frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Finding a former Australian prime minister’s passport number on Instagram (2020)

https://mango.pdf.zone/finding-former-australian-prime-minister-tony-abbotts-passport-number-on-instagram/
98•guiambros•6h ago

Comments

Bilal_io•4h ago
I believe this is the same story covered by Dark Diaries. Very interesting story. https://darknetdiaries.com/episode/84/
protocolture•4h ago
I love this blog post. Its a classic.
santoshalper•3h ago
Really interesting, but the writing was so bad I had to bail out halfway through.
causal•3h ago
I enjoy the meandering style but it did become a little long because of the meandering, glad I skipped ahead instead of just closing tho
tomhow•3h ago
> I had to bail out halfway through

Telling us you didn't read the article is exactly the kind of unsubstantive comment we don't want on HN. The comments thread is for people who did read the article and have something to say about the content.

This kind of comment breaks the guidelines particularly these ones:

Be kind. Don't be snarky. Converse curiously...

Don't be curmudgeonly. Thoughtful criticism is fine, but please don't be rigidly or generically negative.

Please don't fulminate. Please don't sneer....

Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.

Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something.

Please don't complain that a submission is inappropriate. If a story is spam or off-topic, flag it. Don't feed egregious comments by replying; flag them instead. If you flag, please don't also comment that you did.

Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting.

Please take a moment to remind yourself of the guidelines and make an effort to observe them in future.

https://news.ycombinator.com/newsguidelines.html

CAPSLOCKSSTUCK•2h ago
Who asked?
decimalenough•2h ago
tomhow is a HN moderator.
Bjartr•2h ago
I think it was all written for the thing it was trying to be. Which is a casual humorous take on the journey this person went through with a little tech education sprinkled in. Any more formal or sophisticated and it would've lost some of the casual humor and been less an interesting journey. But did so in a way much less aggravating than what qualifies for a food recipe these days.
broodbucket•3h ago
The story is a lot more enjoyable in conference talk form than written form imo https://www.youtube.com/watch?v=lijyQ_HAysA
tomhow•3h ago
Previously:

Finding a former Australian prime minister’s passport number on Instagram (2020) - https://news.ycombinator.com/item?id=34966909 - Feb 2023 (41 comments)

When you browse Instagram and find Tony Abbott's passport number - https://news.ycombinator.com/item?id=24488224 - Sept 2020 (340 comments)

coffeecoders•3h ago
Love the humor. I am a fan of Alex's writing style!
LorenDB•2h ago
It's a shame he apparently no longer blogs. His posts are gold.
ViscountPenguin•2h ago
They/them based on their socials (and iirc, I think that's what they went by at Crikeycon) https://x.com/mangopdf
ethan_smith•2h ago
Despite being from 2020, this vulnerability persists in 2025 with many airlines still exposing sensitive data on boarding passes and luggage tags, making "don't post your boarding pass" still relevant security advice.
bawolff•2h ago
How sensitive is a passport number actually? At first glance it seems like it should be, but is it actually? I honestly don't know.
selcuka•2h ago
Online systems sometimes use it as an indicator to prove your identity. When combined with other sensitive data it can be useful for an identity thief.

Edit: The blog post also mentions this:

https://mango.pdf.zone/finding-former-australian-prime-minis...

moralestapia•2h ago
Can you provide just one example of said systems?
selcuka•2h ago
Sure:

- https://www.myid.gov.au/verifying-your-id-in-myid#myid-Austr...

- https://www.afp.gov.au/sites/default/files/PDF/NPC-100PointC...

- https://www.equifax.com.au/personal/identity-verification-10...

The blog post has more use case examples:

https://mango.pdf.zone/finding-former-australian-prime-minis...

throwaway422432•1h ago
Look up Australia's 100 point proof of identity which is used by Gov and most corporate entities in Australia.

