Live data from Hacker News

One million passports leaked online

theverge.com

191–200 of 264 posts

Re: One million passports leaked online

#192
post #97

Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols. How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.

At smaller hotels or hostels I've had the staff take photos of ID with their own personal devices.

Same. Many times. This cat is out of the bag.

Re: One million passports leaked online

#193
post #99

Earlier quoted context omitted.

So what prevents people applying for loans or doing identity theft, in other countries?

Key difference might be that most countries have centralized Federal ID document. The Americans never allowed the government such a power, which is a tremendous idea. But they did concede to an ID number through a federal tax entity which de facto served as an id number. Turns out one disadvantage there is that a document is easier to prove ownership of than a number.

Sure but all countries have numbers (tax, SS, ID card) that serve de-facto as IDs. The question is why the number alone (i.e. a username without a password) would ever be considered sufficient to authenticate something.

Re: One million passports leaked online

#194

Earlier quoted context omitted.

> Leaking PII should be very, very expensive It should be criminal to leak PII, and company leadership should face imprisonment.

Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer. I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).

Everything is paid for by the customer. If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.

Re: One million passports leaked online

#195
post #173

Earlier quoted context omitted.

What's so utterly unbelievable about this story? Like, almost none of it is surprising at all.

[flagged]

This is true, but I'm not gonna shout you down as a liar for such a statement either, unless I had some evidence to the contrary.

Re: One million passports leaked online

#196
post #165

Earlier quoted context omitted.

To be able to push back you should know the law requirements for hotels in that jurisdiction, so they can't gaslighting you with fake "it's for police" reasons.

Ok then. What should I show or say in Spain, Italy, and Croatia? Usually on plain "I don't consent on making copy, write down the data you need" they become more pushy and even aggressive.

I can talk about Italy because I've researched it.

The first step should be to show them the Privacy Authority press release[1] - "No to preservation of guest ID copies".

You should be prepared to be refused check-in if they're stubborn and feel like you "cause problems". The protection you have is that public service (hotel) is forbidden to refuse service by law[2][3], fine is €516 up to €3098. If it happens you should call police to verbalise and apply the fine. Refusal by police (Rifiuto di atti d'ufficio) is criminal offence and punishable with imprisonment 6mo - 2yr [4].

You should present ID to allow identification. The host must insert, by law at most 24hrs after check-in [5], client data into police portal, like name, DOB, nationality etc.

Everything else is extra and by GDPR you should be informed of any data processing, basis of processing, duration of processing, and your rights.

You can write Garante della Privacy to signal violations of GDPR if you feel it's warranted. I know they're happy to investigate and apply big fines to larger companies, not sure about how they handle smaller companies, like hotels.

1 - https://www.garanteprivacy.it/home/docweb/-/docweb-display/d...

2 -

4 - Italian penal code Art. 328 Refusal of office acts https://www.brocardi.it/codice-penale/libro-secondo/titolo-i...

5- Art. 109 TULPS - Identification of guests https://www.brocardi.it/testo-unico-pubblica-sicurezza/titol...

Re: One million passports leaked online

#197

I will never upload a picture of my passport or id online, ever. I only recently started IDing myself online via eID (german) if available, before that it was usually that I went to the post office and get verified there

It is not an option in every country to do what you do. Thinking of it, its probably a quirk if Germany that you can go to a Post Office to be “verified”.

Re: One million passports leaked online

#198
post #3

Oh god that’s pretty bad > The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicl…

The EU's verification laws will ensure much more of these leaks in the future, and therefore much more fines

> The EU's verification laws will ensure much more of these leaks in the future, and therefore much more fines

So its a feature, not a bug and a clever revenue stream for the governments?

Re: One million passports leaked online

#199
I'm sorry to say this, but most people don't care. Most governments don't care. Companies don't care. Not that it's not important. But protecting people's ID is at the lower part of the list for most organizations. There are hardly any consequences. Leaking PII is still a joke nowadays.

Re: One million passports leaked online

#200

Earlier quoted context omitted.

the whole "not being an automatable remote sql injection away from everything" quality of physical objects grants a filing cabinet a tremendous amount of inherent security compared to anything digital.

Nothing says “we’re watching you” like the wifi password at the hotel I stayed at in Shanghai being my passport number.

[deleted]
Post reply on HN