Slashdot Mirror


New Jersey DMV Employees Caught Selling Identities

phaedrus5001 writes "Ars has an article about two New Jersey DMV employees who have been accused of selling personal information they routinely had access to. The NJ prosecutor's office claims (PDF) their investigation 'uncovered that two employees of the New Jersey Motor Vehicle Commission were providing the names, addresses, dates of birth and social security numbers of unsuspecting residents that they obtained through their employment. They were charging as little as $200 per identity.'"

40 of 279 comments (clear)

  1. Not surprised by Lyrata · · Score: 5, Funny

    I wouldn't pay more than $200 to be from New Jersey, either!

    --
    50,000 characters used to live here.
  2. SSNs? by Manip · · Score: 5, Insightful

    Why can normal day to day employees even view plain text social security numbers? Wouldn't it make a lot more sense to hide that information like banks do with credit card numbers?

    Also, I find it ironic that these two relatively low level criminals will get the book thrown at them, but when the DMV legally sells that information to marketing companies everyone is happy. I guess they don't sell SSNs but still, thin line.

    1. Re:SSNs? by Moheeheeko · · Score: 3, Interesting

      You would be suprised. At the local Community college, thats like a student ID number.

    2. Re:SSNs? by the_fat_kid · · Score: 4, Insightful

      normal day to day employees can probably read them because we have become lax about where we use our SSN.
      Want a phone? SSN
      want a rental? SSN
      want credit? SSN
      talk to someone at support? SSN

      Once upon a time these were supposed to be a Secret number that you only shared with the government and an employer.
      Now it's how you prove your citizenship and credit worth.

      --
      -- Sig under construction...
    3. Re:SSNs? by flaming+error · · Score: 3, Insightful

      Social Security Numbers were never really meant to be all that secret.

      Every organization that decided to use them as a secret was stupid, and if they were intended to secure anything important, irresponsible/criminal.

      SSNs, like biometrics, have all the right characteristics for account ids, and all the wrong characteristics for a password.

    4. Re:SSNs? by Narcocide · · Score: 3, Informative

      I've seen employers use it as the employee ID too. One place I worked at you had to type your SSN in to a physical console twice a shift (to punch in and out.)

    5. Re:SSNs? by ColdWetDog · · Score: 5, Funny

      We needed a universally unique personal identifier. Only the feds could actually create one, and the SSN is the only one they ever got political consensus to create.
      The real problem is treating it as both identification and authentication.

      Three ID's for Credit Reporting Agencies under the sky,
      Seven ID's for Three Letter Agencies in their halls of stone,
      Nine ID's for each system you log on to.

      One ID for the DHS on it's dark throne,
      In the Land called DC, where the shadows lie.

      One ID to rule them, One ID to find them
      One ID to normalize the database and in the darkness bind them.
      In the land called DC where the shadows lie.

      (Apologies to just about everyone)

      --
      Faster! Faster! Faster would be better!
    6. Re:SSNs? by Urza9814 · · Score: 4, Informative

      Once upon a time these were supposed to be a Secret number that you only shared with the government and an employer.

      No. SSNs were NEVER supposed to be private. It's a freakin account number. The problem isn't them being used publicly, the problem is them being assumed private.

    7. Re:SSNs? by PatDev · · Score: 3, Insightful

      I'm assuming this is sarcasm. If it is not, my apologies.

      But no, there is no possible way to lockdown a computer to prevent data from leaving it. You can mitigate by limiting the amount of data that can leave it, but you can't prevent data from coming off it (at least not while being used for its intended purpose at the DMV).

      Sure, you can install filtering software to DPI everything leaving the machine and uninstall all text editors and remove the ability to install additional software. But at some point, the operator has to read information off the screen, and that's the analog hole you've hit right there. Even if sufficient surveillance is employed to prevent employees writing SSNs down on paper, there is still the possibility of the employee just remembering them. Given that a 9-digit SSN doesn't really have 9 bits of entropy and names are generally easy to remember, I'm guessing an employee using mnemonics could still easily recall 3 identities per shift. At $200 or more per identity, an extra $600 per shift is enough of a payday to motivate someone to try.

