Live data from Hacker News

Good Heavens 10M Impacted in Pray.com Data Exposure

threatpost.com

1–10 of 31 posts

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#3
post #2

From this we can safely assume their privacy approach was "lets pray no one will find our S3 buckets"

It would seem that `mysterious ways` was never the best security approach.

Still to impact 10M users given "It has been downloaded by more than 1 million people on Google Play, and ranks as the #24 lifestyle app in the Apple App store" does seem interesting and would love a breakdown upon that as not sure that 9M Apple app users of this. So, probably some deeper breachers of GDPR and the like going on here.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#4
post #3
post #2

From this we can safely assume their privacy approach was "lets pray no one will find our S3 buckets"

It would seem that `mysterious ways` was never the best security approach. Still to impact 10M users given "It has been downloaded by more than 1 million people on Google Play, and ranks as the #24 lifestyle app in the Apple App store" does seem interesting and would love a breakdown upon that as not sure that 9M Apple app users of this. So, probably some deeper breachers of GDPR and the like going on here.

Hah, do they have an "Add a contact to pray for" feature? A Zuckerbergian personal information hoarder/reseller would salivate at the thought of having such info.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#5
post #4
post #3

Earlier quoted context omitted.

It would seem that `mysterious ways` was never the best security approach. Still to impact 10M users given "It has been downloaded by more than 1 million people on Google Play, and ranks as the #24 lifestyle app in the Apple App store" does seem interesting and would love a breakdown upon that as not sure that 9M Apple app users of this. So, probably some deeper breachers of GDPR and the like going on here.

Hah, do they have an "Add a contact to pray for" feature? A Zuckerbergian personal information hoarder/reseller would salivate at the thought of having such info.

"Zuckerbergian personal information hoarder/reseller"

I'm going to have to remember that one. Ha.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#6
Every time I see an exposure like this I'm reminded of a couple things...

1. Security everywhere is an after thought. How many people have performed a threat analysis of the app they're working on? How many have management who will slow down velocity on features to put the time in to securing personal information?

When the culture isn't there the training isn't there either.

2. I don't know if it's the case here but, in the move to move more work on to app developers (ops, etc) there is only so much they can learn while still delivering on the things. How much of the reality of overloading app developers adds to this?

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#9
post #3
post #2

From this we can safely assume their privacy approach was "lets pray no one will find our S3 buckets"

It would seem that `mysterious ways` was never the best security approach. Still to impact 10M users given "It has been downloaded by more than 1 million people on Google Play, and ranks as the #24 lifestyle app in the Apple App store" does seem interesting and would love a breakdown upon that as not sure that 9M Apple app users of this. So, probably some deeper breachers of GDPR and the like going on here.

From the article:

"Most damningly, the cloud database included whole phone books from users. Whenever a person joins the Communities social network, the app asks if it can invite friends to join. If a user says yes, the app uploads the user’s entire ‘phonebook’ from their device, containing all contacts and associated information."

Post reply on HN