PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Three exposed Brit’s privates with sloppy survey code

Posted on June 19, 2015June 26, 2025 by Dissent

Darren Pauli reports:

Hacker Joseph Redfern has reported a privacy flaw at UK telco Three, which exposed names and email addresses in online surveys.

The telco shuttered the offending survey site and the exposed API which returned the private information in JSON forms when a user entered data.

Refern says the flaw meant any phone number could be keyed into the clear text requests. Doing so would produce the real name and email address of the owner.

“The site was making an AJAX request to an API … over cleartext HTTP passing my mobile phone number in the URL,” Redfern says.

Read more on The Register.

No related posts.

Category: BreachesBusinessNon-U.S.Online

Post navigation

← Spy court clears path to renewing NSA powers
Samsung’s security failures leave 600 million Android users vulnerable to simple keyboard hack →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
  • EPIC Publishes New Whitepaper Detailing Privacy Risks of Government Data Mining Programs
  • Modern cars are spying on you. Here’s what you can do about it.
  • Attorney General James and Multistate Coalition Secure $5.1 Million from Education Software Company for Failing to Protect Students’ Data       
  • EU Parliament committee votes to advance controversial Europol data sharing proposal
  • DHS offers “disturbing new excuses” to seize kids’ biometric data, expert says

RSS Recent Posts at DataBreaches.net

  • Manassas City Public Schools close on Monday due to cyberattack
  • San Joaquin County Superior Court concludes sensitive info leaked in data breach
  • NCCIA arrests man over massive data breach involving millions of Pakistanis
  • Defense Contractors Are Silencing Their Cybersecurity Watchdogs
  • Fourth Circuit Weighs in on Standing in Data Breach Class Actions
©2025 PogoWasRight.org. All rights reserved.