Live data from Hacker News

One million passports leaked online

theverge.com

211–220 of 264 posts

Re: One million passports leaked online

#211

I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…

i could swear i have read that same story here before but can't find it

It tends to happen with a reasonable certainty to most whistleblowers, from what I gather.

So yes, you can swear you read that same story before, and I could swear you will read it again :-\

Re: One million passports leaked online

#212

The lack of security is one thing, but why have they retained the information at all ! iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger). Once a document has been used to verify a person's identity…

10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked. WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!? Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager. Until stupid s**t like this becomes illegal, it will just keep continuing.

My first university, back in the 1970s, used my SSN as my student ID and was embossed into the ID card (who is that stranger in the photo?). Nowadays, no university uses SSN for student IDs. There's a saying that applies: the past is a foreign country.

Re: One million passports leaked online

#213

Earlier quoted context omitted.

The real answer? In case you want to retrieve your test scores 10 years after you took it. They need some way to uniquely identify you. Sure, they could have given you a specific test taker ID, but what if you lost that? They could have created a way for you to log in with an e-mail address, but what if you changed e-mail addresses? You might think "Why would I need my test scores from 10+ years ago?", but my wife ju…

Identify the student by full name, dob, date of admission, career, etc. It takes 5 minutes instead of one. The problem here is using a username (the ID) as a password (security check)

And make them call the registrar during regular hours. That’s what I had to do to get a transcript from 15 years ago once. The registrar holds the records and should be able to provide them.

Re: One million passports leaked online

#214

Earlier quoted context omitted.

I think every SSN is already leaked and government is doing nothing. I tried to change SSN and they told me it is not possible.

100s of millions have definitely been exposed already. The best defence is probably to be a baby so your risk window is minimal. I haven't been able to pull that off personally, so I follow the other recommended piece of advice which is to keep your credit checks permanently frozen with the agencies and only temporarily thaw it for specific usages. https://www.upguard.com/breaches/social-insecurity-billions-...

They’ll definitely issue loans to a child. You have to actually put a special freeze on your child’s credit account, which is insane but welcome to the US, where any obstruction to the wheels of commerce is an affront to our national dignity.

Re: One million passports leaked online

#215

Earlier quoted context omitted.

> Leaking PII should be very, very expensive It should be criminal to leak PII, and company leadership should face imprisonment.

Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer. I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).

Then over confident, short sighted or shady characters will accept those directorships and/or sign off on the design because they think nothing will happen or don't care for jail.

Re: One million passports leaked online

#216

Earlier quoted context omitted.

Don't be so hard on 17-ish-year-old you. What exactly were you supposed to do? Not take the ACT (and probably not get into your desired college)?

This is a real problem. I was appalled when renewing my car this year that I now need a Texas by Texas account ( https://www.texas.gov/texas-by-texas/ ), which wants... a social security number because why?!?! Anyway, yet another data breach incoming.

> which wants... a social security number because why?

Because of federal child support legislation. If you are $2500 (or more) in arrears, your passport gets cancelled. Most states will also suspend/revoke your professional licenses and possibly driving license when you cross that state's threshold.

https://travel.state.gov/en/passports/contact-support/legal-...

https://en.wikipedia.org/wiki/Child_support_in_the_United_St...

> In 1996, Congress passed and President Bill Clinton signed the Personal Responsibility and Work Opportunity Act (42 U.S.C. § 666), which required that states adopt UIFSA by January 1, 1998 or face loss of federal funding for child support enforcement. Every U.S. state has adopted either the 1996 or a later version of UIFSA.

https://en.wikipedia.org/wiki/Uniform_Interstate_Family_Supp...

When I worked for my state's motor vehicle bureau, one of the verification apis that the driving license/ID folks got to use was a verification of citizenship/lawful residence service. Which used SSNs.

Re: One million passports leaked online

#217

Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols. How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.

> people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in.

This. I hate it. People expect you to send your documents on messaging apps and god only knows where they end up. Unfortunately, I fear there's nothing we can do to stop this as govs enforce this kind of operations.

Re: One million passports leaked online

#218
post #40

Earlier quoted context omitted.

the whole "not being an automatable remote sql injection away from everything" quality of physical objects grants a filing cabinet a tremendous amount of inherent security compared to anything digital.

Much like that old quip about the bandwidth of a vehicle full of tapes: "Never underestimate the at-rest security of a room full of filing cabinets." Friction and delay have always been aspects of security.

It depends on the stakes?

In the 90s, the French IRS seized massive amounts of files from Elf, then a major French oil company under investigation for various frauds.

Their offices where burglarized maybe a couple nights after that. All that was seized disappeared.

Re: One million passports leaked online

#219
post #117

Earlier quoted context omitted.

Thanks for agreeing with me?

I thought I was elaborating on how to minimize exposure. If this is just what you meant, then sure!

Yeah, my point is that there is a significant exposure they are required to have, if they need to be able to be audited and have to actually prove they are dealing with real people.

At least - as you mention - until the rules catch up and there is some sort of one way hashing/signing or something possible, which for most of these industries is probably decades away (if ever). Most of these industries struggle with photocopies at this point.

Re: One million passports leaked online

#220

Earlier quoted context omitted.

Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer. I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).

Everything is paid for by the customer. If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.

Yep -- and it's good.

Before: customer pays fines for bad security, rolled into the price of the offering.

After: customer pays for actual good security, rolled into the price of the offering.

If the customer doesn't care, no change. If the customer cares (and let's low key assume PII is important) -- they see net gain from this change.

Post reply on HN