Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's a law forbidding storage beyond necessary minimum and law punishing such behaviour unless another law necessitated storage of the original document in the unsecured, unencrypted form. Doubtful.

There's also laws mandating secure systems design.

Separately there's no _need_ to store the original document if the verification system is sound (and audit real, not some phony crap like in some of the scandals posted here on HN).



If you need to prove you sold to real people, storing their credentials is a necessary thing, for as long as your need to prove that. At least with the way things currently are.

How else do you expect it to work? ‘Honest, we checked’ checkboxes?


If the credentials are stored for some period of time, then an inspection will reveal those stored credentials within the preservation window. Unannounced inspections will then show with high certainty a legitimate validation process.

The auditor can act as a customer and validate whether phony credentials are rejected.


Thanks for agreeing with me?


I thought I was elaborating on how to minimize exposure. If this is just what you meant, then sure!


Yeah, my point is that there is a significant exposure they are required to have, if they need to be able to be audited and have to actually prove they are dealing with real people.

At least - as you mention - until the rules catch up and there is some sort of one way hashing/signing or something possible, which for most of these industries is probably decades away (if ever). Most of these industries struggle with photocopies at this point.


You can store for example ID type and serial number AND hash of the personal information.

If the government-affiliated agency decides to check, they can.

But back to my original statement - unless they're explicitly mandated to keep it longer, they are forbidden from doing so, and their DPO would know it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: