5 ms·
Qantas app data breach allows customers to access strangers' booking details
- justinclift 2y agoSounds like an incorrectly scoped WHERE (or maybe even JOIN?) on a SQL query. Plus inadequate (automatic) testing, that should have caught the problem before it was committed to the main development tree.
- selalipop 2y agoSounds more like a typical caching issue than anything
- justinclift 2y agoGood point, yeah that would do it too.
- spondyl 2y agoYeah, it sounds pretty identical to a caching issue that happened to Steam way back on Christmas Day of 2015: https://store.steampowered.com/oldnews/19852 https://store.steampowered.com/oldnews/19852
- lathiat 2y agoYep, plenty of these that have come up over time. Can't think of the names of them at this point but I am sure I recall at least 5+ incidents of exactly this caused by incorrect caching.
- dools 2y agoThis isn’t really a data breach, it’s a bug in the app. And it didn’t “allow people to access strangers details” it showed each person the wrong details after they logged in. Like you couldn’t then pick another person and view their details you were just logged into the wrong account. Still pretty dumb, but also pretty dumb reporting. But then it’s 7 news so …
- NoPicklez 2y agoIt's a bug in the app which has caused a data breach unintendedly But it is not a wide scale data breach caused my a malicious person no
- Narkov 2y ago> This isn’t really a data breach, This is totally a data breach. Show another customers data to a random person = data breach. People had access to valid boarding passes for flights they had no right to board. > it’s a bug in the app. Generally, bugs are responsible for most data breaches. > And it didn’t “allow people to access strangers details” it showed each person the wrong details after they logged in. You are downplaying the incident here. "Strangers" definitely did "access" other peoples' information. Just because it wasn't malicious doesn't mean data hasn't been breached.
- dools 2y ago> This is totally a data breach. Show another customers data to a random person = data breach. Yep you're right, legal definition of a data breach includes "someone’s personal information is sent to the wrong person." https://www.oaic.gov.au/privacy/your-privacy-rights/data-breaches/what-is-a-data-breach https://www.oaic.gov.au/privacy/your-privacy-rights/data-bre... > Generally, bugs are responsible for most data breaches. Sometimes. I don't think you could call all security vulnerabilities bugs. In this case, it was a bug that showed people the wrong flight details. > You are downplaying the incident here. "Strangers" definitely did "access" other peoples' information. Just because it wasn't malicious doesn't mean data hasn't been breached. Well I'm downplaying from the over sensationalised (in my opinion) language in the article. Strangers saw the wrong person's flight details so access was given to that information, but the way it's worded makes it sound as though a stranger was able to pick a person and view their information, or download a bunch of information and view it. To me, seeing one other person's flight details when you login is far less dramatic. Like the headline here could refer to a vulnerability in their system which enabled me to, say, vary a query parameter or change the email in settings to any email and then see that person's flight details. The case is more like accidentally sending a text message to someone with the wrong flight details and allowing them to reply Y or N to confirm the flight. If the headline said "Bug in Qantas app shows people the wrong flight details" (which I think is a much more accurate description of what happened) we probably wouldn't be having this discussion and 7news would have missed out on about 100k hits (although to be fair the HN crowd is probably pretty skewed towards using ad blockers ... )
- contingencies 2y agoPerhaps a whole integer session key value store combined with some form of refresh or update leading to user/session mismatches.
- deleted 2y ago[deleted]
- ec109685 2y agoPII data should be stored in encrypted form with tightly controlled keys. Web servers should decrypt on an as needed basis by exchanging user cookies / token for decryption keys. That prevents having “god” servers in the frontend serving path that are a malformed sql query away from exposing all data.