My car insurance exposed my location
scarpino.xyz
scarpino.xyz
> The company fixed the leak 3 weeks later by providing new Web services endpoints that use authenticated calls. The company mailed its users saying them to update their App as soon as possible. The old Web services have been shutdown after 1 month and half since my first contact with the CERT Nazionale.
> I could be wrong, but I suspect the privacy flaw has been around for 3 years because the first Android version of the App uses the same APIs.
> I got no bounty.
> The company is a leading provider of telematics solutions.
I wonder how much that flaw would have fetched from a malicious actor?
And that's a situation that the US legal system isn't well set up for.
This is the kind of thing that should result in a fine of millions of dollars. They never even tried to secure this.
It's mentioned. From the blog post: "besides the ugliest formatting ever and the fact the request uses plain HTTP"