America's Driver's License Breach Is a National Security Disaster
America’s Driver’s License Breach Is a National Security Disaster
美国驾照泄露事件:一场国家安全灾难
Last week, Krebs on Security broke the story of a newly launched dark web service calling itself Nexus that was selling access to identity documents, including 3 million travel documents and 153 million driver’s licenses from U.S. and Canadian citizens. This is a huge breach that not only will be used for run-of-the-mill cybercrime but also will feed the intelligence machines of America’s adversaries.
上周,安全博客“Krebs on Security”爆料称,一个名为 Nexus 的暗网服务平台开始兜售各类身份证明文件,其中包括 300 万份旅行证件以及 1.53 亿份美国和加拿大公民的驾照。这是一起严重的泄露事件,这些数据不仅会被用于普通的网络犯罪,还将成为美国对手情报机构的“养料”。
Nexus claimed that it had gained unauthorized access to a major identity verification company and had spent more than a year “continuously” exfiltrating new data into a private database. Krebs on Security noted that in a single day the number of licenses in the database increased by nearly 400,000, suggesting regular ingestion of new data.
Nexus 声称,他们未经授权入侵了一家大型身份验证公司,并花费了一年多的时间“持续”将新数据窃取至其私有数据库中。Krebs on Security 指出,该数据库中的驾照数量在一天之内就增加了近 40 万份,这表明该平台正在定期获取新数据。
Krebs on Security was able to verify that the driver’s licenses held by the service were genuine. In addition to Krebs’s own, it contained licenses from nine of his friends and family members. Secretary of War Pete Hegseth, an assistant director at the FBI and other high-ranking U.S. government officials also had licenses in the mix.
Krebs on Security 证实,该服务平台持有的驾照均为真实文件。除了 Krebs 本人的驾照外,其中还包含他九位亲友的驾照。美国国防部长皮特·海格塞斯(Pete Hegseth)、一名联邦调查局(FBI)助理局长以及其他美国政府高官的驾照也赫然在列。
Based on a variety of circumstantial evidence, Krebs linked the incident to identity verification service IDScan. The service’s website says it helps to reduce fraud by confirming that an ID is authentic and being presented by its legitimate owner and by detecting fraudulent documents. The FBI is looking into the incident, and IDScan has confirmed it is investigating a data breach. The Nexus service also disappeared from the dark web shortly after Krebs published his story, although the people responsible for the hack do not claim to have deleted the data. Presumably they are lying low till the publicity dies down.
根据多项间接证据,Krebs 将此次事件与身份验证服务商 IDScan 联系起来。该公司的网站称,其通过确认身份证件的真实性、核实持证人身份以及检测伪造证件来帮助减少欺诈行为。目前 FBI 正在调查此事,IDScan 也已确认正在调查数据泄露情况。在 Krebs 发布报道后不久,Nexus 服务便从暗网上消失了,尽管黑客并未声称已删除数据。推测他们只是在避风头,等待舆论热度消退。
Licenses and identity documents can be used to facilitate identity theft and phishing attacks, but because the data can be used to inform intelligence operations, an incident like this also has national security implications. For the intelligence world, licenses are particularly valuable because they’re key identity documents and license numbers are often used in other databases. These databases, whether hacked or purchased, become much more valuable when records can be linked directly to a particular person with home address and photo included. And it’s not a theoretical threat.
驾照和身份证明文件可被用于身份盗窃和网络钓鱼攻击,但由于这些数据可用于辅助情报行动,此类事件也具有国家安全层面的影响。对于情报界而言,驾照尤为重要,因为它们是关键的身份证明文件,且驾照号码常被用于关联其他数据库。无论这些数据库是通过黑客攻击还是购买获得,一旦记录能与特定个人的家庭住址和照片直接关联,其价值就会大幅提升。这绝非理论上的威胁。
In the mid-2010s, Chinese cyber espionage actors stole complementary data from a variety of sources that, together, would be useful for analyzing the U.S. intelligence apparatus. Various Chinese APT groups stole information from the health insurance company Anthem, credit reporting company Equifax, Marriott hotels, United Airlines, and, perhaps most significantly, security clearance information from the Office of Personnel Management. The U.S. intelligence community is certain that stolen data was used to counter American intelligence efforts against China, as described in this series of Foreign Policy articles by Zach Dorfman.
2010 年代中期,中国网络间谍从多个来源窃取了互补性数据,这些数据汇总后可用于分析美国的各种情报机构。多个中国高级持续性威胁(APT)组织窃取了医疗保险公司 Anthem、信用报告公司 Equifax、万豪酒店、联合航空的信息,其中最严重的或许是美国人事管理局(OPM)的安全许可信息。正如扎克·多夫曼(Zach Dorfman)在《外交政策》系列文章中所述,美国情报界确信这些被盗数据已被用于反制美国针对中国的情报工作。
Of course, China itself isn’t known for releasing detailed reports describing how it exploits its stolen data, but investigative research outfit Bellingcat has shown exactly how similar data can be used to uncover covert government activity. In 2022, a hacked database provided a key piece of travel information that helped Bellingcat identify a deep cover GRU agent (Russian military intelligence) trying to infiltrate a NATO command post in Naples, Italy. And in another striking example, these three Bellingcat reports from 2018 identified suspects in the attempted assassination of Sergei Skripal with the Novichok nerve agent.
