Live data from Hacker News

An insurance company’s API exposed customers’ car location histories

andreascarpino.it

21–30 of 69 posts

Re: An insurance company’s API exposed customers’ car location histories

#21

It's a shame he can't name the telematics company. I have a suspicion it's one I interviewed at a few years ago.

This sparked my curiousity, but I had to find out all insurances use blue as their main color :)

Re: An insurance company’s API exposed customers’ car location histories

#22
post #6

Earlier quoted context omitted.

I have a feeling it's a subtly different problem: the people they've contracted to build this just don't understand security. They've evidently attempted to secure this, just in completely the wrong manner!

Here's an interesting thought: what with the money there is to be made in security these days programmers that actually know everything there is to know about security will leave applications development. There is a good chance that the lure of security consultancy $ is resulting in a degradation of the quality of the applications.

Are you saying developers in general are subconsciously making low security products to raise the $ in security jobs globally, because they might some day switch career?

Re: An insurance company’s API exposed customers’ car location histories

#23
post #7

So they had this vulnerability live for 3 years, didn't even pay a bounty, and they still don't get named or shamed? What incentive is there to do a better job if they can just do a shitty job and nobody finds out? Name and shame, please!

she was a waitress in a cocktail bar now she owns a BMW car... http://bit.ly/2jdTzrM

Re: An insurance company’s API exposed customers’ car location histories

#24

it's really sad how young online political activists have adopted privacy issues instead of adopting issues like workers rights, vacation time, pay, a strong welfare state, universal healthcare etc...

Generally they have adopted a lot of those, but privacy is kind of our specialisation as tech people. Often we see it as a necessary prerequisite to the others. Especially worker's rights: mass surveillance is used against worker organisation.

Dismissing people focusing on "X" instead of "Y" is useless and disruptive.

Re: An insurance company’s API exposed customers’ car location histories

#25
I can't believe that anyone would voluntarily sign up for this. Frankly, insurance isn't that expensive.

Having a little third party controlled snitch hooked to your car is a security issue, period. The fact that the implementation is a shitshow is just icing on the cake.

Re: An insurance company’s API exposed customers’ car location histories

#29

No mention of the irony of someone who doesn't use Google Play Services because he only uses open source software being willing to attach a device to his car, running closed source software, that tracks everything he does in his car?

I think I have a similar attitude. I have Google's location tracking on, but search history, YouTube history, etc turned off. I'm much more sensitive to digital privacy because it has complex, wide-ranging implications, whereas my location is a limited set of data that I'm more comfortable sharing with a semi-trusted company.

Re: An insurance company’s API exposed customers’ car location histories

#30
post #26

Post-GDPR this would have resulted in a 20 million euro fine.....

Could have, not "would" have - the fine is variable. I doubt it'll get enforced regularly.

The GDPR is vague but the description details shockingly vulnerable APIs that do not come close to "industry best practices". They would have been made an example of.
Post reply on HN