One million passports leaked online
101–110 of 264 posts
Re: One million passports leaked online
#102Earlier quoted context omitted.
Is this the CA from FB fame? https://en.wikipedia.org/wiki/Cambridge_Analytica ? If so how come they still exist?
No, it looks like the domain was taken over by squatters after CA went defunct in 2018, and they're currently using it for AI-generated "content".
Re: One million passports leaked online
#103> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk. Why do these systems hold onto user's data post verification?
The real problem is that there aren't many options for real authentication over getting people to upload pictures of high-value credentials. Now every service has to be a security expert, like encrypting the images at rest so they aren't the ones who leak it.
It's kind of like how dumb our credit card system is where you have to both share a secret with everyone (from random websites to random restaurants) while hoping the bad guys never get it because the secret can be used anywhere. It kinda works against everyone except the bad guys.
Maybe it's time we come up with a deliberate system.
Re: One million passports leaked online
#104[stub for offtopicness]
Is this the CA from FB fame? https://en.wikipedia.org/wiki/Cambridge_Analytica ? If so how come they still exist?
Re: One million passports leaked online
#105[stub for offtopicness]
Re: One million passports leaked online
#106[stub for offtopicness]
I think the URL should be changed to The Verge link or something else as the current source is repetitive AI writing and incohesive to read.
Re: One million passports leaked online
#107That's good, just grab one of those whenever your need to prove your age online /s
Re: One million passports leaked online
#108> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk. Why do these systems hold onto user's data post verification?
Re: One million passports leaked online
#109Earlier quoted context omitted.
There's a law forbidding storage beyond necessary minimum and law punishing such behaviour unless another law necessitated storage of the original document in the unsecured, unencrypted form. Doubtful. There's also laws mandating secure systems design. Separately there's no _need_ to store the original document if the verification system is sound (and audit real, not some phony crap like in some of the scandals poste…
If you need to prove you sold to real people, storing their credentials is a necessary thing, for as long as your need to prove that. At least with the way things currently are. How else do you expect it to work? ‘Honest, we checked’ checkboxes?
The auditor can act as a customer and validate whether phony credentials are rejected.
Re: One million passports leaked online
#110Find your rep at congress.gov. Email or mail them this article.