What If We Get Hacked?

not.bot

You've probably seen the story by now: a dark web marketplace called Nexus popped up selling more than 153 million driver's licenses, front and back, some even in infrared and UV. All of it apparently pulled from one identity verification company that works behind the scenes at hotels, rental car counters, convenience stores, and sportsbooks. Brian Krebs, the security reporter who broke the story, found his own license in the data. So did a sitting U.S. cabinet official. Gizmodo has a good overview: Identity Verification Is Broken: The 153 Million Driver's Licenses Now for Sale Are Proof.

This wasn't a one-off screwup. It's what happens by default whenever a company scans your ID and keeps the scan. A company that does that is sitting on a stash of your most sensitive documents, and stashes like that eventually get found by someone patient enough to look.

Privacy is the core ethos behind everything we build at Julia Social. We design systems to avoid collecting sensitive data at all, rather than promising to protect data we didn't need to have in the first place.

So when people ask us "what if you get hacked," we don't answer "we're unhackable." Nobody can promise that. We answer with the specifics: what would and wouldn't be exposed, and why.

If someone broke into our computersPermalink to If someone broke into our computers

They would NOT get:

  • Your passport or ID information
  • Your name, email, or phone number
  • Any payment information
  • Your location or your phone's contacts
  • The contents of anything you've signed or approved through the app
  • A list of which websites or people you've interacted with
  • Which not.bot identity in our system belongs to you (unless you've earned a Verified Signer badge, explained below)

None of that information ever gets saved on our end in the first place, so there's nothing sitting there to steal. You can't leak what was never written down.

What they WOULD get is a much smaller set of details that, on its own, doesn't tell them who you are: internal ID numbers our system uses to keep track of accounts, a couple of details tied to app subscriptions that can't be traced back to your Apple or Google account, and encrypted backups (your recovery data, your contacts list) that we can't read either. If you opted into our anonymous usage statistics, they'd also get weekly aggregate counts that contain no identifiers. None of it links to your real identity by itself.

One exception: if you've earned a "Verified Signer" badge, we do keep a link between your public alias and your account, so we can turn off the badge if a subscription lapses. That's the one case where we hold more than usual.

One more caveat: even the small amount of identity data we do keep encrypted and locked away isn't something one break-in can unlock. Getting to it would require breaking into three separate systems at once, one of which isn't connected to the internet at all, and even then, unlocking one person's information takes days of computing work per person. There's no button that unlocks everyone at once.

If someone attacked the blockchain part of our systemPermalink to If someone attacked the blockchain part of our system

Even less to find here. The blockchain only ever sees random-looking ID numbers and "this credential was cancelled" flags, never your name, your info, or anything personal. We also generate a steady stream of decoy activity that looks identical to real people signing up or recovering their accounts, so even someone watching the blockchain can't tell which activity is real or connect any of it back to a real person.

Why we built it this wayPermalink to Why we built it this way

Nothing about us should be a single point of failure for who you are. That's why unlocking anyone's data takes multiple separate parties acting together instead of one break-in, why using the app day-to-day never has to touch our servers at all, and why most of what other companies collect by default, we never collect in the first place.

We'd rather show you where the seams are than tell you there aren't any.