One million passports leaked online
1–10 of 264 posts
Re: One million passports leaked online
#2Re: One million passports leaked online
#3> The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicly accessible web servers.
I cannot imagine the level of fines under GDPR for leaking that much PII
Re: One million passports leaked online
#4[stub for offtopicness]
Re: One million passports leaked online
#5Re: One million passports leaked online
#6Oh god that’s pretty bad > The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicl…
Re: One million passports leaked online
#7[stub for offtopicness]
Could we update the link to the original article? https://cambridgeanalytica.org/data-breaches-scandals/passpo...
Re: One million passports leaked online
#8Earlier quoted context omitted.
Could we update the link to the original article? https://cambridgeanalytica.org/data-breaches-scandals/passpo...
CA article is just AI;dr on a two week old Verge article: https://www.theverge.com/tech/947157/passports-data-breach-c...
Re: One million passports leaked online
#9iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger).
Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.
It would be reasonable and fair to retain a photo of the user to verify that the person matches the account, but that's it.
Re: One million passports leaked online
#10Oh god that’s pretty bad > The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicl…
The EU's verification laws will ensure much more of these leaks in the future, and therefore much more fines