this post was submitted on 23 Sep 2024
209 points (97.7% liked)

Privacy

31363 readers
1249 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 57 points 3 days ago (7 children)
[–] [email protected] 13 points 3 days ago (6 children)

Probably smart to take it down. What he did could be construed as hacking.

[–] [email protected] 27 points 3 days ago (4 children)

I have no idea what the law is in India, but if he got a "hacking" charge for this it would be a gross miscarriage of justice, considering he never once did anything resembling social engineering, brute forcing passwords, any sort of injection attack, or anything else that might actually be involved in hacking.

However, assuming he never tried to reach out to the company themselves first (and I saw no indication in the article that he had), this is really quite a horrible irresponsible disclosure. It's pretty obviously a significant leak of sensitive data—both customer and business data—and giving them 90 days to fix it before alerting the public to what you found is pretty basic security ethics.

[–] [email protected] 6 points 3 days ago

there's a security researcher in the US currently being sued by some state because he downloaded breached data from TOR that the state was saying didn't leak.

load more comments (3 replies)
load more comments (4 replies)
load more comments (4 replies)