    8. Re:SSNs? by mcgrew · · Score: 5, Informative

      Are you kidding, or are you young? Keeping SS#s secret is a new thing. Hell, they used to print your SS# on your driver's license. ID theft didn't become a big problem until the internet.

  3. Re:This is more proof by s73v3r · · Score: 4, Funny

    Because a private company would never be caught doing something like this. Nope. They are all completely above any kind of corruption.

  4. You're Going To See More and More of This. by smpoole7 · · Score: 4, Insightful

    It's not a government vs. private sector thing, either. The simple fact is, you will always be able to find some corruptible person who's will to sell (or "leak," if he/she is just trying to harm a rival) information.

    I'm a geek and I loves me some technology, but still, I'm not blind to the dangers of giant databases filled with sensitive data And to be honest, I itch at the thought that anyone -- be it the federal government (with the Affordable Health Care Act) or private business (think of some large, national hospital group) has access to all of my medical records -- including prescriptions, diagnoses, and all the rest of it.

    But I don't know what the answer is. Someone smarter than me will have to come up with that.

    --
    Cogito, igitur comedam pizza.
    1. Re:You're Going To See More and More of This. by Sir_Sri · · Score: 3, Interesting

      The answer is government run healthcare with a government run database. Then if your medical records leak out it is *only* a privacy violation, and cannot effect further access to employment or medical care.

      The advantages of a functioning single database are enormous. Depending on where you live, you may have to carry all of your relevant records between specialists as you get sent through the system when something is wrong with you. Each of those steps risks you losing something important, and puts undue pressure on the doctor you are seeing to assess whatever you bring them right there in front of you, while you're waiting. Assuming everything you bring is in a format they can use, and if not, well then there's a lot of time spent faxing/phoning etc. back and forth. The risk that your privacy can be invaded is well outweighed by the fact that your allergy to some random medication, or obscure but potentially serious condition is going to show up in a record somewhere when you get into a car accident on holiday out of province/state.

      I'm in canada, so the only people who particularly care about my medical records but wouldn't be granted access to them are, my 'spouse' my kids (which I don't have but you get the idea), and well, that's it. And it doesn't matter who runs the healthcare system, if there's something in there I'm trying to hide, it's equally likely they'll be told regardless of who runs the database. But in a system where that information matters to insurance companies and employers, well then you have a problem.

      The DMV thing having SSN's is unfortunate, but I guess it makes sense. Criminal activity (which I guess would be tied to your SSN?) is going to impact your ability to interact with the DMV, and as a government agency they're authorized to collect that data. Unfortunately, there's not a lot you can do to secure information they have legal access to under normal circumstances, it doesn't matter if it's paper or electronic.

    2. Re:You're Going To See More and More of This. by dkleinsc · · Score: 5, Insightful

      The solution that someone much smarter than me (Bruce Schneier) has repeatedly proposed is this: When doing something that involves sensitive data, you don't verify identity, you verify transactions. For instance, if you want to transfer money from your bank account, the question is not "Are you smpoole7?", it's "Does smpoole7 really want $150,000 to go to an account in Pakistan?". A smart bank will use alternate ways of contacting you (if they're really worried, they might even ask that you do this in person) to confirm that it is in fact your intent.

      This has a lot of ancillary benefits that probably make it worth the expense. For instance, it helps catch errors by the actual owner of the account.

      --
      I am officially gone from /. Long live http://www.soylentnews.com/
    3. Re:You're Going To See More and More of This. by dkleinsc · · Score: 4, Interesting

      Here's Schneier's essay describing this approach much better than I did.

