> ## Content Index
> Fetch the complete content index at: https://techlore.tech/llms.txt
> Use this file to discover other available public pages before exploring further.

# 153 Million Driver's Licenses For Sale, Plus Chrome Kills uBlock Origin & Texas Kicks Out Flock
- URL: https://techlore.tech/153-million-drivers-licenses-for-sale-plus-chrome-kills-ublock-origin-texas-kicks-out-flock/
- Published: 2026-09-05T03:44:14.000Z
- Updated: 2026-09-05T03:44:14.000Z
- Description: An ID-verification company leaked 153 million driver's licenses to a dark-web market, and it's the perfect case against ID uploads.
- Author: Henry Fisher
- Tags: Surveillance Report

📰

Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG)

[Click For All Sources](#action-item-✅)

---

## On My Radar 🎯

**An ID Company Leaked 153 Million Licenses**

Ars Technica's Dan Goodin rented a car and, within hours, found his own driver's license among more than 153 million for sale on a dark-web market called Nexus. The trail led back to IDScan.net, a company whose entire pitch is preventing ID fraud "at scale." The irony isn't lost on anyone, since it seems they've leaked the ID of nearly everyone they scanned. And it wasn't just licenses!

- Nexus was selling IDs, travel cards, international driver's licenses, medical cards, common access cards, residence cards, and employment authorizations
- It even included the infrared and ultraviolet spectra of the scans.

For context: IDScan partners with Hertz, retailers, gun shops, financial institutions, dispensaries, and hospitality venues, so the blast radius is *enormous*. Nexus (the site selling the data) is down for now and the FBI is investigating, but the reality is cybercriminals probably have your license if you're in the US and used one of impacted services. There's a good chance *I'm* in this one given I've used Hertz several times.

The silver lining to this story is it's *another* reminder against mandated ID uploads. While this breach itself wasn't due to the age verification laws, it's a healthy reminder of what happens when a centralized company is responsible for collecting such sensitive user data. And we've already seen this exact [ID breach in the past caused by age verification](https://www.theguardian.com/media/2025/oct/09/hack-age-verification-firm-discord-users-id-photos). So I'll be referencing this IDScan.net incident going forward as another example for why IDs should never be carelessly collected in any digital context.

**What you can do:** Freeze your credit if you're in a region where that's supported. It's the single best defense against someone opening accounts in your name. Every time you're asked to upload an ID, ask whether it's actually necessary, and if you can't avoid it, use the least-invasive ID you can (ideally one without your home address; a legal private-mailbox address on your license is worth considering if the option exists). I can't recommend much beyond this unfortunately, but I'll be sure to update you all as this story develops—I'm following this one closely.

---

## Bits & Bytes 🤖

**\~ Story 1: Chrome Officially Kills uBlock Origin and AdGuard**  
Manifest V2 is dead in Google Chrome. Google formally removed uBlock Origin and AdGuard from the Chrome Web Store. MV3, Google's replacement, happens to make effective ad blocking harder. Brave still lets you re-enable these (search "Manifest" in settings), and anything Firefox-based still supports MV2.

**My take:** The browser you use comes down to a simple question: who runs it, and what are they incentivized by? Nearly every big-tech browser dropped MV2\. Brave, Vivaldi, and Firefox didn't. I'll let you connect the dots on Google, an ad company, making ad blocking less effective.

**\~ Story 2: California's Age-Verification Bill Carves Out Linux**  
After many distros threatened to pull out of California, the state amended its age-verification bill to exempt Linux and open-source operating systems and package managers. **The good news:** pressure worked from EFF, from distros, from developers, from people who called their reps. **The bad news:** it does nothing for iOS, macOS, Windows, or stock Android users, the two-tier internet keeps forming, and even though this version is self-reported (no ID upload), nothing stops a future amendment from adding one. EFF is separately urging Newsom to reject AB 1709, a sweeping social-media ban for under-16s.

**My take:** I covered this extensively in a [dedicated recent video](https://techlore.tech/california-age-verification-the-good-bad-ugly/), but I'll keep it short here by reminding everyone that this was a *signed law* which originally *included* Linux, but because of public outcry we now have an amendment that completely *excludes* Linux. Take note of these stories as examples of how making your voice heard can work! I receive an obnoxious number of comments from doomers who've given up and want others to give up too—don't listen to them! **Stay optimistic and we can get stuff done.** 

**\~ Story 3: Florida and Texas Step Back From Flock**  
Florida's DOT says it will cease using license-plate readers across state highways, with 30 days to pull the cameras, and Texas is moving the same direction. The caveat: several towns have seen Flock cameras reactivated after officials cancelled contracts, and Flock wouldn't tell TechCrunch whether it'll let Florida and Texas remove theirs.

**My take:** This is a massive win, and what I love most is that Florida's memo targets **license-plate readers** as a category, not just Flock. I'm holding a little optimism in reserve until the cameras actually come down, but this is a big step in the right direction, and it's been wonderful to see bipartisan support for something in these polarizing times. 

