#Digital Identity

Every story tagged Digital Identity, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

115 stories · open in the command center

  • Mobile & Apps9to5MacRyan Christoffel2m

    These US states just said ‘no’ to Apple Wallet driver’s licenses

    Florida and Rhode Island are signaling that Apple Wallet driver’s licenses are not a near-term priority, underscoring how digital identity adoption remains fragmented across the U.S. For CIOs and technology leaders, this highlights that identity modernization will advance unevenly by jurisdiction and platform, with privacy concerns, cost, and interoperability all shaping state decisions. IT organizations that plan to use mobile IDs for verification, access control, or onboarding should expect a multi-format, state-by-state rollout rather than a single standardized solution.

  • Mobile & AppsThe VergeThomas Ricker2m

    Samsung Wallet now unlocks some GM cars

    GM’s rollout of digital car keys in Samsung Wallet, with Apple Wallet and Google Wallet support coming, is another sign that device-based identity and access management is expanding beyond phones and into real-world enterprise-adjacent experiences. For CIOs, the strategic takeaway is that mobile wallet ecosystems are becoming a standard control point for secure access, which increases the importance of cross-platform compatibility, lifecycle governance, and policy controls for shared or stolen devices. IT organizations should expect more demand for provisioning, revocation, and support processes tied to employee mobile devices and external vendor ecosystems as digital keys and other wallet-based credentials proliferate.

  • Security & PrivacyArs TechnicaDan Goodin2m

    Hackers obtain counterfeit TLS certificates for Google and other large services

    Attackers hijacked multiple country-code top-level domains to issue counterfeit TLS certificates for Google and other major services, demonstrating that DNS and certificate-validation weaknesses can be exploited to impersonate trusted digital properties at scale. For CIOs and technology leaders, this highlights that browser-side protections are not enough: IT must treat certificate governance, DNS integrity, and continuous monitoring as core controls for protecting customer trust, transaction security, and brand reputation. The incident also underscores the operational risk of slow certificate revocation and the need for layered defenses across web, identity, and infrastructure teams.

  • Enterprise TechTechCrunchSarah Perez2m

    Bluesky wants to give you your own domain on the open web

    Bluesky’s bid to secure the .bsky domain suffix signals a strategic move beyond social networking toward owned digital identity, potentially turning user profiles into portable, branded web properties. For CIOs and technology leaders, it underscores the growing importance of identity control, open-web interoperability, and platform trust—areas that can shape future customer engagement, employee presence, and governance models across IT organizations.

  • Security & PrivacyThe Register2m

    Denmark's ID register spills more people's details than the country has residents

    Denmark’s Central Population Register breach exposed 8.8 million records through abuse of a private contractor’s legitimate access, underscoring how third-party and overbroad data access can turn core government identity systems into high-impact risk surfaces. For CIOs and technology leaders, the strategic takeaway is that identity data cannot be treated as static or secret by default; organizations should strengthen least-privilege controls, continuously monitor privileged access, and assume that large-scale records may include historical, migrated, or deceased individuals that still require protection.

  • Security & PrivacyTechCrunchZack Whittaker2m

    Hackers steal 8 million citizens’ records from Danish government database

    Hackers reportedly stole records on 8 million people from Denmark’s central citizen registry, a breach that underscores how a single compromise in a foundational identity system can create nationwide operational, legal, and reputational risk. For CIOs and technology leaders, the key takeaway is that third-party and privileged access to sensitive government or enterprise data must be tightly governed, continuously monitored, and minimized, because trusted access paths are increasingly a primary attack vector. The incident also highlights the business cost of weak data segmentation and long-lived identity data stores, which can amplify exposure far beyond the current population and complicate response and remediation.

  • Security & PrivacyTechMemeOwen Dahlkamp2m

    Sources: Apple and Google pitch state bills with self-attested age checks and no private lawsuits; Meta backs ones making app stores, not platforms, verify ages (Owen Dahlkamp/Politico)

    Apple, Google, and Meta are actively shaping state-level age-verification laws, signaling that the regulatory burden around kids' online safety may shift toward app stores and away from individual apps or platforms. For CIOs and technology leaders, this raises near-term compliance and product-design risks: IT organizations may need to support new age-assurance workflows, privacy controls, and app-distribution policies across a patchwork of state rules.