      --
      I am officially gone from /. Long live http://www.soylentnews.com/
  5. Sigh by Aerorae · · Score: 5, Insightful

    I didn't realize that our identities were so worthless. Whether it is attributed to evil, or a lack of humanity on the part of the two employees, this represents a fundamental problem among people today: "Doesn't affect me, so I don't care."
    I believe that will destroy us even faster than bank collapses or political corruption, in a sense because those maladies are results of the "I don't care" problem. "I can buy these horrible securities, if it goes bad, it doesn't affect me, so I don't care", "My constituents want this, sure it'll put 100,000 people out of work, but it doesn't affect me, so I don't care", "Hell I'll sell peoples identities, sure they'll be plagued by this for a matter of decades to come, but it doesn't affect me, so I don't care."
    People need to care about things that don't affect them or else this world is very very doomed.

    1. Re:Sigh by Jeng · · Score: 4, Funny

      If the person cared about others they wouldn't be working at the DMV.

      --
      Don't know something? Look it up. Still don't know? Then ask.
    2. Re:Sigh by Anonymous Coward · · Score: 3, Insightful

      Welcome to the repercussions of the "Me" generation. It all started with shifting focus from the outside and how to fit into society and live with others to the inside. People don't know how to empathize with others any more. If it feels good to them, do it. Thanks hippies.

  6. Social security numbers? by schwit1 · · Score: 3, Insightful

    How does providing a SSN verify that the DL requester is who they say they are?

  7. $200 is not cheap by argmanah · · Score: 3, Interesting

    If you work in computer security and have dealt with the black market for stolen identities, you'll find out that $200 an identity is really pricey. It's a little scary, but the market rate for this kind of information is more like $5 a pop.

    --
    Overrated Moderation: This posts sucks... because.
  8. Re:This is more proof by 0123456 · · Score: 4, Insightful

    Because a private company would never be caught doing something like this. Nope. They are all completely above any kind of corruption.

    Unlike the DMV, a private company can't force you to use their services. Nor can they push a unique identifier on you which is then used as an id by numerous different databases.

  9. Re:This is more proof by cptdondo · · Score: 4, Insightful

    Great soundbite. Now expand on it. Tell us how, exactly, you would put your proposal into practice.

    Fewer cops? Less regulations? Which ones? Fewer teachers? No DMV (and no vehicle registrations, or safety regulations, or license plates, or insurance?)

    I want to know.

  10. Re:This is more proof by zAPPzAPP · · Score: 3, Insightful

    If the private company owns any of your local infrastructure, or it got an outsourcing deal for a former gouvernment service that you need to use, how do you avoid them?
    Because that's what "less gov" means around here.

  11. Re:This is more proof by cptdondo · · Score: 5, Insightful

    Experian? Other credit rating companies?

    I'm sure I could come up with a lot of others that disprove your hypothesis. There are lots and lots of private companies that we have to do business with. We have no choice in the matter.

  12. downside to buying IDs from DMV by corbettw · · Score: 4, Funny

    You have to stand in line for hours just waiting to get the CD with the data on it. And don't get me started on all the forms you have to fill out!

    --
    God invented whiskey so the Irish would not rule the world.
  13. Re:This is more proof by DanTheStone · · Score: 5, Funny

    Obviously the government shouldn't know your Social Security number...

  14. Re:This is more proof by Jessified · · Score: 3, Insightful

    Well, just like if you don't like airport security you don't have to fly, if you don't like the DMV you don't have to drive, amiright? /sarcasm

  15. Re:This is more proof by vlm · · Score: 5, Informative

    No DMV (and no vehicle registrations, or safety regulations, or license plates, or insurance?)

