Live data from Hacker News

Moonpig.com Vulnerability – Exposes customer data

ifc0nfig.com

111–120 of 124 posts

Re: Moonpig.com Vulnerability – Exposes customer data

#111

Earlier quoted context omitted.

Or don't do it in the first place, because it's obviously wrong...

> because it's obviously wrong... // Are you trying to say it's morally wrong to read data made publicly available through a site's API? I think that's a stretch. Clearly there are very obviously malevolent things you could do with data acquired with such queries, but just iterating on a URL query string seems pretty far from an obvious moral wrong. Legally questionable, for sure. Morally forthright, doubtful. The wr…

> Are you trying to say it's morally wrong to read data made publicly available through a site's API? I think that's a stretch. Clearly there are very obviously malevolent things you could do with data acquired with such queries, but just iterating on a URL query string seems pretty far from an obvious moral wrong.

I used to think this. But I changed my opinion and yes, in this particular instance, it's pretty much unambiguously morally wrong.

Why did I change my opinion? Because the previous one was wrong (morally). Ethics isn't rocket science or brain surgery. Well, maybe a little like brain surgery.

I could download that data and IMO, it'd be wrong to do so. I'm not always a good person, even by my own standards of ethics, so I might download that data. I wouldn't use the data maliciously because IMO that'd be even wronger (but by now why are you taking my word for this? I already violated my own ethical code once!). So all in all (if you take my word for it), the consequence of me downloading that data is strictly less bad than some malicious actor doing the same. I'm not really a big fan of Consequentialist Ethics. It's nice in theory (say, Utilitarianism), but in practice people simply have to use a derived code, which is not always as clearly defined. I like to keep my hypocrisies at surface-level.

So I could do it, things would probably turn out right for everyone involved, but I'm not going to kid myself and tell myself it's not wrong to do so in the first place.

(Also, there's the risk where having a copy of the data could mean I could lose control of it, fall into more malicious hands, and that'd be bad. Practical considerations I do not disagree with, but I should not need these to determine whether something is right or wrong)

Re: Moonpig.com Vulnerability – Exposes customer data

#112

Earlier quoted context omitted.

If this were the USA it would certainly be bad enough to warrant prosecution of the researcher. I am not familiar with laws in the UK, however. Keep in mind the similarities between this research and weev's research. This type of blatant insecurity definitely should be punished and I wish more policy makers both cared, and made the effort to understand the terminology behind phrases like "No authentication", "Plainte…

> If this were the USA it would certainly be bad enough to > warrant prosecution of the researcher Sounds like he didn't access any data he wasn't allowed to, if he read the data of test accounts. Not sure how you'd prosecute this in the UK. Also you'd need to convince the CPS that it was in the public interest to prosecute, and they're not elected officials who need to appear Tough On Crime unlike the US. And even i…

In the UK the relevant law AFAIK is the Computer Misuse Act, http://www.legislation.gov.uk/ukpga/1990/18/.

He has authorisation to access the data, and authorisation to access the computers in question. He doesn't, perhaps, have authorisation to use the specific mode of access but that isn't pertinent to the Act as written AFAICT.

The only possible part he falls foul of is Section 3(3) in that his actions might have caused the system to fail, but "recklessly" has a suggestion of him knowing that such deleterious outcomes were likely, and I don't think that's really true. I think his actions as reported are not in breach of this Act.

However, the proposed Section 3A will cover such actions if he [the reporter of the security lapse] believes that the information (see 3A(4)) he published is likely to be used to assist in the commission of an offence.

>"A person is guilty of an offence if he supplies or offers to supply any article believing that it is likely to be used to commit, or to assist in the commission of, an offence under section 1 or 3." (CMA 1990, proposed S.3A(2))

This section is exceptionally broad. Indeed it appears to outlaw the disclosure of bugs found without malice and without intent. Communicate to Google, say, a program/data that could be used to break in to their system and it seems you fall foul of the letter of that Section. Chilling indeed.

Re: Moonpig.com Vulnerability – Exposes customer data

#113
post #32

It's astonishing that somewhere out in the modern world there's an api that returns personally identifiable information without requiring any sort of authentication. What I find absurd is that the company hasn't done anything about it. Even if they don't care/know about security they must at least care for bad PR... But with all of that in mind, I don't know what's the best way to fight these clueless behemoths. You…

> They should be waterboarded

Except, you know, for the part where that is an inhumane thing to do, even when done to people that are actually guilty of committing terrible crimes.

