Adult site leaks data of cam models
vpnmentor.com
vpnmentor.com
Full name
Birth date
Birthplace
Citizenship status
Nationality
Passport/ID number
Passport issue & expiration dates
Nationally registered gender
ID photo
Personal signature
Parent’s full names
Fingerprints
Additional country-specific details (e.g. emergency contact information for UK citizens)
This is bad. IDs shouldn't be stored on your server once you've confirmed the age/identity/whatever of the user.There was a case years ago of a man who was on trial for child porn. It took the actress physically coming into the courtroom and showing her ID before the case was dropped.
It's just a really scary place to be in terms of society and the law, so I can understand making the decision to do the 'wrong' thing in this instance.
But I don't think it is short, and it at least extends as long as you are selling the material to which it relates, since it is expressly illegal to sell depictions without the records.
source: i work in this field
They could be accused many years after the fact.
Companies just choose to give them realtime access because they charge an admin fee for data access, and if it's realtime, they'll earn more.
You do know that the legal recordkeeping requirements mandate specific indexing and cross-referencing requirements, and that the age records must legally include copies of portions of every covered piece of media sufficient to identify the performer against the photos in the age recors, and also must include cross-reference to every individual full work.
If your media is live streamed, it doesn't seem to me likely that you could meet the requirements with an offline system.
You store all the PII offline and assign each performer a unique identifier. Then tag each stream with the unique identifier.
Why would that not work?
It would work if the law is applied on such a way that the list of media retrieved by querying using the performer ID on the media server is acceptable as the listing of depictions that is required to be part of the age verification records. It's pretty clear in the combination of statute and regulation that either hardcopy or digital records can be used, but it's not at all obvious that a hybrid of that particular form satisfied the requirements. From an information management perspective, I can see it making sense; from what I've seen of administration of legal rules I can see where it might not be. Especially in an industry that politicians (and lead US federal prosecutors are all a brand of politicians) like to score points against, I would expect people to be extremely conservative about uncertain legal exposure; you don't want a setup where you have a decent but uncertain argument of it goes to court, you want one that would never give anyone a reason to think it was a viable pretext for legal action against you in the first place.
If so, there's a simple solution, albeit one that involves hiring a decent-sized staff of file clerks: whenever a model uploads a video, have a printer start spewing screenshots and have an file clerk grab a selection of photos that both identify the video and clearly show the model's face and put them in that model's file in the cabinet.
I guess today was my day to put my foot in my mouth for assuming that I can solve complicated systems with a "why don't you just" :/
That way, if they need it as proof, they can just decrypt the data set. But if the data is stolen, it is of no use for the attacker.
I don't get why they do it though. Faking a card photo is trivial so anyone trying to defraud them will just do so. These guys can manufacture physical replicas of cards to cash them out at ATMs, do the companies really think they won't be capable of altering a picture?
I'm assuming someone somewhere told them to do it and nobody took a minute to actually look into it deeper and realise how easy it is to exploit (and thus useless at preventing fraud).
And/or it ticks a checkbox in some compliance checklist.
And given that this is a site paying their webcammers, the other information is presumably back-up identification in case of account recovery or some such.
I see what you did there.
Keep the data encrypted and only allow KYC providers access to the decryption keys.
I'm not a cryptographer but that sounds like a good strategy when encrypting very short strings to resist cryptanalysis.
ec109685 is right and this is precisely what VGS does. Most companies collect sensitive data (PII/PCI) to achieve a business objective, like verifying identity, age, creditworthiness or to authorize payment. Storing and securing this data is not their primary objective and possession of data comes with the burden of compliance and regulations. VGS acts as a proxy aliasing sensitive datasets as the data flows between systems. When it is time to use this data, VGS acts as a proxy replacing the aliases with real values as data has to be exchanged with third parties.
When dealing with short attributes, combining several other parts of the form to create a composite alias partitioned over the different parts of the payload gets the job done. This would expand the size of the short integer. Adjacent encodings in Chinese, Korean and Japanese characters further expand possibilities.
Just like banking regulations that seems stupid, they come from real abuses and a solution to it at the time. I doubt laws signed in 1988 had internet scale and access in mind, nor could they predict it.
