惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
L
LINUX DO - 最新话题
T
Troy Hunt's Blog
博客园_首页
量子位
Jina AI
Jina AI
S
SegmentFault 最新的问题
IT之家
IT之家
Hacker News - Newest:
Hacker News - Newest: "LLM"
大猫的无限游戏
大猫的无限游戏
N
News | PayPal Newsroom
P
Proofpoint News Feed
Cyberwarzone
Cyberwarzone
S
Securelist
Google Online Security Blog
Google Online Security Blog
P
Privacy International News Feed
博客园 - Franky
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
NISL@THU
NISL@THU
C
Cisco Blogs
V
Vulnerabilities – Threatpost
腾讯CDC
The Hacker News
The Hacker News
K
Kaspersky official blog
C
Cyber Attacks, Cyber Crime and Cyber Security
雷峰网
雷峰网
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Security Archives - TechRepublic
Security Archives - TechRepublic
A
About on SuperTechFans
Webroot Blog
Webroot Blog
The Register - Security
The Register - Security
Scott Helme
Scott Helme
B
Blog
Security Latest
Security Latest
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
W
WeLiveSecurity
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tenable Blog
Blog — PlanetScale
Blog — PlanetScale
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
Schneier on Security

Daring Fireball

Anthropic's Safety Superpower Kennedy Center removes Trump’s name from building — The Washington Post Private Cloud Compute - Apple Developer Statement on the US government directive to suspend access to Fable 5 and Mythos 5 Every Frame Perfect The Talk Show: Live From WWDC 2026 What is the true story behind Apple’s decision not to roll out "Siri AI" in the EU? This decision is Apple’s and Apple’s only. Because absolutely nothing in the DMA prohibits Apple from rolling out… | Thomas REGNIER | 111 条评论 Due to DMA, Siri AI delayed in EU for iOS 27 and iPadOS 27 Steven Spielberg Answers YOUR Questions Sweet Jeebus, MacOS 27 Golden Gate Removes the Dumb Icons From Menu Items WWDC26 — The Small Things - Oneberri Blog Apple WWDC 2026 June 8: Introducing Siri AI and more Apple’s App Store rolls out personalized recommendations Unlock Autonomous AI Agents with auth.md, Michael Grinich | MCP Night: Agent Mode Keynote From the Annals of People Having Knowledge of the Matter, Siri AI Extensions Edition Apple’s WWDC AI demos looked more real after $250M false ad settlement Craig Federighi details Apple’s collaboration with Google for Siri AI in iOS 27 SwiftUI Only Makes It Easy to Develop Bad Apps 60 Minutes Correspondents Lesley Stahl, Bill Whitaker, and the Other Guy Will Stay at Show Trump Can Tear Down Statue of Liberty, Says Trump Lawyer Nieman Journalism Lab: Twitter/X Punishes Accounts That Post Links Regarding Those Rumors of Apple Pursuing an Acquisition of Perplexity ‘The Insider’ Lingon - Peter Borg Apps Chrome is Bad Gemini for macOS - your native AI desktop app Nick Bilton Shits the Bed With Pseudoscience-Laden ‘Could Wearable Computers Be as Harmful as Cigarettes?’ New York Times Column Nick Bilton on an Apple Television Set: ‘It’s Not a Matter of if, It’s a Matter of When.’ Instagram 用户 Scott Pelley Road to WWDC 2026: What’s a developer? Sorry - Not Allowed How People With Meta Glasses Can Secretly Record You Microsoft and OpenAI broke up — now they’re ready to fight CBS Fires Scott Pelley After Pelley Tries Very Hard to Get Fired CBS News Fires Scott Pelley of ‘60 Minutes’ Meta Reportedly Has a Slew of New Smart Glasses Planned for This Year Meta Says Fuck That Metaverse Shit ‘The Metaverse Fever Dream’ Scott Pelley Accuses CBS News Boss of ‘Murdering’ ‘60 Minutes’ Of all the dickovers, the dickover that blueballs you with some first-time buyer incentive. “Sign up and get 10% discount, new accounts only”, the dickover boasts. Never understood why you’d ever penalize returning customers with a dickover, blue-balling them with 10% off teaser Video API for developers | Mux Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked The Talk Show Live From WWDC 2026 exe.dev - ssh exe.dev Take Two Apple introduces Siri AI, a profoundly more capable and personal assistant Apple Intelligence brings powerful AI capabilities into everyday experiences What Apple Knows About AI That Silicon Valley Won't Admit Daniel Jalkut on AI - YouTube What Is a Dickover? If You Take the Weasel Job Then You Must Be the Weasel Who’s Deranged, Exactly? Websites have a new way to spy on visitors: Analyzing their SSD activity Meta launches Instagram, Facebook, and WhatsApp subscriptions, with more to come, including AI plans Halide Mark III We Are Living in Pinocchio’s World Jay Haynes: ‘Apple’s $3 Trillion Valuation’ Thieves Are Texting Threats to Victims of iPhone Theft in London Pipes – WorkOS Docs MLS Wrap-Up⁩, 05/24/26 - Watch the Highlights Why Steve Kerr Stayed With the Warriors Trump Mobile investigating potential exposure of would-be customers’ personal information The Fonts of the U.S. Federal Courts The Ninth Circuit Appeal Ruling in ‘Epic v. Apple’ That Apple Is Seeking to Overturn at the Supreme Court (PDF) Zero Sum Problems Stephen Colbert’s ‘The Late Show’ Finale Apple TV to air first major live pro sports event shot on iPhone 17 Pro Apple seeks Supreme Court review of contempt finding and injunction scope in Epic Games case BBEdit 16 is here! | Bare Bones Software x.com WSJ: ‘Google Unveils New Gemini AI Agent for Personal Tasks’ NYT: ‘Powered by A.I., Google Changes Its Search Box for the First Time in 25 Years’ www.tiktok.com The Metaverse Fever Dream The 13 biggest announcements at Google I/O 2026 Andrej Karpathy (@karpathy) on X Apple Sports expands to more than 90 new countries and regions Jury Rejects Elon Musk’s Claim Against Sam Altman in Unanimous Verdict Define ‘Boom’ Please - YouTube Drata AI Is Technology, Not a Product Greg Brockman Officially Takes Control of OpenAI’s Products in Latest Shakeup ArXiv to Ban Researchers for a Year if They Submit AI Slop Americans Oppose AI Data Centers in Their Area Nextpad++ Santa Clara County sues Meta over alleged scam ads Software as the Product of Obsession Times Voice Why Reddit blocked my daily visit to its mobile website Y Combinator’s Stake in OpenAI Geography is four-dimensional | Derek Sivers Amazon made AI podcasts for products. Civilization had a good run. EU tells Google to open up AI on Android; Google says that's "unwarranted intervention" John Appleseed Social media is turning into a freak show AI, "Humanity", and Dr. Manhattan Syndrome The Hilarious History of 'OK' Three Ways to Get Paid Alaska Permanent Fund
Nearly a million passports and photo IDs were left unprotected on the public internet
Sean Hollister · 2026-06-29 · via Daring Fireball