> It's astonishing that somewhere out in the modern world there's an api that returns personally identifiable information without requiring any sort of authentication.

Hello, have you met the 21st century? It's a freakshow and clusterfuck of planetary proportions. Although even accepting that fact, yes, I suppose that doesn't make it less astonishing. Spoiler alert: things will probably get even more astonishing before it gets less. Fasten your seatbelts, wear a hat, etc.

Re: Moonpig.com Vulnerability – Exposes customer data

#114
post #14

http://www.conosco.com/case-studies/moonpig-outsourced-it/ >Protection against cyber attacks Wow...

They've already removed it...

Google cached version: http://webcache.googleusercontent.com/search?q=cache:gkzZ7YK...

Re: Moonpig.com Vulnerability – Exposes customer data

#115
post #27

This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data. Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer. Dealing with this via legal chann…

Probably downvoting because the whole (ir)responsible disclosure discussion has been had, for decades, with all arguments from all sides and repeating it here, again, would be just going through the motions.

Re: Moonpig.com Vulnerability – Exposes customer data

#116
post #43

Earlier quoted context omitted.

You're getting mad at the wrong person here, full stop. This is gross, inexcusable negligence and incompetence. I'm surprised this guy didn't wait more than a few months, given the severity of this problem. > whilst protecting customer data from any opportunistic bad actor Riiiight. Do you honestly think something this basic wouldn't be discovered by criminals soon, if not already?

I would say that the period August 2013 to January 2015 is more than "a few months".

My wording was crappy there. I meant I'm surprised he didn't wait just a few months. As in, I'm surprised he didn't get impatient and do this earlier.

Re: Moonpig.com Vulnerability – Exposes customer data

#117
post #87

Earlier quoted context omitted.

> WOW. You are a terrible human being. Yes, heaven forbid someone qualified run their IT dept. What's he supposed to do? Sit around, idly hoping that someone else notices the incompetence? I think OP made the right move. To me it sounds like the guy should have been fired rather than demoted.

really David ? Come on. How many times you made mistake ? Were you demoted and/or fired for mistake ? Now, let's not argue that you or all of us has not fucked up. In my 7 yrs. as engineer I have seen worse. However, that's not excuse to run to boss/CEO to demote someone and take over their job. Think about their family,kids before you do such act. If you defend such behavior for taking over job/demotion I seriously…

Everyone has made mistakes. But it takes a certain special person to stick their head in the sand when their mistakes are pointed out.

Make your mistake, take responsibility, learn and continue on.

Re: Moonpig.com Vulnerability – Exposes customer data

#118

Earlier quoted context omitted.

I don't think there's any ambiguity here. Deliberately downloading personal information—clearly not intended to be released publicly—does not seem to be a defensible action. We're not talking about downloading a couple of records and alerting someone about it, after all.

> does not seem to be a defensible action // What harm is there in viewing data? None. Defended. Which do you find is indefensible, seeking to consume data or consuming it? Or, does one need to actively seek it and also consume it to cross your threshold of immorality? Or ...

What harm is there in viewing data? None.

Yes there is – you've consumed other people's data without permission.

Would the same apply to physical trespass in your mind? Is there any harm in entering an accidentally unlocked house and snooping around? There's nothing preventing you from doing so...

I'd argue that it's wrong, and equivalent to consuming data which is obviously intended to be private. It's not like there's ambiguity about it's status.

Which do you find is indefensible, seeking to consume data or consuming it

Surely you can only consume data if you seek to do so?

Re: Moonpig.com Vulnerability – Exposes customer data

#119
post #97

Earlier quoted context omitted.

I agree, and feel that the EFF made quite the strategic error in supporting Auernheimer's appeal.

“ The trouble with fighting for human freedom is that one spends most of one’s time defending scoundrels. For it is against scoundrels that oppressive laws are first aimed, and oppression must be stopped at the beginning if it is to be stopped at all. ” — H. L. Mencken

> "For it is against scoundrels that oppressive laws are first aimed..."

[Citation Needed]

Re: Moonpig.com Vulnerability – Exposes customer data

#120

To anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.

> That is exactly what weev was arrested and convicted for. Please don't spread this misinformation, the USA justice system doesn't work (... like that). Weev was arrested for having a (very, very ) loud mouth and pissing off the wrong, powerful people/businesses/corporations. If he'd have enumerated customer IDs for a smaller, lesser-known company such as Moonpig, reported it to the media like he did, without being…

There is more context to his arrest but the actions and evidence supporting his conviction were as I described.
Post reply on HN