This makes me physically sick.
Also, because of face recognition there really is zero anonymity at this point. It would be very misleading to represent to someone otherwise.
Also, there is a very big difference between citing facial recognition tech (which while rapidly becoming more common, is still something that requires a degree of skill to use and has a real cost to using) as a reason for “zero anonymity” and having public records with direct ties to nude photos and videos leaked. It’s even more misleading to represent that these have the same risk profile.
[1]: https://lawofsex.wordpress.com/2014/03/25/keeping-your-recor...
More like the state should not need it at all. Why support even more surveillance?
Age verification and privacy aren't mutually exclusive. The law can be amended in a way to remain effective without exposing people to such risks.
Back when the law was designed data breaches and being able to find everything online wasn't a thing so it wasn't a problem anyone thought of. Now it's time to fix the law to address the new risks.
Considering that getting it wrong is a federal felony, the incentive set by the law is clear even if, arguably, unintended.
I don’t think you’re wrong, but I would argue that if getting it wrong is a felony, not properly protecting the data should be a felony as well. I realize it isn’t, but incidents like this showcase just how poorly the laws around this type of thing are written. If you can’t properly protect the data, you shouldn’t be in this type of business.
Of course, in this case, this is a site registered in Andorra. So who even know what those laws required in the first place.
What I will say is that just as computers are a force-multipler for getting important stuff done, they are also a force-multiplier for causing harm. As the old saying goes: “to er is human, to really foul up requires a computer”.
This leak did not endanger just one or two people, which would be bad enough, but 4000. Even if the remedy is limited to a fine sufficient for each affected person to change their names and address, it is still a more serious harm than almost anything normal intuition will help with because of how many were involved.
I wish that being in the sex industry was socially neutral for men and women and that nobody would be assaulted or insulted for it. I don’t know why that isn’t the case already, but I do recognise that it isn’t — and given that it isn’t, this leak is still extremely likely to result in someone getting hurt.
It probably should be; I suspect that it's not because making involvement in porn risky for adult participants (and thereby discouraging it), while not the central focus of the law, isn't actually undesirable to lawmakers.
> Of course, in this case, this is a site registered in Andorra. So who even know what those laws required in the first place.
My understanding is that the US applies it's rules to anything of an adult nature sold into or among the US states, regardless of origin, though in practice applying it to foreign entities with little US exposure is difficult; but certainly it wouldn't be the only law that applies, to the extent it might apply.
If you’re required to handle this kind of sensitive information — for any purpose, but I would say this is even more true for anything tied to anything of a sexual nature or anything tied to health — you should take every precaution that that information is secure, encrypted when possible, and that your systems are regularly audited for vulnerabilities.
If the onus of properly protecting sensitive data — whether you’re legally required to hold it or not — is too much or too expensive, you shouldn’t be in that type of business. Period.
And to counter that, the victims are porn actors/actresses, so the perpetrators probably won't face consequences for it.
I'd like to /s this comment, but I'm not sure I can.
The law of having to hold the identification of the models is pretty much the only law you need to uphold. These sites are created from shills of shells.
You have one company, from there you then have two or three other companies which create white label brands utilising one of the shell companies.
So the brand “bangshelia” would be registered with a shell company “adult dating world”. This brand would then be bought by a shill and branded as “purple dating” but registered by a company called “dating purple”.
You would then affiliate with “adult dating tonight” where they would provide the data for your brand.
To get anywhere near close to chasing the company, you need to launch a lawsuit against the active site, (the company registered to) and then the company behind that and from that the company providing the database. Which all costs money.
As my CEO did, you pack up shop on one of those brands and rebrand yourself. Claim your not associated to the previous company by registering another director.
There are no resources available to attempt to make anything secure. The website of the company I used to work for kept all passwords in plain text in a database that was accessible online publicly for other affiliates to borrow to create their own “brand”.
It’s shill of shells. The CEO makes one company, another “investor” buys a brand of the original company and registers it in their name and then sells that on.
That's pretty much a good rule of thumb for, well, everything.
(Sure, there are exceptions. But, there's a reason AWS not only doesn't enable public access to buckets by default, but actually by default has superceding policies in place which block setting normal policies to allow public access; it's almost always the wrong choice.)