---

## This Week on Techlore 📺

Things started with an exciting interview on Techlore Talks with Josh from All Things Secured, I'm sure many of you know of his channel 😀 I specifically discussed safety when traveling, and learned about his wild story being interrogated & deported from China. It's a must-listen!

[Border Crossings, Burner Phones, and Surviving Interrogation in China with Josh Summers from All Things SecuredTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-c5f1c508-872a-4db0-affc-fe94c5091cac.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260829-JOSH-ATS-INTERVIEW-thumbnail-v1-f93e53c8-3ed4-4127-8936-41c87e32d980.jpg)](https://techlore.tech/border-crossings-burner-phones-and-surviving-interrogation-in-china-with-josh-summers-from-all-things-secured/)

In light of Apple gearing up for their likely folding phone. I made a quick blog with my take on folding devices and how it's unfortunate they came at the cost of repairable & budget devices to get here:

[Folding Phones Are the Worst Thing to Happen to SmartphonesFolding phones are the most fragile, least repairable, most expensive phones ever made.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-0c09a872-3830-4fd4-be4a-3be5cca4ca53.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/photo-1756487564693-5d5f4c196fd5-abff2010-ad45-4972-82fb-ec8adbcc2bb4.jpeg)](https://techlore.tech/folding-phones-are-the-worst-thing-to-happen-to-smartphones/)

As I covered earlier, I made some coverage on California's age verification amendment which excludes Linux:

[California Age Verification: The Good, Bad & UglyIn 2027, your operating system is going to ask how old you are. California’s age verification law (AB 1043) takes effect January 1st, and AB 1856 just carved Linux out of it. But the law still leaves many questions open, here’s the good, the bad, and the ugly.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-5fb9834d-5fd4-4c6e-9704-ad57057d68cf.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/Untitled4-82821856-dd74-4907-934c-d000186b5913.png)](https://techlore.tech/california-age-verification-the-good-bad-ugly/)

---

## Action Item ✅

Freeze your credit this week if you haven't. It's free, it's reversible, and it's the one move that blunts the worst outcome of breaches like the IDScan.net leak. While you're at it: if you use Mullvad's public encrypted DNS, they're shutting it down, so switch to another provider before **November 2**. I covered that story more in the podcast, and you can see the OG announcement [here](https://www.mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead/).

**Until next week 🫡**

#### This Week's Sources

****Highlight: 153 Million Driver's Licenses For Sale, Breach Linked to IDScan.net, FBI Probing**

- <https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/>
- <https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/>

****Story 1: Chrome Kills Manifest V2 — uBlock Origin & AdGuard Removed from the Web Store**

- <https://adguard.com/en/blog/adguard-adblocker-manifestv2-removal.html>

****Story 2: California Age-Verification Bill Passes With a Linux Exemption**

- <https://linuxiac.com/californias-age-verification-bill-passes-with-linux-exemption-intact/>
- <https://youtu.be/rTlHMyzLuAM>
- <https://www.eff.org/deeplinks/2026/08/eff-gov-newsom-veto-californias-ab-1709>

****Story 3: Florida and Texas Step Back from Flock / ALPRs**

- <https://techcrunch.com/2026/09/01/florida-and-texas-move-to-block-flock-cameras-over-privacy-concerns/>
- <https://youtu.be/hOU7A1x67o8>

****The Defense Bulletin**

**Data Breaches*

- <https://techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/>
- <https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/>
- <https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/>
- <https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/>
- <https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/>
- <https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/>
- <https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/>

**Threats*

- <https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/>
- <https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/>
- <https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/>
- <https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/>
- <https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/>
- <https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/>
- <https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage>
- <https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/>

**FOSS+ Updates*

- <https://alternativeto.net/news/2026/9/firefox-155-expands-smart-window-adds-quic-v2-for-http-3-connections-and-fixes-linux-bug/>
- <https://tails.net/news/version%5F7.12/>
- <https://www.mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead/>
- <https://tools.techlore.tech/#dns-providers>
- <https://alternativeto.net/news/2026/8/brave-launches-email-aliases-and-new-brave-accounts-that-keep-passwords-off-its-servers/>
- <https://calyxos.org/news/2026/08/28/august-feature-update/>
- <https://alternativeto.net/news/2026/8/libreoffice-26-8-released-with-new-paragraph-composer-and-variable-font-support-still-no-ai/>
- <https://alternativeto.net/news/2026/9/organic-maps-adds-carplay-dashboard-bookmark-multi-select-and-tracks-hidding-on-the-map/>
- <https://youtu.be/XCzVQKLBkhM>
- <https://blog.mozilla.org/en/firefox/ad-blocker-on-ios/>
- <https://alternativeto.net/news/2026/9/brave-news-now-lets-desktop-users-import-opml-feeds/>
- <https://alternativeto.net/news/2026/9/brave-screenshot-tool-adds-selected-full-and-visible-captures/>
- <https://www.eff.org/deeplinks/2026/08/doxxing-safety-pt-i-prevention-and-footprint-management>
- <https://www.eff.org/deeplinks/2026/08/doxxing-safety-part-ii-incident-response>