• HasturInYellow@lemmy.world
    link
    fedilink
    English
    arrow-up
    39
    ·
    1 month ago

    What!? One of the thousands of separate and individually “secured” systems that you have to give your information to on a daily basis failed? But how could this be? Everyone knows having 1747627994 points of possible failure is the only way to ensure digital security!

  • solrize@lemmy.ml
    link
    fedilink
    English
    arrow-up
    20
    ·
    1 month ago

    The hotel check-in system, called Tabiq, is maintained by the Japan-based tech startup Reqrea. According to its website, Tabiq is used in several hotels across Japan and relies on facial recognition and document scanning to check guests in.

    They left an S3 bucket open.

    • Wispy2891@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 month ago

      this is why other s3 compatible servers like garage intentionally ignore admin commands to leave a bucket open, it’s simply not possible as there’s no valid reason except developer laziness

    • Electricblush@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      edit-2
      1 month ago

      No. A properly managed eid system like the EU digital wallet would be better.

      You would not hand over any document to the hotel. They would ask the central authority server if you are who you claim. You would get a prompt to confirm that you allow the hotel to confirm your identity. The server would respond, yes you are indeed that person. End of transaction.

      No data would be left to whatever security standard (or lack there of) that the hotel has. No critical documents stored on their end.