Sign In

Communications of the ACM

ACM News

38M Records Were Exposed Online—Including Contact-Tracing Info

View as: Print Mobile App Share:
The Power Apps logo.

Secure default settings matter, says Kenn White, director of the Open Crypto Audit Project. When a pattern emerges in Web-facing systems built using a particular technology that continue to be misconfigured, something is very wrong."

Credit: Microsoft

More than a thousand web apps mistakenly exposed 38 million records on the open internet, including data from a number of Covid-19 contact tracing platforms, vaccination sign-ups, job application portals, and employee databases. The data included a range of sensitive information, from people's phone numbers and home addresses to social security numbers and Covid-19 vaccination status.

The incident affected major companies and organizations, including American Airlines, Ford, the transportation and logistics company J.B. Hunt, the Maryland Department of Health, the New York City Municipal Transportation Authority, and New York City public schools. And while the data exposures have since been addressed, they show how one bad configuration setting in a popular platform can have far-reaching consequences.

The exposed data was all stored in Microsoft's Power Apps portal service, a development platform that makes it easy to create web or mobile apps for external use. If you need to spin up a vaccine appointment sign-up site quickly during, say, a pandemic, Power Apps portals can generate both the public-facing site and the data management backend.

From Wired
View Full Article



No entries found