Live data from Hacker News

One million passports leaked online

theverge.com

181–190 of 264 posts

Re: One million passports leaked online

#181

I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…

I admire the naive optimism of someone who'd expect otherwise but why would you? If you want to pursue such a thing, get a lawyer because you're now legal enemies with the school leadership and this should be obvious the moment you start thinking getting yourself involved in such an affair.

Re: One million passports leaked online

#182
post #148

Earlier quoted context omitted.

I'm somewhat knowledgable on privacy topics, pasting my answer to another comment: The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept". ^1: https://www.edpb.europa.eu/system/files/docume…

Link is broken

The original post (and correct link) is here: https://news.ycombinator.com/item?id=48725917>

Re: One million passports leaked online

#183
post #146

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again. Leaking PII should be very, very expensive, and then this idiocy would stop.

> Leaking PII should be very, very expensive

It should be criminal to leak PII, and company leadership should face imprisonment.

Re: One million passports leaked online

#184
That reminds me of the insanity in places like Spain where they want your passport or resident information for every little thing.

We really need to start building a new form of “Democracy” in the backbone of not only that anything that the ruling class wants to apply to everyone else needs to be first implemented on themselves so to double the degree, but that all politicians, bureaucrats, and even contractors need to be bonded against their personal wealth for things they say, promise, contract, or agree to. It is high time that liars, cheats, frauds, and thieves just get to get away with little more than a shoulder shrug and their billions on plunder and lies.

Re: One million passports leaked online

#185
post #139
post #120

In EU, eIDAS 2.0 will fix all of these issues and future leaks alltogether. Check authbound.io

Looks like this only works on smartphones? Well... no thanks.

how did you come to this conclusion? its not even true

Edit: if it is only about authbound, maybe. But they are not the only ones offering this service

Re: One million passports leaked online

#187
post #146

Earlier quoted context omitted.

If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again. Leaking PII should be very, very expensive, and then this idiocy would stop.

> Leaking PII should be very, very expensive It should be criminal to leak PII, and company leadership should face imprisonment.

Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer.

I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).

Re: One million passports leaked online

#188
post #161
post #146

Earlier quoted context omitted.

If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again. Leaking PII should be very, very expensive, and then this idiocy would stop.

This one is a clear breach of the GDPR. If the Spanish enforcers have any teeth, there will be a hefty fine.

It looks like Spain is the most aggressive about pursuing cases, but they also settle for smaller fines than other countries.

https://www.enforcementtracker.com/statistics

Re: One million passports leaked online

#189

Earlier quoted context omitted.

> It doesn't even have common currency. This statement is about as accurate as saying the US doesn't have a common language, or Vatican City residents don't have a common religion. https://en.wikipedia.org/wiki/Economic_and_Monetary_Union_of...

Economic and monetary union is as a group of policies aimed at CONVERGING the economies. From your link. The European Union consists of 27 countries. 25% of them did not adopt Euro as the currency. "common" language is orthogonal here - it would be valid if you could legally use euro everywhere. You can't, it's not a currency in the quarter of the states. Sure, someone may accept it and offer you the exchange to the…

The last line was unnecessary.

Re: One million passports leaked online

#190

That's good, just grab one of those whenever your need to prove your age online /s

For liveness i suppose you need a good graphics card. So dystopian

> a good graphics card

Well, see, for safety reasons we're not going to let consumers have those anymore. You could be doing all kinds of shenanigans, running LLMs locally like a pirate.

Post reply on HN