Earlier quoted context omitted.
I think every SSN is already leaked and government is doing nothing. I tried to change SSN and they told me it is not possible.
100s of millions have definitely been exposed already. The best defence is probably to be a baby so your risk window is minimal. I haven't been able to pull that off personally, so I follow the other recommended piece of advice which is to keep your credit checks permanently frozen with the agencies and only temporarily thaw it for specific usages. https://www.upguard.com/breaches/social-insecurity-billions-...
One million passports leaked online
91–100 of 264 posts
Re: One million passports leaked online
#92Earlier quoted context omitted.
The EU's verification laws will ensure much more of these leaks in the future, and therefore much more fines
How so, are you purely speculating or you found a hole in the zero knowledge proof system some countries are implementing ?
https://ageverification.dev/av-doc-technical-specification/d...
Re: One million passports leaked online
#93Re: One million passports leaked online
#94> PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. At least we’re keeping the children safe though by verifying ages. It’s worth giving up privacy for that…
Re: One million passports leaked online
#95Oh god that’s pretty bad > The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicl…
Store that fact in the computer. Good for one ID usage. Good for less critical stuff like this weed thing (versus say a visa application which may need to store).
The analogy is a nightclub bouncer checks your ID.
Re: One million passports leaked online
#96Oh god that’s pretty bad > The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicl…
Why can't verification simply be go to post office, clerk will affadavit that you presented correct ID via online form. Which could also do the photo lookup for good measure. Store that fact in the computer. Good for one ID usage. Good for less critical stuff like this weed thing (versus say a visa application which may need to store). The analogy is a nightclub bouncer checks your ID.
...the obvious thing to deploy is a cannabis club bouncer that checks your ID with only his eyes and hands and either bounces you or lets you in, depending on the outcome of that check.
That's far simpler than involving some unrelated third party and far more secure than storing any information about the event in any computer.
Re: One million passports leaked online
#97Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols. How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.
Re: One million passports leaked online
#98I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…
Re: One million passports leaked online
#99Earlier quoted context omitted.
10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked. WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!? Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager. Until stupid s**t like this becomes illegal, it will just keep continuing.
I'm not american, but the idea that your SSN, which is effectively a (federal) unique identifier for a person, would be secret, is very foreign. In most countries, like most databases, our primary keys do not hold an expectation of secrecy. I would even argue that the expectation of secrecy is what creates it's secret semantics, that is, it's secret because you make it secret. I get that it's a collective action thin…
Re: One million passports leaked online
#100I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…
After all of that why protect the company by not mentioning their name?
The image of people standing up for the noble whistleblower is far from the truth. Disclosing the company here won't achieve anything apart from garnering a few karma points and generating some short lived outrage at the company.
I'd consider disclosing it to the ICO, and made tentative steps in that direction at the time, but it's not clear that they are interested and whose interests they would protect.
Here's a question that might make this discussion useful: What is people's experience of reporting data breaches to the UK's ICO? In your case, was meaningful action taken by the ICO and was the person doing the reporting protected? .