

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- > PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe.
At least we’re keeping the children safe though by verifying ages. It’s worth giving up privacy for that…
by cebert - Yep. Teenagers are famously incapable of finding a dealer who might even be their mate.by hahahaa
- Oh god that’s pretty bad
> The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicly accessible web servers.
I cannot imagine the level of fines under GDPR for leaking that much PII
by dgellow - Show me the consequences. I hear there are supposed to be repercussions, but these asshats never seem to pay for their crimes.by voakbasda
- Why can't verification simply be go to post office, clerk will affadavit that you presented correct ID via online form. Which could also do the photo lookup for good measure.
Store that fact in the computer. Good for one ID usage. Good for less critical stuff like this weed thing (versus say a visa application which may need to store).
The analogy is a nightclub bouncer checks your ID.
by hahahaa - The EU's verification laws will ensure much more of these leaks in the future, and therefore much more finesby real_chudson
- Remember that there is no such thing as identity theft. There is just fraud. You weren't involved at all.by spullara
- Identity theft is a term made up by banks and institutions who don't want to take responsibility for who they sign contracts with. Despite billions of profits they have every year.
- The lack of security is one thing, but why have they retained the information at all!
iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger).
Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.
It would be reasonable and fair to retain a photo of the user to verify that the person matches the account, but that's it.
by gertrunde
Might KYC laws and general CYA policies prefer to keep the proof of age? For instance to protect e.g. against a minor altering the date on their passport. Especially in such a regulated industry.> Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.by dotancohen- 10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked.
WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!?
Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager.
Until stupid s**t like this becomes illegal, it will just keep continuing.
by rationalist - Back when S3 buckets were rarely protected, I found hundreds of passports of people operating in the diamond business here in Antwerp.
In another one I found all passports that had been scanned by a hostel in Bangkok.
by stef25 - > No hacking was required—documents were accessible through direct URLs with zero authentication or encryption.
You would be surprised what some courts already count as hacking
by croes - Don't forget to send your congress person a reminder about what their vote for age verificiation systems does.
Find your rep at congress.gov. Email or mail them this article.
by monksy - We should stop treating digital pictures of physical documents as some sort of crdentials.
There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.
- Different countries handle these things differently, but it's honestly surprising to me that a photo of a passport or drivers license have any value. It provides no security, so why would anyone ever accept it a proof of identity?by mrweasel
- > We should stop treating digital pictures of physical documents as some sort of credentials.
This is how biometric "authentication" works - you slide a picture (of a face, or maybe a fingerprint or hand geometry) under a door, and the guard on the other side of the door looks at the picture, maybe compares it to some database somewhere and then says PASS/FAIL. Maybe the device taking the picture has some sort of cryptography to prevent yourself from shoving a picture of some authorized person. Usually not.
People keep trying to find the correct magic spell to make biometrics "foolproof". That's a waste of time. Blackhat/DEFCON type conferences were showing people how to make fingerprints out of (the gelatin that makes) gummy bears back in the late 90s. Make them thin enough and you can fool pulse detection (carjackers in some Asian countries were chopping fingers off to bypass theft deterrent systems that used fingerprints).
by Tangurena2 - > Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk.
Why do these systems hold onto user's data post verification?
by tartoran - Why wouldn't they? There are probbaly significant downsides if they fail an audit requirement, and they're probably mandated to retain records for some period, with no consequences to extended retention.
Set up a system so that it costs you nothing to do a bad thing but possibly wrecks you legally and financially to do the good thing, and people will inevitably do the bad thing. They shouldn't be collecting this information in the first place.
The people who design these policies are incapable of actually building things that work. They are not the intelligent, competent leaders exercising a careful craft that they like to pretend they are.
They keep going after age verification, online ID, central bank digital currencies, etc - keep this incident in mind. The people who implement and write these policies are morons. They don't game things out and plan for redundancy or resiliency. They don't take into account bad faith actors. They don't account for deliberate exploitation of the system.
- In a word: complaints.
