Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Having happily used AirBNB in the past, I recently tried to book a stay in Toronto. They wanted a full photo of my passport or driving license to complete the boking. Looking a little deeper, not only did they outsource the processing, but when others had questioned them about it the response seemed a little noncomittal.

With leaks and lapses of judgment ocurring daily I feel like it would be an identity fraud ticking timebomb to use AirBNB and other services like it, especially given the attitude they seem to attach to security. I know others on HN feel diferently.

I took my business elsewhere.



> I know others on HN feel diferently.

Remember a lot of the people on HN work at these firms, and therefore defend them. For example, I've noticed if I say anything negative about Facebook, the up/down votes on my comments swing wildly; initially starting fairly positive (say +30) then back down to slightly negative (say -2). The voting pattern is certainly intriguing and unusual. Basically, what I'm trying to say is, if you feel something about a particular tech company, HN may not always be the best place to validate that opinion as bias does exist. Stick with your gut (as you have done)!


Prime example why we need laws that would forbid companies to do verification using your passport and other documents containing personal information.


Identity verification using passports is not the problem. Identity verification by exclusively looking at pictures of passports is the problem.

The point of a passport is to bind your legal identity (name, place you live, dob) to characteristics of your body (signature, face), so that people can then use it to verify that the body standing in front of them is for legal purposes the legal entity described in the passport. The point is that in order to check the identity, you compare the picture to the face, you compare the signature on the passport to the signature they write with you watching, so you then can be reasonably sure they are the person described in the passport.

What happens nowadays is that people check whether someone can send them a picture of a passport, and if they can, then that is considered proof that the entity that sent the picture obviously necessarily must be the person described by the passport depicted in that picture. That's just completely broken logic and should simply not have any legal weight at all.

It's as if your web browser checked that the server sends a certificate that matches the requested host name, but didn't check any signatures or anything to ensure they are indeed talking to the owner of that certificate and its corresponding secret key.


> Identity verification using passports is not the problem. Identity verification by exclusively looking at pictures of passports is the problem.

I think another significant part of the problem is the fact that sending someone a picture of your passport means that they, and anyone with whom they choose to share it, thereafter permanently have a picture of your passport. For example, I would have no problem if I were somehow able to audit these companies' use of the passport data and to make sure it was used responsibly and deleted after use. (I would compare to the way that I see everything a customs officer does with my passport, but of course that's not really true, since I have no idea what processing is going on on their computer. However, whatever they've got on the computer comes from access to government databases, to which (hopefully!) private companies don't have access.)


Most modern passports have the ability to sign things with a secret key.

Most phones have NFC to talk to passports.

If only websites said 'sign this text with your passport to prove who you are', that would be excellent security.

Sadly, I think the barrier to this today is iphones lackluster NFC support and androids browsers which don't let you talk NFC directly (hence requiring a special app).


> Most modern passports have the ability to sign things with a secret key.

Really? How? I have a fairly recent US passport, and the ability to do it is not clear. (Genuinely curious—this sounds like a neat thing to be able to do.)


The NFC chip in the passport (the wire loop antenna on the page with your photo on) has a bunch of commands you can send it. Only passports made in the last 5 years or so have this. Old passports are paper only and have no such smartness...

Hook up an NFC debugger app on an android phone and put your passport next to the phone and you can send it commands.

Different countries passports vary, and take different commands etc.


Except it's not, because it makes a black box the arbiter of legal obligations, and judges get the role of signing off on whatever the black box says.


“Prove you are who you say you are by sending us your bank password. Oh, and we’ll keep it on file indefinitely.”


It is rather easy to photoshop and scan a passport. All you would have to do is get a random scan of a passport from your desired country, import the desired photo, print it and scan it a couple times and you have a new id as far as Airbnb is concerned. I highly doubt the outsourced workers checking it would care. There were quite a few driver license templates and passport template on demonoid a few years back...


It's going the other direction.

We're accumulating laws that (usually implicitly) requiring companies to do verification using your passport and other documents containing personal information. Online versions of the kinds of rule whereby hotels need a photcopy of your passport.

We are tangentially getting privacy initiatives from a different set of regulators/legislators, but... well... they're not doing a great job.


"Know your customer" anti money-laundering laws are growing more stringent.

In the U.S. the Patriot Act made it even more mandatory:

https://www.pwc.com/gx/en/financial-services/publications/as...


but then how would a company that need to verify your identity before providing you a service do so? I m talking about things such as transferwise.com (or, even airbnb, which, if i were a host, i want to know who i m hosting).


And the best way of verification is obtaining a copy of my passport?


Yup. The surprise request for passport/id is exactly what caused me to delete my Airbnb account and cancel the booking that I had already made without the request for passport/Id.

Airbnb you don’t get to pull this kind of unethical shit.


Airbnb employees not happy with my comment I guess, but it's true. I don't want to have to give you my passport before I can go stay somewhere that I already booked like 6 months ago.


Playing devil's advocate:

Where is the problem? Or, what does a passport or id card contain, which should be kept secret?

Your name? They have that anyway? A passport number? What could be done with it, except verifying that the passport is legit and not stolen? My height? Who cares?

While I really think there's much too much shenanigans, which can be done with an (US) social security number and personal information I just don't see the same issue with identification.

I'm happy, of course, to be educated otherwise.

Disclaimer: i did upload a foto of my passport in ordet to rent an AirBnb in Sapporo.


