Earlier quoted context omitted.
(I'm naive in this area, but..) I wonder if the various "proof of age" laws coming into play will clash with the GDPR in insidious ways. Like requiring identity providers to hold definitive "proof" of why they made an assessment rather than merely proving and discarding. I assume/hope there is some cryptographic way to do this rather than hang on to passport and ID images, however.
I'm somewhat knowledgable on privacy topics, pasting my answer to another comment: The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept". ^1: https://www.edpb.europa.eu/system/files/docume…
One million passports leaked online
151–160 of 264 posts
Re: One million passports leaked online
#152Earlier quoted context omitted.
(I'm naive in this area, but..) I wonder if the various "proof of age" laws coming into play will clash with the GDPR in insidious ways. Like requiring identity providers to hold definitive "proof" of why they made an assessment rather than merely proving and discarding. I assume/hope there is some cryptographic way to do this rather than hang on to passport and ID images, however.
I'm somewhat knowledgable on privacy topics, pasting my answer to another comment: The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept". ^1: https://www.edpb.europa.eu/system/files/docume…
Re: One million passports leaked online
#153Earlier quoted context omitted.
It happened as described. Before it happened, I didn't think there were people like that in this world. To his credit, the family member took it as a life lesson and moved on (probably more than I have given my posting here). These days he deals with companies that value his contributions, and it turns out that his ex-employer's loss is other companies' (significant) gain.
[flagged]
Re: One million passports leaked online
#154We should stop treating digital pictures of physical documents as some sort of crdentials. There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.
Different countries handle these things differently, but it's honestly surprising to me that a photo of a passport or drivers license have any value. It provides no security, so why would anyone ever accept it a proof of identity?
Because there is no other universal method that works online, and because companies don’t really care about identity verification – they just need something “good enough” so that they can say “hey, we’ve followed industry standard protocols, how could we have known this passport scan was photoshopped?”
And to be honest I think it’s for the best. I really don’t want to be scrutinized even more online (and give even more personal data so it gets leaked a couple years later).
Re: One million passports leaked online
#155I only recently started IDing myself online via eID (german) if available, before that it was usually that I went to the post office and get verified there
Re: One million passports leaked online
#156I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…
During vacation in an Asian country on the other side all of this was basically a no brainer for smaller to medium businesses. I once rented a scooter there and the business owner had all her documents organised in WhatsApp chats. Including now my passport plus drivers licence... The people in general in that country were also very relaxed when it came to giving out their contact details to random businesses.
I don't want to throw shade on them, thus no country name. Incredible friendly and welcoming people there.
Re: One million passports leaked online
#157I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…
After all of that why protect the company by not mentioning their name?
Re: One million passports leaked online
#158Earlier quoted context omitted.
I'm not american, but the idea that your SSN, which is effectively a (federal) unique identifier for a person, would be secret, is very foreign. In most countries, like most databases, our primary keys do not hold an expectation of secrecy. I would even argue that the expectation of secrecy is what creates it's secret semantics, that is, it's secret because you make it secret. I get that it's a collective action thin…
So what prevents people applying for loans or doing identity theft, in other countries?
If someone takes a loan in my name and I don't receive the money it is not an identity theft it is fraud and the victim is the bank not me.
Re: One million passports leaked online
#159I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…
Isn't this classic wrongful termination?
Re: One million passports leaked online
#160Earlier quoted context omitted.
I'm not american, but the idea that your SSN, which is effectively a (federal) unique identifier for a person, would be secret, is very foreign. In most countries, like most databases, our primary keys do not hold an expectation of secrecy. I would even argue that the expectation of secrecy is what creates it's secret semantics, that is, it's secret because you make it secret. I get that it's a collective action thin…
So what prevents people applying for loans or doing identity theft, in other countries?