the API endpoint GET [redacted] will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else’s data,” she wrote.
This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That’s it. That’s the exploit.”
My God, that’s horrific. Plus it doesn’t even delete your data if you delete your account, it’s still vulnerable.
I don’t know much about GDPR… is it illegal to have badly written software like this? Technically the user is bypassing normal usage and “hacking” the API
Negligence to delete the account data after termination is a reason to be fined.
They don’t need to keep that data.
Afaik the only reason would be if MTX were offered (for book-keeping reasons)
I know, but a lot of people don’t click the article, they just look at headline + comments, so it’s still a reduction of visibility or an extra step. My comment is like exposing the endpoint right there front and centre. Plus, I don’t like being personally responsible for any data breach. Maybe it’s just a tiny thing but it felt like the right thing to do
My God, that’s horrific. Plus it doesn’t even delete your data if you delete your account, it’s still vulnerable.
I wonder of the vatican is part of the gdpr…
Would be funny to read about the church getting sued for that.
I don’t know much about GDPR… is it illegal to have badly written software like this? Technically the user is bypassing normal usage and “hacking” the API
Negligence to delete the account data after termination is a reason to be fined.
They don’t need to keep that data.
Afaik the only reason would be if MTX were offered (for book-keeping reasons)
It is illegal to keep deleted profiles
Yes, especially once you have been informed about it
It sill works, you get first name and last name.
Maybe I should remove that from my comment lol, I feel like I’m contributing to a data breach or something
It is in the article doesn’t matter if you remove it. The moment the article became public it is already too late.
I know, but a lot of people don’t click the article, they just look at headline + comments, so it’s still a reduction of visibility or an extra step. My comment is like exposing the endpoint right there front and centre. Plus, I don’t like being personally responsible for any data breach. Maybe it’s just a tiny thing but it felt like the right thing to do
What’s more, scammers now have a list of 750k people known for their gullibility