The use of passport is an example of an attempt to do identity proofing. In the practice of identity management there's a concept of "Identity Assurance Levels" where you have varying levels of validation of a person's identity. If you are interested in this, check out NIST Special Publication 800-63A.

AirBNB is trying to use the passport photo as a way to link you to a real-world identity, cheaply. They are in a sticky situation because their bonkers business model will suffer if customers need to go through intrusive processes. Simultaneously, they need to do something to avoid being held negligent when a fake AirBNB host/guest hurts someone. The problem is that it doesn't really provide assurance of anything other than possession of an image of a passport.

The problem is that it's spewing alot of information that if handled improperly is a high risk for fraudulent use. For example, knowing your citizenship, date, and place of birth makes it trivial to fraudulently obtain your birth certificate. That makes it pretty trivial to do something like obtain a fraudulent driver's license.

There are many ways to do this more effectively and at much lower risk to the customer. For example, you could verify ownership of a bank account with trivial deposits. Or you could mail the customer a token. Or require a notarized document. Or some combination. But the risk to AirBnb of a negative outcome is low, so they push a risk that you may not understand to you.


I just stumbled over your reply right now (a $ short, a day late) and, well:

Thank you very much.

That was instructive, insightful and taught me a lot; namely what the actual problem is.

Sheesh! Sometimes it's really worthwhile to be a bit prissy, but seriously, I learned something from your reply and I really appreciate it.


Well, given an image of an ID uploaded to service A you could obviously use it as credentials to service B; someone else could reupload your ID in order to rent from AirBNB as you.


Thanks & fair enough.

I really prefer a legitimate answer, like yours, as opposed to be voted down for posting a legitimate question.


>"Or, what does a passport or id card contain, which should be kept secret?"

Well for one the passport as a whole can then be used to commit identity fraud or cloned on the black market.


Combined with some othe rpersonal info it can get you registered for the UK online tax portal etc


Either sending someone a picture of a passport is accepted as proof that you are the owner of the depicted passport, or having a picture of a passport is worthless. Choose one, and then explain why sending a picture of a passport to airbnb makes sense and security on their part doesn't matter.


Most Bitcoin exchanges also require id/passport, I assume these checks are also outsourced. Not exactly comfortable to share my passport with a random stranger.


Ultimately, there're competing requirements here: person verification & privacy. The requirements are partly AirBnB solving its own problems (like expensify in this case). Partially (substantially), these are "the man's"requirementsˆ.

If a photo of your passport or whatnot is private information that must be kept secret, or else identity theft... well then it can't be sent to AirBnB en masse. Those two do not (easily) go together. Certainly not if it's AirBnB, uber and twelve other things every year. Mechanical turking the review is bad, but doing it internally is probably just as bad. Lots of people will have access to the docs, copies will be emailed around..

Over the last few years (and ongoing) there's been persistent attempts to regulate and change business norms such that transactions are de-anonymized. A lot of it under the heading of "AML." Even most AML has nothing to do with money laundering. The norms of validating customers for fraud prevention or other reasons are becoming a general business/regulatory norm, boilerplate practices. The specific implementations are half-hazard and often negligent.


I just had a case where I was locked out of an account because their backend couldn't send 2FA auth code to my phone. In order to unlock my account, they wanted me to provide "scanned copy of official ID", I refused.

The basis of my refusal was: If your backend systems cannot send 2FA to my phone because of some unknown reason, why should I trust it to securely store my ID info?

I told them I would rather remain locked out of the account and simply post the entire conversation on twitter for all to see. Within 5 mins she capitulated and suddenly "discovered another way she could unlock". There are numerous things that are sort of scary about that encounter. (Was my ID actually required? Threats to post on twitter change security requirements, etc)


I think we’re on the same page.

Well.. This is inevitable if for internal or external reasons, something on the internet needs to verify your identity. Either (A) they live without this verification (B) we find some way of verifying or (C) every tom dick & harry has a dropbox folder full of people’s "scanned copy of official ID.”

To me, it seems like “verifying people” in this manner is stupid. The whole premise is that there are documents that only I have. By sending the document to you, I show that only I could be me. Using this process widely breaks the premise. I know for a fact that several parties’ employees, contractors and such have scanned copies of my official ID …I sent it to them.


Agree. There is actually a pre-existing, low-tech solution to 90% of these issues: Use a Public Notary to verify identity.

Company sends document with unique barcode to person they are trying to verify. Person takes to local UPS store and has public notary verify that person signing document really is "John Q Smith". Person sends back doc, with notary stamp and recordation number showing licensed person has authenticated.

This way your actual ID never leaves your possession.


That's how public student loan applications in Ontario work. They send you a document with a unique barcode, you go to the post office and prove your identity there. They scan the document and that sends a message to the loan centre that this person was positively identified.


> If a photo of your passport or whatnot is private information that must be kept secret, or else identity theft... well then it can't be sent to AirBnB en masse.

I think the main issue is that it’s not really you, but service providers who get to decide what’s an information that need to be kept secret.

For instance if most banks decide to exclusively use bits of your fingernails to verify you, your fingernails become something you need to keep secret, your personal position be damned.

And the more agencies that decide to use your fingernail bits, the more valuable they get.

For Airbnb, if the practice propagates enough, your photo with your passport in it will become the new way to fake you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: