An insurance company’s API exposed customers’ car location histories
andreascarpino.it
An insurance company’s API exposed customers’ car location histories
1–10 of 69 posts
Re: An insurance company’s API exposed customers’ car location histories
#2Re: An insurance company’s API exposed customers’ car location histories
#3Re: An insurance company’s API exposed customers’ car location histories
#4Until there is some kind of law in place that makes companies financially responsible for this kind of blunder, it will proliferate. In the current state of affairs it's simply not economically justified to implement proper security.
Re: An insurance company’s API exposed customers’ car location histories
#5It's a shame he can't name the telematics company. I have a suspicion it's one I interviewed at a few years ago.
Re: An insurance company’s API exposed customers’ car location histories
#6Until there is some kind of law in place that makes companies financially responsible for this kind of blunder, it will proliferate. In the current state of affairs it's simply not economically justified to implement proper security.
I have a feeling it's a subtly different problem: the people they've contracted to build this just don't understand security. They've evidently attempted to secure this, just in completely the wrong manner!
There is a good chance that the lure of security consultancy $ is resulting in a degradation of the quality of the applications.
Re: An insurance company’s API exposed customers’ car location histories
#7Name and shame, please!
Re: An insurance company’s API exposed customers’ car location histories
#8Re: An insurance company’s API exposed customers’ car location histories
#9Re: An insurance company’s API exposed customers’ car location histories
#10Until there is some kind of law in place that makes companies financially responsible for this kind of blunder, it will proliferate. In the current state of affairs it's simply not economically justified to implement proper security.
I have a feeling it's a subtly different problem: the people they've contracted to build this just don't understand security. They've evidently attempted to secure this, just in completely the wrong manner!
If the company providing the service were financially liable for these blunders, they would be careful to select contractors that are capable of meeting the security needs.
As it is now, there is no financial incentive to select the "security aware" contractor, and the "non-aware" one is so much cheaper...