Feeds

Privacy breach nuked in Canadian passport site

Applicants' intimate details free for the taking

Choosing a cloud hosting partner with confidence

Red-faced Canadian passport officials say they've closed a privacy breach on their website that leaked the personal information of applicants, including their driver's license numbers, birth dates - even whether they owned a gun.

The hole was discovered last week by an Ontario man who found a simple way to cause the Passport Canada site to volunteer information about people he never even met. Altering the URL that was in the address bar of his browser while viewing his own application, he found it was possible to view the applications of others.

Passport officials called Jamie Laning's experience "an isolated anomaly" and insisted their site remained highly secure. But The Globe and Mail, which broke the story on Tuesday, said the website continued to reveal applicants' names, home addresses and emergency contacts, after resuming operation yesterday afternoon. (Story is here.)

"This is precisely the sort of information a bank might ask someone to confirm they are who they claim to be before giving them a mortgage," said Carlisle Adams, a professor specializing in privacy and network security at the University of Ottawa.

Passport Canada's gaffe is the latest example of a large government agency having trouble safeguarding its citizens' personal information. Last month the Chancellor of the Exchequer admitted that Her Majesty's Revenue and Customs lost child benefit records relating to 25 million people. The US Department of Veterans Affairs has also exposed the records of 25.6 million people following the theft of a laptop.

Jamie Laning, the 47-year-old IT worker who discovered the breach, informed passport officials of the breach last week, and the site was temporarily closed through Monday. A Passport Canada representative acknowledged a security problem to The Globe and Mail, but said the outage was caused by different problems.

We'd be interested in hearing from Canadian citizens about whether the breach on the Passport Canada site has, in fact, been fixed. Leave your comments below. ®

Intelligent flash storage arrays

More from The Register

next story
WHY did Sunday Mirror stoop to slurping selfies for smut sting?
Tabloid splashes, MP resigns - but there's a BIG copyright issue here
Spies, avert eyes! Tim Berners-Lee demands a UK digital bill of rights
Lobbies tetchy MPs 'to end indiscriminate online surveillance'
How the FLAC do I tell MP3s from lossless audio?
Can you hear the difference? Can anyone?
Google hits back at 'Dear Rupert' over search dominance claims
Choc Factory sniffs: 'We're not pirate-lovers - also, you publish The Sun'
EU to accuse Ireland of giving Apple an overly peachy tax deal – report
Probe expected to say single-digit rate was unlawful
Inequality increasing? BOLLOCKS! You heard me: 'Screw the 1%'
There's morality and then there's economics ...
While you queued for an iPhone 6, Apple's Cook sold shares worth $35m
Right before the stock took a 3.8% dive amid bent and broken mobe drama
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.