all 8 comments

sorted by: hot top controversial new old
[–] 28 points 2 years ago (1 child)

Surely allowing access to this personal data via a public API is a data breach? Its just taking it from something that shouldnt have exposed it rather than hacking into a system

  • source
  • hideshow 2 child comments
  • [–] 11 points 2 years ago (1 child)

    Yeh.
    Same as if it was a CSV mailing list on an unprotected URL or whatever.
    The term "data breach" suggests there was security there to be breeched. Maybe it needs a better term?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 2 years ago* (2 children)

    Data leak? In the security field, they categorize it as "information disclosure"... But it doesn't have the same level of gravitas to it

  • source
  • parent
  • hideshow 4 child comments
  • [–] 0 points 2 years ago* (1 child)

    It does if you consider it from the point of view of a. Someone went out of their way to design this API so as to allow this or b. A team of individuals deployed it without realizing how it would be exploited

    You can generally learn things from a breach, but finding and remediating systemic issues like those mentioned above is a big ask

    Edit: I either responded to the wrong comment or misunderstood what you said. It's late in the day...

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)

    I think you replied to the right post (mine) but I didn't downvote you.

    Information disclosure doesn't necessarily imply it's intentional or unintentional, just that information was disclosed. But in a sense I do agree somewhat with that you said, only that WHO the person who developed the API receives that message from makes a huge difference. The IT security team coming to you and says "information disclosure" is scarier than a team mate

  • source
  • parent
  • hideshow 2 child comments