Live data from Hacker News

One million passports leaked online

theverge.com

21–30 of 264 posts

Re: One million passports leaked online

#21
> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk.

Why do these systems hold onto user's data post verification?

Re: One million passports leaked online

#22

The lack of security is one thing, but why have they retained the information at all ! iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger). Once a document has been used to verify a person's identity…

  > Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.
Might KYC laws and general CYA policies prefer to keep the proof of age? For instance to protect e.g. against a minor altering the date on their passport. Especially in such a regulated industry.

Re: One million passports leaked online

#23
post #8

Earlier quoted context omitted.

Ok, then changing the link to the verge article. Thanks for pointing that out

The verge is not a good source as it's pay walled

From the HN FAQ:

> Are paywalls ok?

> It's ok to post stories from sites with paywalls that have workarounds.

> In comments, it's ok to ask how to read an article and to help other users do so. But please don't post complaints about paywalls. Those are off topic. More here.

https://news.ycombinator.com/newsfaq.html

You can pay for the paywall, or there are ways around.

Re: One million passports leaked online

#25
post #11

Earlier quoted context omitted.

The EU's verification laws will ensure much more of these leaks in the future, and therefore much more fines

How so, are you purely speculating or you found a hole in the zero knowledge proof system some countries are implementing ?

[dead]

Re: One million passports leaked online

#27

The lack of security is one thing, but why have they retained the information at all ! iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger). Once a document has been used to verify a person's identity…

10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked. WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!? Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager. Until stupid s**t like this becomes illegal, it will just keep continuing.

Don't be so hard on 17-ish-year-old you. What exactly were you supposed to do? Not take the ACT (and probably not get into your desired college)?

Re: One million passports leaked online

#29
Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols.

How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.

Post reply on HN