Live data from Hacker News

One million passports leaked online

theverge.com

261–264 of 264 posts

Re: One million passports leaked online

#261
post #63

Earlier quoted context omitted.

AFAIK not all NFC-enabled passports support Active Authentication. E.g least before US passports did not support it so cloning them is as easy as reading them via NFC. So you cant fake non-existing passport because of issuer signature, but cloning is not a rocket science for many countries passports.

Nowadays, for US passports (I don't know about other countries), the number/key needed to let the chip talk to you is printed on the photo page, so the older way of reading the NFC from afar won't work without that number.

This has nothing to do with ability to clone the passport. E.g anyone who held your passport for 10 seconds can still create clone with exactly the samw data on NFC chip.

Active Authentication is when NFC chip itself hold cross-signed signing key thar is not exportable so its possible to confirm passport wasnt cloned.

Re: One million passports leaked online

#262
post #63

Earlier quoted context omitted.

AFAIK not all NFC-enabled passports support Active Authentication. E.g least before US passports did not support it so cloning them is as easy as reading them via NFC. So you cant fake non-existing passport because of issuer signature, but cloning is not a rocket science for many countries passports.

Nowadays, for US passports (I don't know about other countries), the number/key needed to let the chip talk to you is printed on the photo page, so the older way of reading the NFC from afar won't work without that number.

[deleted]

Re: One million passports leaked online

#263

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

> the pretense posed by the article that the club has no blame.

Remember that these clubs are mostly small, local businesses. Their owners just don't have the technical sophistication to evaluate software security. Or the clout to demand an audit.

Re: One million passports leaked online

#264
post #258

Earlier quoted context omitted.

Key difference might be that most countries have centralized Federal ID document. The Americans never allowed the government such a power, which is a tremendous idea. But they did concede to an ID number through a federal tax entity which de facto served as an id number. Turns out one disadvantage there is that a document is easier to prove ownership of than a number.

That seems irrelevant. The most commonly used ID document for many things in the US is a driver's license; it's issued by the states, not federal govt, so what. Similarly you could argue that addresses and zip codes are assigned by the USPS not directly by the federal govt, so what. Combine this with date-of-birth and phone no. and you have a very small set of sufficiently near-unique identifiers (even if that wasn't…

>The most commonly used ID document for many things in the US is a driver's license; it's issued by the states, not federal govt, so what.

That doesn't uniquely identify a person though does it? You could get a license from Florida, open an account, then get a license from New York and open another account, and if you defaulted on the credit of one, the other bank would be the wiser and issue you a new loan.

>Similarly you could argue that addresses and zip codes are assigned by the USPS not directly by the federal govt, so what.

Similarly, you could trivially open two accounts under different addresses.

>One big mistake was not to legislate (at any point between the 1930s and 1980s) to criminalize third parties from using the SSN as unique identifier, as is done by other countries.

Certainly it has its disadvantages, but it has its advantages, not really by virtue of not having a central document, but by the other benefits that a legal system that doesn't bestow so much power on the federal government has.

While I agree that the relation of between the lack of central document and the secrecy of SSN numbers isn't proven or self-proving, it's certainly worth considering up to the point that it's a reasonable default and the burden on proof is on disproving it. I can't think of any other country where there's no central document or where a citizen ID is considered secret, so that's pretty good evidence in itself.

Post reply on HN