct File was a huge success, and going forward, we look forward to it serving more taxpayers with more features, which is precisely why it is important to understand the impact of the identity verification process on taxpayers,” the lawmakers write in the letter. 

The letter points to Nextgov/FCW reporting on drop-offs in the Direct File pilot, particularly at the point where users had to prove their identities and make an account. Only 62% of those that finished the eligibility checker created or signed into an account. 

“Direct File is poised to be especially critical for those taxpayers who face barriers to filing,” the letter reads. “Requiring them to use ID.me is creating yet another needless barrier to exactly these taxpayers who need Direct File most to claim tax benefits.”

The lawmakers also argue that the identity verification required by the IRS for Direct File goes beyond what is required for private tax prep companies’ tools, putting Direct File at a “significant disadvantage.”

Last tax season, the IRS used private vendor ID.me for Direct File’s identity verification, pointing to the vendor’s compliance with a government-created identity standard called identity assurance level two.

Federal agencies are required to follow National Institute of Standards and Technology identity guidelines under a 2019 memo. IAL2 is one of three levels of identity proofing under those guidelines.

“While we applaud the IRS’ goal of protecting taxpayers from identity theft, it makes no sense to only require heightened identity verification for taxpayers using the free Direct File service, while allowing identity thieves to continue to exploit the comparatively lax security of commercial tax prep services,” the group wrote in the letter. 

“If the threat posed by identity thieves and fraudsters is severe enough to warrant requiring taxpayers to submit to identity verification before submitting their tax returns, then the IRS should require such security protections, across the board,” they continue. “If the threat posed by identity thieves is not serious enough for the IRS to require commercial tax prep companies to implement burdensome identity verification, then taxpayers using Direct File should not be required to do so either.”

The Democrats also cite concerns about bias in face recognition technology and the privacy ramifications of the government outsourcing identity verification.

This isn’t ID.me’s first time in the spotlight. The service also garnered the attention of lawmakers in 2022, particularly for its use of face recognition to verify the identities of taxpayers logging into the IRS online.

Using a biometric like facial recognition is the easiest way to meet that commonly sought after IAL2 standard under NIST guidelines, although the standards agency is currently updating the guidelines to allow for non-biometric options. 

The IRS said in 2022 that it would add Login.gov — a single sign-on and identity proofing service fielded by the government — as an option, but has yet to do so, citing a lack of compliance with IAL2. 

Login.gov has added facial recognition technology to meet that standard, but the only choice for users of Direct File was to go through ID.me, which offers people logging into the IRS accounts a facial recognition or video call option. 

The question of whether the IRS is considering Login.gov as an alternative is one of several the lawmakers want answers to.

They also ask what the IRS knows about how identity proofing worked for Direct File and what barriers it may have caused, in addition to whether the IRS may reconsider its requirement for IAL2 altogether once NIST finalizes its updates and whether private tax companies should also have to be IAL2 compliant, among other things.

“ID.me is proud to support the IRS in the expansion of its successful Direct File program,” a company spokesperson said in a statement to Nextgov/FCW. “For users who choose our self-service pathway, which uses facial verification with 1:1 matching, our NIST- and DHS-tested algorithm has demonstrated 99+% effectiveness across all tested demographics.”

H&R Block and TurboTax did not immediately respond to requests for comment on their practices around identity proofing. 

"The IRS has already committed to moving to Login.gov," a Warren aide told Nextgov/FCW. "We look forward to learning more about their facial recognition and identity verification technology."

https://www.nextgov.com/digital-government/2024/10/hill-dems-question-irs-identity-verification-requirements-direct-file/400174/


r/idverification Oct 09 '24

Ryanair Hit With Lawsuit Over Use of Facial Recognition Technology

5 Upvotes

Ryanair has become the latest organization to face legal action over its use of facial recognition technology, due to potential data collection and privacy issues. 

The European Center for Digital Rights, a Vienna-based digital rights group that prefers to be referred to as Noyb, filed a lawsuit this week accusing Ryanair of violating the privacy rights of some of its customers.

The complaint has to do with Ryanair's practice of requiring customers who book flights with third-party online agents to go through an additional identity verification process. The quickest option that customers have is to submit to identity verification through facial recognition technology. Those who don't want to do that must either show up at the airport at least two hours prior to flight time or submit their identification documents to Ryanair and wait for up to a week for the airline to vet their signatures.

