Latest / Elon Musk Podcast / Tabiq hotel leaks a million passports
Transcript
- 0:00The Tabik Hotel check in system, maintained by a Japan based
- 0:03startup called Recrea, left an Amazon cloud storage bucket
- 0:07completely open. It exposed over 1,000,000
- 0:11customer passports, driver's licenses and facial recognition
- 0:15selfies directly to the Internet.
- 0:17And it was not a sophisticated breach.
- 0:19I mean, no malware, no advanced persistent threat, no zero day
- 0:23exploit. They just left it publicly
- 0:25accessible without a password. Right, the bucket name was
- 0:28simply. Tabik So anyone with a standard
- 0:31web browser who guessed or, you know, stumbled upon that word
- 0:34could type it in and view the entire database.
- 0:36No authentication required at all, you just needed the URL.
- 0:39Correct, which forces a very specific question about our own
- 0:43habits and the systems we trust. We physically hand over our most
- 0:46sensitive identification documents to hotel front desks
- 0:50or automated kiosks without a second thought.
- 0:52Yeah, we do it all the time. Right.
- 0:54But why is the hospitality industry so exceptionally
- 0:56vulnerable to losing that data? And why do simple
- 0:59misconfigurations like an open bucket continue to happen?
- 1:02Well, to get to the bottom of that vulnerability, we have to
- 1:04look at the financial reality driving the theft of these
- 1:07specific documents. On dark web marketplaces,
- 1:11identification documents command incredibly high prices.
- 1:14How high are we talking? A registered European Union
- 1:17biometric passport sells for around $4500, a Maltese passport
- 1:22goes for 3500, AUK passport fetches 2500 and AUS passport is
- 1:28priced around 1680 dollars. The price disparity is
- 1:32interesting there. An EU passport offers freedom of
- 1:35movement across dozens of countries, Which likely inflates
- 1:39its value on those secondary markets compared to AUS
- 1:42passport. Yeah, it makes sense.
- 1:43But what is a malicious actor actually doing with a passport
- 1:46scan or a passport number? We generally think of passports
- 1:49purely as travel documents. If someone isn't trying to
- 1:52physically board an international flight in your
- 1:54name, the utility of a digital scan seems kind of limited.
- 1:58So passports are foundational documents.
- 2:00They act as the root of your verified identity.
- 2:02Criminals use them to bypass secondary verifications to
- 2:05access your existing financial accounts.
- 2:07Like if you get locked out of your bank.
- 2:08Exactly. If a bank detects suspicious
- 2:11activity, they might ask for a photo ID to verify your
- 2:14identity. The criminal can use the scanned
- 2:17passport to bypass that check, take over your account, or add
- 2:20unauthorized users to it. They also use the data to open
- 2:24entirely new fraudulent accounts.
- 2:26They apply for healthcare, unemployment and other
- 2:29government benefits using your foundational identity.
- 2:32So they use the passport to prove they are you to people who
- 2:35have never actually met you. Exactly.
- 2:38Or they construct A synthetic identity.
- 2:40They take the real personal information from your passport,
- 2:43your valid document number, your birth date, your exact legal
- 2:47name, and they blend it with fabricated data.
- 2:50Like a newly generated address or a different phone number.
- 2:52Right, they create a completely new ghost pedophile, and because
- 2:56the core foundational document is valid, it passes initial
- 3:00automated checks allowing this ghost profile to apply for
- 3:03credit cards or loans. But modern passports have built
- 3:06in biometrics designed to prevent exactly this type of
- 3:09fraud. If you look at the cover of AUS
- 3:11Passport issued in the last decade, there is a rectangular
- 3:14icon with a circle inside it. Yeah, the chip symbol.
- 3:18Right. That symbol indicates the
- 3:19presence of a biometric chip embedded in the passport cover.
- 3:23That chip holds a cryptographic signature and a digital copy of
- 3:27your photograph. Custom systems and airports rely
- 3:30on that chip. So if all a criminal has is a
- 3:33scanned image of the document from a cloud bucket, they don't
- 3:36have the cryptographic chip. How are they bypassing those
- 3:39biometric protections? They use a technique called
- 3:42morphing. The bad actors take the photo
- 3:45from the stolen passport scan and use image editing software
- 3:48to seamlessly blend their own face with the victim's face.
- 3:51They combine the two faces, yes. They align the eyes, the nose,
- 3:55the mouth and create an amalgamation.
- 3:57They then put that morphed photo onto a forged physical document.
- 4:02Does that actually work on scanners?
- 4:04It does. Because the facial features are
- 4:06mathematically blended, it can actually fool basic biometric
- 4:10optical scanners. The scanner reads the geometry
- 4:13of the face, and because the criminal's geometry is partially
- 4:16present in the image, it registers as a match.
