Live data from Hacker News

Notice of Data Breach

content.myfitnesspal.com

11–20 of 160 posts

Re: Notice of Data Breach

#17

Perhaps this will also prompt them to start using HTTPS as well?

It's funny you would mention that because I also got annoyed by this and submitted a feature request for https. This is the response I received:

Hello,

Thanks for writing into us regarding https on MyFitnessPal.

We have technical and organizational measures in place to protect your information. Specifically, we have a secure login process designed to protect your information as you access MyFitnessPal (i.e., login and profile data are submitted using HTTPS POST actions).

The login pages of the MyFitnessPal that are encrypted via https include:

http://www.myfitnesspal.com http://www.myfitnesspal.com/login http://www.myfitnesspal.com/logout

Although our home page at http://www.myfitnesspal.com may not indicate the presence of https in your browser's interface, the actual login "lightbox" or pop-over window on the home page does send your login credentials via https.

After login, the MyFitnessPal website does not always load in HTTPS only mode (i.e. padlock not fully closed or green). This is because we sometimes load public content like images, public text from Under Armour, images & text from our advertising partners, and other non-user data using HTTP. While we load that public content using HTTP, we load user content using HTTPS.

We also continue to evaluate the security of our platforms, and have a dedicated team of cybersecurity professionals focused on this area. We will continue to review our security protocols to protect personal data.

Please let us know if you have additional questions or concerns.

Re: Notice of Data Breach

#18
post #12

No info either way about whether peoples very personal fitness data was breached, eating habits, weight, other measurements. Appaling PR speak.

I hope the log of my sex activity resulting in losing 20 lbs wasn't breached!

well played ... or is it? Freddy Mercury anyone?

Re: Notice of Data Breach

#20
post #8
post #3

> The affected data did not include government-issued identifiers, such as Social Security numbers and driver’s license numbers, information that the app does not collect from users Well, I suppose it wouldn't, would it? Is this supposed to be impressive? How many more of these before serious legislation gets through?

> It also doesn't include your mother's maiden name, nor does it include your browsing history, email dump, or your camera roll - information that the 'app does not collect from users' /s

Well, there are some apps that recorded your call history, even if they had no business knowing that as well.

So it propably doesn't hurt to mention?

Post reply on HN