Comment by toyg

16 hours ago

Yeah, it's old-school people control. This said, these days it could be done electronically, without the hotel storing physical information: at check-in, you put your passport in goverment-issued, (hopefully) tamper-proof machines, the hotel confirms length of stay, police server gets the info and that's it; early checkouts, the hotel must notify via some web portal. It would be relatively easy to implement.

But nobody really cares enough to spend money modernising this sort of system.

I'm sure they're done electronically in some places: Your passport details are appended to the shared Google Spreadsheet...

I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere.

Yeah, honestly I'd prefer the remote, simple hotel makes a physical photocopy which at least has a chance of being thrown out after a couple of weeks vs the government of "random country" gets a digital copy which will never, ever, ever be deleted.

Ironically, that would enable tracking much more than the normal case, which is a hotel stores the scans on a hard drive on the closet that nobody every looks at unless they get a subpoena.

  • That's not what happens in Italy, at least - the documents are scanned and uploaded to a police portal in less than 24h. I expect that's roughly the same elsewhere. (I honestly did not know until today, I just knew the police would come every night to collect copies - good to see some modernization...)

All these giant data leaks are coming from the government's "tamper proof" systems!

  • I know, and it's really the trade-off whenever this sort of system is centralized: you can better secure the leafs, but the central repository becomes an even juicier target.

    This said, the police already has a database with these info, and it likely is somehow already on the network, so adding an api (if done properly) would not dramatically alter the exposure profile.

> This said, these days it could be done electronically

Are you 'avin a laugh mate?

A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.

The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.

  • The whole point is that the hotel would not even get a copy, the machine would just send hashes around and the hotel would only get an anonymous transaction ID to store. It would probably be even more secure than what you have today at the airport.

    If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you.

    • I’m sure this can be done, but somehow I doubt it.

      When I toured apartments they would often take a photocopy of my ID. Okay, overkill. But realistically I have no idea where that photocopy is stored.

      Probably in a OneDrive somewhere to this day.