Live data from Hacker News

One million passports leaked online

theverge.com

101–110 of 264 posts

Re: One million passports leaked online

#102
post #43

Earlier quoted context omitted.

Is this the CA from FB fame? https://en.wikipedia.org/wiki/Cambridge_Analytica ? If so how come they still exist?

No, it looks like the domain was taken over by squatters after CA went defunct in 2018, and they're currently using it for AI-generated "content".

Yeah, this article is pretty sloppy. No effort. No research. Just raw plagiarism and AI tropes.

Re: One million passports leaked online

#103

> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk. Why do these systems hold onto user's data post verification?

There are various reasons. What if it turned out someone was using a stolen ID or a fake ID, or the ID didn't match the face, or it wasn't even an ID? You'd want to be able to see how your process missed it.

The real problem is that there aren't many options for real authentication over getting people to upload pictures of high-value credentials. Now every service has to be a security expert, like encrypting the images at rest so they aren't the ones who leak it.

It's kind of like how dumb our credit card system is where you have to both share a secret with everyone (from random websites to random restaurants) while hoping the bad guys never get it because the secret can be used anywhere. It kinda works against everyone except the bad guys.

Maybe it's time we come up with a deliberate system.

Re: One million passports leaked online

#106
post #113

[stub for offtopicness]

I think the URL should be changed to The Verge link or something else as the current source is repetitive AI writing and incohesive to read.

Was about to say the exact same thing. This AI slop is just painful to read. The Verge link ( https://www.theverge.com/tech/947157/passports-data-breach-c... ) should be the default as it seems to be the first party source.

Re: One million passports leaked online

#107

That's good, just grab one of those whenever your need to prove your age online /s

Not even needed many times, I was recently at an overseas airport that wanted you to scan your passport to log into the internet. Ya not happening. On another device I downloaded a "sample" passport image of a British passport, the first one on Google images, pointed the phone at the device screen. "This will never work" , he thought as he was immediately logged in. All this stuff really hurts the people who follow the rules the most.

Re: One million passports leaked online

#108

> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk. Why do these systems hold onto user's data post verification?

The leak came from a third party ID/age verification service for a regulated substance in a heavily regulated region. I think there's a good chance that they're under various regulatory/KYC type laws that would make holding onto user data mandatory. One practical scenario where this would come into play is if they were suspected of intentionally accepting fraudulent credentials, basically acting like a fake ID service for hire. In that case authorities would want to be able to see all data that they were basing acceptance on.

Re: One million passports leaked online

#109
post #82

Earlier quoted context omitted.

There's a law forbidding storage beyond necessary minimum and law punishing such behaviour unless another law necessitated storage of the original document in the unsecured, unencrypted form. Doubtful. There's also laws mandating secure systems design. Separately there's no _need_ to store the original document if the verification system is sound (and audit real, not some phony crap like in some of the scandals poste…

If you need to prove you sold to real people, storing their credentials is a necessary thing, for as long as your need to prove that. At least with the way things currently are. How else do you expect it to work? ‘Honest, we checked’ checkboxes?

If the credentials are stored for some period of time, then an inspection will reveal those stored credentials within the preservation window. Unannounced inspections will then show with high certainty a legitimate validation process.

The auditor can act as a customer and validate whether phony credentials are rejected.

Post reply on HN