Why do these systems hold onto user's data post verification?
Why do these systems hold onto user's data post verification?
I was working on a project, client is a Real Estate agency, they use a CRM where they upload houses and it in turn uploads it to various sites like Zillow. We needed a list of their listed houses, so we wanted to use that data source instead of making a CRUD where they have to add houses yet again.
We ask the CRM sales team about APIs, they tell us that there's no accounts for third parties, client accounts have APIs, so we have to ask the client for an API key (or for their account password).
Which makes sense in general I guess, but the data is public in our case, so the CRM sales staff 's idea was that we should ask the client to let us access their account in order to get public data. We proceeded to scrape the houses from a website like Zillow like cavemen.
As it happens, our project was ancilliary low-value. So I don't doubt that the clients of this CRM are vulnerable in a similar way, and the root cause of the issue isn't evident at all, I can see 2:
1- Paradoxically, having an API that always requires an API KEY (as opposed to allowing unauthenticated access for public data) is less secure, as credentials/tokens will be used more often when not necessary.
2- This CRM effectively acted as an aggregator, consuming the APIs to publish to other vendors, but they don't provide an API for other vendors to read data from them. This effectively causes third party vendors to authenticate as the client, which is just incorrect. Credentials should identify a person/group, not a usecase.
Depending on the company, you could rate the reasons on a scale from "incompetence/naivete" to "revenue stream".
The real problem is that there aren't many options for real authentication over getting people to upload pictures of high-value credentials. Now every service has to be a security expert, like encrypting the images at rest so they aren't the ones who leak it.
It's kind of like how dumb our credit card system is where you have to both share a secret with everyone (from random websites to random restaurants) while hoping the bad guys never get it because the secret can be used anywhere. It kinda works against everyone except the bad guys.
Maybe it's time we come up with a deliberate system.
An incredible risk to take on someone elses behalf, for personal gain. Don't worry, market forces will surely fix this, no need for regulation.
We are decades beyond the days where the waitress uses a credit card imprinter to copy your credit card so the restaurant can charge your credit card later, yet that's still basically the state of our tech when it comes to authentication and payment.
Not even KYC institutions have better tech. You still upload a scan of your high value creds, maybe with your face in frame.
This statement is about as accurate as saying the US doesn't have a common language, or Vatican City residents don't have a common religion.
https://en.wikipedia.org/wiki/Economic_and_Monetary_Union_of...
The European Union consists of 27 countries.
25% of them did not adopt Euro as the currency.
"common" language is orthogonal here - it would be valid if you could legally use euro everywhere. You can't, it's not a currency in the quarter of the states. Sure, someone may accept it and offer you the exchange to the local currency.
Vatican City example is also not very good (to put it mildly), because Catholicism is a state religion. You're not going to be deported for being Sikh, yes, but it's akin to the Romanian not being deported form Portugal for carrying lei in his pocket.
Euro is NOT a common currency in the EU. It is by far the most popular. It is a common currency in the Eurozone countries. And these two are distinct from Europe as well.
I'd suggest you discuss your ideas with someone before posting them again.
Or, more politely, a suggestion to post arguments that are relevant.
No surprise you got back what you dished out.
Look, non sequitur doesn't hold as much as you think it does.
And I'd also like to point to something you missed:
>> *attempted* ridicule.
_If_ their arguments were sound and relevant, maybe. But, well, they weren't.
Note I wasn't even responding to you, just replied to someone else seemingly conflating EU with Eurozone, trying to make fun of one phrase out of several statements, omitting the key "EU is a loose federation".
Now I fully expect @bluebarbet descent again and either chastise me for being amused at your comment, or tell you off for rudely implying malicious intent that wasn't there.
Especially since I wasn't even talking to you right now, and from your first comment's first sentence it could be clearly inferred you expect some sort of the federal policy, and this is what I was trying to address concisely, in a good faith.
Do with it whatever you want, I wasted too much time on that already anyway.
Have a good day, sir or madam.
https://azcir.org/news/2025/04/10/are-az-medical-marijuana-c...
It’s somewhat understandable but also part of the problem.
Set up a system so that it costs you nothing to do a bad thing but possibly wrecks you legally and financially to do the good thing, and people will inevitably do the bad thing. They shouldn't be collecting this information in the first place.
The people who design these policies are incapable of actually building things that work. They are not the intelligent, competent leaders exercising a careful craft that they like to pretend they are.
They keep going after age verification, online ID, central bank digital currencies, etc - keep this incident in mind. The people who implement and write these policies are morons. They don't game things out and plan for redundancy or resiliency. They don't take into account bad faith actors. They don't account for deliberate exploitation of the system.
They most likely weren't allowed to keep it past the verification per GDPR art.5. Once the passport has been verified for whatever purpose they needed it ("age verified to be > 18yo on 2026-06-12" or "identity verified to be XXXX YYYY"), there is no legitimate use for the passport photo and details anymore, and they should delete it.
You can compare this in a certain way to file hashes. A successful verification with a predefined minimum level of credibility can be encrypted to a special string for later being used, if a service needs to verify the person again. It doesn't matter then, that the original passport images or video ident has been deleted the second after id verification has been completed.
The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept".
^1: https://www.edpb.europa.eu/system/files/documents/2025-04/ed..., number 36.
Right, and keeping old passports used for verification should cause an audit to fail.
If there is a law about verifying buyers, how else are they going to pass that audit?
There's also laws mandating secure systems design.
Separately there's no _need_ to store the original document if the verification system is sound (and audit real, not some phony crap like in some of the scandals posted here on HN).
How else do you expect it to work? ‘Honest, we checked’ checkboxes?
The auditor can act as a customer and validate whether phony credentials are rejected.
At least - as you mention - until the rules catch up and there is some sort of one way hashing/signing or something possible, which for most of these industries is probably decades away (if ever). Most of these industries struggle with photocopies at this point.
If the government-affiliated agency decides to check, they can.
But back to my original statement - unless they're explicitly mandated to keep it longer, they are forbidden from doing so, and their DPO would know it.