Live data from Hacker News

Good Heavens 10M Impacted in Pray.com Data Exposure

threatpost.com

21–30 of 31 posts

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#21
> “The people whose data Pray.com had stored in these phonebook files were not app users,” according to vpnMentor’s analysis this week. “They were simply people whose contact details had been saved on a Pray.com user’s device. In total, we believe Pray.com stored up to 10 million peoples’ private data without their direct permission – and without its users realizing they were allowing it to happen.”

This is the part about this that annoys me the most. I hate how many companies see no issue with grabbing the data of someone else without consent.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#23
post #22

This does highlight how tough it can be for a non-tech entity, especially one run by non-tech volunteers, to play in tech spaces.

For bridges we have decided to only allow licensed engineers anywhere near the process. Maybe it's time to do the same for (parts of) tech.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#24
post #23
post #22

This does highlight how tough it can be for a non-tech entity, especially one run by non-tech volunteers, to play in tech spaces.

For bridges we have decided to only allow licensed engineers anywhere near the process. Maybe it's time to do the same for (parts of) tech.

That's a hard argument to make when even the pros still do this stuff. My point was if the pros have trouble doing it then the volunteers more likely will.

There's also a point that many professional techies would probably not want to work on these kinds of products or websites.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#25

> up to 10 million people > Subscriptions run anywhere from $50 to $120. Holy shit. And presumably it's all tax free. I wonder if there is some secret underground religious Venture Capital system that we don't know about.

I’m not sure if they still does it, but as recently as 2017 the Vatican operated/backed a tech accelerator[1]. It included seed funding, demo days, etc.

[1] https://www.fastcompany.com/40424655/inside-the-vaticans-tec...

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#26
post #6

Every time I see an exposure like this I'm reminded of a couple things... 1. Security everywhere is an after thought. How many people have performed a threat analysis of the app they're working on? How many have management who will slow down velocity on features to put the time in to securing personal information? When the culture isn't there the training isn't there either. 2. I don't know if it's the case here but,…

I don't think it's possible for a sub-$1B consumer operation to be secure, unless they operate inside a very tight sandbox where all the data and processing live inside a Google/Apple/similar sandbox. If the data is managed by the vendor system (which includes most data-monetization plays), it's leaked. Security is too complicated and expensive to get right.

Security isn't a binary state. It's more layered like an onion. There are a lot of layers that even a small startup can do... that many don't.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#27
post #6

Every time I see an exposure like this I'm reminded of a couple things... 1. Security everywhere is an after thought. How many people have performed a threat analysis of the app they're working on? How many have management who will slow down velocity on features to put the time in to securing personal information? When the culture isn't there the training isn't there either. 2. I don't know if it's the case here but,…

Another, somewhat related issue is the fragmenting of teams. Having a few in-house devs, an outsourced team in Argentina, and a few other contractors, all coordinated by non-technical managers. This more or less describes all the projects I've worked on in my career and it creates the ideal conditions for security problems.

There are ways to combat that. For example, some clear processes and documentation. This will help many other issues in organizations as well. Someone can have security as part of their KPI. That will put a focus on it.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#28
> “Through further investigation, we learned that Pray.com had protected some files, setting them as private on the buckets to limit access,” they explained. “However, at the same time, Pray.com had integrated its S3 buckets with another AWS service, the AWS CloudFront content delivery network (CDN). Cloudfront allows app developers to cache content on proxy servers hosted by AWS around the world – and closer to an app’s users – rather than load those files from the app’s servers. As a result, any files on the S3 buckets could be indirectly viewed and accessed through the CDN, regardless of their individual security settings.”

I have minimal knowledge of this kind of configuration, but it seems like making content available via a CDN from the same vendor should by default carry forward access restrictions on the original backend data.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#29
post #24
post #23

Earlier quoted context omitted.

For bridges we have decided to only allow licensed engineers anywhere near the process. Maybe it's time to do the same for (parts of) tech.

That's a hard argument to make when even the pros still do this stuff. My point was if the pros have trouble doing it then the volunteers more likely will. There's also a point that many professional techies would probably not want to work on these kinds of products or websites.

If the Engineers say, they wont build your dream bridge, then you wont get a bridge. Easy as that. Sometimes there is a reason pros wont do it.

Re: Good Heavens 10M Impacted in Pray.com Data Exposure

#30
post #29
post #24

Earlier quoted context omitted.

That's a hard argument to make when even the pros still do this stuff. My point was if the pros have trouble doing it then the volunteers more likely will. There's also a point that many professional techies would probably not want to work on these kinds of products or websites.

If the Engineers say, they wont build your dream bridge, then you wont get a bridge. Easy as that. Sometimes there is a reason pros wont do it.

Yeah, I really doubt that has much merit in this context. If you're one of these engineers feel free to explain why you wouldn't do it and why these entities don't deserve work but an entity like Facebook does.
Post reply on HN