It’s somewhat understandable but also part of the problem.
by baliex - I'm not sure how it works in the EU, but in the US, most states have a "PMP" (prescription monitoring program) that tracks the sale of marijuana in many states (nevermind that its not an actual prescription, but it is a controlled substance) and viewable by your doctor back up to ~12 months or so. Most people don't know this however and think it works like alcohol sales where it's sold after ID verification and then everyone forgets about it. Some states treat marijuana sales like prescription drug dispensing, it has to be reported to a central database including the intimate details of the persons involved. I have no idea if this is the case in Spain, however.by mothballed
- There are various reasons. What if it turned out someone was using a stolen ID or a fake ID, or the ID didn't match the face, or it wasn't even an ID? You'd want to be able to see how your process missed it.
The real problem is that there aren't many options for real authentication over getting people to upload pictures of high-value credentials. Now every service has to be a security expert, like encrypting the images at rest so they aren't the ones who leak it.
It's kind of like how dumb our credit card system is where you have to both share a secret with everyone (from random websites to random restaurants) while hoping the bad guys never get it because the secret can be used anywhere. It kinda works against everyone except the bad guys.
Maybe it's time we come up with a deliberate system.
by hombre_fatal - > Why do these systems hold onto user's data post verification?
Depending on the company, you could rate the reasons on a scale from "incompetence/naivete" to "revenue stream".
- I have a story about this, although it's a bit convoluted and not entirely related. But it does showcase low-value usecase compromising a high-value auth mechanism.
I was working on a project, client is a Real Estate agency, they use a CRM where they upload houses and it in turn uploads it to various sites like Zillow. We needed a list of their listed houses, so we wanted to use that data source instead of making a CRUD where they have to add houses yet again.
We ask the CRM sales team about APIs, they tell us that there's no accounts for third parties, client accounts have APIs, so we have to ask the client for an API key (or for their account password).
Which makes sense in general I guess, but the data is public in our case, so the CRM sales staff 's idea was that we should ask the client to let us access their account in order to get public data. We proceeded to scrape the houses from a website like Zillow like cavemen.
As it happens, our project was ancilliary low-value. So I don't doubt that the clients of this CRM are vulnerable in a similar way, and the root cause of the issue isn't evident at all, I can see 2:
1- Paradoxically, having an API that always requires an API KEY (as opposed to allowing unauthenticated access for public data) is less secure, as credentials/tokens will be used more often when not necessary.
2- This CRM effectively acted as an aggregator, consuming the APIs to publish to other vendors, but they don't provide an API for other vendors to read data from them. This effectively causes third party vendors to authenticate as the client, which is just incorrect. Credentials should identify a person/group, not a usecase.
by TZubiri - The leak came from a third party ID/age verification service for a regulated substance in a heavily regulated region. I think there's a good chance that they're under various regulatory/KYC type laws that would make holding onto user data mandatory. One practical scenario where this would come into play is if they were suspected of intentionally accepting fraudulent credentials, basically acting like a fake ID service for hire. In that case authorities would want to be able to see all data that they were basing acceptance on.
- Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols.
How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.
by shmoobadge - that shoebox would prob be thrown or burnt at some point tho, rather than being accessed by savvy hackers from across the globe.by didntknowyou
- At smaller hotels or hostels I've had the staff take photos of ID with their own personal devices.by fy20
- It's far worse than that. In a lot of cases when you pay on booking.com, they don't charge your card. Instead, they send all your information (including CVV) along to the hotel where they can charge you how they want. A hotel I visited in Austria, had my card details printed out on a piece of A4 paper.by deanc
- My guess is that the machine readable chip standards and the production quality required to replicate a physical passport are high enough that only the most organized of organized crime can fake the highest value passports effectively, and if a passport is easy to replicate, it is less likely to have visa free access to most countries.
To second the photographed/photocopied requirements, as an expat, I am frequently asked to send a scan of my passport to people or entities that are not necessarily the most secure.
I also have a couple of important documents that are literally PDFs. My Canadian citizenship certificate is a PDF with a barcode in it, that I can print off a copy of if I need to mail it, or show on my phone to a consular office or a border guard if needed. My work visa here in New Zealand is a PDF with my passport number and a visa number, which my workplace and bank checked with an online database. Fundamentally, these and my passport are pointers to a row in various databases.
by annzabelle