Typing a few letters and numbers into my web browser, I find myself gaping at the identity documents of complete strangers. The passport of a young woman from Germany. The passport of a man from Spain with glasses resting on his head. The front and back of another man’s driver’s license, a stereotypically goofy expression on his face.

They were all sitting unprotected at public URLs, with no password or access control of any sort. If I sent you a link, you could have looked at someone’s passport.

“We have to do something about it as fast as possible, because people will find this and resell it. It will do damage,” Sammy Azdoufal told me in May.

Azdoufal is the security researcher who used Claude Code to help discover that every DJI Romo robot vacuum cleaner and a million baby monitors and security cameras were embarrassingly easy to hack. This time, he says he discovered over 985,000 photo IDs sitting on the public internet for any half-decent hacker to steal.

If you’ve visited a cannabis club in Spain, Azdoufal says, chances are your photo ID was among them — and possibly your phone number, address, your favorite strains of cannabis, and how much you consumed each month while there. Azdoufal says celebrities are in the database, too, and visitors from all over the world, including 30,000 from the United States. “They have famous people,” says Azdoufal. “People who don’t want everyone to know they smoke weed.”

Here’s a rough summary of the user base that Azdoufal’s automated tool was able to see and the names of some of the clubs:

The image shows that Spain, Italy, France, South Africa, and Britain are the top five nationalities represented, and names various clubs, primarily in Barcelona.

Image: Sammy Azdoufal

It’s not the clubs that didn’t protect these identity documents. An Irish company called Cannabis Club Systems (CCS), formally Nefos Solutions, develops and provides the software these clubs use for sales, accounting, and admissions, including a verification system where receptionists upload your IDs and selfies to Nefos’ cloud.