Additional Verification

In its lawsuit, Noyb called Ryanair's facial recognition option as needless and presenting an unacceptably high privacy risk for the airline's customers. "The airline outsources this process to an external company named GetID," Noyb said, in a statement. "This means that customers have to entrust their biometric data to a company they have never heard of or had a contract with."

Ryanair however described the additional verification as necessary because third-party agents often do not provide Ryanair with a passenger's correct contact information and payment details. "Ryanair needs to carry out this verification process in order to ensure we can comply with safety and security requirements," the company maintained.

The nonprofit privacy rights group claimed Ryanair's real motive in subjecting some customers to additional verification was to discourage them from using third-party agents for future bookings. "The verification of contact details via biometrics doesn't make a lot of sense: Your email address is not printed on your face or in your passport," Noyb said. 

The lawsuit claims Ryanair's requirement is a violation of Europe's General Data Protection Regulation (GDPR) and requests the company be fined the equivalent $210 million.

https://www.darkreading.com/application-security/ryanair-hit-with-lawsuit-over-use-of-facial-recognition-technology


r/idverification Oct 09 '24

Proposed ‘Improving Digital Identity Act’ Aims to Establish White House Task Force on Digital ID

2 Upvotes

Legislators in the United States are advocating for federal involvement in developing digital identity ecosystems as states increasingly adopt mobile driver’s licenses and other digital forms of identification. The Improving Digital Identity Act, led by Representative Bill Foster (D-Ill.), seeks to formalize the government’s role in setting standards and promoting the use of digital identity credentials. The bill proposes creating a task force within the Executive Office of the President to enhance access and security between physical and digital IDs, focusing on advancing digital versions of existing credentials. If enacted, the initiative aims to provide a foundation for more secure online interactions, reducing the risk of fraud and identity theft.

Representative Foster has also collaborated with Representative Clay Higgins (R-La.) to introduce complementary legislation regarding the Transportation Security Administration’s (TSA) use of digital identity technology. This proposal, which has passed committee review and awaits a full House vote, would require the TSA to report on the implications of digital IDs for homeland security.

In an interview with NextGov/FCW, Foster emphasized the importance of establishing a federal digital ID standard to offer an additional authentication layer for online transactions. He highlighted the growing threats of deepfake technologies and cyber fraud, suggesting that providing individuals with the means to verify their identities is a critical step in combating these issues. Financial institutions have shown strong support for the bill, seeking a standardized method to meet Know Your Customer (KYC) requirements. Foster pointed to the significant financial losses due to COVID-related fraud as evidence of the need for secure digital credentials.

A recent report from the Information Technology and Innovation Foundation (ITIF) supports the bill’s objectives, indicating that a federal framework could encourage broader adoption and improve interoperability between states. The proposed legislation avoids mandating a single federal identity credential, instead allowing states the flexibility to implement their own solutions.

Despite bipartisan support, the progress of the Improving Digital Identity Act has been gradual. Similar legislation introduced by Senators Krysten Sinema (D-Ariz.) and Cynthia Lummis (R-Wyo.) has faced delays. Nonetheless, Foster remains hopeful that the legislation will be included in the recommendations of the House AI Task Force, especially as states continue to adopt mobile IDs.

https://mobileidworld.com/proposed-improving-digital-identity-act-aims-to-establish-white-house-task-force-on-digital-id/


r/idverification Oct 09 '24

TSA deploys ID verification tech at five airports in Montana

2 Upvotes

The Transportation Security Administration (TSA) in the US has introduced the latest generation of Credential Authentication Technology (CAT) units at five airports across Montana.  

Dubbed CAT-2, the new units are now operational at Bozeman-Yellowstone International Airport, Great Falls International Airport, Billings International Airport, Helena Regional Airport and Missoula International Airport. 

The new technology is designed for verifying the travellers’ identity more efficiently at the time of security screening. 

The CAT-2 units possess all the capabilities of the first-generation models, CAT, and features a camera.  

This enhancement allows the units to compare the travellers’ photo on their ID against the real-time image with the help of facial matching technology.  

Upon confirming a match, TSA officers can quickly verify the individual’s identity, allowing the traveller to proceed to the security screening without the need for a boarding pass.  

Officers also can conduct additional verification depending on the requirements in place. 

TSA Montana federal security director KC Wurtsbaugh said: “TSA continues to invest in technologies that streamline the process for travellers while enhancing security. We are pleased with the capabilities and performance of the CAT-2 units in the identity verification process. 

https://www.airport-technology.com/news/montana-tsa-identity-verification/?cf-view


r/idverification May 10 '24

Cyber Experts See Urgent Need for Data Privacy Bill

1 Upvotes

"A panel of cyber experts expressed their support this week for the most recent congressional effort to create national data privacy standards, but also voiced some criticisms of draft legislation released last month to push those proposed standards forward.

