back
219 comments
Leaked data includes:

    Full name
    Birth date
    Birthplace
    Citizenship status
    Nationality
    Passport/ID number
    Passport issue & expiration dates
    Nationally registered gender
    ID photo
    Personal signature
    Parent’s full names
    Fingerprints
    Additional country-specific details (e.g. emergency contact information for UK citizens)
This is bad. IDs shouldn't be stored on your server once you've confirmed the age/identity/whatever of the user.
The law requires the identity records to be kept with copies of each work containing explicit depictions sufficient to match the performer to the identification. If you do online real-time live streaming of depictions, how do you do that if they aren't on the same system?
AFAIK (IANAL) this contradicts laws such as California's adult entertainment laws. I believe the studio is required to maintain records of the cast. (Thanks to the Traci Lords incident).

And given that this is a site paying their webcammers, the other information is presumably back-up identification in case of account recovery or some such.

It's funny that there are a tons of requirements before you are allowed to store credit cards (PCI DSS), which are easily changed and expire anyway, yet none for storing ID photo or other highly sensitive personal data, much of which is unchangeable (like date of birth).

As always, the powerful (banks) can rig the system in their favor.

This is very serious actually, short of addresses also being added I can't think of a worse situation to be in if you were a model.
This is the way they should do it: https://www.verygoodsecurity.com/

Keep the data encrypted and only allow KYC providers access to the decryption keys.

And apparently pictures of credit cards for some reason.
Parent’s full names? That seems weird
FYI: all cam model websites do this and hold onto it. i.e manyivds, mfc, onlyfans, etc.
generally I agree, but I can understand why they did it. If they're accused of allowing underage models they'll be in a spot they definitely don't want to be in.

There was a case years ago of a man who was on trial for child porn. It took the actress physically coming into the courtroom and showing her ID before the case was dropped.

It's just a really scary place to be in terms of society and the law, so I can understand making the decision to do the 'wrong' thing in this instance.

These include scans of documents that prove the model's age, things like ID cards, birth certificates, and passport scans. Also included were performer release forms and profile information. This is particularly bad given the sensitive nature of the work and the need to maintain the personal privacy and safety of the X-rated web stars. There is also the risk that, as the records from virtually every occupied part of the world, that LGBTQ+ performers in some areas could be at risk of persecution.
Persecution is putting it mildly. It could put people at physical risk of harm.
Another reason to never send IDs "required" by many companies today .. using email or their app
What makes it even worse, is that this is an industry where un-sane individuals frequently get obsessed / fall in love / stalk the models in question very frequently due to the context in which they work. This leak is going to be life-ruining (and potentially dangerous) for many of them.
Yes. I don’t say this lightly: this is the sort of data that if used the wrong way could wind up with someone being killed. This is a situation where the real-life consequences could literally be death.
Obsessed simps who donate thousands upon thousands of dollars are very dangerous. Even on Twitch these people are a sight to behold.
"We were able to access Pussycash’s S3 bucket because it was completely unsecured and unencrypted. Using a web browser, the team could access all files hosted on the database."

This is absurd

This is terrible. The sensitive nature of this information could have significantly impact on the victims. This is the type of data, that coupled with the sensitive nature of the sites content, could pose significant safety risks — and I don’t say that lightly.

Moreover, the jurisdiction of this place (Andorra), leaves a lot of open questions about what (if any) recourse there could be either from a punitive or criminal standpoint.

This is terrible.

It's amazing how often you find companies/individuals asking for personal information/documents over email and SMS. I've been on the hunt for a flat for the last few weeks. Being in NZ, I used the TradeMe platform where many of the landlords/listing owners asked for Passport scans, employment letters, bank statements etc via email before evening looking at the property. No mention of how that information will be secured and how it will be discarded.

They've likely received hundreds of messages with personal information, all stored in Gmail inboxes. What happens to them after they're sighted - I wouldn't know.

I don't know what the 'adult' industry is like but I suspect there's some sites that verify their models by similar email/SMS mediums.

