Full name
Birth date
Birthplace
Citizenship status
Nationality
Passport/ID number
Passport issue & expiration dates
Nationally registered gender
ID photo
Personal signature
Parent’s full names
Fingerprints
Additional country-specific details (e.g. emergency contact information for UK citizens)
This is bad. IDs shouldn't be stored on your server once you've confirmed the age/identity/whatever of the user.And given that this is a site paying their webcammers, the other information is presumably back-up identification in case of account recovery or some such.
As always, the powerful (banks) can rig the system in their favor.
Keep the data encrypted and only allow KYC providers access to the decryption keys.
There was a case years ago of a man who was on trial for child porn. It took the actress physically coming into the courtroom and showing her ID before the case was dropped.
It's just a really scary place to be in terms of society and the law, so I can understand making the decision to do the 'wrong' thing in this instance.
This is absurd
Moreover, the jurisdiction of this place (Andorra), leaves a lot of open questions about what (if any) recourse there could be either from a punitive or criminal standpoint.
This is terrible.
They've likely received hundreds of messages with personal information, all stored in Gmail inboxes. What happens to them after they're sighted - I wouldn't know.
I don't know what the 'adult' industry is like but I suspect there's some sites that verify their models by similar email/SMS mediums.
Besides that, Equifax got away with a slap on the wrist even though it was a highly publicised case.
This case will have zero attention outside of HN and the likes so I'd be very surprised if it even makes it to court.
There's also the issue that bringing the case to court will attract more attention to the leak and potentially force the plaintiffs to state their real details on the record, so while it's definitely unfair to let the website operators go unpunished, maybe leaving the mess alone and hoping the dust settles is the best course of action.
Plus, the people who are the victims here are not the people who typically have the money to pursue this (and may live in countries where pursuing anything would cause more harm).
Marginalized victims, opaque legal jurisdiction/laws, and little/no incentive to go after the owners means that I feel confident absolutely nothing will happen.
Think about it: Equifax doxxed more than half the US population and got away with a slap on the wrist and was rewarded with even more government contracts.
What do?
Also it never needs to be updated. Once you've proved you're old enough to legally appear you never need to do so again, at least as long as no time-travel shenanigans are possible.
Is the website stepping up to take responsibility?
Particularly when it comes to all the copies of Government Photo IDs (Passports, Drivers licence, etc.)
Let's say each registered user pays $1 a month for access to this one site they run. That's $66 million/month in revenue. Enough to secure data and comply with privacy laws.
Does anyone know offhand what the penalty would be if this had been a Californian or EU company?
Ideally there should be a way for the websites to fulfil their legal obligations regarding age verification without actually handling any ID data themselves. Maybe a government-provided oAuth style service where you are redirected there, authenticate with the government (no extra risk there, they already have the data) and then they return a signed blob to the website asserting that you are of legal age without actually disclosing any details.