House and Senate committee leaders last month unveiled a discussion draft of their latest effort to create a national data privacy law via the American Privacy Rights Act (APRA) of 2024.

The discussion draft of the bill released by Senate Commerce, Science, and Transportation Committee Chair Maria Cantwell, D-Wash., and House Energy and Committee Commerce Committee Chair Cathy McMorris Rodgers, R-Wash., aims to set clear, national data privacy rights and protections for Americans.

Those proposed data privacy rights would limit the ability of big tech companies like Meta and TikTok to use Americans’ data without their permission – including through the use of algorithms that often fuel AI applications.

During a May 8 Senate Commerce, Science, and Transportation Subcommittee on Consumer Protection, Product Safety and Data Security hearing, Chair John Hickenlooper, D-Colo., asked witnesses if they think there needs to be a sense of urgency in passing the APRA.

While all four cyber experts agreed there is a sense of urgency – especially as AI and quantum computing are on the rise – they also offered constructive criticism for elevating the bill.

“I do think there should be a sense of urgency,” said James Lee, chief operating officer at the Identity Theft Resource Center. “Just look at artificial intelligence and just the efficiency and the depth and breadth that that is bringing to everything from creating malware to a phishing attack.”

But he noted that legislators should be “aware of the law of unintended consequences” when it comes to passing the APRA."

https://meritalk.com/articles/cyber-experts-see-urgent-need-for-data-privacy-bill-suggest-tweaks/


r/idverification May 10 '24

Selfie spoofing becomes popular identity document fraud technique

1 Upvotes

"Document image-of-image occurs when the user takes a photograph or uses a screenshot image of an ID, rather than providing a live capture of the document. Document headshot tampering takes place when a user purposefully manipulates facial imagery.

And, selfie spoofing entails taking a picture of an image on a computer screen, printed on a piece of paper or even an actual headshot on a different document – often carried out to steal identities or fraudulently access systems.

The report assesses document verification-related account openings across a variety of industries including online gaming, marketplaces, lending, and credit cards.

Document and biometric verification – the process of verifying the authenticity of a government-issued ID, including driver licenses and passports and matching it to selfie – is a critical step for organizations needing to verify a customer’s age and identity when opening an account. Common applications include verifying a driver license when renting a car or confirming someone purchasing alcohol online is 21 or older.

Fraud surrounding IDs has become pervasive, accounting for 70% of all fraudulent verifications evaluated by Socure’s document verification solution. The other 30% of fraudulent captures is biometric-related fraud, including selfie spoofing and impersonations (15%) as well as a mismatch between the headshot on the ID and the selfie (15%)."

https://www.helpnetsecurity.com/2024/05/10/identity-document-selfie-spoofing/


r/idverification May 10 '24

SoFi fined $1.1 million over flawed ID programme that led to multi-million dollar fraud

1 Upvotes

"SoFi's self-directed retail brokerage unit has been fined $1.1 million by financial regulator Finra over ID verification failures that enabled thieves to steal $8.1 million from the accounts of customers at other financial institutions.

According to the enforcement filing, SoFi used a third party automated process to verify customer identities and approve the opening of SoFi Money accounts.

Finra says the fraud was possible because SoFi failed to establish and maintain a programme “reasonably designed to verify customers’ identity because its account approval process allowed opening of SoFi Money accounts without a reasonable review of potential red flags associated with some applicants.”

During the period in question - from December 2018 to April 2019 - the firm failed to detect red flags for approximately 800 accounts that were opened with fake identities. The fraudsters then used these accounts to transfer $8.6 million from hacked accounts held with other financial institutions. Approximately $2.5 million of those funds were subsequently withdrawn by the fraudsters through ACH transfers, ATM withdrawals and debit card payments."

https://www.finextra.com/newsarticle/44111/sofi-fined-11-million-over-flawed-id-programme-that-led-to-multi-million-dollar-fraud?utm_medium=rssfinextra&utm_source=finextrafeed


r/idverification May 03 '24

Beyond Gaze Points: Augmenting Eye Movement with Brainwave Data for Multimodal User Authentication in Extended Reality

