2026-09-18

Passport Leak

Image: Unsplash

The data behind every passport and ID card has been leaked. No one accepts them as valid ID anymore without question. “You'd like to open a bank account? Please come in to our office.”

For this blog I can still draw on notes I took earlier this year during Security (b)log LIVE, during our internal ‘Love for Your Profession’ week. The scenario above was sketched out there too. I sometimes say I get paid to think up doom scenarios – but you all contribute your fair share too…

Let's see whether this is actually a realistic scenario. The Netherlands has the Basisregistratie Personen (the Personal Records Database, kept per municipality). A copy of that data goes to the Rijksdienst voor Identiteitsgegevens (RvIG, the national Identity Data Agency). So yes, all the data you need to produce a passport sits in one place.

That data is included in the passport in two ways: optically and digitally. The first is what you see and can read; the second sits on a chip embedded in the document. That digital data is digitally signed by the government. That guarantees authenticity and means the data can't be altered without it being noticed.

Whether the leaked passport data can actually be used for identity fraud depends on the purpose. A criminal with the right resources and enough dedication will undoubtedly manage to produce a document convincing enough to, say, rent a car – especially if a scan of the original document has also leaked. Checks for that kind of application tend to be fairly superficial: no one looks at the security features of the document.

For more serious applications, such as opening a bank account online, the data on the chip is checked. That happens via Near Field Communication (NFC). The bank's app reads the chip directly when you hold your phone against the document. As the name NFC suggests, this only works over a (very) short distance. As mentioned, the data on the chip is digitally signed. A forged chip lacks that signature, so the document fails the check. That effectively debunks the scenario sketched above. But there is still “room” for abuse wherever checks rely on the naked eye alone.

Could you board a plane with such a forged document? That depends on where you're headed. Within most of Europe (the Schengen countries) you don't pass through passport control at all; for flights outside that area, the Royal Marechaussee (the Dutch military police responsible for border control) does check every traveller's passport. They do that with their own eyes, backed up by an optical scanner that reads the two lines of text at the bottom of the document and checks the security features. If you go through an automated gate instead of a desk, the chip gets read, and the gates also use facial recognition. The odds of someone slipping through with a fake Dutch passport are probably not that high.

After that you reach the gate, where your boarding pass is scanned and ground staff give your travel document a quick glance. I suspect they're mainly checking whether the name on both documents matches and whether the photo looks enough like you. The odds of getting away with a forged document there seem considerably higher to me.

Would the Netherlands grind to a halt if the RvIG had a data breach? Probably not immediately, but it would cause a lot of hassle – both for (legitimate) passport holders and for the authorities doing the checking: the former group would feel distrusted, the latter would need to deploy extra capacity for more thorough checks. At least in places where correctly establishing someone's identity actually matters. Fortunately, they know that all too well over at the RvIG.

 

And in the big bad world…

2026-09-04

Getting hosed

Photo: author

Summer is my favourite time of year to gather stories for this blog. You travel to other countries and get a taste of other cultures. Those cultures aren't limited to good food, beautiful buildings, and friendly people. That's why a summer rarely goes by without me picking up something useful.

Take this so-called fire hose. I found it quite remarkable – a fire hose at a holiday home; I hadn't seen that before. Curious, I opened the fire hose cabinet. Inside was a kit: a few metres of garden hose tied together, a nozzle, and a couple of clips.

I can picture it already. A pan catches fire. You remember that red cabinet, sprint over, and discover that the “fire hose” is held together with three sturdy plastic straps. You dash back into the now-burning house to grab a knife or scissors. Coughing from the smoke, you manage to unroll the hose. You push the nozzle into one end and stare forlornly at the other. Your hands search in vain through the fire-engine-red cabinet for a coupling to connect the hose to the tap. Meanwhile, this fire cabinet is the only thing left of your holiday home. It all took too long. And around these parts, the fire brigade generally has a somewhat longer response time than back home, I'd imagine. [A quick aside: never attempt to put out a pan of oil or fat with water.]

Someone bought the product but neglected to install it. The IT equivalent of that is not (properly) configuring a product – that is, not adjusting the settings to your needs. Or to the organisation's security policies. That can result in every network port being wide open (creating a huge attack surface), or data ending up unchecked in the cloud, or a product never receiving updates, to sketch just a few doom scenarios.

Ah, that's something for IT people, I hear you think. That doesn't concern me as an ordinary user. But that's not entirely true – or maybe not true at all. Because as an end user, you too sometimes make choices that can affect the organisation. Because while a lot is locked down, plenty is still possible. And “if something can be done” doesn't mean “it's allowed.” You might be able to install an app for work use, but are you allowed to? And if you are, can you, for instance, choose between storing data in the cloud or locally on the device? And what's permitted in which situation? None of that is straightforward.

Regulations are constantly evolving, and sometimes they simply don't exist yet – for instance with new technology. We saw that with the rise of the cloud, and it happened again when consumer AI entered the stage. That obviously makes things extra tricky. For an organisation, it's then important that not everyone just does their own thing, because that gets messy (to avoid the word chaotic).

At home, too, it's worth taking a look at your devices' settings. Change a factory-set password to one of your own (which you naturally store in your password manager). Can the thing do something you never use? Do you, for example, have a NAS (a network drive) that's reachable from outside but that you never actually use that way? Then check whether that function is switched off. Because the fewer openings you offer hackers, the sooner they'll go looking for another victim.

 

And in the big bad world…

 

Passport Leak

Image: Unsplash The data behind every passport and ID card has been leaked. No one accepts them as valid ID anymore without question. “You...