> If you’re required to handle this kind of sensitive information ... you should take every precaution that that information is secure, encrypted when possible, and that your systems are regularly audited for vulnerabilities.
None of that solves the problem, though.
You can protect an S3 bucket, but anyone who wants it simply checks it periodically.
Then one day someone is working with the data and changes the permissions to get access, and before they know it, it's downloaded in minutes. It just takes one attacker to get lucky and catch it before your audits do.
And S3 is not unusual, it's just an Internet service like any other, they all have this problem. Even if you have your own data center on a private network, it's only private until someone needs to transmit something and opens a route.
It's ultimately a human problem, there's no magic that can prevent it.
> If the onus ... you shouldn’t be in that type of business. Period.
Ending an unjustified opinion with "period" highlights the fact that you didn't justify the opinion. And it sounds fatuous.
Store all the identifying data they need to hold onto for compliance purposes plus the user ID in offline storage.
[1] https://en.wikipedia.org/wiki/Child_Protection_and_Obscenity...
The law should allow for schemes that prove a performer is legal, identified, etc., but that don't keep individual private details. Even if the site was completely compromised, all the attackers would gain is a single bit of data on each performer. The data would be worthless for personal identification
As always, the powerful (banks) can rig the system in their favor.
A credit card number is managed/owned/valid within the payment networks. Since they manage it, they get to dictate what means of protection are required in order for you to engage in business on those networks.
Government IDs are usually property of the body which issues them. That means each state can (and IIRC, does) have rules about what you can and cannot use that information for. Therefore you'd have to know the rules for each state or issuing body.
That's not to say that common sense _ought_ to dictate that these things should happen anyway, but who thinks to look up various state government rules on handling a Driver's License?
It's a matter of incentives.
Even discarding things like prejudice, cammers have stalker problems fairly regularly as I understand it.
When you can get doxxed by a traffic sign reflected in your eyes ... https://www.bbc.com/news/world-asia-50000234
People would post pictures of the view from their hotel window when travelling and the other members would compete in being the first to find the exact location.
When I say exact, I mean exact. They had to find from which window the picture was taken.
It amazed me how some people could figure it out in a few hours and sometimes even less. Only post pictures online if you are alright with being doxxed from them.
so far, if the tiny number of places i’ve needed to send a DL or something, no one has complained that it’s pretty much just my name and picture. i imagine the staff checking isn’t paid enough to care.
People are going to do it, but it needs to be understood that there are major risks with doing it.
We tell kids "just don't do drugs" for lots of reasons. No one would ever suggest with a straight face that we shouldn't tell children this because some of them will end up doing the drugs anyway due to all manner of reason, including their circumstances.
I bet your argument is going to be "but alcohol is technically a drug", at which point I'm going to roll my eyes so hard they roll out the door.
Could they have firewalled the data better? Hell yeah, there’s a long list of ways this could have been done more responsibly.
I’m in the industry and we take the security of this data very seriously. Very few folks have access to IDs once age verification has happened.
You can't even delete dud uploads. If a customer is involved in fraud or money laundering investigation, every document they have ever uploaded is evidence. So is the type, time and timing of different uploads: in fact, the uploading of a bad document is itself a valid and potentially valuable data point. Multiple uploads in tight sequence with duds in the mix? Hello...
The submitted KYC documentation is TOXIC. It is essentially an archive to impersonate customers. Hell, I consider the material so dangerous that we built a dedicated protection system to guarantee the fraud potential of our archive would be seriously limited even if the whole archive leaked[0].
0: https://smarketshq.com/shields-up-on-user-information-b7093f...
Nope, in US law. Full copies are required of primary producers; redistributors are allowed to have copies with some redactions.
The main damage here isn't the data leaking (it's already out there thanks to countless other breaches anyway), it's the data leaking and the association with the porn site.
This is absurd
Moreover, the jurisdiction of this place (Andorra), leaves a lot of open questions about what (if any) recourse there could be either from a punitive or criminal standpoint.
This is terrible.
They've likely received hundreds of messages with personal information, all stored in Gmail inboxes. What happens to them after they're sighted - I wouldn't know.