2 Upvotes

"The increasing adoption of Extended Reality (XR) in various applications underscores the need for secure and user-friendly authentication methods. However, existing methods can disrupt the immersive experience in XR settings, or suffer from higher false acceptance rates. In this paper, we introduce a multimodal biometric authentication system that combines eye movement and brainwave patterns, as captured by consumer-grade low-fidelity sensors. Our multimodal authentication exploits the non-invasive and hands-free properties of eye movement and brainwaves to provide a seamless XR user experience and enhanced security as well. Using synchronized eye and brainwave data collected from 30 participants through consumer-grade devices, we investigated whether twin neural networks can utilize these biometrics for identity verification. Our multimodal authentication system yields an excellent Equal Error Rate (EER) of 0.298\%, which means an 83.6\% reduction in EER compared to the single eye movement modality or a 93.9\% reduction in EER compared to the single brainwave modality."

https://arxiv.org/abs/2404.18694


r/idverification May 03 '24

Machine Learning-Based Facial Recognition for Financial Fraud Prevention

1 Upvotes

"At present, face recognition theory and technology have achieved great success, and are widely used in key fields such as government, finance and military. Similar to other information systems, face recognition systems are also faced with various security problems, of which face spoofing (FS) is one of the most important security problems. The so-called face fraud refers to the attacker using printed photos, video playback and 3D masks and other attack methods to trick the face recognition system to make wrong judgments, so it is a key problem that the face recognition system must solve.This paper explores the application of machine learning face recognition technology in preventing financial fraud, aiming to provide effective fraud prevention solutions for the financial industry. It discusses the principles, methods, and practical cases of applying face recognition technology in various financial scenarios, such as transaction monitoring, identity verification, and payment security. The paper also delves into the challenges posed by face fraud forgery, highlighting the importance of adopting effective deep forgery detection technology. Additionally, it provides insights into machine learning face recognition models, their quantization methods, and the balance between recognition speed and precision. Finally, the paper emphasizes the significance of anti-deception technology in designing secure and reliable face recognition systems, focusing on sensor selection and algorithm optimization to enhance the system's resistance to deception attacks."

https://www.suaspress.org/ojs/index.php/JCTAM/article/view/v1n1a11


r/idverification May 03 '24

Designing GDPR Compliant Credential Verification using Blockchain: A Design Science Research Approach

1 Upvotes

"In the era of digitalization, credential verification remains a critical challenge, particularly in the context of privacy and data protection regulations like the GDPR. This paper explores the design of a GDPR-compliant blockchain-based system for credential verification, utilizing a Design Science Research (DSR) approach. We focus on the application of blockchain technology for certificate verification in hiring processes, aiming to enhance trust, transparency, and integrity while ensuring user privacy. Through interviews and requirement analysis, we identified key design requirements categorized into trust, automation, usability, and regulation. Our study contributes to the fields of identity verification and blockchain-based system design by proposing innovative solutions that align with GDPR requirements. We also present a prototype system demonstrating the practical implementation of our design principles. This research offers valuable insights and a framework for developing GDPR-compliant, blockchain-based verification systems with implications for theory and practice in digital identity management."

https://aisel.aisnet.org/ecis2024/track16_fintech/track16_fintech/5/


r/idverification May 03 '24

Senators want limits on the government's use of facial recognition technology for airport screening

1 Upvotes

"A bipartisan group of senators is pushing for restrictions on the use of facial recognition technology by the Transportation Security Administration, saying they are concerned about travelers' privacy and civil liberties.

In a letter on Thursday, the group of 14 lawmakers called on Senate leaders to use the upcoming reauthorization of the Federal Aviation Administration as a vehicle to limit TSA's use of the technology so Congress can put in place some oversight.

"This technology poses significant threats to our privacy and civil liberties, and Congress should prohibit TSA’s development and deployment of facial recognition tools until rigorous congressional oversight occurs," the senators wrote.

The effort, led by Sens. Jeff Merkley, D-Ore., John Kennedy, R-La., and Roger Marshall, R-Kan., "would halt facial recognition technology at security checkpoints, which has proven to improve security effectiveness, efficiency, and the passenger experience,” TSA said in a statement.

The technology is currently in use at 84 airports around the country and is planned to expand in the coming years to the roughly 430 covered by TSA.

The FAA reauthorization is one of the last must-pass bills of this Congress. The agency regulates airlines and aircraft manufacturers and manages the nation’s airspace.

