惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
腾讯CDC
Vercel News
Vercel News
Recent Announcements
Recent Announcements
博客园 - Franky
小众软件
小众软件
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Cloudflare Blog
宝玉的分享
宝玉的分享
I
InfoQ
博客园 - 聂微东
Jina AI
Jina AI
J
Java Code Geeks
V
V2EX
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
L
LangChain Blog
T
The Blog of Author Tim Ferriss
量子位

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
China - Faces and Vehicle License Plates Leaked | iubenda
2022-09-07 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

Another large-scale data breach reveals new vulnerabilities in China’s extensive surveillance state.

Faces and Vehicle License Plates Leaked

Although its contents may not seem noteworthy for China, where state monitoring is widespread and facial recognition is commonplace, its scale is astounding. A significant data leak of 1 billion records from a Shanghai police database in June was the largest known data security breach of the year by magnitude. At its peak, the database had over 800 million records. Both times, it’s likely that human error led to the data being accidentally released.

A tech company called Xinai Electronics is the owner of the leaked data. The business creates systems for restricting access to buildings, parking lots, construction sites, and workplaces in China for both people and cars. On its website, the company promotes the use of facial recognition for a variety of uses beyond building access, for example, personnel management, such as payroll, monitoring employee attendance and performance, and its cloud-based vehicle license plate recognition system, which enables users to pay for parking in unattended garages that are managed by staff remotely.

Millions of face prints and license plates have been collected by Xinai through a massive network of cameras, and according to the company’s website, the data is “securely stored” on its servers.

Anurag Sen, a security researcher, discovered the organization’s exposed database on a Chinese server hosted by Alibaba.

Sen claimed that the database had hundreds of millions of records. But neither the database nor the hosted image files had password protection, so anyone with the right information could access them via a web browser.

In addition to other personal information like the person’s name, age, sex, and resident ID numbers. The database also included links to high-resolution photos of faces, including those of construction workers entering construction sites and office visitors checking in. The database also contained information on vehicles’ license plates captured by Xinai cameras in parking lots, driveways, and other office entryways.

The Personal Information Protection Law, China’s first comprehensive data protection law, which is seen as China’s answer to the GDPR privacy regulations in Europe, was passed last year. Its goal is to restrict the amount of data that businesses collect while broadly exempting the police and other governmental organizations that makeup China’s extensive surveillance state.

However, following two significant data breaches in recent months, the Chinese government and IT firms are finding that they are both ill-prepared to protect the enormous amounts of data that their surveillance systems gather.