A passport is a primary document (equivalent to a birth certificate) and gives you 60-70 points. It can't be used alone, but in conjunction with another id (forged or stolen) would allow for identify theft.

dafelst•1h ago
There is an example in the article
phs318u•1h ago
Understanding that Australia doesn't have a Social Security ID (as the US does), might explain why passports play a similar role with respect to "proof of identity".
bigDinosaur•1h ago
The Australian Tax File Number is presumably more similar to the Social Security ID? Millions of Australians don't have a passport. You don't need one for much - it's perhaps the easiest way of verifying citizenship if you already have one but not the only way.
throwaway422432•2m ago
You would only have a TFN if you are working and potentially paying tax. So generally anyone under 16 would not have one.

Closest might be a Medicare Card which gives you access to free/discounted public health that can be used as part of identification. Usually children are on their parents card.

Drivers licence is also a primary identifier, and students can use their school student id.

SchemaLoad•1h ago
Pretty sure you can use one to sign up for a phone number in Aus
soulofmischief•1h ago
Wait hold on, you have to apply for phone numbers in Australia? You can't just grab a burner from Walmart?
SchemaLoad•1h ago
Yes, every phone number gets linked to an ID. You can grab a sim from the supermarket but when you plug it in you've got to activate it which requires ID.
soulofmischief•18m ago
I'm so sorry. Australia is such a draconian nanny state, hell-bent on surveillance and authoritarian control.

It always reminds me a lot of here in the US: Incredible land, a vast ecology, great history and subcultures, and some truly amazing people unfortunately drowned out by a staggeringly large population of loud morons who seem hellbent on voting in the worst possible people to run the whole thing, people who often couldn't care less about the things that make their country truly great, while leaning heavily on populism and deception as a means to retain power.

I wouldn't be surprised if the US eventually requires ID for phone numbers, either, the way things have been going.

petesergeant•2h ago
> Based on advice I got from two independent lawyers that was definitely not legal advice: I haven’t done a crime.

I will trust his lawyers are right _for Australia only_ (although I have my doubts, and would love to see their reasoning), but in the UK this feels like a clear breach of the Computer Misuse Act[0], and I can't recommend enough that you don't do this.

0: https://www.legislation.gov.uk/ukpga/1990/18/section/1

rao-d•1h ago
Love it
moneywaters•1h ago
Also a security tip, mosaic like he used in the picture is not a safe way to hide sensitive data, especially the one that has movement like in the gif where he is scrolling down, the mosaic changes and gives more data to reconstruct original. The safe way is to fully black out, but be wary of not plain color almost opaque marker tools, it could look like black out but playing with contrast will still reveal the data.
jampa•1h ago
Reading the "Why is it bad for someone else to have your passport number?" is scary, especially since when traveling to countries like Spain and Italy, every Airbnb / Hotel requires you to send a picture of your passport. Japanese stores take your passport stamp picture for their tax-free, which contains the number on the page. Some embassies even take your passport for a few days before returning it with the visa.

Why do we treat passport numbers as passwords instead of a login?

creakingstairs•24m ago
I once checked in at a pretty decent hotel in India and realised that they used re-used customers passport scans and invoices to print wifi coupons! I strongly complained but I don’t really know if they’ve changed.
imarkphillips•52m ago
What a great story teller! Well done Alex.

NativeJIT: A C++ expression –> x64 JIT

https://github.com/BitFunnel/NativeJIT
11•nateb2022•1h ago•1 comments

Touching the back wall of the Apple store

https://blog.lauramichet.com/touching-the-back-wall-of-the-apple-store/
88•nivethan•3d ago•53 comments

I made my VM think it has a CPU fan

https://wbenny.github.io/2025/06/29/i-made-my-vm-think-it-has-a-cpu-fan.html
457•todsacerdoti•14h ago•116 comments

Cell Towers Can Double as Cheap Radar Systems for Ports and Harbors (2014)

https://spectrum.ieee.org/cell-tower-signals-can-improve-port-security
61•transpute•6h ago•28 comments

The Book of Shaders

https://thebookofshaders.com/
70•max_•3d ago•12 comments

Amber insect fossils reveal "zombie" fungi likely lived alongside dinosaurs

https://www.cnn.com/2025/06/24/science/amber-insect-zombie-fungi-fossil
23•jackgavigan•3d ago•4 comments

Ask HN: What Are You Working On? (June 2025)

