This is just sad. I'm sure someone was using the extra information for debugging purposes at one point and never thought to remove it from the json interface.
The Westfield’s iPhone app privacy smorgasbord
11–20 of 37 posts
Re: The Westfield’s iPhone app privacy smorgasbord
#12That is amazing. How are people this short-sighted and reckless with people's data? It's so frustrating. I just told my family that no vehicles are to be parked at a Westfield parking garage until further notice. I'm used to them rolling their eyes at me over data security issues, but I gave them the link to this one and their jaws dropped.
wow, you and i are very different people.
Re: The Westfield’s iPhone app privacy smorgasbord
#13So there's a camera at every spot? Seems like overkill when a simple sensor (IR/magnetic) would have gotten pretty much the same information. Instead of letting a camera guess your tag, just number each spot and send the number of the spot to the phone once you park.
Additionally, this tech is better for the car park owners because they can (are?) using the same technology to check for cars parked too long in a spot. For that you need the number plate.
Re: The Westfield’s iPhone app privacy smorgasbord
#14Re: The Westfield’s iPhone app privacy smorgasbord
#15Earlier quoted context omitted.
I hope there's authentication on the signs.json PUT update API, or Westfield's signs are probably about to go crazy...
I have notified ParkAssist (Australia); appropriate contact details were found via the API: http://120.151.59.193/v2/email-alerts
We cannot thank you enough for notifying us.
Here's what happened:
1. The API should never have been made accessible publicly. The regular authentication that protects API access was incorrectly disabled. We have corrected the configuration and the services are now protected again.
2. The code snippet should never been placed on pastie. We were sloppy in that regard.
While the information in the API is mostly used to get counts of how many spaces in the car park are currently occupied (which you can find out by going to the site and reading the digital signage), any unauthorized access to the data is an unacceptable breach.
We acknowledge that these mistakes should never have occurred and we will need to take a hard look into our security procedures to ensure this does not happen again.
If anyone would like to discuss this issue further, we welcome your comments and advice.
Thanks once again. Ian
Re: The Westfield’s iPhone app privacy smorgasbord
#16It only gets worse.
Re: The Westfield’s iPhone app privacy smorgasbord
#17Further Down the Rabbit Hole: http://westfi48.lnk.telstra.net It only gets worse.
Re: The Westfield’s iPhone app privacy smorgasbord
#18Further Down the Rabbit Hole: http://westfi48.lnk.telstra.net It only gets worse.