7 ms·
Tell HN: Royal Mail Data Leak
Royal Mail (the UK's postal service) has a product called click and drop that allows businesses to pay for and print shipping labels online. It has some value-add features like order-syncing to make buying labels easier. Today when loading pages on click and drop it will show you details from some random account each page load. We saw details of other businesses orders and customer addresses before we logged out and called them about it. We asked another business if they noticed the same and they confirmed that they had.
- andrelaszlo 4y agoOuch. I've seen this happen (luckily never in production) when caches doesn't get keyed properly.
- dcminter 4y agoKlarna (pay-later lender) had a similar production issue a little while back: https://www.klarna.com/us/blog/detailed-incident-report-incorrect-cache-configuration-leading-to-klarna-app-exposing-personal-information/ https://www.klarna.com/us/blog/detailed-incident-report-inco...
- PuffinBlue 4y agoNow currently down for planned maintenance. EDIT: https://clickanddrop.statuspage.io/incidents/8cd3bf2qyz5h https://clickanddrop.statuspage.io/incidents/8cd3bf2qyz5h
- pmx 4y agoThe person I spoke to called me back and said "They've turned it all off". I wouldn't want to be working in their devops team today!
- cr3ative 4y agoSounds like caching issues resulting in a leak, not an explicit breach.
- lmkg 4y agoIt's not a hack, but it's still a breach. A data breach just means that data is accessed by unauthorized parties. Accidental data breaches are not only possible, but common. If a company accidentally emails a group of customers with CC instead of BCC that's technically a data breach, although in most circumstances a low-impact one.
- rrwo 4y agoIf it's actionable by the ICO, it isn't a low impact one either.
- willcipriano 4y agoBreach used in this case is really spin. Calling it what it is, a "inadvertent disclosure" puts the blame where it belongs.
- omginternets 4y agoWe call it a breach because the original sense of the word refers to an opening, tear or rupture. In that sense, this is exactly the correct term. Who or what caused the opening is irrelevant.
- willcipriano 4y agoHey man I'm just trying to get done work, breach my front door and than breach a few cold ones.
- iso1631 4y agoIf a bank left $1b of cash at a bus stop and somebody takes it, it's not an explicit bank robbery, but it's still a theft. This however is worse, as the property they were negligent with wasn't their own property. It's the bank taking your safe deposit contents and leaving it at the bus stop.
- dang 4y agoOk, we've made the title say leak instead. Thanks!
- okasaki 4y agoOne time years ago I visited Youtube and for a few minutes I was logged in as a different user (some guy from North Europe). I could look at their Google profile, etc. It was crazy. I don't think I've ever told anyone (how would it come up?) but this reminded me of it.
- dontbenebby 4y ago[flagged]
- aliqot 4y ago
- ratg13 4y agoProblem with their cache (redis / elasticsearch / etc.) Happens even to the best companies.
- riknox 4y agoInteresting how many people go straight to the cache - seems like we've all been there when we're accidentally overwriting keys with the wrong data! Experience is the best teacher I guess, although we all seem to be doomed to make the same mistakes.
- Crosseye_Jack 4y agoHeck, at least it wasn't DNS... This time. DAMN YOU DNS!
- lambic 4y ago"There are 2 hard problems in computer science: cache invalidation, naming things, and off-by-1 errors." -- Leon Bambrick
- dboreham 4y ago> Happens even to the best companies. Er...no. This is an inexcusable screwup.
- gliffie 4y agoA similar event occured on the Steam Store in 2015 due to a caching problem: https://arstechnica.com/gaming/2015/12/valve-explains-ddos-induced-caching-problem-led-to-xmas-day-steam-data-leaks-and-downtime/ https://arstechnica.com/gaming/2015/12/valve-explains-ddos-i...
- rrwo 4y agoIt seems like good practice is to check data retrieved from the cache is what is expected, e.g. the user id from the cache matches the logged-in user id. Unfortunately, most devs don't think there is ever a need to check that until it fails.
- 3pt14159 4y agoI always put the user id in the cache name. Something like: user_profile_bio.[user_id] If that returns the wrong bio from Redis, then something is broken in Redis, no? Or are you suggesting that I create some sort of format that duplicates the user id in the data itself?
- cr3ative 4y agoWorks great until the Vary configuration on your CDN accidentally drops that.
- contravariant 4y agoShould you add a user_id in the data and check it's the one you want? Yes, I think that is exactly what they're saying, relying on the caching mechanism to handle your data protection sounds like it may be one of the steps involved in the bug Royal Mail is facing. Undoubtedly you are sure this won't ever go wrong, but all it takes is someone else to cache something at user_profile_bio.[customer_id] and you've got a problem (at best it won't work, at worst you'll get the wrong user profile).
- rowid 4y agoWhen I created Amazon account I had some French delivery address and some card. I tried to use it, but they asked for CVV. So I deleted it. And added new one. The account was new and I never used Amazon before. I did received the book thou.
- whywhywhywhy 4y agoAnyone else believe royal mail parcel details are getting siphoned off at some point and sold to scammers. Every time I get a parcel through them I get a phishing sms about the parcel.
- pmx 4y agoThere are a lot of ecommerce integrations with Royal Mail that have access to order data, it's more likely it's one of these 3rd party services selling off the details than it being Royal Mail