- 4:18It also easily passes a simple visual check from a human guard.
- 4:23The criminal uses their real face for the live in person
- 4:26check, but the accompanying photo on their forged document
- 4:30has been doctored just enough to look like them while still
- 4:33retaining enough of the original victims features to match the
- 4:37stolen data. Well, that makes the facial
- 4:39recognition selfies that were included in the Tabic leak
- 4:42exceptionally valuable. I mean, the leak didn't just
- 4:44contain the flat scan of the passport, it contained the live
- 4:48verification selfie the person took when shooting into the
- 4:50hotel. That's right.
- 4:51The attackers have the official document and the live
- 4:54verification photo right next to it, giving them perfect
- 4:57reference material for the morphing process.
- 4:59There is an additional threat specific to travellers, too,
- 5:03beyond just financial fraud. The Department of Homeland
- 5:05Security maintains a public online tool that tracks
- 5:08international travel history. Oh right, I've used that.
- 5:11It is meant for legitimate travellers to look up their own
- 5:14arrival and departure records, but by inputting a full name, a
- 5:18birthday and a passport number, which are, you know, all data
- 5:21points perfectly packaged together in the Tabak leak,
- 5:25anyone can query that database. So they can map a victim's exact
- 5:29travel habits. Down to the day.
- 5:31Criminals use that travel data to target specific individuals,
- 5:36like if they observe through that tool that you are the type
- 5:40of person who travels infrequently.
- 5:42Say you take one international trip every five years and
- 5:45otherwise keep your passport locked in a drawer.
- 5:47You become an ideal target. Because you won't notice.
- 5:50Exactly. It drastically reduces the
- 5:52chances that you will notice the fraud quickly.
- 5:55If they steal the identity of someone who travels weekly for
- 5:57business, that person will realize their passport has been
- 6:00compromised almost immediately. Right the first time they go
- 6:03through security. But targeting an infrequent
- 6:05traveler gives the criminal months or even years to operate
- 6:09under that identity before the victim ever tries to use their
- 6:12passport again and discovers the issue.
- 6:14Moving from the black market value of the data to exactly
- 6:17where it is stored brings us to the central nervous system of a
- 6:21modern hotel. The entire operation revolves
- 6:24around the property Management system, or PMS. The hub for
- 6:27everything. Exactly.
- 6:29The PMS is the core hub. It connects the reservation
- 6:32system, the point of sale terminals at the hotel, bar and
- 6:35restaurant, the guest Wi-Fi networks, and the electronic
- 6:39door locks on the rooms. When you hand your passport over
- 6:42at the front desk, the scan goes straight into the PMS. You have
- 6:46to look at the physical environment of a hotel to
- 6:48understand the systemic weakness of that setup.
- 6:51The hospitality industry is characterized by high employee
- 6:54turnover and a massive web of interconnected third party
- 6:58vendors. Very true.
- 6:59The front desk employee checking you in today might be entirely
- 7:02new to the job. They might have minimal security
- 7:04training, yet they are interacting with a terminal that
- 7:07is networked into millions of sensitive financial and
- 7:10biometric records. They are the gatekeepers to the
- 7:12PMS. The hotel's network is basically a building with 1000
- 7:16doors, and third party vendors are constantly walking in and
- 7:20out of them. You have one vendor managing the
- 7:22Wi-Fi network, a completely different vendor handling the
- 7:24online booking engine, and another vendor supplying the
- 7:27software for the electronic door locks.
- 7:29And they all need access. Every single one of those
- 7:32vendors requires a connection into the PMS to function.
- 7:35If any one of those vendors has weak security, the entire hotel
- 7:39network is exposed. The integration of smart room
- 7:42controls and automated check in kiosks has expanded that attack
- 7:45surface even further. A kiosk scanning your face in
- 7:48the lobby is just another endpoint talking directly to the
- 7:51PMS, right? And Tabik is just one instance
- 7:54of a much larger industry problem.
- 7:56If you look at the Marriott breach, an unauthorized party
- 8:00accessed the Starwood reservation database and
- 8:02compromised the information of 500 million guests. 500 million.
- 8:07Yes, hackers were inside the system for years before they
- 8:10were detected, siphoning off passport numbers, travel details
- 8:13and payment cards. Hotel databases have effectively
- 8:16become intelligence gold mines. They hold your payment
- 8:19information, your movement history, your physical location
- 8:22on specific dates, your home address, and your biometric
- 8:26data. They hold a more complete
- 8:28picture of your life than many government databases.
