Live data from Hacker News

The Westfield’s iPhone app privacy smorgasbord

troyhunt.com

1–10 of 37 posts

Re: The Westfield’s iPhone app privacy smorgasbord

#3
So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing.

Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181), and exposed their entire web service documentation here: http://120.151.59.193/v2/help (although it will probably be down by now).

Re: The Westfield’s iPhone app privacy smorgasbord

#4
post #3

So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing. Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181 ), and exposed their entire web service documentation here: http://120.151.5…

How did you find this?

Re: The Westfield’s iPhone app privacy smorgasbord

#5
That is amazing. How are people this short-sighted and reckless with people's data? It's so frustrating.

I just told my family that no vehicles are to be parked at a Westfield parking garage until further notice. I'm used to them rolling their eyes at me over data security issues, but I gave them the link to this one and their jaws dropped.

Re: The Westfield’s iPhone app privacy smorgasbord

#6
post #3

So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing. Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181 ), and exposed their entire web service documentation here: http://120.151.5…

I hope there's authentication on the signs.json PUT update API, or Westfield's signs are probably about to go crazy...

Re: The Westfield’s iPhone app privacy smorgasbord

#7
post #3

So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing. Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181 ), and exposed their entire web service documentation here: http://120.151.5…

Still up, 1 hour and counting...

Someone is going to get fired over this.

Re: The Westfield’s iPhone app privacy smorgasbord

#9
post #6
post #3

So the underlying server is getting hammered with traffic right now, but this really illustrates why you should always be encrypting this kind of thing. Because not only did the developers of the app expose public data, they also managed to post their own source code online by using Pastie (check it out here: http://pastie.org/pastes/1789181 ), and exposed their entire web service documentation here: http://120.151.5…

I hope there's authentication on the signs.json PUT update API, or Westfield's signs are probably about to go crazy...

I have notified ParkAssist (Australia); appropriate contact details were found via the API:

    http://120.151.59.193/v2/email-alerts

Re: The Westfield’s iPhone app privacy smorgasbord

#10
So there's a camera at every spot? Seems like overkill when a simple sensor (IR/magnetic) would have gotten pretty much the same information. Instead of letting a camera guess your tag, just number each spot and send the number of the spot to the phone once you park.
Post reply on HN