Traditionally, you’d need to provide a photo ID every time you wanted to get into a club. But with the verification system, the receptionist can pull up your stored identity documents and check if your face matches. There’s also an optional app called PuffPal that lets clubs scan a QR code for faster entry.

But when Azdoufal decompiled that PuffPal app, he explains in his report, he discovered that Nefos had no meaningful level of security. He discovered a secret key for the Stripe payments platform sitting inside the app in plain text. He discovered he could pull up any member’s profile just by changing one number. If those profiles included their phone number, home address, passport, and weed preferences, he now had access to them too.

And then, he discovered that those passports, drivers licenses, and photo IDs were stored at public URLs as simple as this: https://ccsnubev2.com/v8/images/_{club}/ID/{user_id}-front.jpg

Those clubs were uploading 5,000 new photo IDs with these insecure URLs every day, Azdoufal tells me.

He also found an admin portal accessible via the public internet — and that the cannabis clubs had a trivial level of security on their own accounts, using passwords that could theoretically be cracked in minutes with a modern GPU. Private chat messages between clubs and members through the PuffPal app were also vulnerable.

The good news: Roughly a month after we reached out to Nefos, the company seems to finally be taking meaningful action. The company says it’s shutting down its entire PuffPal system and vulnerable APIs until they can be fixed — in Azdoufal’s latest tests on June 10th, passport images and personal data seem to be secure. Nefos has also informed local authorities and says it will take responsibility to make fixes, pay fines, and tell users what happened.

In a phone interview, Nefos cofounder Andreas Nilsen tells The Verge that he’s in touch with Ireland’s Data Protection Commission (DPC) about the data breach — a fact that DPC spokesperson Evan O’Leary confirmed to us by email. “We have to communicate to everyone that was potentially exposed,” Nilsen tells me, saying he hopes the DPC can show his company how to do that properly. Nilsen claims there’s currently no evidence that any outsider accessed the data other than Azdoufal.

But it took far too long for Nefos to take the threat seriously. It took five days and the threat of a story before the company replied to us, long after Azdoufal reached out. Then, Nefos began by papering over the holes instead of risking business.

I was prepared to write this story at the beginning of June, after Azdoufal told me Nefos had finally locked down the passport images. But on June 4th, I surprised Azdoufal by showing him that his very own passport was online once again, without any protection.

That’s because Nefos had not yet stopped cannabis clubs from using the PuffPal app, and clubs were complaining the locked-down images weren’t showing up the way they used to — so Nefos simply unlocked the images again. While Nilsen claims the images were locked down “70 percent of the time” since Azdoufal and I got in touch, it’s pretty clear that Nefos made a decision to prioritize its customers instead of the threat.

On June 9th, Azdoufal discovered that even though Nefos had locked down the passport images and photo IDs with tokens, everything else in the user profiles was still easily accessible: passport numbers, phone numbers, email addresses, home addresses, everything.

All a hacker had to do was type “curl -X POST https://ccsnubev2.com/v8/api/userProfile.php -d “user_id=[NUMBER]&[CLUB NAME]=test&language=en” into a command line, and the servers would freely give up a ream of personal information. After we brought this to Nefos’ attention, that hole, too, has been closed.

But how could the company be so careless? “I don’t want to put the blame on others because at the end of the day it resides with us,” Nilsen says. But he does point the finger at 9Series, an outsourcing firm he claims was responsible for developing the PuffPal app and creating all the vulnerable APIs it used to pull unprotected data from Nefos’ user database. (9Series did not have a response by publish time.)

Now that PuffPal is down, Nefos is emailing every club to let them know their members won’t be able to use those QR codes for entry — but they can still pull up IDs from Nefos’ servers after scanning a member’s RFID card or typing in their phone number, among other examples.

Nilsen claims his company will not simply relaunch unsecured PuffPal if the clubs ask. “We’re going to tell them we can’t,” he says. “We will make sure, after this debacle, that this is verified by an independent security researcher and guarantee that this is 100 percent secure.” He says Nefos is parting ways with 9Series and hopes to have a new app within a few months.

Nilsen says he’s aware that under EU law, his company legally had to disclose the breach within 72 hours or pay significant fines, something the company didn’t do. “I’m sure we’ll get whatever kind of penalty there is,” Nilsen says.

Just last month, a website called the UK Visa Portal similarly exposed at least 100,000 passports to anyone who could guess a URL. Let’s hope this is a wakeup call.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

  • Sean Hollister