- 8:31The mechanism of the Tabik leak was an unsecured Amazon S3
- 8:35bucket. S3 stands for Simple Storage
- 8:38Service. It is essentially a digital
- 8:40filing cabinet in the cloud where companies store their
- 8:42data. But why doesn't security
- 8:44software immediately flag and lock down a public bucket
- 8:47containing passports? If a hotel or a tech startup is
- 8:51utilizing a cloud environment, they usually have some form of
- 8:54cloud native application protection platform monitoring
- 8:56it. I would think so.
- 8:57A bucket sitting completely open to the Internet, filled with
- 9:00files named like passport scans, should trigger every alarm in
- 9:03the security system. Well, it does trigger alarms,
- 9:05but that creates A phenomenon known as alert fatigue.
- 9:08Recent testing in simulated production environments showed
- 9:11that default security rules for S3 buckets generate a false
- 9:15positive rate of over 80%. An 80% failure rate on the
- 9:19alerts. Yes, an analyst receives an
- 9:22alert about a potentially open bucket.
- 9:24They have to stop what they're doing and investigate.
- 9:27They spend up to 10 minutes triaging that single alert.
- 9:32Because of the false positive rate, a vast portion of their
- 9:35time is wasted investigating completely benign
- 9:38configurations. Why is the false positive rate
- 9:40so high though? Because cloud environments are
- 9:43incredibly complex, a bucket might trigger an alert because
- 9:47it's access control list looks overly permissive at a surface
- 9:50level. But there might be a
- 9:51compensating control in place, like an IP block list applied at
- 9:55the network level, that restricts access only to
- 9:58employees within the corporate office.
- 10:00OK, I see. The security software sees the
- 10:02permissive access list and flags it, but it doesn't recognize the
- 10:05IP block list that actually keeps the data secure.
- 10:08It sees the open door, but it completely misses the 20 foot
- 10:11concrete wall surrounding the building.
- 10:13Exactly. The analysts are buried under so
- 10:16much noise from false positives that they become desensitized.
- 10:19When you are clicking Ignore on hundreds of meaningless alerts
- 10:22every single day, you inevitably miss the genuine exposures like
- 10:25the Tabic bucket. That makes sense.
- 10:27The solution currently being implemented in the industry
- 10:30relies on writing custom context aware detection rules.
- 10:34How do context aware rules differ from the default rules?
- 10:39They consolidate multiple alerts into a single high fidelity
- 10:43signal instead of just flagging a bucket.
- 10:45Because one specific setting looks public, the system checks
- 10:48multiple conditions simultaneously before generating
- 10:51an alert. Like checking the wall in the
- 10:52door. Right.
- 10:54It checks for public access lists, it confirms the lack of
- 10:56any network restrictive conditions like the IP block
- 10:59list, and it scans the actual contents of the bucket for the
- 11:02presence of sensitive data tags. By tying all those specific
- 11:06conditions together, the system only alerts the analysts when
- 11:09all signs point to a true exposure.
- 11:11That seems a lot more efficient. In testing, this approach
- 11:14dropped the false positive rate to 0 and the triage time for an
- 11:17analyst was cut to under a minute.
- 11:20But there is still the human element to consider.
- 11:22Security software can only do so much if the people configuring
- 11:26the cloud storage rely entirely on default settings and actively
- 11:30ignore the overwhelming noise generated by their own defense
- 11:32systems. Very true.
- 11:34If a security team is receiving 1000 alerts a day and 800 of
- 11:38them are false, they eventually stop looking at the dashboard
- 11:41altogether. The software can be fixed, but
- 11:44the organizational culture prioritizing speed over security
- 11:48is harder to patch. And the infrastructure holding
- 11:51all of this up is constantly decaying.
- 11:53It requires continuous attention just to maintain the baseline of
- 11:57security. Yeah, a fourth Linux kernel flaw
- 11:59was discovered recently that allows for stolen SSH host keys.
- 12:04SSH keys are the cryptographic master keys that administrators
- 12:07use to securely log into remote servers.
- 12:10Without those keys you can't access the back end systems.
- 12:12Right, they're the keys to the Kingdom.
- 12:14If a flaw allows an attacker to steal them, they gain full
- 12:17administrative control over the server.
- 12:19The servers running the massive cloud databases we are talking
- 12:22about are largely built on operating systems like Linux.
- 12:25They require constant patching and maintenance to fix flaws
- 12:28like the one affecting the SSH keys.
- 12:30There is a sharp contrast between how much attention goes
- 12:33to consumer facing technology rebrands like Microsoft deciding
- 12:38to rebrand Xbox to an all caps XPOX, while the hidden
- 12:42foundational infrastructure holding our sensitive data rots
- 12:45from the inside out. It really does.
