Live data from Hacker News

One million passports leaked online

theverge.com

61–70 of 264 posts

Re: One million passports leaked online

#61
So much of our information is being leaked nowadays that news like these don’t surprise me anymore…

I think everyone should understand that if they truly want something private, storing it offline or destroying it completely, are the only safer options.

Any sort of convenience to access said data, is a possible surface of attack.

Re: One million passports leaked online

#62

The lack of security is one thing, but why have they retained the information at all ! iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger). Once a document has been used to verify a person's identity…

10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked. WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!? Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager. Until stupid s**t like this becomes illegal, it will just keep continuing.

The real answer?

In case you want to retrieve your test scores 10 years after you took it. They need some way to uniquely identify you. Sure, they could have given you a specific test taker ID, but what if you lost that? They could have created a way for you to log in with an e-mail address, but what if you changed e-mail addresses?

You might think "Why would I need my test scores from 10+ years ago?", but my wife just started a job and they demanded her college transcripts to prove she went there...over 20 years ago.

Re: One million passports leaked online

#63

Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols. How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.

My guess is that the machine readable chip standards and the production quality required to replicate a physical passport are high enough that only the most organized of organized crime can fake the highest value passports effectively, and if a passport is easy to replicate, it is less likely to have visa free access to most countries. To second the photographed/photocopied requirements, as an expat, I am frequently…

AFAIK not all NFC-enabled passports support Active Authentication. E.g least before US passports did not support it so cloning them is as easy as reading them via NFC.

So you cant fake non-existing passport because of issuer signature, but cloning is not a rocket science for many countries passports.

Re: One million passports leaked online

#65
post #17
post #4

Earlier quoted context omitted.

Could we update the link to the original article? https://cambridgeanalytica.org/data-breaches-scandals/passpo...

Ok, let's use that and put the other two in the toptext.

It was written by the Verge, and this Cambridge summary admits that (the first paragraph "journalist" is the original author at the Verge).. perhaps we can go back to original source? It's been submitted twice.

Author: Sean Hollister https://www.theverge.com/tech/947157/passports-data-breach-c...

Similar sounding (recent) leak: Hotel check-in system exposed 1M passports and driver's licenses (4 points, May/2026) https://news.ycombinator.com/item?id=48152759

Re: One million passports leaked online

#66

Earlier quoted context omitted.

Don't be so hard on 17-ish-year-old you. What exactly were you supposed to do? Not take the ACT (and probably not get into your desired college)?

This is a real problem. I was appalled when renewing my car this year that I now need a Texas by Texas account ( https://www.texas.gov/texas-by-texas/ ), which wants... a social security number because why?!?! Anyway, yet another data breach incoming.

I'd hope that there's an in-person option for renewal. Maybe people without a data plan don't exist anymore?

Re: One million passports leaked online

#67

Earlier quoted context omitted.

The EU's verification laws will ensure much more of these leaks in the future, and therefore much more fines

I had to receive a letter from France (I'm not french, I don't live in France, but we've got family real estate there). To be able to open this letter, online (!), I had to scan my EU ID card, tilt it, and scan my face (pointing at the camera, looking to the left, etc.). We're talking about a major french institution here, either public or private but colluding with the government to have their monopoly (don't know,…

The governments want to retain their abilities to target people for kidnapping/finger-lopping.

Re: One million passports leaked online

#68
post #49
post #41

Earlier quoted context omitted.

>Why wouldn't they? There are probbaly significant downsides if they fail an audit requirement, Right, and keeping old passports used for verification should cause an audit to fail.

Not if there is no law about it. If there is a law about verifying buyers, how else are they going to pass that audit?

There's a law forbidding storage beyond necessary minimum and law punishing such behaviour unless another law necessitated storage of the original document in the unsecured, unencrypted form. Doubtful.

There's also laws mandating secure systems design.

Separately there's no _need_ to store the original document if the verification system is sound (and audit real, not some phony crap like in some of the scandals posted here on HN).

Re: One million passports leaked online

#69

> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk. Why do these systems hold onto user's data post verification?

I'm not sure how it works in the EU, but in the US, most states have a "PMP" (prescription monitoring program) that tracks the sale of marijuana in many states (nevermind that its not an actual prescription, but it is a controlled substance) and viewable by your doctor back up to ~12 months or so. Most people don't know this however and think it works like alcohol sales where it's sold after ID verification and then…

EU is not a country and the laws covering illicit substances vary wildly between member states.

Re: One million passports leaked online

#70
post #4

Earlier quoted context omitted.

Could we update the link to the original article? https://cambridgeanalytica.org/data-breaches-scandals/passpo...

Wow it's insane that Cambridge Analytica is still around after the scandals.

They dissolved and reconstituted as Emerdata. This domain was squatted.
Post reply on HN