  • Security & PrivacyTechCrunchAnthony Ha2m

    Federal judge calls Flock ‘indiscriminate mass surveillance’

    A federal judge’s ruling that a warrantless Flock Safety license-plate search violated the Fourth Amendment is a warning sign for organizations relying on AI-enabled surveillance and location-intelligence tools, even though the decision is not binding precedent. The broader business impact is rising legal, reputational, and procurement risk for public-sector and enterprise IT teams that deploy or integrate sensitive monitoring technologies, especially as political scrutiny and cancellations accelerate. CIOs and technology leaders should expect stronger demands for privacy-by-design controls, tighter data governance, and more rigorous vendor and use-case reviews before approving similar systems.

  • Security & PrivacyHacker News3m

    Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

    Magnet Forensics claims it has found a way to preserve an iPhone’s post-unlock state and bypass Apple’s automatic reboot protections, potentially restoring law enforcement access to data that Apple intended to make harder to extract. For CIOs and technology leaders, this is a reminder that mobile-device security is an ongoing arms race: endpoint controls, encryption, and lock-state protections can be undermined by sophisticated forensic tools, so organizations must assume that sensitive data on devices may still be recoverable in the event of seizure or compromise. The strategic implication for IT is to double down on data minimization, strong MDM/UEM policies, and policies that limit what business data resides on mobile endpoints in the first place.

  • Security & PrivacyHacker News3m

    OpenID Foundation: Identity Management for Agentic AI [pdf] (2025)

    As enterprises begin deploying agentic AI that can take actions across business systems, identity becomes a core control point rather than a back-end security detail. The OpenID Foundation’s guidance signals that CIOs will need standards-based ways to authenticate, authorize, delegate, and audit AI agents so organizations can safely scale automation without losing governance, compliance, or visibility. For IT teams, this means extending IAM, policy enforcement, and logging beyond human users to include autonomous and semi-autonomous machine identities.

  • Security & PrivacyHacker News3m

    Returning from vacation? The government can search your phone without a warrant

    The article highlights a growing risk for business travelers: U.S. border authorities can search and copy data from phones without a warrant, creating exposure for sensitive corporate, legal, and personal information. For CIOs and technology leaders, this underscores the need to treat mobile devices as high-risk endpoints during travel and to strengthen policies around data minimization, encryption, and travel-specific access controls.

  • Security & PrivacyHacker News3m

    Cities Are Forced to Funnel License Plate Data to a Federal Surveillance Program

    The article describes how federal and state programs are pressuring cities to route automated license plate reader (ALPR) data into centralized federal surveillance databases, creating a de facto national data-sharing layer with limited transparency or oversight. For CIOs and technology leaders, the business impact is heightened compliance, privacy, and reputational risk: IT organizations that manage public-safety and mobility data must assume that vendor-collected data may be redistributed beyond local control, making data governance, contract language, retention rules, and access controls strategic priorities.

  • Security & PrivacyArs TechnicaCyrus Farivar2m

    Returning from vacation? The government can search your phone without a warrant.

    The article underscores that employee phones and other mobile devices can be searched and potentially copied at the U.S. border without a warrant, creating a real risk that sensitive corporate data, intellectual property, credentials, and regulated information could be exposed during travel. For CIOs and technology leaders, this is a reminder to treat cross-border mobility as a security and compliance issue: IT should assume devices may be inspected, limit local data on travel devices, and strengthen controls such as encryption, remote wipe, least-privilege access, and travel-specific device policies.

  • Security & Privacy9to5MacSponsored Post2m

    Elder fraud is rising – here’s how to protect your family

    Elder fraud is increasingly powered by exposed personal data, with scammers using information from data brokers, public sources, and even family chats to execute highly convincing impersonation and SIM-swap attacks. For CIOs and technology leaders, the broader implication is that identity protection now depends as much on data minimization and mobile-account hardening as on encryption, and IT teams should treat SMS-based authentication as a material risk. Organizations should also expect more support and security incidents stemming from social engineering that blends stolen data, deepfake voice, and compromised communications channels.

  • Security & PrivacyThe Register3m

    UK rail cops' £320K face-scanning spree nets zero matches

    British Transport Police’s six-month live facial recognition pilot scanned more than 500,000 commuters, cost over £320,000, consumed nearly 100 officer-hours, and produced only one alert that was a false positive. For CIOs and technology leaders, the takeaway is that high-profile AI surveillance programs can fail to deliver operational value while creating material cost, governance, privacy, and reputational risk—especially when deployed without clear legal guardrails or demonstrable accuracy. IT organizations should treat biometric AI as a tightly controlled, evidence-based investment, not a default modernization path.

