Notice of Data Breach
11–20 of 160 posts
Re: Notice of Data Breach
#12Re: Notice of Data Breach
#13Re: Notice of Data Breach
#14Re: Notice of Data Breach
#15No info either way about whether peoples very personal fitness data was breached, eating habits, weight, other measurements. Appaling PR speak.
Re: Notice of Data Breach
#16Re: Notice of Data Breach
#17Perhaps this will also prompt them to start using HTTPS as well?
Hello,
Thanks for writing into us regarding https on MyFitnessPal.
We have technical and organizational measures in place to protect your information. Specifically, we have a secure login process designed to protect your information as you access MyFitnessPal (i.e., login and profile data are submitted using HTTPS POST actions).
The login pages of the MyFitnessPal that are encrypted via https include:
http://www.myfitnesspal.com http://www.myfitnesspal.com/login http://www.myfitnesspal.com/logout
Although our home page at http://www.myfitnesspal.com may not indicate the presence of https in your browser's interface, the actual login "lightbox" or pop-over window on the home page does send your login credentials via https.
After login, the MyFitnessPal website does not always load in HTTPS only mode (i.e. padlock not fully closed or green). This is because we sometimes load public content like images, public text from Under Armour, images & text from our advertising partners, and other non-user data using HTTP. While we load that public content using HTTP, we load user content using HTTPS.
We also continue to evaluate the security of our platforms, and have a dedicated team of cybersecurity professionals focused on this area. We will continue to review our security protocols to protect personal data.
Please let us know if you have additional questions or concerns.
Re: Notice of Data Breach
#18Re: Notice of Data Breach
#19Re: Notice of Data Breach
#20> The affected data did not include government-issued identifiers, such as Social Security numbers and driver’s license numbers, information that the app does not collect from users Well, I suppose it wouldn't, would it? Is this supposed to be impressive? How many more of these before serious legislation gets through?
> It also doesn't include your mother's maiden name, nor does it include your browsing history, email dump, or your camera roll - information that the 'app does not collect from users' /s
So it propably doesn't hurt to mention?