Earlier quoted context omitted.
Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer. I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).
Everything is paid for by the customer. If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.
One million passports leaked online
221–230 of 264 posts
Re: One million passports leaked online
#222Earlier quoted context omitted.
Ok then. What should I show or say in Spain, Italy, and Croatia? Usually on plain "I don't consent on making copy, write down the data you need" they become more pushy and even aggressive.
I can talk about Italy because I've researched it. The first step should be to show them the Privacy Authority press release[1] - "No to preservation of guest ID copies". You should be prepared to be refused check-in if they're stubborn and feel like you "cause problems". The protection you have is that public service (hotel) is forbidden to refuse service by law[2][3], fine is €516 up to €3098. If it happens you sho…
[3] - analysis by a police association of the Refusal of Service https://accademiapolizialocale.wordpress.com/wp-content/uplo...
Re: One million passports leaked online
#223Earlier quoted context omitted.
10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked. WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!? Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager. Until stupid s**t like this becomes illegal, it will just keep continuing.
I'm not american, but the idea that your SSN, which is effectively a (federal) unique identifier for a person, would be secret, is very foreign. In most countries, like most databases, our primary keys do not hold an expectation of secrecy. I would even argue that the expectation of secrecy is what creates it's secret semantics, that is, it's secret because you make it secret. I get that it's a collective action thin…
Over the years, it ended up becoming the de facto federal identity number. It has no check digits, so you can make up any you want (I used to use a phone number of a major customer - only dropping 1 digit). I was a rebel/jerk/butthead back then. Now I just yell at clouds.
Long ago, I worked at a place that handled electronic prescriptions, lab results and insurance claims. There were huge numbers of incorrect SSNs which meant there were huge numbers of duplicates. Someone transposed 2 digits? Yep. Someone remembered their number incorrectly? Sure. Someone made one up? Like from a phone number? Oh noes! Before 911, trying to match someone with faulty ID numbers and messed up names was called "patient matching" and after 911 all the academics doing research into this stuff disappeared into large defense contractors or 3-letter-agencies trying to find more terrorists/bad guys.
For a good start in this area of research, I recommend this dissertation:
> Adaptive detection of approximately duplicate database records and the database integration approach to information discovery
> AE Monge - 1997
https://scholar.google.com/citations?view_op=view_citation&h...
> The most misused SSN of all time was [see link]. In 1938, wallet manufacturer the E. H. Ferree company in Lockport, New York decided to promote its product by showing how a Social Security card would fit into its wallets. A sample card, used for display purposes, was inserted in each wallet. Company Vice President and Treasurer Douglas Patterson thought it would be a clever idea to use the actual SSN of his secretary, Mrs. Hilda Schrader Whitcher.
> The wallet was sold by Woolworth stores and other department stores all over the country. Even though the card was only half the size of a real card, was printed all in red, and had the word "specimen" written across the face, many purchasers of the wallet adopted the SSN as their own. In the peak year of 1943, 5,755 people were using Hilda's number.
https://www.ssa.gov/history/ssn/misused.html
Most state agencies redact the SSN from public records. I want to say that they all do, but I work for a state and I see too many in all the wrong places.
Re: One million passports leaked online
#224Earlier quoted context omitted.
10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked. WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!? Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager. Until stupid s**t like this becomes illegal, it will just keep continuing.
I've had stuff like this happen too, and always wondered if they really leaked my data or were just notifying everyone whose data they possibly leaked.
Re: One million passports leaked online
#225Remember that there is no such thing as identity theft. There is just fraud. You weren't involved at all.
Identity theft is a term made up by banks and institutions who don't want to take responsibility for who they sign contracts with. Despite billions of profits they have every year.
Re: One million passports leaked online
#226We should stop treating digital pictures of physical documents as some sort of crdentials. There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.
This is how biometric "authentication" works - you slide a picture (of a face, or maybe a fingerprint or hand geometry) under a door, and the guard on the other side of the door looks at the picture, maybe compares it to some database somewhere and then says PASS/FAIL. Maybe the device taking the picture has some sort of cryptography to prevent yourself from shoving a picture of some authorized person. Usually not.
People keep trying to find the correct magic spell to make biometrics "foolproof". That's a waste of time. Blackhat/DEFCON type conferences were showing people how to make fingerprints out of (the gelatin that makes) gummy bears back in the late 90s. Make them thin enough and you can fool pulse detection (carjackers in some Asian countries were chopping fingers off to bypass theft deterrent systems that used fingerprints).
Re: One million passports leaked online
#227I have a real problem with the pretense posed by the article that the club has no blame. They should have understood the risk they were taking on by subcontracting a vendor to collect passports, and better vetted that vendor. Obviously the service provider was completely inept, but that doesn't absolve the fools using them. I preach to my clients this sort of PII should be treated as a toxic, hazardous substance. Ide…
It is quite interesting how this is handled world wide. For me PII is very sensitive and I advice people to be very cautious. Every business in the EU (were I live) also has to be very careful with such data by law. Fines are now at a level were they can hurt the business significantly. During vacation in an Asian country on the other side all of this was basically a no brainer for smaller to medium businesses. I onc…
So I’m not sure the EU law is really working.
Re: One million passports leaked online
#228I'm aware of another batch of leaked passports, from a few years ago. A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip. He notified the CRM compa…
I'm sorry, how many figures?
Most of those contacts are probably random leads that got imported, not actual clients that would have uploaded their passport info, but it seems reasonable to think that a CRM of our size (which, again, is not very big) that served exclusively travel agents would have millions of actual "clients" with passport info. 1 million passports across 25k users would just be 40 per user. If you assume a typical trip is for a family of four, that would mean the average user has just booked 10 international trips ever which seems pretty low to me.
I want to reiterate that we're not travel-specific and we don't have a feature for capturing passport info, etc., so I'm really just commenting on the volume of records that might be impacted by something like this.
Re: One million passports leaked online
#229Earlier quoted context omitted.
How’s that any different than the US? States determine what they can do.
Cannabis is federally illegal in the US, and the federation has its own enforcement teams that can come and get you even if your state's enforcement teams won't.
Re: One million passports leaked online
#230Earlier quoted context omitted.
The last line was unnecessary.
That was the measured response to the attempted ridicule (that's not nice too). Or, more politely, a suggestion to post arguments that are relevant.
No surprise you got back what you dished out.