Absolutely valid. In the context of identity verification, I trust ID.me more than random companies that do not have government contracts because government contracts come with security and compliance regulations that require regular audit and make the chances of breach less likely. In either case, it’s a private company and, as any security nut would have told you, when it gets sold all bets are off like 23andme. Even more importantly, in the US, any kind of ID verification is a terrible idea, government or private, because we have no data regulation or privacy constraints. I call out the US here because we have no GDPR equivalent (CCPA wouldn’t hold up to federal data). Even if ID verification were conducted by the government, it can still be used for gnarly shit like we saw with ICE and DOGE.
On a sliding scale of evil, ID.me is the evil I know will currently fight to continue remaining the only evil which is the only solace I have in the US.
This is exactly like the whole Lifetouch story. It beggars belief.
Rackspace is, and has been, ISO 27001 certified. Part of that means they can’t directly access customer data. You didn’t link any documents covering the contract that “requires” Rackspace hosting; my base assumption is they’re normal contracts that define hosting for regulatory purposes. None of the documents you’ve linked show Apollo had access to Rackspace infrastructure much less encrypted customer data on Rackspace doesn’t have keys for. The pedo employee had CSAM which does not provide Apollo access to Rackspace infrastructure much less encrypted customer data Rackspace doesn’t have keys for.
Just like with Lifetouch, if you can show that somehow the equity owners Apollo had direct access to the infrastructure of their investments and somehow managed to either hide or justify it during multiple security audits spanning a decade and somehow got access to customer encryption keys, it’s a possibility. I’m not even using Occam’s razor here; there’s genuinely nothing to even consider hanging a hat on here.
On the other hand, if Leon Black had direct access to the company running the database, all bets are off. Law enforcement shit gets to sidestep audit shit in dumb ways. But if that were the case, we wouldn’t need Rackspace as the incredibly tenuous connection because he would have had direct access.