  • Mobile & Apps9to5MacMarcus Mendes2m

    Apple Pay now rolling out to Axis Bank customers in India

    Apple Pay’s rollout in India, starting with Axis Bank customers, expands a major global payment platform into one of the fastest-growing consumer and device markets. For CIOs and technology leaders, this signals rising demand for seamless, secure mobile payments and reinforces the need to prioritize digital wallet compatibility, payments integration, and customer-experience modernization across banking and retail channels. It also reflects Apple’s deeper strategic push in India, where ecosystem participation could influence customer acquisition, retention, and future fintech partnerships.

  • Enterprise Tech9to5MacBen Lovejoy2m

    Instagram partner schools can now post content only their students can view

    Meta is expanding Instagram’s school partnership program from a cyberbullying-reporting tool into a controlled school communications platform, giving verified schools the ability to post student-only stories, notes, clubs, teams, and directories. For CIOs and technology leaders, this signals a broader shift toward platform-mediated campus engagement, but it also raises governance, privacy, and student-safety considerations that IT teams will need to manage carefully, especially around identity verification, access control, and moderation workflows.

  • Security & PrivacyHacker News3m

    500k facial scans at UK stations yield no arrests, 1 false positive

    A six-month live facial recognition trial in London’s rail stations scanned more than 500,000 faces at a cost of over £320,000 and nearly 100 police hours, yet produced no arrests and only one false positive. For CIOs and technology leaders, the key takeaway is that biometric AI deployments can generate significant operational, legal, and reputational risk without clear ROI unless they are tightly governed, accurately tuned, and aligned to a defensible business or public-safety use case. IT organizations should treat this as a reminder to set strict success metrics, data-minimization controls, and oversight mechanisms before scaling surveillance or other high-risk AI systems.

  • Mobile & AppsAndroid PoliceAnu Joy2m

    I use Google Wallet every day, but these are the security settings I wouldn't ignore

    The article highlights that as employees increasingly use Google Wallet for payments, tickets, and passes, small configuration choices can materially reduce the risk of unauthorized transactions and overexposure of sensitive data. For CIOs and technology leaders, the strategic takeaway is that consumer-grade convenience features can create enterprise risk unless mobile-payment settings, account sharing, and credential lifecycle controls are standardized and periodically reviewed as part of endpoint and identity governance.

  • Security & PrivacyHacker News3m

    Flock Wants the Most Detailed Map of Its Surveillance Cameras Taken Offline

    The article highlights how a cybersecurity researcher exposed a publicly accessible Flock data set that mapped more than 170,000 cameras and related devices nationwide, underscoring the scale of the company’s surveillance footprint and the sensitivity of its location data. For CIOs and technology leaders, the key takeaway is that even widely deployed, mission-critical platforms can create major privacy, reputational, and regulatory risk when exposed data, weak access controls, or third-party integrations are not tightly governed.

  • Enterprise TechHacker News3m

    First Steps of the PLC Organization – Independent Public Ledger of Credentials

    The creation of an independent PLC organization is a meaningful step toward more durable, vendor-neutral identity infrastructure for AT Protocol and Bluesky users. For CIOs and technology leaders, it signals a broader trend toward open, cryptographically verifiable identity services being governed outside a single company, which can improve trust, resilience, and portability while also introducing new governance, policy, and operational dependencies to manage. IT organizations building on or evaluating decentralized identity should watch closely, as the handoff to an independent association may influence account lifecycle management, security controls, and long-term platform strategy.

  • Security & PrivacyHacker News3m

    One Piece of Flock Camera Data Put This Innocent Woman in Jail for 13 Days

    A wrongful arrest and 13-day jail stay show how a single flawed automated license plate reader alert can cascade into severe legal, reputational, and human harm when organizations trust surveillance data without adequate validation. For CIOs and technology leaders, the strategic takeaway is that AI-enabled systems used in high-stakes workflows need strict governance, human review, audit trails, and clear accountability before they influence irreversible decisions. IT organizations should treat these tools as safety-critical infrastructure, not just software purchases, and require rigorous accuracy checks, integration controls, and escalation paths for exceptions.

  • Security & PrivacyAndroid PoliceBen Khalesi2m

    Google finally let me pack up my passkeys and leave, so I did it in one afternoon

    Google’s new Credential Transfer API removes a major barrier to passkey adoption by making credentials portable between password managers on Android, reducing vendor lock-in and making it easier for employees and customers to move to stronger, phishing-resistant authentication. For IT leaders, this is strategically important because it lowers migration friction, strengthens the business case for passkeys over passwords, and gives organizations more flexibility in selecting or changing identity and credential management platforms. It also signals a maturing ecosystem where authentication strategy can be based more on security and user experience than on the risk of trapping credentials in one vendor’s vault.