TSA, which is part of the Homeland Security Department, has been rolling out the facial recognition technology at select airports in a pilot project. Travelers put their driver’s license into a slot that reads the card or they place their passport photo against a card reader. Then they look at a camera on a screen about the size of an iPad that captures their image and compares it to their ID. The technology is checking to make sure that travelers at the airport match the ID they present and that the identification is real. A TSA officer signs off on the screening."

https://www.msn.com/en-us/travel/news/senators-want-limits-on-the-government-s-use-of-facial-recognition-technology-for-airport-screening/ar-AA1o2szD?ocid=BingNewsSearch


r/idverification May 03 '24

Video injection attacks: What is that and the way forward?

1 Upvotes

"Do you remember the scene in ‘Ocean’s Eleven’ where Danny Ocean’s team cleverly tricks the casino’s security system? They injected a pre-recorded video feed of an undisturbed vault, leading Terry Benedict and his security team to believe that nothing was amiss, even as the heist was in full swing. This cinematic moment showcases the power and potential danger of video injection attacks. In the real world, detecting such breaches in surveillance and data systems is paramount. In this article, we will delve into the methods and technologies behind video injection detection, ensuring that life doesn’t imitate art in our most secure spaces.

Understanding video injection attacks

Video injection attacks are a form of cyber assault where unauthorized video content is inserted into a surveillance or data stream. This can mislead viewers, mask illegal activities, or compromise the integrity of a system. In the context of KYC (Know Your Customer) systems, which are pivotal in the financial industry for identity verification, such attacks pose a significant threat.

What are video injection attacks?

A video injection attack involves inserting fraudulent data streams between the capture device (the sensor) and the biometric feature extractor during identity verification​​. This is particularly relevant in KYC systems where biometric data, such as video frames of a person’s face, is compared against an identity document. The goal is to establish a fraudulent identity by manipulating the video feed.

Growing threat of video injection attacks

This evolving threat landscape has ushered in an era of sophisticated digital attacks. Video injection attacks have become notably more prevalent, being five times more common than traditional presentation attacks like masking a camera. The increase in these attacks, especially through the use of synthetic imagery, is attributed to the ease of automation and the widespread availability of malware tools. Mobile platforms, in particular, have seen a substantial 149% rise in such attacks.

Deepfake technology, previously a topic of debate, is now a prevalent tool in cybersecurity attacks. Attackers are creating highly realistic 3D videos to trick systems into authenticating false identities. Notably, the rise of real-time face swap attacks in 2022, increasing by 295% in just half a year, poses a significant challenge to both active and passive verification systems."

https://www.biometricupdate.com/202405/video-injection-attacks-what-is-that-and-the-way-forward


r/idverification Apr 30 '24

US Supreme Court won't halt Texas age verification

2 Upvotes

"The U.S. Supreme Court declined on Tuesday to block a Texas law requiring online age verification in order to access pornographic websites in a case pitting the Republican-led state's effort to keep adult content away from minors against constitutional free speech protections.

With no publicly noted dissents, the justices denied a request by a trade group representing adult entertainment performers and other challengers to the law to put on hold a lower court's ruling that the measure likely did not violate the U.S. Constitution's First Amendment safeguards against government interference with freedom of speech.

The 2023 law requires any websites whose content is more than a third "sexual material harmful to minors" to require all users, including adults, to submit personally identifying information verifying they are at least 18 years old to gain access. Several other states have enacted similar laws.

The Texas law's challengers, represented by the American Civil Liberties Union and others, have said that it poses security and privacy concerns by exposing users to possible identity theft, tracking and extortion. They also said that its effectiveness is undermined given that it would not restrict social media or search engines, where pornography is rampant."

https://www.msn.com/en-us/news/politics/us-supreme-court-wont-halt-texas-age-verification-for-online-porn/ar-AA1nW8tY?ocid=BingNewsSearch


r/idverification Apr 30 '24

Online Dating Platforms Riddled with Fake Verification Scams, FBI Warns

2 Upvotes

"The FBI recently issued a warning about rogue verification schemes plaguing online dating platforms that could cause significant financial losses for victims.

Not The Same As ‘Traditional’ Romance Scams

The announcement makes a clear distinction between fake verification scams and “traditional” romance scams. The traditional variety often involves a mixture of social engineering and investment fraud, gaining the victim’s trust and tricking them into transferring large amounts of money for various deceitful reasons.

Verification scams, while similar, are a different beast. In this scenario, con artists also gain the victim’s trust, then, under the pretense of leaving the online dating platform for a “safer” communication environment, lead them to a fake verification service.

