The Westfield’s iPhone app privacy smorgasbord
troyhunt.com
The Westfield’s iPhone app privacy smorgasbord
1–10 of 37 posts
Re: The Westfield’s iPhone app privacy smorgasbord
#2Re: The Westfield’s iPhone app privacy smorgasbord
#3Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181), and exposed their entire web service documentation here: http://120.151.59.193/v2/help (although it will probably be down by now).
Re: The Westfield’s iPhone app privacy smorgasbord
#4So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing. Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181 ), and exposed their entire web service documentation here: http://120.151.5…
Re: The Westfield’s iPhone app privacy smorgasbord
#5I just told my family that no vehicles are to be parked at a Westfield parking garage until further notice. I'm used to them rolling their eyes at me over data security issues, but I gave them the link to this one and their jaws dropped.
Re: The Westfield’s iPhone app privacy smorgasbord
#6So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing. Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181 ), and exposed their entire web service documentation here: http://120.151.5…
Re: The Westfield’s iPhone app privacy smorgasbord
#7So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing. Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181 ), and exposed their entire web service documentation here: http://120.151.5…
Someone is going to get fired over this.
Re: The Westfield’s iPhone app privacy smorgasbord
#8Re: The Westfield’s iPhone app privacy smorgasbord
#9So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing. Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181 ), and exposed their entire web service documentation here: http://120.151.5…
I hope there's authentication on the signs.json PUT update API, or Westfield's signs are probably about to go crazy...
http://120.151.59.193/v2/email-alerts