    The following licenses I have, or previously held, none of which are "IDs" requiring SS number:
    ham radio license
    GROL
    former private pilot license (maybe this has changed to photo now?)
    former fishing license
    several former military operators licenses including really weird stuff like immersion heater (I kid you not) and RTFL rough terrain forklift
    my library card is functionally a license as opposed to an ID card
    my old non-photo college ID card (I guess those are mostly photo "real forms of ID" now?). It was mainly used at the library and to pay for photocopies.
    My temp drivers license when I was 15 until I passed my formal DL test had no "id" properties, it just gave me permission to drive with a parent in the car supervising me.

    Functionally American drivers license functionality is merged with ID card functionality, as if any separation is impossible, but its certainly not required. None of the stuff you listed requires ID directly, although registration title transfer is gonna require the services of a notary, and the notary will demand an ID, or the DMV personnel could operate as notaries, ending up right where we started...

    --
    "Science flies us to the moon. Religion flies us into buildings." - Victor Stenger
  16. Re:This is more proof by neonKow · · Score: 3, Insightful

    You are probably forced to use Experian a lot more than you are forced to use New Jersey DMV.

  17. Re:This is more proof by lucifuge31337 · · Score: 3, Insightful

    "I'll take the sniper rifle and a couple of boxes of ammo. Am I convicted felon with a history of violence? No sir, I am not. Why thank you, you have a good day too!"

    This might be a convincing argument if it weren't for the fact that one can do this in most states legally for a private party face to face transfer. Also, "sniper rifles" aren't all that scary. They are typically nothing more than an off the rack deer rifle (that you can walk in and buy from Wal Mart) with a bipod and a different stock. Better ones have some accuracy work done to them, but it's really not much of a huge difference.

    --
    Do not fold, spindle or mutilate.
  18. Re:This is more proof by jackbird · · Score: 5, Insightful

    A credit check is increasingly becoming part of employment screening, and is entirely necessary for both renting and purchasing a home (unless buying the home for cash). Being homeless rises above "inconvenient."

    Providing a social security number is also required to open a bank account, the lack of which is also a bit more than "inconvenient."

  19. Re:This is more proof by rickb928 · · Score: 4, Insightful

    This is the debate. If you don't like the restrictions, don't drive.

    This is the WRONG attitude and approach.

    We expect our government to, among other things, serve us by managing certain things. One of these is the licensing of drivers, so that we can be marginally safe on the roads, that entirely unqualified drivers are not allowed to operate vehicles, and that dangerous drivers are removed from the road to some degree. Imperfection is rampant, but it works farly well.

    Driving is, in much of American a NECESSITY. To claim it is a privilege may be linguistically accurate, but it is not accurate at all. It is a necessity for most of us.

    In that light, our governments' role shoudl never be to make licensing as difficult as possible, nor should it be to force applicants to exert themselves merely to satisfy the bureacracy's self-serving purposes. It should be the goverments' role to facilitate and deliver the needed service, IE licensing etc.

    The argument that driving is a privilege is to leave open the option that for some reason, we should serve our govermnent. The opposite is the desired relationship, and one that should be not only normal, but expected.

    I know you're being sarcastic, and you're excused from being the target this screed. But some people actually hold that driving as a privilege means that the agencies can be permitted to make it difficult to maintain the privilege.

    That is wrong.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  20. Re:This is more proof by cptdondo · · Score: 4, Insightful

    It might interest you that there used to be way fewer teachers, no administrators, no dept of education ... and the quality of education was way higher.

    Citation, please. Hard data, not more soundbites.

  21. Re:This is more proof by Anonymous Coward · · Score: 5, Insightful

    Actually it is forced on you. Just try going through your entire life without ever having credit pulled on you. Want a phone? Credit check. Internet? Credit check. Car insurance? Credit check. Rent an apartment? Credit check.

    Or how about a job? Credit check.

    None of these involve providing credit, and all of them are part of a normal responsible American lifestyle. Yet you still get a credit check.

  22. Re:This is more proof by icebraining · · Score: 5, Informative

    Our ID card here in Portugal is a smartcard with a key pair. When connected to an appropriate reader, it can provide copies of the public key or sign stuff with the private key (without ever copying it to the machine).
    You don't need a smartphone, a data plan or know what is a key pair or even that your card has one.