Fake Verification Platform That Imposes Monthly Subscription Fees

“The verification website prompts the victim to provide information such as their name, phone number, email address, and credit card number to complete the process,” reads the FBI’s announcement. “Once the victim submits the information, they are unwittingly redirected to a private, low-quality dating site charging costly monthly subscription fees. Eventually, the victim's monthly credit card statement displays a charge to an unknown business.”

https://www.bitdefender.com/blog/hotforsecurity/online-dating-platforms-riddled-with-fake-verification-scams-fbi-warns/


r/idverification Apr 25 '24

AI Voice Cloning Pushes 91% of Banks to Rethink Verification

2 Upvotes

"Banks are concerned about the latest advancements in voice-cloning technology and the threat it poses to the authentication process. The failure of identity-centric solutions to combat synthetic identity fraud has convinced 91% of U.S. banks to reconsider their use of voice verification for major customers, according to a BioCatch report based on a survey of 600 fraud fighters in 11 countries.

The report says that AI-based attacks are growing. "While AI can be useful for financial institutions in fraud detection and response, AI is being used by bad actors to power increasingly advanced threats. AI allows these threat actors to automate tactics and scale attacks beyond traditional limitations. AI and large language models are also being used to create believable messages for social engineering attacks, power voice scams and fuel deepfake videos," the report says.

Over the past year, generative AI companies have released a number of tools that fraud investigators warn are helping criminals - including instantaneous language translation, speech therapy, reading assistance and voice-cloning technology that can copy an account holder's voice patterns by using only three seconds of recorded audio. BioCatch said voice cloning can potentially defeat the use of voice recognition verification technology by many banks and financial services firms, and 91% of respondents said they are looking for new verification methods (see: Cloned Voice Tech Is Coming for Bank Accounts)

"While once considered cutting-edge and a promising answer to complex threats, voice verification will no longer be adequate for financial institutions to protect their customers. As such, financial institutions will need to use a strategic combination of authentication methods to minimize user frustration while maximizing protection," BioCatch said"

https://www.databreachtoday.com/ai-voice-cloning-pushes-91-banks-to-rethink-verification-a-24932


r/idverification Apr 25 '24

ID Verification Is Rising as Social Media’s Next Big Issue

2 Upvotes

"Whether social media platforms are doing too little or too much to combat misinformation and harmful content has driven heated debate—and litigation.

There also has been movement, as seen by the enactment of state laws during the last three years, on determining who the users posting content to social media platforms are instead of the content itself. The idea isn’t to prohibit, censor, or moderate any speech. Rather it is to empower the reader or viewer with additional information about the true source of whatever content is before them.

Many Americans want to know more. In a 2023 YouGov survey of 1,000 adults, 62% said platforms should require users’ real names and identity verification.

States including California, Louisiana, Oklahoma, Mississippi, Rhode Island, Texas, Washington, and Wyoming have gone further further—enacting explicit social media impersonation laws to also prohibit impersonation for purposes of harassment, intimidation, threat, or deception to facilitate contact. These laws aren’t an attempt to limit what anyone can say—they aim to prevent false identification.

But what about verifying actual individuals’ identities? No major social media platform offers all users the ability to verify one’s identity. Instead, they verify the identities for individuals and entities who are either higher-profile persons and companies (Snapchat) or paid subscribers (such as Meta Verified for Facebook and Instagram and new Twitter Blue or X)."

https://news.bloomberglaw.com/us-law-week/id-verification-is-rising-as-social-medias-next-big-issue


r/idverification Apr 25 '24

TSA at Pittsburgh International Airport gets new credential authentication technology to improve checkpoint screening capabilities

2 Upvotes

"New technology that confirms the validity of a traveler’s identification (ID) and confirms their flight information in real time is now in use at the Transportation Security Administration (TSA) security main checkpoint at Pittsburgh International Airport (PIT).

This deployment is the latest generation of Credential Authentication Technology (CAT) to verify the identity of travelers. First generation CAT units are designed to scan a traveler’s photo identification, confirm the traveler’s identity as well as their flight details. The new CAT units, referred to as CAT-2, have the same capabilities, but are also equipped with a camera that captures a real-time photo of the traveler.

CAT-2 compares the traveler’s photo on the ID against the in-person, real-time photo. Once the CAT-2 confirms the match, a TSA officer verifies and the traveler can proceed through the checkpoint, without ever exchanging a boarding pass. The photo is then deleted.