I don't know what the 'adult' industry is like but I suspect there's some sites that verify their models by similar email/SMS mediums.
Besides that, Equifax got away with a slap on the wrist even though it was a highly publicised case.
This case will have zero attention outside of HN and the likes so I'd be very surprised if it even makes it to court.
There's also the issue that bringing the case to court will attract more attention to the leak and potentially force the plaintiffs to state their real details on the record, so while it's definitely unfair to let the website operators go unpunished, maybe leaving the mess alone and hoping the dust settles is the best course of action.
Plus, the people who are the victims here are not the people who typically have the money to pursue this (and may live in countries where pursuing anything would cause more harm).
Marginalized victims, opaque legal jurisdiction/laws, and little/no incentive to go after the owners means that I feel confident absolutely nothing will happen.
Think about it: Equifax doxxed more than half the US population and got away with a slap on the wrist and was rewarded with even more government contracts.
What do?
Also it never needs to be updated. Once you've proved you're old enough to legally appear you never need to do so again, at least as long as no time-travel shenanigans are possible.
In US law the records have recency requirements, content-sample requirements for each work the model appears in, and indexing and cross-referencing requirements, and must at the time of each depiction include all names, nicknames, and aliases, the model has ever used in any context (which can expand over time), so, no, it will require updates after being stored.
As long as there aren't too many parties who can ask for the records, and you don't have to provide them on very short order, I think the approach I'd take is to encrypt each document separately using a public key system, and not keep the plaintext. Each encrypted document would be assigned an ID. Indexes and cross references would refer to those IDs.
Since each document is separately encrypted, new and updated documents can be added to the collection without having to decrypt earlier documents.
The private key would be kept on a system that is not online. When a request for records is received, the indexes and cross references could be consulted to determine the IDs of the relevant documents, which could then be taking to the system that has the private key via flash drive, where they could be decrypted and turned over to the requesting party (presumably law enforcement).
For the system with the private key, I'd consider using cheap Linux tablets. Maybe three of them. One for the CEO, one for the CTO, and one kept by the company's lawyer. The tablets are meant to get locked into a safe and stay there except when the company is responding to a records request.
You are required to maintain the records at your place of business or with an identified custodian, with specified content, indexing and cross-reference structure, to provide identification of where they are stored along with any depictions sold/distributes, and make them immediately available for inspection by inspectors authorized by the US Attorney-General (which will generally, as I understand, be any US law enforcement agency which asks for such authority) on demand during normal business hours which are either 9-5 local time or, for inspections at the producer's place of business, the producer's actual working hours, which must be provided to inspectors and, if not at least 20 regular working hours per week, must provide notice of at least 20 hours per week during which the records are available for on-demand inspection even if they aren't otherwise working hours for the producer.
> As long as there aren't too many parties who can ask for the records, and you don't have to provide them on very short order,
I don't think either of those qualifications actually holds, especially the second.
Is the website stepping up to take responsibility?
Why?
If we have decided something, it is not very objective, is it? There is a difference between truth and consensus.
Collecting information (which is public by the way) is just yet another hobby, which can be used for good (training an ML algorithm), bad (annoying someone), or just be neutral (sitting in someone's archive). It does not mean that you use it to ruin someone's life.
Also, there is nothing wrong with stalking people, as long as you do not interact with them, let them know, or affect them in any way.
Particularly when it comes to all the copies of Government Photo IDs (Passports, Drivers licence, etc.)
But to answer your question: Because it is destructive and wrong, no matter the age of the viewer. Calling it "adult" not only suggests that it is fine for adults, but entices minors to it under the false impression that they will be more adult by viewing or participating in it.
Let's say each registered user pays $1 a month for access to this one site they run. That's $66 million/month in revenue. Enough to secure data and comply with privacy laws.
Does anyone know offhand what the penalty would be if this had been a Californian or EU company?
Regarding fines, they wouldn't undo the damage of the leak either. I don't think this kind of leak can be mitigated with any amount of money, short of giving all the people involved a new identity and forcing them to start a new life somewhere else (and even then, they can still be recognised by their physical appearance).
GDPR doesn't say you don't need to properly secure data even if you're legally required to collect it.
