Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

When I type some letters and numbers into my web browser, I find myself looking at the identity documents of complete strangers. Passport of a young woman from Germany. Passport of a man from Spain wearing glasses on his head. The front and back of another man’s driver’s license, and a stereotypical goofy expression on his face.
They were all sitting unprotected on public URLs, with no password or access control of any kind. If I sent you a link, you could have looked at someone’s passport.
“We have to do something about this as quickly as possible,” Sami Azdoval told me in May, “because people will find this and resell it. It will cause damage.”
Azduval is the security researcher who used Cloud Code to help discover this All DJI Romo Robotic Vacuum Cleaner and One million baby monitors and security cameras It was embarrassingly porous. This time, he says, he discovered more than 985,000 photo IDs exist on the public Internet that any half-decent hacker could steal.
If you’ve been to a cannabis club in Spain, Azduval says, your photo ID will likely be among them — and perhaps your phone number, address, favorite cannabis strains, and how much you’ve been consuming each month while you’re there. Celebrities are in the database too, Azduval says, and visitors from all over the world, including 30,000 from the United States. “They have famous people,” Azdoval says. “People who don’t want everyone to know they smoke weed.”
Here is a rough summary of the user base that Azdoval’s automated tool was able to see, and the names of some of the clubs:
It is not the clubs that have not protected these identity documents. An Irish company called Cannabis Club Systems (CCS), formally known as Nefos Solutions, develops and provides the software these clubs use for sales, accounting and admissions, including a verification system where receptionists upload your IDs and personal photos to the Nefos cloud.
Traditionally, you would need to present photo ID each time you wanted to join the club. But with the verification system, the receptionist can pull your stored identity documents and check whether your face matches. There is also an optional app called PuffPal that allows clubs to scan a QR code for faster entry.
But when Azdoval dismantled PuffPal, He explains in his reportHe discovered that Nevos did not have a meaningful level of security. Discover a secret key to Stripe’s payments platform located within the app in plain text. He discovered that he could view any member’s profile just by changing one number. If these profiles include their phone number, home address, passport, and preferences, he can now access those as well.
Then, he discovered that passports, driver’s licenses and photo IDs were stored in public URLs as simple as this: https://ccsnubev2.com/v8/images/_{club}/ID/{user_id}-front.jpg
These clubs were uploading 5,000 new photo IDs with unsafe URLs every day, Azduval told me.
He also found an administrative portal accessible over the public internet – and that cannabis clubs had a trivial level of security on their private accounts, using passwords that could theoretically be cracked in minutes with a modern GPU. Private chat messages between clubs and members through the PuffPal app were also at risk.
The good news: About a month after we reached out to Nefos, it appears the company is finally taking meaningful action. The company says it will shut down the entire PuffPal system and vulnerable APIs until they can be fixed — in Azdoufal’s latest tests on June 10, passport photos and personal data appear to be safe. Nefos also notified local authorities, saying it would take responsibility for making repairs, paying fines, and telling users what happened.
In a phone interview, Andreas Nielsen, co-founder of Nefos, said Edge It has been in contact with the Irish Data Protection Authority (DPC) regarding the data breach – a fact confirmed to us by DPC spokesperson Ivan O’Leary via email. “We have to contact everyone who may have been exposed,” Nielsen told me, saying he hoped the DPC could show his company how to do this properly. Nielsen claims that there is currently no evidence that any outsider has accessed the data other than Azduval.
But it took a very long time for Nevos to take the threat seriously. It took five days and a story threat before the company got back to us, long after Azduval reached out. After that, Nevos began covering the holes with paper rather than risk the work.
I was ready to write this story at the beginning of June, after Azduval told me that Nevos had finally secured passport photos. But on June 4, she surprised Azdoval when she explained to him that his passport was available online again, without any protection.
This is because Nefos had not yet banned cannabis clubs from using the PuffPal app, and clubs were complaining that locked photos were no longer appearing the way they used to – so Nefos simply unlocked the photos again. While Nilsen claims that the images have been shut down “70 percent of the time” since Azdoufal and I communicated, it is very clear that Nefos made the decision to prioritize its customers rather than the threat.
On June 9, Azdoval discovered that although Nefos had locked passport photos and ID cards with tokens, Everything else User profiles were still easily accessible: passport numbers, phone numbers, email addresses, home addresses, everything.
All the hacker had to do was type “curl -X POST https://ccsnubev2.com/v8/api/userProfile.php -d “user_id=(NUMBER)&(CLUB NAME)=test&language=en” in the command line, and the servers would freely give up a bunch of personal information. After we brought this to Nefos’ attention, this vulnerability was closed as well.
But how could a company be so negligent? “I don’t want to put the blame on others, because ultimately it’s on us,” Nielsen says. But he points the finger In 9 seriesan outsourcing company that claims to have been responsible for developing the PuffPal app and creating all the vulnerable APIs it used to pull unprotected data from the Nefos user database. (9Series did not have a response by press time.)
Now that PuffPal is down, Nefos is sending an email to all clubs letting them know that their members won’t be able to use QR codes to enter — but they can still pull IDs from Nefos’ servers after scanning a member’s RFID card or typing in their phone number, among other examples.
Nilsen claims his company will not simply relaunch the non-guaranteed PuffPal if clubs ask for it. “We’ll tell them we can’t do that,” he says. “We will make sure, after this debacle, that this is verified by an independent security researcher and ensure that it is 100 percent safe.” He says Nefos is parting ways with the 9Series, and he hopes to have a new app in a few months.
Nielsen says he realizes that Under European Union lawHis company was legally required to disclose the violation within 72 hours or pay hefty fines, something the company did not do. “I’m sure we’ll get any kind of punishment,” Nielsen says.
Just last month, a website called the UK Visa Portal appeared Likewise at least 100,000 passports were uncovered To anyone who can guess the URL. Let’s hope this is a wake-up call.