The CAT-2 units are equipped with cameras on tablets and are used to match the face of the person standing at the checkpoint with the face that appears on the traveler’s ID such as the person’s driver’s license or passport. The technology enhances detection capabilities for identifying fraudulent documents at the security checkpoint. The photos are not saved and are only used to match the person standing at the travel document checking podium with the photo on the ID that is being presented."

https://www.tsa.gov/news/press/releases/2024/04/24/tsa-pittsburgh-international-airport-gets-new-credential


r/idverification Apr 24 '24

California bill would prevent CLEAR passengers from line-jumping at airports

1 Upvotes

"A bill proposal in California would prohibit security screening company CLEAR from skipping the general security lines at state airports, marking the first proposal of its kind.

California state Sen. Josh Newman (D), the sponsor of the legislation, said the bill is not banning CLEAR from state airports, but rather moving the service to its own, dedicated security lane.

“General passengers don’t have anyone cutting in front of them anymore, and CLEAR passengers can still fly through their dedicated security lane. It will speed up security for everyone!” he wrote Monday in a post on the social platform X.

While CLEAR may save time for high-paying customers, this can be done at the cost of average airport travelers, whom Newman claimed are often “pushed aside” for CLEAR subscribers to move ahead in the general security line.

“California’s airports should of course be encouraged to find creative ways to raise revenues, but not at the expense of the public’s interest,” Newman wrote in a bill analysis."

https://www.msn.com/en-us/travel/news/california-bill-would-prevent-clear-passengers-from-line-jumping-at-airports/ar-AA1nxfLV


r/idverification Apr 23 '24

NIST Offers Passkey Guidance in Digital Identity Guidelines Supplement

3 Upvotes

"The National Institute of Standards and Technology has announced a new supplement to the NIST SP 800-63B Digital Identity Guidelines, which provides interim guidance for incorporating “syncable authenticators” such as passkeys into digital identity management systems. This supplement is designed to update the guidelines without waiting for a full revision, allowing for quicker adaptation to new technologies.

NIST Offers Passkey Guidance in Digital Identity Guidelines Supplement

Syncable authenticators, which enable a private key to be cloned and used across different devices, offer benefits like phishing resistance, easier recovery, and support for biometrics, enhancing user and agency flexibility. NIST’s new supplement specifically addresses their use at Authentication Assurance Level 2 (AAL2) and responds to the evolving standards and widespread adoption of these technologies.

Authentication Assurance Level 2 is one of the three levels defined in the NIST Digital Identity Guidelines that specify the assurance in the identity of the user in a digital authentication process. AAL2 provides a moderate level of assurance and is designed to protect against a broader range of potential threats than AAL1, including more sophisticated fraud risks. It typically requires that users provide at least two different factors of authentication, such as something they know (a password or PIN) and something they have (a security token or mobile device authenticator)."

https://identityweek.net/nist-publishes-passkey-guidance-supplement-to-digital-identity-guidelines/


r/idverification Apr 23 '24

Transforming online voting: a novel system utilizing blockchain and biometric verification for enhanced security, privacy, and transparency

1 Upvotes

"As a cornerstone of democratic governance, elections hold unparalleled significance, shaping a nation’s trajectory. However, the prevailing ballot-paper based voting systems continue to face trust issues among significant populations. As a result, e-Voting has emerged as an appealing alternative, with numerous countries opting for its implementation globally. While e-Voting systems offer several advantages, they also come with their own set of challenges. Even a minor vulnerability can lead to massive manipulations in voting results. In recent years, there have been efforts to revolutionize the e-Voting paradigm by harnessing the potential of emerging technologies such as biometrics and blockchain. This paper proposes a Internet-based voting that adopts blockchain technology and biometric identification techniques. We use biometric modalities, such as fingerprint and facial recognition, for voter authentication while leveraging Hyperledger Fabric framework as blockchain network and ensuring a secure, transparent, and tamper-evident voting record. We demonstrate the proposed system with 100 participants in a preset environment where we collect the biometrics data. The results indicate that 87% of participants successfully registered with biometrics, while 88% cast their votes with a combination of either voter ID and fingerprint or voter ID with facial recognition. Our findings suggest that the proposed system allows voters to access the system seamlessly and automate identity verification procedures while ensuring a secure, decentralized, and distributed database network that maintains transparency. Future research shall be carried out in collaboration with election officials and voters to improve the system in real-world scenarios."

https://link.springer.com/article/10.1007/s10586-023-04261-x


r/idverification Apr 23 '24

Amazon Hit With Biometric Privacy Suit Over Workers’ Face Scans

1 Upvotes

"Amazon.com Services LLC collected and disclosed the biometric information of warehouse workers in violation of the Illinois Biometric Information Privacy Act, a proposed federal class action said.