当然,中国官方并不会发布关于如何利用被盗数据的详细报告,但调查研究机构 Bellingcat 已经展示了类似数据如何被用于揭露政府的秘密行动。2022 年,一个被黑的数据库提供了一条关键的旅行信息,帮助 Bellingcat 识别出了一名试图渗透意大利那不勒斯北约指挥部的俄罗斯军事情报局(GRU)深度潜伏特工。另一个引人注目的例子是,Bellingcat 在 2018 年发布的三份报告中,锁定了使用“诺维乔克”神经毒剂暗杀谢尔盖·斯克里帕尔(Sergei Skripal)的嫌疑人。
Clearly, leaked and hacked databases are incredibly useful for Bellingcat’s Russia-related investigations. In 2020, it said it had “acquired dozens of leaked databases over the past few years, giving us a large number of data points to cross-reference and verify any new data we acquire.” If a small investigative outfit is hoovering up Russian data when it is leaked, you can bet your bottom yuan that China’s intelligence services are doing the same for any American data that pops up.
显然,泄露和被黑的数据库对于 Bellingcat 的俄罗斯相关调查极其有用。2020 年,该机构表示:“过去几年我们获取了数十个泄露的数据库,这为我们交叉比对和验证新获取的数据提供了大量数据点。”如果一家小型调查机构都能在数据泄露时收集俄罗斯的数据,那么你完全可以确信,中国的相关情报部门也会对任何出现的美国数据采取同样的行动。
The IDScan breach is big. The number of U.S. licenses in the database is roughly 63 percent of the country’s total licenses. But breaches from identity verification companies occur depressingly frequently. In the past two years, breaches have occurred at AU10TIX, at Discord’s age verification service provider 5CA, and at National Public Data. Identity verification services are necessary to help to prevent fraud but are also a point of vulnerability when security is poorly done. The sheer volume of sensitive data these services handle means they should be subject to strict regulation and oversight.
IDScan 的泄露规模巨大。数据库中的美国驾照数量约占全美驾照总数的 63%。然而,身份验证公司的数据泄露事件发生得令人沮丧地频繁。在过去两年中,AU10TIX、Discord 的年龄验证服务提供商 5CA 以及 National Public Data 都曾发生过泄露事件。身份验证服务对于防止欺诈是必要的,但如果安全措施不到位,它们也会成为脆弱的攻击点。这些服务处理的敏感数据量巨大,意味着它们必须受到严格的监管和审查。
We’re realists here at Seriously Risky Business, though, and recognize that there is no chance of swift government action. In the short term, we can only hope that significant financial consequences will help encourage these firms to shore up their security. Law firms are already lining up class-action suits against IDScan, but a little federal government attention from the Federal Trade Commission wouldn’t be unwelcome either.
不过,我们“Seriously Risky Business”团队是现实主义者,我们认识到政府不太可能迅速采取行动。短期内,我们只能希望重大的经济后果能促使这些公司加强安全防护。律师事务所已经在筹备针对 IDScan 的集体诉讼,但如果联邦贸易委员会(FTC)能给予一些关注,那也是再好不过了。
The U.S. Military’s Ad-Tracking Fig Leaf
美国军方的广告追踪“遮羞布”
Back in June, Reuters reported that commercial location data was being used to target U.S. military personnel in the Middle East. At the time, we wrote that the Department of Defense’s existing policies regarding the issue, which already included disabling advertising identifiers on military-owned devices, did “not fill us with confidence.” They simply weren’t comprehensive enough.
早在今年 6 月,路透社就报道称,商业位置数据正被用于定位中东地区的美国军事人员。当时我们写道,国防部针对该问题的现有政策(已包括禁用军用设备上的广告标识符)“并不能让我们感到放心”。这些政策显然不够全面。
It turns out that these policies weren’t even being well implemented. This week, Reuters reported that some branches of the U.S. military have finally gotten around to disabling some advertising identifiers on military-owned devices. The U.S. Air Force said it disabled Windows and Android advertising identifiers in late July, although they were already disabled on Apple devices.
事实证明,这些政策甚至都没有得到很好的执行。本周,路透社报道称,美国军方的一些分支机构终于开始着手禁用军用设备上的部分广告标识符。美国空军表示,他们已于 7 月下旬禁用了 Windows 和 Android 系统的广告标识符,尽管这些标识符在苹果设备上早已被禁用。