Live data from Hacker News

One million passports leaked online

theverge.com

131–140 of 264 posts

Re: One million passports leaked online

#131

> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk. Why do these systems hold onto user's data post verification?

There are various reasons. What if it turned out someone was using a stolen ID or a fake ID, or the ID didn't match the face, or it wasn't even an ID? You'd want to be able to see how your process missed it. The real problem is that there aren't many options for real authentication over getting people to upload pictures of high-value credentials. Now every service has to be a security expert, like encrypting the imag…

> You'd want to be able to see how your process missed it.

An incredible risk to take on someone elses behalf, for personal gain. Don't worry, market forces will surely fix this, no need for regulation.

Re: One million passports leaked online

#132
post #97

Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols. How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.

At smaller hotels or hostels I've had the staff take photos of ID with their own personal devices.

Nothing starts better a stay at a new place, than (most likely) illegal immigrant working (most likely) illegally at the reception of a grubby hotel or hostel taking photo of my passport with their private smartphone. Then I really fell that everything will go well and that I'm safe.

Re: One million passports leaked online

#133

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

[flagged]

Re: One million passports leaked online

#135
post #115

I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…

[flagged]

Very believable. Many, many years ago when auditing a health company website we found a similar "exploit". If any member of the public created a record, there was a page which was (something like) /display.php?record=123. Needless to say if you altered the ID you could read every other medical record. The company took some persuading to even understand that this was a problem, never mind actually fixing it. (Since this was a commercial job, I won't mention the company name)

Re: One million passports leaked online

#136
post #115

Earlier quoted context omitted.

[flagged]

It happened as described. Before it happened, I didn't think there were people like that in this world. To his credit, the family member took it as a life lesson and moved on (probably more than I have given my posting here). These days he deals with companies that value his contributions, and it turns out that his ex-employer's loss is other companies' (significant) gain.

[flagged]

Re: One million passports leaked online

#137

Remember that there is no such thing as identity theft. There is just fraud. You weren't involved at all.

Identity theft is a term made up by banks and institutions who don't want to take responsibility for who they sign contracts with. Despite billions of profits they have every year.

Re: One million passports leaked online

#138
post #98

Earlier quoted context omitted.

After all of that why protect the company by not mentioning their name?

Because it's not worth it. I'm protecting the family member, not the company. The image of people standing up for the noble whistleblower is far from the truth. Disclosing the company here won't achieve anything apart from garnering a few karma points and generating some short lived outrage at the company. I'd consider disclosing it to the ICO, and made tentative steps in that direction at the time, but it's not clea…

This kind of behavior should be punished.
Post reply on HN