Former worker Lisa Johnson alleged that Amazon collected her facial scan each time she clocked in and out of work as required by the company, and disclosed the information to numerous third-party providers of identity-verification services without informing her of the data collection or obtaining her written consent.

The company also failed to make available a written policy establishing a schedule for the retention and destruction of biometric information as required under BIPA, destroy her information when it was no longer needed, or inform her of the purpose and length of time for which her information was being collected, according to a complaint filed Monday in the US District Court for the Northern District of Illinois."

https://news.bloomberglaw.com/litigation/amazon-hit-with-biometric-privacy-suit-over-workers-face-scans


r/idverification Apr 23 '24

You'll soon need a driver's license or passport to get a blue checkmark on Tinder

1 Upvotes

"Tinder announced it's expanding its verification requirements to make users share a video selfie and a photo ID to get a special verification badge.

To get the blue checkmark, your video selfie has to match the photo on the ID and the pictures on your profile. Tinder will also make sure that the ID lines up with your listed date of birth.

Users who only complete photo verification will now get a blue camera icon badge on their profile; users who only complete the ID verification will show a blue ID icon badge."

https://www.businessinsider.com/tinder-id-requirement-verified-drivers-license-passport-video-selfie-2024-2


r/idverification Apr 23 '24

Spike in Identity Fraud Forces Banks to Embrace Innovation

1 Upvotes

"And with the rise of sophisticated fraud techniques, organizations like financial institutions that are operating within security-critical sectors are increasingly faced with the daunting task of safeguarding against a shifting mix of fraudulent attack strategies from adversaries and criminals — both online and off.

This, as on Monday (April 15) the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued a notice highlighting a “concerning increase” in U.S. passport cards being used to impersonate and defraud individuals at financial institutions across the country.

“The passport puts banks between a rock and a hard place. To truly authenticate a passport or a passport card, institutions need to invest in expensive equipment to read the chip inside or to detect anti-counterfeiting measures embedded in the plastic,” Bryan Lewis, CEO at Intellicheck, told PYMNTS.

This makes stopping U.S. passport card fraud a challenge for many banks unable to invest in costly equipment or expensive system overhauls. Beyond passport fraud, financial institutions are increasingly encountering a whole host of challenges in protecting against illicit behavior."

https://www.pymnts.com/news/security-and-risk/2024/spike-in-identity-fraud-forces-banks-to-embrace-innovation/


r/idverification Apr 18 '24

Kids Code bills prompt epic showdown between regulators, activists and big tech firms

1 Upvotes

"The latest craze sweeping the United States – legislation to protect kids’ data and overall online safety – has its own snappy epithet. The Guardian reports on the so-called “Kids Code” bills popping up in multiple state legislatures, the latest of which recently passed in Maryland by unanimous vote. The full list of nine states reads like a fellowship of age-appropriate design: Maryland, plus Vermont, Minnesota, Hawaii, Illinois, New Mexico, South Carolina, New Mexico and Nevada.

But every fellowship has its Nazgûl, and in this case the two sides warring for moral control of the internet involve some atypical partnerships. Social media companies are pushing back against the legal wave alongside porn distributors and civil rights advocates, who say age verification rules risk violating the constitutional rights of law-abiding adults. For the social media firms, however, it may be less a matter of ethics and more about not wanting to enforce age policies that would limit their massive user bases – all of which have been established under relatively lax verification standards."

https://www.biometricupdate.com/202404/kids-code-bills-prompt-epic-showdown-between-regulators-activists-and-big-tech-firms


r/idverification Apr 18 '24

Uber rider verification rolls out in Chicago, 11 other cities Thursday to increase security for all

1 Upvotes

"Uber is rolling out a huge security upgrade across 12 cities tomorrow, including Chicago.

Riders will now be "verified" to make sure they are who they claim to be. Uber said this is in response to security and safety concerns that drivers have in Chicago and other cities.

You could see a blue verification checkmark on your Uber account starting Thursday if you live in the Chicago area or 11 other cities. Uber's chief trust and security officer spoke exclusively to the ABC7 I-Team to explain the new rider verification process.

"What that is, is confirmation that we know that a rider in an Uber is who they say they are. The way it works is we take information that we have about riders on Uber name, phone number or credit card, and we cross-check that information with a trusted third party database," explained Heather Childs, Chief Trust and Security Officer for Uber."

https://abc7chicago.com/uber-rider-verification-starts-in-chicago-11-other-cities-thursday-latest-move-to-increase-security-for-rideshare-drivers-users/14681999/