    If you want to authenticate when physically present, just insert it in their reader and input the PIN (as said, the private key will NOT be copied out of the card, so it's safe).

    If you want to authenticate online with it, you just need a $16 reader (available on big retail stores) which is supported by IE, Firefox, Safari and Chrome, using PKCS#11 or similar.
    Again, no need to understand how it works - the follow the simple steps on the site.

  23. Re:This is more proof by erroneus · · Score: 3, Interesting

    Yeah, this is thought to be funny, but in reality, the SSN should be used only for Social Security purposes. Instead it is a national serial number which was everyone's concern when the program was set up.

    Texas does not use the SSN for the driver's license... not yet anyway... not the last time I got it renewed. I hate to see when other states disregard this and abuse its citizens for a bit of convenience like this. And of course, the SSN is a widely abused thing and the more abused it is, the more damage abusers can case innocents. It's annoying.

  24. Re:This is more proof by mcgrew · · Score: 4, Insightful

    If the manufacturer and/or seller of a gun is liable for what the new owner does with it,

    He isn't. Where are you getting this nonsense?

    or a bartender is liable for what a patron does after purchasing booze,

    He isn't liable selling booze to a sober person. Are you ten years old? It is definitely irresponsible to sell booze to someone who's drunk, especially if you know he's driving. In this case the bartender is responsibe, as he should be.

    or I get in trouble for selling you a class 4 laser and you do something dumb

    But you don't. Are you trolling, or are you really that ignorant?

    Thats how it works in private aviation, anytime anyone crashes for any reason, the vehicle manufacturer gets sued, because that's where the money is.

    Citation needed... and considering the earlier fantasies in the same comment, it needs to be a damned good citation.

  25. Re:This is more proof by silverspell · · Score: 3, Insightful

    If you have NO credit history whatsoever, then yes, I think it's a fair bet that you're the kind of person who's too attached to his fantasies of perfect autonomy, and who uses words like "sheeple". Such a person is someone I'd rather not hire, if an equally (or more) competent candidate is available; they're generally tiresome, pedantic, and childish, and see themselves as enlightened figures in a world of fools.

    It's a serious hassle to do without credit in this society, and you have to have some serious ideological baggage to make a lifelong point of doing so. More to the point, credit represents a willingness to take on obligations to other people and fulfill them over the long term. Going into long-term debt and repaying it in a timely manner is a sign (not 100% reliable, but still a sign) good judgment, fiscal discipline, and personal integrity.

    If someone isn't willing to do that -- if they go to great lengths to retain the fantasy that they can give it all up at any time and head off into the wilderness, perfectly autonomous and beholden to no one -- then it seems to me that they probably haven't come to terms with adulthood.

  26. Re:This is more proof by Kamiza+Ikioi · · Score: 4, Insightful

    That's a great system that the United States will never adopt. Between the tin foil hats and the Apocalypse believers, we're thoroughly terrified against any type of secure identity verification cards. Because, after all, it's a slippery slope to reading your brain, watching you have sex with your wife using satellite x-ray vision, and tattooing 666 on your forehead.

    So... "no need to understand how it works"? I see you've not encountered sheer stupidity in its raw, unbridled form. Welcome to the United States!

    --
    I8-D
  27. Re:This is more proof by Anonymous Coward · · Score: 3, Insightful

    Correction: We are rightfully concerned about being *compelled* to use such an identification scheme.

    I see you've not encountered sheer stupidity in its raw, unbridled form.

    No doubt there are some people who refuse to be a cog in the machine for stupid reasons. But many people have considered the consequences and decided they prefer to not have these so-called "smart IDs." Reasonable people can disagree, but it is certainly remarkable that your stance is basically "damn your preferences, damn your reasoning, you are stupid!"