- 12:48The stakes of that infrastructure failing are
- 12:50incredibly high because it processes the information
- 12:53driving our entire society. To illustrate the gravity of the
- 12:57data flowing through these digital platforms, we should
- 12:59look at several socio political events currently circulating
- 13:02online. And we need to explicitly state
- 13:05to the listener right now, we are impartially reporting the
- 13:08following topics strictly to convey the ideas circulating in
- 13:11the source material. We are absolutely not taking any
- 13:14sides or endorsing any viewpoints here.
- 13:16Right, we are just looking at the tech housing them.
- 13:19The political or legal merits are not the focus.
- 13:21We are impartially reporting these events to convey what is
- 13:24circulating without taking sides or endorsing the viewpoints.
- 13:28So here are the events currently circulating on the platforms
- 13:31hosted on this infrastructure. A leaked Pentagon report
- 13:34regarding civilian harm mitigation measures.
- 13:36A lawsuit filed by a Georgia town over an ICE immigration
- 13:40detention center. The Supreme Court rejecting a
- 13:43bid to restore a Virginia congressional map.
- 13:46A Colorado governor commuting the sentence of Kina Peters and
- 13:49a Kansas State court blocking a gender affirming Caribbean.
- 13:53And again stating for clarity, we are impartially reporting
- 13:57those topics strictly to convey the ideas in the source material
- 14:00without taking any sides or endorsing any viewpoints.
- 14:03Just looking at the data. The connection here is that
- 14:05whether a platform is hosting a hotel guests passport scan,
- 14:09internal military reports on mitigation measures, or highly
- 14:12charged legal and political rulings, they are all relying on
- 14:15the exact same vulnerable cloud infrastructure and operating
- 14:18system. If the underlying Linux kernel
- 14:21has a flaw allowing SSH keys to be stolen, the specific nature
- 14:25of the data on the server doesn't matter.
- 14:27The entire system is compromised.
- 14:29The military data is just as exposed as the passport selfie.
- 14:32So what happens to the companies that fail to secure this
- 14:35infrastructure? The General Data Protection
- 14:38Regulation, or GDPR, provides the regulatory hammer in Europe.
- 14:42Under GDPR, fines can reach 20 million, or 4% of a firm's
- 14:46global annual revenue, depending on which number is higher.
- 14:49We have seen some astronomical penalties levied under this
- 14:51regulation since it went into effect.
- 14:53The heaviest penalties are almost entirely against the
- 14:55major tech companies. Meadow was fined 1.2 billion for
- 14:59transferring European Union users data to the United States
- 15:02without proper privacy protections in place.
- 15:04Billion with AB? Yep.
- 15:06Amazon faced a 746,000,000 fine for failing to acquire proper
- 15:11user consent for their targeted advertising systems.
- 15:14TikTok received a 345,000,000 penalty regarding children's
- 15:18privacy, specifically for setting child profiles to public
- 15:21by default and failing to adequately secure their family
- 15:24pairing features. And WhatsApp faced a 225 million
- 15:28fine for failing to provide a lawful basis for processing user
- 15:32data and not being transparent enough about how that data was
- 15:35shared with other Meta companies.
- 15:36The hospitality companies are definitely not immune to this
- 15:39level of enforcement either. Marriott was hit with a 20.45
- 15:43million fine following the start Farwood breach we discussed
- 15:45earlier. British Airways faced a 22.4
- 15:48million penalty after hackers compromised their systems and
- 15:52directed users to a fake website, harvesting the payment
- 15:55data and personal information of over 400,000 customers.
- 15:59The law applies to everyone processing data, regardless of
- 16:03their size or sector. The enforcement actions actually
- 16:05detail how even very small entities are penalized for non
- 16:09compliance. It is not just the multi billion
- 16:12dollar tech giants. Like who?
- 16:14A kebab shop in Austria received a 1500 fine because they had an
- 16:18insufficient legal basis for their data processing.
- 16:21A primary school received A6000 wellard penalty for uploading a
- 16:25video of children to YouTube without acquiring the necessary
- 16:28parental consent. But you have to question the
- 16:30actual efficacy of these fines against massive corporations.
- 16:33I mean, does a 20 million fine actually change the behavior of
- 16:36a multinational hotel chain? That's the real question.
- 16:39When a corporation brings in 10s of billions of dollars in
- 16:42revenue every single year, a €20 million fine simply becomes a
- 16:47line item in their annual budget.
- 16:49It becomes the standard cost of doing business in the digital
- 16:51age, rather than a severe deterrent that forces a total
- 16:56ground up overhaul of their security practices.
