Hacker News new | ask | show | jobs
by throwaway692675 32 days ago
I'm aware of another batch of leaked passports, from a few years ago.

A family member was booking a school tour, when he noticed the URL of the Travel CRM included an id number. Sure enough, the CRM would return all his details given only the (sequential) id number without a need for credentials: high resolution passport scan, and all the other details provided when booking an overseas trip.

He notified the CRM company, and that email was ignored. He emailed again, proposing disclosure, and the problem was silently fixed with no response.

A few months later he mentioned it to the school, along with the fact that he had followed up and had the vulnerability fixed. The school went straight into panic mode, called him to the principal's office and forced him to write a statement so they could refer him to the Feds. I intervened, explaining that he was the good guy who got the vulnerability fixed, and the problem was the school's, since they had supposedly vetted the CRM for security when choosing a tour company.

All of a sudden from the school's point of view there was no problem and no need to mention it to any of the people whose information had been disclosed, despite my insistence. The people still haven't been notified. The school did acknowledge that the family member had done the right thing and verbally thanked him, but would not put anything in writing.

The people involved in the tour had their details leaked, but there was nothing special about those people in the system, so realistically every person whose details were in that CRM had their details, including passports, leaked. It was a major travel CRM provider, so the number of people in the system would have been 6 or 7 figures.

The kicker is that the family member was employed by a software company that had the school system as a customer. The IT person who was responsible for vetting the travel CRM (and had verbally thanked him) arranged for the school system to phone his employer and deliver an ultimatum: that the family member be sacked or they would risk losing a customer. The family member got the sack.

5 comments

I admire the naive optimism of someone who'd expect otherwise but why would you? If you want to pursue such a thing, get a lawyer because you're now legal enemies with the school leadership and this should be obvious the moment you start thinking getting yourself involved in such an affair.
> The family member got the sack.

Isn't this classic wrongful termination?

It wasn't worth pursuing, partly because it was a part time job. A bit sad, as the company had promised to sponsor him though further study. It was the right decision, as it turned out to be less effort than a court case to get better opportunities with other companies.
It was the right choice for the individual, wrong choice for society.
After all of that why protect the company by not mentioning their name?
Because it's not worth it. I'm protecting the family member, not the company.

The image of people standing up for the noble whistleblower is far from the truth. Disclosing the company here won't achieve anything apart from garnering a few karma points and generating some short lived outrage at the company.

I'd consider disclosing it to the ICO, and made tentative steps in that direction at the time, but it's not clear that they are interested and whose interests they would protect.

Here's a question that might make this discussion useful: What is people's experience of reporting data breaches to the UK's ICO? In your case, was meaningful action taken by the ICO and was the person doing the reporting protected? .

And one thought about this situation and the common view that companies/corporation are a being on their own: I'm pretty sure that the IT guy that gave the OK to the CRM and then asked to sack your family member is directly responsible and could have took another decision if they were a person with a higher moral ground, like accept responsibility and accepting the risk of being fired. And the same apply to every level of the chain of command.

But it's easier to say that people are removed by design from the consequences of their acts so it's not easy to take the right decision for anyone. It's just not convenient, instead.

This kind of behavior should be punished.
If you can't actually substantiate these claims (they probably can't prove it, even if it's true) then this could be a very expensive claim to make.
i could swear i have read that same story here before but can't find it
It tends to happen with a reasonable certainty to most whistleblowers, from what I gather.

So yes, you can swear you read that same story before, and I could swear you will read it again :-\

I'm sorry, how many figures?
I run a small CRM company that serves some travel agents (we're not travel-specific, but we have a lot of small broker/agent businesses using us). We have ~11,000 customers with ~25,000 users between them, and our database stores ~100 million contacts, so about 4k contacts per user.

Most of those contacts are probably random leads that got imported, not actual clients that would have uploaded their passport info, but it seems reasonable to think that a CRM of our size (which, again, is not very big) that served exclusively travel agents would have millions of actual "clients" with passport info. 1 million passports across 25k users would just be 40 per user. If you assume a typical trip is for a family of four, that would mean the average user has just booked 10 international trips ever which seems pretty low to me.

I want to reiterate that we're not travel-specific and we don't have a feature for capturing passport info, etc., so I'm really just commenting on the volume of records that might be impacted by something like this.