Live data from Hacker News

One million passports leaked online

theverge.com

241–250 of 264 posts

Re: One million passports leaked online

#241

Earlier quoted context omitted.

Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer. I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).

Everything is paid for by the customer. If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.

> If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.

And then you get your lunch eaten by a competitor who understands that the PII is unnecessary for the business relationship.

But only if that externality is actually accounted for in regulation.

Re: One million passports leaked online

#242

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

Processing such PII here with an external AI partner:

- last week, we had bug: I said: "couldnt you just re-run the same step with the same data again" - their answer: "we cant! look at paragraph XY in our GDPR agreement, we are deleting all input documents everything after it has been processed"

Very well implemented! :)

(though, I had to upload and re-initiate eveything again)

Re: One million passports leaked online

#243

Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols. How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.

It's far worse than that. In a lot of cases when you pay on booking.com, they don't charge your card. Instead, they send all your information (including CVV) along to the hotel where they can charge you how they want. A hotel I visited in Austria, had my card details printed out on a piece of A4 paper.

Re: One million passports leaked online

#244
post #99

Earlier quoted context omitted.

So what prevents people applying for loans or doing identity theft, in other countries?

To sign on for a house, marry, claim a child as yours etc you need witnesses where I live. Web of trust I guess? If someone takes a loan in my name and I don't receive the money it is not an identity theft it is fraud and the victim is the bank not me.

do you think scammers don't travel in packs?

Re: One million passports leaked online

#245

Earlier quoted context omitted.

(I'm naive in this area, but..) I wonder if the various "proof of age" laws coming into play will clash with the GDPR in insidious ways. Like requiring identity providers to hold definitive "proof" of why they made an assessment rather than merely proving and discarding. I assume/hope there is some cryptographic way to do this rather than hang on to passport and ID images, however.

I'm somewhat knowledgable on privacy topics, pasting my answer to another comment: The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept". ^1: https://www.edpb.europa.eu/system/files/docume…

Fixing the link: https://www.edpb.europa.eu/system/files/documents/2025-04/ed...

Re: One million passports leaked online

#246

Earlier quoted context omitted.

> Leaking PII should be very, very expensive It should be criminal to leak PII, and company leadership should face imprisonment.

Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer. I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).

So then the customer will just pay more, because the "prevent you from getting fined into oblivion" insurance businesses you just created with the flick of a pen will need to get paid their overhead and won't do it without a profit.

Re: One million passports leaked online

#247
post #146

Earlier quoted context omitted.

If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again. Leaking PII should be very, very expensive, and then this idiocy would stop.

> Leaking PII should be very, very expensive It should be criminal to leak PII, and company leadership should face imprisonment.

I used to have a book dropped off at my house that had the names, phone numbers, and physical addresses of everyone in my area.

Re: One million passports leaked online

#248
post #146

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again. Leaking PII should be very, very expensive, and then this idiocy would stop.

> "If these kinds of breaches were actually costly, then people would indeed treat PII as toxic."

But they are costly ... just not to big business or government. They couldn't give two flips about our misery.

Re: One million passports leaked online

#249

Earlier quoted context omitted.

> Leaking PII should be very, very expensive It should be criminal to leak PII, and company leadership should face imprisonment.

I used to have a book dropped off at my house that had the names, phone numbers, and physical addresses of everyone in my area.

Are you seriously comparing an analog phonebook to machine-searchable structured data made available in a data breach?

Re: One million passports leaked online

#250

Earlier quoted context omitted.

> Leaking PII should be very, very expensive It should be criminal to leak PII, and company leadership should face imprisonment.

I used to have a book dropped off at my house that had the names, phone numbers, and physical addresses of everyone in my area.

What you didn't have was a computerised database which could spam everyone on that list in milliseconds, or profile everyone's character, purchase history, medical history, and more.

We used to do a lot of worse stuff too, like eat radium hoping for brighter skin.

Post reply on HN