Live data from Hacker News

One million passports leaked online

theverge.com

141–150 of 264 posts

Re: One million passports leaked online

#141
post #98

Earlier quoted context omitted.

After all of that why protect the company by not mentioning their name?

Because it's not worth it. I'm protecting the family member, not the company. The image of people standing up for the noble whistleblower is far from the truth. Disclosing the company here won't achieve anything apart from garnering a few karma points and generating some short lived outrage at the company. I'd consider disclosing it to the ICO, and made tentative steps in that direction at the time, but it's not clea…

And one thought about this situation and the common view that companies/corporation are a being on their own: I'm pretty sure that the IT guy that gave the OK to the CRM and then asked to sack your family member is directly responsible and could have took another decision if they were a person with a higher moral ground, like accept responsibility and accepting the risk of being fired. And the same apply to every level of the chain of command.

But it's easier to say that people are removed by design from the consequences of their acts so it's not easy to take the right decision for anyone. It's just not convenient, instead.

Re: One million passports leaked online

#142
post #139
post #120

In EU, eIDAS 2.0 will fix all of these issues and future leaks alltogether. Check authbound.io

Looks like this only works on smartphones? Well... no thanks.

Duh, and only on iOS and Android ones, and only on their latest versions... but don't worry they have good intents I would trust them.

Re: One million passports leaked online

#144

I said if before, and I'll say it again: as long as they're is nothing to fear, companies will continue being lax with your valuable private data. As long as there's no liability, there's no incentive to care.

And they will continue to ask for data, that they don't actually need like phone numbers and home addresses.

Re: One million passports leaked online

#145
We should stop treating digital pictures of physical documents as some sort of crdentials.

There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.

Re: One million passports leaked online

#146

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again.

Leaking PII should be very, very expensive, and then this idiocy would stop.

Re: One million passports leaked online

#147

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

[flagged]

I wish people stopped using distracting animations below the text I'm trying to read and comprehend.

Re: One million passports leaked online

#148

Earlier quoted context omitted.

(I'm naive in this area, but..) I wonder if the various "proof of age" laws coming into play will clash with the GDPR in insidious ways. Like requiring identity providers to hold definitive "proof" of why they made an assessment rather than merely proving and discarding. I assume/hope there is some cryptographic way to do this rather than hang on to passport and ID images, however.

I'm somewhat knowledgable on privacy topics, pasting my answer to another comment: The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept". ^1: https://www.edpb.europa.eu/system/files/docume…

Link is broken

Re: One million passports leaked online

#149

We should stop treating digital pictures of physical documents as some sort of crdentials. There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.

Different countries handle these things differently, but it's honestly surprising to me that a photo of a passport or drivers license have any value. It provides no security, so why would anyone ever accept it a proof of identity?

Re: One million passports leaked online

#150
post #139

Earlier quoted context omitted.

Looks like this only works on smartphones? Well... no thanks.

Duh, and only on iOS and Android ones, and only on their latest versions... but don't worry they have good intents I would trust them.

This is the problem with pretty much all of the EUs attempts of getting away from US infrastructure. One of the VISA/MasterCard alternative is also a bloody app, on a smartphone, with an operating system from one of two US software gigants (One of which is know to give zero fucks about privacy).

If the EU wants to continue down this road, step on has to be a mobile operating system. Avoiding tying solution to people phones would be better.

Post reply on HN