• chevron_right

      Experian Privacy Vulnerability

      news.movim.eu / Schneier · Wednesday, 11 January, 2023 - 20:53

    Brian Krebs is reporting on a vulnerability in Experian’s website:

    Identity thieves have been exploiting a glaring security weakness in the website of Experian, one of the big three consumer credit reporting bureaus. Normally, Experian requires that those seeking a copy of their credit report successfully answer several multiple choice questions about their financial history. But until the end of 2022, Experian’s website allowed anyone to bypass these questions and go straight to the consumer’s report. All that was needed was the person’s name, address, birthday and Social Security number.

    • chevron_right

      100,000 Razer users’ data leaked due to misconfigured Elasticsearch

      Jim Salter · news.movim.eu / ArsTechnica · Monday, 14 September, 2020 - 13:35

    This redacted sample record from the leaked Elasticsearch data shows someone

    Enlarge / This redacted sample record from the leaked Elasticsearch data shows someone's June 24 purchase of a $2,600 gaming laptop. (credit: Volodymyr Dianchenko )

    In August, security researcher Volodymyr Diachenko discovered a misconfigured Elasticsearch cluster, owned by gaming hardware vendor Razer, exposing customers' PII (Personal Identifiable Information).

    The cluster contained records of customer orders and included information such as item purchased, customer email, customer (physical) address, phone number, and so forth—basically, everything you'd expect to see from a credit card transaction, although not the credit card numbers themselves. The Elasticseach cluster was not only exposed to the public, it was indexed by public search engines.

    Diachenko reported the misconfigured cluster—which contained roughly 100,000 users' data—to Razer immediately, but the report bounced from support rep to support rep for over three weeks before being fixed.

    Read 12 remaining paragraphs | Comments

    index?i=3Bsb1MKNaIE:3PIVIFuDzG0:V_sGLiPBpWUindex?i=3Bsb1MKNaIE:3PIVIFuDzG0:F7zBnMyn0Loindex?d=qj6IDK7rITsindex?d=yIl2AUoC8zA