I think everyone should understand that if they truly want something private, storing it offline or destroying it completely, are the only safer options.
Any sort of convenience to access said data, is a possible surface of attack.
61–70 of 264 posts
I think everyone should understand that if they truly want something private, storing it offline or destroying it completely, are the only safer options.
Any sort of convenience to access said data, is a possible surface of attack.
The lack of security is one thing, but why have they retained the information at all ! iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger). Once a document has been used to verify a person's identity…
10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked. WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!? Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager. Until stupid s**t like this becomes illegal, it will just keep continuing.
In case you want to retrieve your test scores 10 years after you took it. They need some way to uniquely identify you. Sure, they could have given you a specific test taker ID, but what if you lost that? They could have created a way for you to log in with an e-mail address, but what if you changed e-mail addresses?
You might think "Why would I need my test scores from 10+ years ago?", but my wife just started a job and they demanded her college transcripts to prove she went there...over 20 years ago.
Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols. How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.
My guess is that the machine readable chip standards and the production quality required to replicate a physical passport are high enough that only the most organized of organized crime can fake the highest value passports effectively, and if a passport is easy to replicate, it is less likely to have visa free access to most countries. To second the photographed/photocopied requirements, as an expat, I am frequently…
So you cant fake non-existing passport because of issuer signature, but cloning is not a rocket science for many countries passports.
You would be surprised what some courts already count as hacking
Earlier quoted context omitted.
Could we update the link to the original article? https://cambridgeanalytica.org/data-breaches-scandals/passpo...
Ok, let's use that and put the other two in the toptext.
Author: Sean Hollister https://www.theverge.com/tech/947157/passports-data-breach-c...
Similar sounding (recent) leak: Hotel check-in system exposed 1M passports and driver's licenses (4 points, May/2026) https://news.ycombinator.com/item?id=48152759
Earlier quoted context omitted.
Don't be so hard on 17-ish-year-old you. What exactly were you supposed to do? Not take the ACT (and probably not get into your desired college)?
This is a real problem. I was appalled when renewing my car this year that I now need a Texas by Texas account ( https://www.texas.gov/texas-by-texas/ ), which wants... a social security number because why?!?! Anyway, yet another data breach incoming.
Earlier quoted context omitted.
The EU's verification laws will ensure much more of these leaks in the future, and therefore much more fines
I had to receive a letter from France (I'm not french, I don't live in France, but we've got family real estate there). To be able to open this letter, online (!), I had to scan my EU ID card, tilt it, and scan my face (pointing at the camera, looking to the left, etc.). We're talking about a major french institution here, either public or private but colluding with the government to have their monopoly (don't know,…
Earlier quoted context omitted.
>Why wouldn't they? There are probbaly significant downsides if they fail an audit requirement, Right, and keeping old passports used for verification should cause an audit to fail.
Not if there is no law about it. If there is a law about verifying buyers, how else are they going to pass that audit?
There's also laws mandating secure systems design.
Separately there's no _need_ to store the original document if the verification system is sound (and audit real, not some phony crap like in some of the scandals posted here on HN).
> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk. Why do these systems hold onto user's data post verification?
I'm not sure how it works in the EU, but in the US, most states have a "PMP" (prescription monitoring program) that tracks the sale of marijuana in many states (nevermind that its not an actual prescription, but it is a controlled substance) and viewable by your doctor back up to ~12 months or so. Most people don't know this however and think it works like alcohol sales where it's sold after ID verification and then…
Earlier quoted context omitted.
Could we update the link to the original article? https://cambridgeanalytica.org/data-breaches-scandals/passpo...
Wow it's insane that Cambridge Analytica is still around after the scandals.