Live data from Hacker News

Viewing profile — g48ywsJk6w48

g48ywsJk6w48

HN member
Joined
Sun, Jul 18, 2021, 12:08 AM UTC
HN karma
38
Public activity
25 items

About g48ywsJk6w48

No profile information was provided.

Recent public activity

  1. comment
  2. comment
    Comment #47912919

    This is not a data leakage. They deliberately included 999 of their customers' email addresses in publicly accessible JavaScript code in order to test certain features on them.

  3. comment
    Comment #47912872

    I was curious to know which service provider they use. So I went to look at the source code of their websites.

  4. comment
    Comment #47912560

    Yes, and it's a company that makes hundreds of millions of dollars a year.

  5. comment
    Comment #47911932

    Just open app.medvi.org and search in DevTools gmail/yahoo/icloud and you will see js bundle with emails. or seasonhealth/openloophealth to find another js bundle with staff emails…

  6. comment
    Comment #47910441

    Would you like me to show you specific JavaScript files right here?

  7. comment
    Comment #47910428

    Yes, LLM assisted.

  8. comment
    Comment #47910420

    They look like real people's email addresses. I checked a few. They belong to real people.

  9. story
    Tell HN: Medvi (telehealth) hardcodes 999 patient emails in public JavaScript

    Medvi is a telehealth pharmacy that has received significant media attention recently. While browsing their site with DevTools open, I noticed that their public JavaScript bundle c…

  10. comment
  11. comment
    Comment #44948094

    Thank you for sharing such a great product. Last week after getting fed up with a lot of slow commercial products and wrote my own similar app that works locally in the loop and ca…

  12. comment
  13. comment
  14. comment
    Comment #43783642

    There are indeed several services that help manage subscriptions and the budget for them. There are separate applications that help manage passwords and track password database lea…

  15. comment
  16. comment
    Comment #41862591

    Thank you for data set!!! It is not always lowercase, so it have some duplicates. Also you can avoid unnecessary data with analyze CNAME records. -- domain.tld CNAME www.domain.tld…

  17. comment
  18. comment
  19. comment
    Comment #35019183

    Unfortunately, he did not answer for a week. Started thinking data leak is not a super interesting topic for professionals. It happened every week, so my discovery is just another …

  20. comment
    Comment #35019164

    Unfortunately, Brian Krebs did not answer for a week. Started thinking data leak is not a super interesting topic for professionals. It happened every week, so my discovery is just…

  21. comment
    Comment #35019161

    Unfortunately, they did not answer for a week. Started thinking data leak is not a super interesting topic for professionals. It happened every week, so my discovery is just anothe…

  22. comment
    Comment #35019159

    Unfortunately, he did not answer for a week. Started thinking data leak is not a super interesting topic for professionals. It happened every week, so my discovery is just another …

  23. comment
    Comment #34934049

    I absolutely agree. It is unlikely that I will be thanked for such an act. Destroy the reputation of a company with 10+ years of experience on the market. And force dozens of other…

  24. story
    Ask HN: Found a leak of US citizens personal data. Should I report it?

    Security research is my hobby. Yesterday I found a pretty big (estimated at tens of thousands of records) data leak. Full name, date of birth, mail, phone, address. Nothing to do w…

  25. comment