Live data from Hacker News

One million passports leaked online

theverge.com

111–120 of 264 posts

Re: One million passports leaked online

#112
post #113

[stub for offtopicness]

Is this the CA from FB fame? https://en.wikipedia.org/wiki/Cambridge_Analytica ? If so how come they still exist?

(The URL above was https://cambridgeanalytica.org/data-breaches-scandals/passpo... for a while but we've since changed it to the original source.)

Re: One million passports leaked online

#114
post #65
post #17

Earlier quoted context omitted.

Ok, let's use that and put the other two in the toptext.

It was written by the Verge, and this Cambridge summary admits that (the first paragraph "journalist" is the original author at the Verge).. perhaps we can go back to original source? It's been submitted twice. Author: Sean Hollister https://www.theverge.com/tech/947157/passports-data-breach-c... Similar sounding (recent) leak: Hotel check-in system exposed 1M passports and driver's licenses (4 points, May/2026) http…

Ok! changed now.

Re: One million passports leaked online

#115

I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…

[flagged]

Re: One million passports leaked online

#116
post #115

I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…

[flagged]

[deleted]

Re: One million passports leaked online

#117
post #82

Earlier quoted context omitted.

If you need to prove you sold to real people, storing their credentials is a necessary thing, for as long as your need to prove that. At least with the way things currently are. How else do you expect it to work? ‘Honest, we checked’ checkboxes?

If the credentials are stored for some period of time, then an inspection will reveal those stored credentials within the preservation window. Unannounced inspections will then show with high certainty a legitimate validation process. The auditor can act as a customer and validate whether phony credentials are rejected.

Thanks for agreeing with me?

Re: One million passports leaked online

#118
post #117

Earlier quoted context omitted.

If the credentials are stored for some period of time, then an inspection will reveal those stored credentials within the preservation window. Unannounced inspections will then show with high certainty a legitimate validation process. The auditor can act as a customer and validate whether phony credentials are rejected.

Thanks for agreeing with me?

I thought I was elaborating on how to minimize exposure. If this is just what you meant, then sure!

Re: One million passports leaked online

#119
post #115

I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…

[flagged]

It happened as described. Before it happened, I didn't think there were people like that in this world.

To his credit, the family member took it as a life lesson and moved on (probably more than I have given my posting here). These days he deals with companies that value his contributions, and it turns out that his ex-employer's loss is other companies' (significant) gain.

Post reply on HN