PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Three exposed Brit’s privates with sloppy survey code

Posted on June 19, 2015 by pogowasright.org

Darren Pauli reports:

Hacker Joseph Redfern has reported a privacy flaw at UK telco Three, which exposed names and email addresses in online surveys.

The telco shuttered the offending survey site and the exposed API which returned the private information in JSON forms when a user entered data.

Refern says the flaw meant any phone number could be keyed into the clear text requests. Doing so would produce the real name and email address of the owner.

“The site was making an AJAX request to an API … over cleartext HTTP passing my mobile phone number in the URL,” Redfern says.

Read more on The Register.

Category: BreachesBusinessNon-U.S.Online

Post navigation

← Spy court clears path to renewing NSA powers
Samsung’s security failures leave 600 million Android users vulnerable to simple keyboard hack →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

RSS Recent Posts on DataBreaches.net

  • Credit Control Corporation data allegedly from 9.1 million consumers listed for sale on forum
  • Copilot AI Bug Could Leak Sensitive Data via Email Prompts
  • FTC Provides Guidance on Updated Safeguards Rule
  • Sentara Health terminates remote employees after realizing they couldn’t be sure who was doing the work.
  • Hackers Break Into Car Sharing App, 8.4 Million Users Affected
©2025 PogoWasRight.org. All rights reserved.