Live data from Hacker News

One million passports leaked online

theverge.com

201–210 of 264 posts

Re: One million passports leaked online

#202

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

It is quite interesting how this is handled world wide. For me PII is very sensitive and I advice people to be very cautious. Every business in the EU (were I live) also has to be very careful with such data by law. Fines are now at a level were they can hurt the business significantly. During vacation in an Asian country on the other side all of this was basically a no brainer for smaller to medium businesses. I onc…

WhatsApp probably has better security than random KYC-as-a-service vendors who upload all the documents to a publicly accessible bucket.

Re: One million passports leaked online

#203

Earlier quoted context omitted.

Economic and monetary union is as a group of policies aimed at CONVERGING the economies. From your link. The European Union consists of 27 countries. 25% of them did not adopt Euro as the currency. "common" language is orthogonal here - it would be valid if you could legally use euro everywhere. You can't, it's not a currency in the quarter of the states. Sure, someone may accept it and offer you the exchange to the…

The last line was unnecessary.

That was the measured response to the attempted ridicule (that's not nice too).

Or, more politely, a suggestion to post arguments that are relevant.

Re: One million passports leaked online

#204
post #196

Earlier quoted context omitted.

Ok then. What should I show or say in Spain, Italy, and Croatia? Usually on plain "I don't consent on making copy, write down the data you need" they become more pushy and even aggressive.

I can talk about Italy because I've researched it. The first step should be to show them the Privacy Authority press release[1] - "No to preservation of guest ID copies". You should be prepared to be refused check-in if they're stubborn and feel like you "cause problems". The protection you have is that public service (hotel) is forbidden to refuse service by law[2][3], fine is €516 up to €3098. If it happens you sho…

> The host must insert, by law at check-in time and not later(!), client data into police portal, like name, DOB, nationality etc.

> Everything else is extra and by GDPR you should be informed of any data processing, basis of processing, duration of processing, and your rights.

It's basically common sense yet they still insist they have to copy the document "for the police". Almost as if they are specifically sourcing these copies for someone.

Re: One million passports leaked online

#205

I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…

i could swear i have read that same story here before but can't find it

Re: One million passports leaked online

#206
post #146

I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…

If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again. Leaking PII should be very, very expensive, and then this idiocy would stop.

The Payment Card Industry takes breaches deadly seriously. It is my opinion that any organization that collects PII should be held to the same standard (and penalties) that any organization that collects/processes credit card information.

https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...

Re: One million passports leaked online

#207
post #40

Earlier quoted context omitted.

Much like that old quip about the bandwidth of a vehicle full of tapes: "Never underestimate the at-rest security of a room full of filing cabinets." Friction and delay have always been aspects of security.

Not sure if they're still doing this, but as of a few years ago, the IRS was still using literal trucks full of tapes to transport data to backup facilities. Tapes are good for this because they don't degrade as quickly as hard drives, so if you're actually looking to do archival storage that will outlast the cloud provider of the decade, they are surprisingly practical.

As long as the janitors aren't using electric floor buffers, like NASA used to do, the tapes will last forever. However NASA ended up losing the data (from 1960s space missions) on the bottom 2 rows of tapes. It took a couple decades though.

Example of those mag tapes: https://www.computerhistory.org/revolution/memory-storage/8/...

How they were stored: https://www.hewlettpackardhistory.com/item/an-attractive-sol...

The newer stuff is a heck of a lot better than the olden stuff.

Re: One million passports leaked online

#208
post #63

Earlier quoted context omitted.

My guess is that the machine readable chip standards and the production quality required to replicate a physical passport are high enough that only the most organized of organized crime can fake the highest value passports effectively, and if a passport is easy to replicate, it is less likely to have visa free access to most countries. To second the photographed/photocopied requirements, as an expat, I am frequently…

AFAIK not all NFC-enabled passports support Active Authentication. E.g least before US passports did not support it so cloning them is as easy as reading them via NFC. So you cant fake non-existing passport because of issuer signature, but cloning is not a rocket science for many countries passports.

Nowadays, for US passports (I don't know about other countries), the number/key needed to let the chip talk to you is printed on the photo page, so the older way of reading the NFC from afar won't work without that number.

Re: One million passports leaked online

#209

Earlier quoted context omitted.

Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer. I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).

Everything is paid for by the customer. If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.

[deleted]

Re: One million passports leaked online

#210
post #63

Earlier quoted context omitted.

AFAIK not all NFC-enabled passports support Active Authentication. E.g least before US passports did not support it so cloning them is as easy as reading them via NFC. So you cant fake non-existing passport because of issuer signature, but cloning is not a rocket science for many countries passports.

Nowadays, for US passports (I don't know about other countries), the number/key needed to let the chip talk to you is printed on the photo page, so the older way of reading the NFC from afar won't work without that number.

Yes for other countries, it’s a standards thing not something unique to the US!
Post reply on HN