  • Security & PrivacyThe Register4m

    HSBC decides Samsung Secure Folder and Android's Private Space are no place for a banking app

    HSBC’s decision to block its mobile banking app inside Samsung Secure Folder and Android Private Space shows how security controls can create major customer-access and support risks when they are deployed without warning or fallback paths. For CIOs and technology leaders, the key lesson is that app hardening must be balanced with continuity of access, regulatory expectations, and clear change management—especially when mobile authentication is also the gateway to desktop and web channels.

  • Security & PrivacyThe VergeEmma Roth2m

    Reddit mod ordered to pay Nintendo $4.5 million in Switch piracy lawsuit

    Nintendo’s $4.5 million win against a Reddit moderator underscores how aggressively major software and content owners are enforcing IP rights against piracy networks, even when activity is distributed across forums and online stores. For CIOs and technology leaders, the case is a reminder that platform governance, digital rights management, and monitoring of user-generated ecosystems are strategic risk areas—not just legal concerns—and IT teams may need stronger controls, escalation paths, and evidence-preservation processes when abuse is suspected.

  • Enterprise TechTechMemeCharlie Wells2m

    Revolut is piloting a new POS system that uses facial recognition for payments at the UK coffee chain Kiss the Hippo, ahead of a full launch later this year (Charlie Wells/Bloomberg)

    Revolut’s pilot of facial-recognition payments at a UK coffee chain signals a broader move to turn checkout into a biometric, software-led customer experience that could improve speed, convenience, and differentiation for merchants. For CIOs and technology leaders, the strategic implication is that payments are increasingly becoming a platform battleground where identity, POS, and financial services converge—raising important requirements around privacy, consent, security, and integration with existing retail systems. IT organizations should expect growing demand for biometric-enabled commerce and prepare governance, compliance, and architecture decisions before wider adoption accelerates.

  • Security & PrivacyArs TechnicaJon Brodkin2m

    Discord age verification rolls out today with changes spurred by user backlash

    Discord’s rollout of privacy-preserving age verification shows how regulatory pressure is forcing consumer platforms to balance compliance, user trust, and security architecture at scale. The shift away from direct ID/face collection toward third-party age signals and behavioral inference reduces exposure to sensitive data, but it also raises strategic questions for IT leaders about vendor governance, data minimization, and how to operationalize age- or identity-based access controls across regions with differing legal requirements. This is a strong signal that age assurance is becoming a standard platform capability, not just a policy issue, and IT organizations should expect similar requirements to influence product design, security controls, and third-party risk management.

  • Enterprise TechThe VergeJess Weatherbed2m

    Discord will now automatically estimate your age

    Discord is moving from intrusive ID/selfie-based age checks to an automated age-estimation model that uses account and usage signals, with manual verification only for edge cases. For CIOs and technology leaders, this underscores the growing business need to balance regulatory compliance and child-safety controls with lower-friction user experiences, while minimizing privacy exposure, third-party vendor risk, and support burden. IT organizations should expect broader adoption of AI-driven identity and age-assurance workflows, along with new governance requirements for data minimization, auditability, false-positive handling, and regional policy enforcement.

  • Security & PrivacyTechCrunchSarah Perez2m

    LinkedIn adds new tools to fight fake profiles and bogus work histories

    LinkedIn is introducing stronger verification and brand-control tools to counter the growing risk of fake profiles, impersonation, and bogus employment claims amplified by AI. For CIOs and technology leaders, this signals that professional identity verification is becoming a core trust layer for talent brand protection, recruiting integrity, and enterprise reputation management across digital platforms. IT organizations should expect tighter expectations around identity assurance, governance of employee-facing profiles, and integration with third-party verification ecosystems as authentication becomes a competitive and security requirement.

  • Enterprise TechTechCrunchAmanda Silberling2m

    Discord’s age verification era is upon us, despite community backlash

    Discord is moving ahead with age verification across its platform to meet expanding global regulations, despite user backlash over privacy and biometric-ID risks. For CIOs and technology leaders, the key implication is that age assurance is becoming a broader compliance and trust issue that requires balancing regulatory obligations, customer experience, and data-minimization practices. IT organizations should expect increased scrutiny of identity workflows, ML-based classification, third-party verification vendors, and retention/security controls as more consumer platforms adopt similar requirements.

Browse all tags