A friend of mine who did a few movies in the 2000s told me she felt much more violated by the paperwork for the required record keeping than she did having sex on camera.
It’s there for very good reason- to ensure that the models are adults.
Predictions, bets and opinions on what punishment will PussyCash/ImLive be facing? A fine proportional to their earnings?
Absolutely zero, considering their business is already shady as fuck powered by spammers spamming the affiliate links, nasty ads and no doubt lots of dark patterns. If the law cared they would already be in trouble for something else.

Besides that, Equifax got away with a slap on the wrist even though it was a highly publicised case.

This case will have zero attention outside of HN and the likes so I'd be very surprised if it even makes it to court.

There's also the issue that bringing the case to court will attract more attention to the leak and potentially force the plaintiffs to state their real details on the record, so while it's definitely unfair to let the website operators go unpunished, maybe leaving the mess alone and hoping the dust settles is the best course of action.

My prediction, a public statement apologising. With 2-1 odds that it will contain : "We value our clients privacy" mentioned at least twice.
Nothing. The jurisdiction this place operates in is fuzzy at best and I feel confident the owners will just abscond and go off to the next place.

Plus, the people who are the victims here are not the people who typically have the money to pursue this (and may live in countries where pursuing anything would cause more harm).

Marginalized victims, opaque legal jurisdiction/laws, and little/no incentive to go after the owners means that I feel confident absolutely nothing will happen.

Think about it: Equifax doxxed more than half the US population and got away with a slap on the wrist and was rewarded with even more government contracts.

Given the requirements to keep this data, I'd be curious what data-model would make sense to prevent leaking it. I honestly can't think of anything practical that's better than "encrypt at rest, better hygiene with database credentials". After all, the webserver needs the ability to submit this data, and logically people are going to want to be able to review their own data on the web in order to update it.

What do?

Each person's records could be given an ID (say, a UUID) and stored encrypted in a database. Strong access controls over the decryption keys, etc. Then each video gets metadata with the UUIDs of the people in it.

Also it never needs to be updated. Once you've proved you're old enough to legally appear you never need to do so again, at least as long as no time-travel shenanigans are possible.

Most of the information should have never been kept in the first placed. Hell, it never should have touched their servers in the first place
I feel sorry for the girls. All should stay away from the leaked data

Is the website stepping up to take responsibility?

FTA: PussyCash never replied to any of our attempts to contact them regarding the data leak, including their Data Protection Officer. ImLive finally responded to one of our emails, stating that they would take care of it and pass on the information to the PussyCash tech team.
And guys. And others.
This is horrible, and very very dangerous for the people involved.
Alongside the risk of exposing people's private peccadilloes and the danger that presents, there's a huge risk of identity fraud, bank fraud, sim-swapping etc. with all this data.

Particularly when it comes to all the copies of Government Photo IDs (Passports, Drivers licence, etc.)

The models are all legally adults so why would the producers need their parent's full names?
Let's hope nobody gets murdered, injured or raped. This is about as bad as it gets.
This is terrifying for the models. One of the worst leaks to date, surely?
I wish people would stop referring to pornography as "adult".
> They boast 66 million registered members on their webcam chat arena, ImLive, alone.

Let's say each registered user pays $1 a month for access to this one site they run. That's $66 million/month in revenue. Enough to secure data and comply with privacy laws.

Will this leaked data be used by the IRS in the thot audit?
This is another example of why the US urgently needs legislation along the lines of GDPR. I know California’s law took effect on Jan 1.

Does anyone know offhand what the penalty would be if this had been a Californian or EU company?

And this is why I recommend using fake details & IDs when signing up to sensitive services like this. Not an ideal situation and I'm not blaming the victims here, just stating what I would do if I had no choice but to sign up for such a site. Given the life-changing consequences of a leak and the risk of harm (stalkers showing up at home, or being an LGBT performer in a location where the government doesn't approve of that) the consequences of being caught with a fake ID are tame in comparison.

Ideally there should be a way for the websites to fulfil their legal obligations regarding age verification without actually handling any ID data themselves. Maybe a government-provided oAuth style service where you are redirected there, authenticate with the government (no extra risk there, they already have the data) and then they return a signed blob to the website asserting that you are of legal age without actually disclosing any details.