Live data from Hacker News

One million passports leaked online

theverge.com

121–130 of 264 posts

Re: One million passports leaked online

#121
post #82

Earlier quoted context omitted.

There's a law forbidding storage beyond necessary minimum and law punishing such behaviour unless another law necessitated storage of the original document in the unsecured, unencrypted form. Doubtful. There's also laws mandating secure systems design. Separately there's no _need_ to store the original document if the verification system is sound (and audit real, not some phony crap like in some of the scandals poste…

If you need to prove you sold to real people, storing their credentials is a necessary thing, for as long as your need to prove that. At least with the way things currently are. How else do you expect it to work? ‘Honest, we checked’ checkboxes?

You can store for example ID type and serial number AND hash of the personal information.

If the government-affiliated agency decides to check, they can.

But back to my original statement - unless they're explicitly mandated to keep it longer, they are forbidden from doing so, and their DPO would know it.

Re: One million passports leaked online

#122
post #74

Earlier quoted context omitted.

EU is not a country and the laws covering illicit substances vary wildly between member states.

How’s that any different than the US? States determine what they can do.

Still, EU is a loose federation with some common laws and mostly common border policy. It doesn't even have common currency.

Re: One million passports leaked online

#123

Earlier quoted context omitted.

> Why wouldn't they? They most likely weren't allowed to keep it past the verification per GDPR art.5. Once the passport has been verified for whatever purpose they needed it ("age verified to be > 18yo on 2026-06-12" or "identity verified to be XXXX YYYY"), there is no legitimate use for the passport photo and details anymore, and they should delete it.

(I'm naive in this area, but..) I wonder if the various "proof of age" laws coming into play will clash with the GDPR in insidious ways. Like requiring identity providers to hold definitive "proof" of why they made an assessment rather than merely proving and discarding. I assume/hope there is some cryptographic way to do this rather than hang on to passport and ID images, however.

I'm somewhat knowledgable on privacy topics, pasting my answer to another comment:

The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept".

^1: https://www.edpb.europa.eu/system/files/documents/2025-04/ed..., number 36.

Re: One million passports leaked online

#124

I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…

[deleted]

Re: One million passports leaked online

#125
Back when S3 buckets were rarely protected, I found hundreds of passports of people operating in the diamond business here in Antwerp.

In another one I found all passports that had been scanned by a hostel in Bangkok.

Re: One million passports leaked online

#126
post #40

Earlier quoted context omitted.

Much like that old quip about the bandwidth of a vehicle full of tapes: "Never underestimate the at-rest security of a room full of filing cabinets." Friction and delay have always been aspects of security.

Not sure if they're still doing this, but as of a few years ago, the IRS was still using literal trucks full of tapes to transport data to backup facilities. Tapes are good for this because they don't degrade as quickly as hard drives, so if you're actually looking to do archival storage that will outlast the cloud provider of the decade, they are surprisingly practical.

Working with tape storage was part of my high school education. So was mainframe job scheduling...

Europe is as much ahead as it is behind.

Re: One million passports leaked online

#128
I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them.

I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ideally don't touch it with a 10 foot pole, and if you can't help it then limit the scope, protect it with strong access policies that severely limit who can touch it (including encryption keys conservatively custodied), and securely delete it all as soon as possible.

Too many companies these days point you to shoddy third parties for some kind of functionality (e.g. book an appointment, perform KYC on you, host the online learning platform for your course, etc.), inappropriately foisting both a new business relationship on you that you never asked for along with their partner's terms of service that you have no bargaining power in negotiating.

This is a side-effect of the SaaS era, and the model is broken.

Re: One million passports leaked online

#129
post #115

Earlier quoted context omitted.

[flagged]

It happened as described. Before it happened, I didn't think there were people like that in this world. To his credit, the family member took it as a life lesson and moved on (probably more than I have given my posting here). These days he deals with companies that value his contributions, and it turns out that his ex-employer's loss is other companies' (significant) gain.

[flagged]

Re: One million passports leaked online

#130

Earlier quoted context omitted.

Ok, how about the google photos archive from the hotel next door with 1000s of pictures of passports taken on the shared unlocked $100 android phone that sits on the front desk? Not millions I grant you, but again, there doesn't seem to be an issue with active exploitation of these.

There is an issue with active exploitation of passports, of course the scale can change. Due to banking KYC / other KYC laws there's a market for these copied identities and of course so criminals don't even get a speedbump by KYC whereas the boot is used up the ass of the normal person trying to pass KYC when they're missing some stupid document like proof of address.

> the boot is used up the ass of the normal person trying to pass KYC when they're missing some stupid document like proof of address.

We are not there yet, Sir. First you must provide inheritance document showing the amount inherited and deed of purchase and sale of real estate. This is the law.

Post reply on HN