- 16:59That shifts the burden of defense entirely.
- 17:01If the regulatory fines aren't enough to force perfect
- 17:04security, we have to look at what can actually be done
- 17:07internally by these companies to stop the bleeding on the
- 17:11corporate side, security guidelines recommend
- 17:13implementing a zero trust architecture, strict network
- 17:16segmentation, and data tokenization within the property
- 17:19management systems. Network segmentation is crucial.
- 17:22Think of segmentation like a submarine.
- 17:24OK, if one compartment of a submarine is breached and starts
- 17:27taking on water, you seal the bulkheads.
- 17:30You lock that compartment down to the water can't spread and
- 17:32the whole ship doesn't sink. That makes sense.
- 17:35Right now, many hotels are operating like a giant hollow
- 17:38cruise ship. Once a hacker gets inside the
- 17:40system, maybe by compromising a weak password on a vendor's
- 17:44Wi-Fi portal, they can walk right through the entire network
- 17:47and access the reservation database.
- 17:50There are no bulkheads. Network segmentation forces
- 17:53strict boundaries between systems.
- 17:55Tokenization is another really effective tool.
- 17:57It involves taking a guest's credit card number or their
- 18:00passport number and replacing it with a randomly generated token.
- 18:04How does that work in practice? Think about handing your coat to
- 18:08a coat check. You give them your actual coat,
- 18:10which has real value. They give you back a small paper
- 18:13ticket with a number on it. That ticket is useless to anyone
- 18:16else, right? If a thief robs the coat check
- 18:18attendant and steals all the tickets, they don't have the
- 18:20coats. In a property management system,
- 18:23the passport number is the coat, the token is the paper ticket.
- 18:27So the hotel's local database only stores the tickets.
- 18:30Yes, the actual coats, the passports and credit card
- 18:33numbers are stored in a fortified, entirely separate
- 18:37external vault. So when hackers breach the PMS
- 18:40and access the local database, they don't get the actual credit
- 18:43card or passport, they only steal those randomized tokens.
- 18:47They walk away with millions of useless paper tickets.
- 18:50Exactly. But when a company fails to
- 18:52implement those measures and the data is left sitting in an open
- 18:55S3 bucket, individual action becomes the only defense left.
- 18:59If your passport or identity is caught in a leak like Tabik, the
- 19:03immediate action is placing a credit freeze or a fraud alert
- 19:06with the four major credit bureaus.
- 19:09Experian, TransUnion, Equifax and IT of us.
- 19:12Right. A fraud alert tells businesses
- 19:14they must contact you and verify your identity before granting
- 19:17new credit in your name. A credit freeze locks the file
- 19:20entirely, requiring you to provide a specific pen ion to
- 19:24unfreeze it before any new credit can be opened.
- 19:27A lot of people know about those 4 bureaus, but there's a lesser
- 19:30known step that is just as crucial.
- 19:32What's that? You need to request a security
- 19:33freeze with the National Consumer Telecom and Utilities
- 19:36Exchange, or NCTUE. Oh, for utility.
- 19:39Yeah, criminals don't just open credit cards with stolen
- 19:41passports. Identity thieves will open cell
- 19:44phone contracts or utility accounts in your name, run up
- 19:46the bills and abandoned them. That can ruin your credit just
- 19:50as quickly as a fraudulent loan. Wow.
- 19:52Yeah, the NCTUE freeze stops them from doing that by locking
- 19:56your utility and telecom credit file.
- 19:58You also need to opt out of pre screened credit card offers.
- 20:01Because they can steal the mail. Exactly.
- 20:03Criminals can intercept those physical offers in your mail and
- 20:06use the stolen data to activate them.
- 20:08And of course enable 2 factor authentication on all of your
- 20:11sensitive accounts. So a stolen password alone isn't
- 20:14enough to compromise you? The physical documents you slide
- 20:17across a hotel desk instantly become digital assets stored in
- 20:21a highly vulnerable, globally connected cloud ecosystem.
- 20:25It is entirely up to you to utilize credit freezes and
- 20:28authentication tools to protect yourself when those systems
- 20:31inevitably fail. If a completely unsecured,
- 20:34unpassworded bucket simply named Tabik can sit undetected on the
- 20:38Internet holding a million passports, how many identically
- 20:42configured cloud buckets are sitting out there right now just
- 20:45waiting for someone to type in the right URL?
- 20:47If you're not subscribed yet, take a second and hit follow on
- 20:50whatever app you're using. It helps us keep making this.
- 20:52We appreciate you being here. Also, check out our YouTube
- 20:54channel for more business and tech updates.
- 20:56There's a link in the description.