A database of nearly one million passports was leaked online after being stored in an ID verification system used by cannabis dispensaries. The core issue highlighted is that a high-value credential (a passport) was entrusted to a low-value, ancillary authentication system, and when that weaker system was breached, the high-value credentials were exposed. This illustrates the risk of using sensitive identity documents in third-party systems with weaker security postures.

1m read timeFrom schneier.com
Post cover image
401 Impressions