Live data from Hacker News

An insurance company’s API exposed customers’ car location histories

andreascarpino.it

11–20 of 69 posts

Re: An insurance company’s API exposed customers’ car location histories

#11
post #9
post #5

Earlier quoted context omitted.

Funny, you don't name it either.

Naming it on a suspicion alone would be irresponsible.

That's a qualified statement, there is nothing irresponsible about that. Telematics companies bear close watching anyway. Right now it is as far as I'm concerned a content free statement.

Re: An insurance company’s API exposed customers’ car location histories

#12
post #6

Earlier quoted context omitted.

I have a feeling it's a subtly different problem: the people they've contracted to build this just don't understand security. They've evidently attempted to secure this, just in completely the wrong manner!

Here's an interesting thought: what with the money there is to be made in security these days programmers that actually know everything there is to know about security will leave applications development. There is a good chance that the lure of security consultancy $ is resulting in a degradation of the quality of the applications.

Apart from this time to market is also one of the reasons that such things get released to end customers.

Re: An insurance company’s API exposed customers’ car location histories

#13
The EU and its member countries are still interested in personal privacy. Do they regulate insurance providers? Could EU, or Italy, exact a penalty against this provider for failing to do the most elementary of penetration tests on this system? Perhaps some of the penalty should be a return of premium payments to customers whose information was potentially exposed.

The point is to make the business-risk managers in other provider companies say to their executives: "We cannot take the risk of skipping cybersecurity hardening. If we do skip it and we get caught, our business will be forced into bankruptcy."

Re: An insurance company’s API exposed customers’ car location histories

#14
post #9

Earlier quoted context omitted.

Naming it on a suspicion alone would be irresponsible.

That's a qualified statement, there is nothing irresponsible about that. Telematics companies bear close watching anyway. Right now it is as far as I'm concerned a content free statement.

It's absolutely irresponsible, even with qualifications, given what we now know about how people use that information. Witch hunts happen even with qualified statements, and down the road people who read qualified statements tend to forget the qualification and give the negativity more weight than it deserves.

Re: An insurance company’s API exposed customers’ car location histories

#18

It's a shame he can't name the telematics company. I have a suspicion it's one I interviewed at a few years ago.

They would probably turn around and sue him for unauthorized use of their API or some such nonsense.

Re: An insurance company’s API exposed customers’ car location histories

#19
post #10

Earlier quoted context omitted.

I have a feeling it's a subtly different problem: the people they've contracted to build this just don't understand security. They've evidently attempted to secure this, just in completely the wrong manner!

Actually, the parent is correct. If the company providing the service were financially liable for these blunders, they would be careful to select contractors that are capable of meeting the security needs. As it is now, there is no financial incentive to select the "security aware" contractor, and the "non-aware" one is so much cheaper...

Or rather they would hire more pentesters to make sure the sw they get is robust. On paper everyone can write "secure" apps...

Re: An insurance company’s API exposed customers’ car location histories

#20

it's really sad how young online political activists have adopted privacy issues instead of adopting issues like workers rights, vacation time, pay, a strong welfare state, universal healthcare etc...

The struggle for privacy and for workers rights, vacation time etc. can coexist, I don't see anything wrong in that.
Post reply on HN