GDPR solves this problem as much as any legislation can.
Ideally there should be a way for the websites to fulfil their legal obligations regarding age verification without actually handling any ID data themselves. Maybe a government-provided oAuth style service where you are redirected there, authenticate with the government (no extra risk there, they already have the data) and then they return a signed blob to the website asserting that you are of legal age without actually disclosing any details.
The law is IMO the least of your concerns here (you are not stealing or causing harm to anyone, so very little incentive for someone to look into it), the fallout when your real ID leaks like what happened here would be a much bigger concern especially for LGBT performers in certain regions.
Regarding credit cards, using a prepaid one or a service such a Privacy.com is enough so no fakery needed there.
None of that works in the realm of reality.
Creating a fake ID = super illegal.
Credit cards: prepaid can be detected and blocked, same as the privacy.com ones - especially when the credit card is being used to validate something. Look at any major fraud prevention software, these things are trivial.
In the real world, if you want to make money, you need to show and prove ID with matching banking details. Any inconsistencies and you don't get paid. This isn't something you can outsmart. People smarter than you and I have been thinking very long and hard about these points, much more so than the two minutes you took to think up your post. The idea is like those videos of 'primitive underground dwellings with a swimming hole on top'. Cute, creative, but terribly impractical and useless in any real world situation.
Yes that is correct. I am thankful I have other means of income meaning I don't need to model for a cam site.
> Creating a fake ID = super illegal.
Agreed. But if I'm at the desperate stage where I have no choice but to sign up to a cam site, I would prefer taking that risk than having such PII leak many years in the future and affect my career prospects (the article mentions some of the data being up to 20 years old - most of these people now have no doubt left the scene but their new life can now be screwed up by this data leaking). Neither is a good solution, but IMO the risks of the latter outweigh those of the former.
Regarding prepaid cards, yes I know they can be detected and blocked, but is there any incentive to do so? It makes sense for a performer to want to protect their privacy, so I don't see why the site would block these cards?
https://leginfo.legislature.ca.gov/faces/codes_displaySectio...
> 470b. Every person who displays or causes or permits to be displayed or has in his or her possession any driver’s license or identification card of the type enumerated in Section 470a with the intent that the driver’s license or identification card be used to facilitate the commission of any forgery, is punishable by imprisonment in a county jail for not more than one year, or by imprisonment pursuant to subdivision (h) of Section 1170.
You have to have the intent to commit a forgery. This is defined elsewhere but means to use the id to commit fraud.
So you have a novelty id that says your name is Mickey Mouse and you are 100 years old. You show it to your friends. Or maybe you get one as a gag gift for a friend. Not illegal in California. Using a fake id to misrepresent your age for legal purposes such as buying alcohol, tobacco, firearms, voting, acting in porn? Very illegal.
The owners of this site should be ordered to pay restitution for the damages it has caused to all the performers impacted by this leak. If there are no consequences for things like this, companies will continue to be poor custodians of sensitive data that we entrust to them. The most vulnerable people in society will, as usual, suffer the greatest harm.
No, it would not. ”...the records shall also include a legible hard copy or legible digitally scanned or other electronic copy of a hard copy of the identification document examined and, if that document does not contain a recent and recognizable picture of the performer, a legible hard copy of a picture identification card.” 28 CFR 75.2(a)(1); and there's a lot more besides, see https://www.law.cornell.edu/cfr/text/28/75.2 and 28 CFR 75 generally, as well as 18 USC § 2257.
It's no surprise at all that the sites demand an extraordinary amount of PII about the performers before they are allowed to post a single image.
Shame the punishments for leaking PII are nowhere near as severe.
Asking for a lot of PII is one thing, actually checking that PII to be accurate is another thing. The latter can be exploited to regain a slight bit of privacy.
(1) ascertain, by examination of an identification document containing such information, the performer’s name and date of birth, and require the performer to provide such other indicia of his or her identity as may be prescribed by regulations; (2) ascertain any name, other than the performer’s present and correct name, ever used by the performer including maiden name, alias, nickname, stage, or professional name; and (3) record in the records required by subsection (a) the information required by paragraphs (1) and (2) of this subsection and such other identifying information as may be prescribed by regulation.