3 ms·
It's still a breach if an org misconfigures an API, allowing more records to be available than was indended.
by wslack 5y ago
It's still a breach if an org misconfigures an API, allowing more records to be available than was indended.
- uoaei 5y agoMens rea is honestly a mistake. I don't care what the org "intended" to do. The org assumed the responsibility of providing an API and with it the responsibility of securing private data. They failed and should be held culpable. Boeing doesn't call it a "cyberattack" when their altitude control systems fail because of poor design.