Email us! Subscribe to Liquidmatrix!

Massive Privacy Breach In Canada’s Passport Site

passport.jpg

Holy oops! Passport Canada’s website was breached last week due to a flaw in the site.

From Globe & Mail:

A security flaw in Passport Canada’s website has allowed easy access to the personal information - including social insurance numbers, dates of birth and driver’s licence numbers - of people applying for new passports.

The breach was discovered last week by an Ontario man completing his own passport application. He found he could easily view the applications of others by altering one character in the Internet address displayed by his Web browser.

“I was expecting the site to tell me that I couldn’t do that,” said Jamie Laning of Huntsville. “I’m just curious about these things so I tried it, and boom, there was somebody else’s name and somebody else’s data.”

That data included social insurance numbers, driver’s licence numbers and addresses.

And to think…I was going to update mine this weekend. Yipes.

Canadian law does not require organizations to disclose when they’ve suffered security breaches. In the United States the majority of states have enacted legislation requiring organizations to disclose security breaches within a specified period of time.

I would say that time is up. Time for some disclosure discussions.

Read on.

Article Link

Tags: , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • How to Deal with a Security Breach
  • Is it OK for Google to Own Us?
  • Privacy Breach Companies ‘Must Be Named’
  • Federal Watchdog Wants More Privacy Powers
  • Trend Micro Nailed As Part Of Massive Web Hack
  • Leave a Comment