3 ms·
Lot of companies are shooting themselves in their own foot by sharing critical data with a plethora of third-parties. They put sensitive information like usern
by kkm 8y ago
Lot of companies are shooting themselves in their own foot by sharing critical data with a plethora of third-parties.
They put sensitive information like username, orderid in the URL which is then shared with all the third-parties on that page, simply because referrers are not sanitized.
This happens:
- Without user-consent
- More dangerously without the companies knowing it too.
On reporting, the companies do not want to fix these issues.
Shameless plug: You can find some of such cases, which I've been trying to highlight to the companies:
- https://medium.freecodecamp.org/how-airlines-dont-care-about-your-privacy-case-study-emirates-com-6271b3b8474b https://medium.freecodecamp.org/how-airlines-dont-care-about...
- https://threatpost.com/def-con-2018-telltale-urls-leak-pii-to-dozens-of-third-parties/134960/ https://threatpost.com/def-con-2018-telltale-urls-leak-pii-t...
- https://cliqz.com/en/magazine/lufthansa-data-leak-what-a-single-url-can-reveal-about-you https://cliqz.com/en/magazine/lufthansa-data-leak-what-a-sin...
- https://fosdem.org/2019/schedule/event/web_extensions_exposing_privacy_leaks/ https://fosdem.org/2019/schedule/event/web_extensions_exposi...