Live data from Hacker News

One million passports leaked online

theverge.com

251–260 of 264 posts

Re: One million passports leaked online

#251
post #99

Earlier quoted context omitted.

So what prevents people applying for loans or doing identity theft, in other countries?

To sign on for a house, marry, claim a child as yours etc you need witnesses where I live. Web of trust I guess? If someone takes a loan in my name and I don't receive the money it is not an identity theft it is fraud and the victim is the bank not me.

I meant online. Lower-value types of fraud, like e-commerce, prepaid mobile phone bills.

Re: One million passports leaked online

#252
post #99

Earlier quoted context omitted.

So what prevents people applying for loans or doing identity theft, in other countries?

To sign on for a house, marry, claim a child as yours etc you need witnesses where I live. Web of trust I guess? If someone takes a loan in my name and I don't receive the money it is not an identity theft it is fraud and the victim is the bank not me.

Sure, but what if someone steals your money by impersonating you? Here too, ideally the victim is the bank, but now the onus is on you to convince the bank that they are the victim. They are going to say you're the victim, your identity got stolen, sorry you lost all your savings!

We need to update our laws. This is not "Identity Theft", this is "Negligent Verification Fraud", and it is the bank's fault because they were lax in their verification process.

Re: One million passports leaked online

#253

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

> I preach to my clients this sort of PII should be treated as a toxic, hazardous substance

I've heard this phrasing a lot, but it's hard to believe when there are no consequences after a leak.

Re: One million passports leaked online

#254

Earlier quoted context omitted.

I used to have a book dropped off at my house that had the names, phone numbers, and physical addresses of everyone in my area.

Are you seriously comparing an analog phonebook to machine-searchable structured data made available in a data breach?

I'm saying allowing distributing books but criminalizing distributing the digital version is an overrotation.

As much as extreme viewpoints play well on the internet.

Re: One million passports leaked online

#255
post #163

Earlier quoted context omitted.

While visiting Italy I've had the hotel photocopy my ID. I've researched and the legal requirement for the hotel is to fill a form on the police website, nothing more. While doing the checkout I've pressed them on the reason for keeping the photocopy ("is it for identity theft? "), the duration they were going to keep the copy etc. Basic info they were bound to disclose because of GDPR _before_ the data processing, w…

> Since I was the only client who ever asked about it Says... this perpetrator?

Guilty as charged. I often perpetrate actually

Re: One million passports leaked online

#256
post #146

Earlier quoted context omitted.

If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again. Leaking PII should be very, very expensive, and then this idiocy would stop.

> Leaking PII should be very, very expensive It should be criminal to leak PII, and company leadership should face imprisonment.

Every time I send a work email I leak my pii. We should all use government issued uuids on linked in / facebook.

Re: One million passports leaked online

#257

Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols. How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.

that shoebox would prob be thrown or burnt at some point tho, rather than being accessed by savvy hackers from across the globe.

Re: One million passports leaked online

#258
post #99

Earlier quoted context omitted.

So what prevents people applying for loans or doing identity theft, in other countries?

Key difference might be that most countries have centralized Federal ID document. The Americans never allowed the government such a power, which is a tremendous idea. But they did concede to an ID number through a federal tax entity which de facto served as an id number. Turns out one disadvantage there is that a document is easier to prove ownership of than a number.

That seems irrelevant. The most commonly used ID document for many things in the US is a driver's license; it's issued by the states, not federal govt, so what.

Similarly you could argue that addresses and zip codes are assigned by the USPS not directly by the federal govt, so what.

Combine this with date-of-birth and phone no. and you have a very small set of sufficiently near-unique identifiers (even if that wasn't the intent of the SSN).

One big mistake was not to legislate (at any point between the 1930s and 1980s) to criminalize third parties from using the SSN as unique identifier, as is done by other countries.

Imagine if the East German Stasi had merely outsourced surveillance to data brokers and credit bureaux - different regime, same effect.

Re: One million passports leaked online

#259
post #139

Earlier quoted context omitted.

Looks like this only works on smartphones? Well... no thanks.

how did you come to this conclusion? its not even true Edit: if it is only about authbound, maybe. But they are not the only ones offering this service

> how did you come to this conclusion

I didn't see any reference to the possibility of using anything else on their website. And yes I was only speaking of authbound.

Re: One million passports leaked online

#260
post #44

Earlier quoted context omitted.

Stealing a shoebox of photocopied passports from every hotel in the city sounds like way more work and way riskier than downloading an already aggregated trove of digital data.

Ok, how about the google photos archive from the hotel next door with 1000s of pictures of passports taken on the shared unlocked $100 android phone that sits on the front desk? Not millions I grant you, but again, there doesn't seem to be an issue with active exploitation of these.

Yeah, that should be criminalised.

I never have seen it happen thought, usually hotels dont even copy the passport, they just make you fill a form and then check your passport to see if that's correct. Taking a photocopy is already next level.

Is it a region specific thing? Where did you see hotels like that?

Post reply on HN