126•david927•8h ago•451 comments

Revisiting Knuth's "Premature Optimization" Paper

https://probablydance.com/2025/06/19/revisiting-knuths-premature-optimization-paper/
95•signa11•3d ago•44 comments

Continuous Glucose Monitoring

https://www.imperialviolet.org/2025/06/29/cgm.html
18•zdw•2h ago•4 comments

We accidentally solved robotics by watching 1M hours of YouTube

https://ksagar.bearblog.dev/vjepa/
94•alexcos•12h ago•73 comments

The $25k car is going extinct?

https://media.hubspot.com/why-the-25000-car-is-going-extinct
109•pseudolus•12h ago•203 comments

Building untrusted container images safely at scale

https://depot.dev/blog/container-security-at-scale-building-untrusted-images-safely
8•Telstrom90•3d ago•5 comments

Finding a former Australian prime minister’s passport number on Instagram (2020)

https://mango.pdf.zone/finding-former-australian-prime-minister-tony-abbotts-passport-number-on-instagram/
98•guiambros•6h ago•33 comments

4-10x faster in-process pub/sub for Go

https://github.com/kelindar/event
124•kelindar•13h ago•26 comments

Use keyword-only arguments in Python dataclasses

https://chipx86.blog/2025/06/29/tip-use-keyword-only-arguments-in-python-dataclasses/
12•Bogdanp•3h ago•2 comments

Nearly 20% of cancer drugs defective in 4 African nations

https://www.dw.com/en/nearly-20-of-cancer-drugs-defective-in-4-african-nations/a-73062221
84•woldemariam•5h ago•45 comments

Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

https://krebsonsecurity.com/2021/05/try-this-one-weird-trick-russian-hackers-hate/
231•air7•10h ago•131 comments

Anticheat Update Tracking

https://not-matthias.github.io/posts/anticheat-update-tracking/
28•not-matthias•7h ago•5 comments

WorldVLA: Towards Autoregressive Action World Model

https://arxiv.org/abs/2506.21539
14•chrsw•4h ago•1 comments

The Chan-Zuckerbergs stopped funding social causes

https://www.washingtonpost.com/technology/2025/06/29/mark-zuckerberg-priscilla-chan-school-closure/
76•1vuio0pswjnm7•3h ago•48 comments

Error handling in Rust

https://felix-knorr.net/posts/2025-06-29-rust-error-handling.html
110•emschwartz•8h ago•91 comments

Commodore acquired for a 'low seven figure' price – CEO from retro community

https://www.tomshardware.com/video-games/retro-gaming/commodore-acquired-for-a-low-seven-figure-price-new-acting-ceo-comes-from-the-retro-community
62•amichail•5h ago•12 comments

The Medley Interlisp Project: Reviving a Historical Software System [pdf]

https://interlisp.org/documentation/young-ccece2025.pdf
83•pamoroso•13h ago•7 comments

Show HN: Rust -> WASM, K-Means Color Quantization Crate for Image-to-Pixel-Art

https://github.com/gametorch/image_to_pixel_art_wasm
33•gametorch•3d ago•4 comments

Modelling API rate limits as diophantine inequalities

https://vivekn.dev/blog/rate-limit-diophantine
47•viveknathani_•2d ago•5 comments

Loss of key US satellite data could send hurricane forecasting back 'decades'

https://www.theguardian.com/us-news/2025/jun/28/noaa-cuts-hurricane-forecasting-climate
278•trauco•11h ago•128 comments

Reverse Engineering the Microchip CLB

http://mcp-clb.markomo.me/
26•_Microft•7h ago•5 comments

ICE test train reaches speeds of up to 405.0 km/h

https://www.deutschebahn.com/de/presse/pressestart_zentrales_uebersicht/ICE-Testzug-faehrt-bis-zu-405-0-km-h-und-sammelt-wichtige-Erkenntnisse-fuer-den-Hochgeschwindigkeitsverkehr-13428394
14•doener•6h ago•8 comments

Ask HN: Is the header CSS broken for you?

33•LorenDB•3h ago•9 comments

My home servers are not a homelab

https://blog.nradk.com/posts/homelab/
47•nradk•2h ago•53 comments