Lot of companies are shooting themselves in their own foot by sharing critical data with a plethora of third-parties.
They put sensitive information like username, orderid in the URL which is then shared with all the third-parties on that page, simply because referrers are not sanitized.
This happens:
- Without user-consent
- More dangerously without the companies knowing it too.
On reporting, the companies do not want to fix these issues.
Shameless plug: You can find some of such cases, which I've been trying to highlight to the companies:
- https://medium.freecodecamp.org/how-airlines-dont-care-about...
- https://threatpost.com/def-con-2018-telltale-urls-leak-pii-t...
- https://cliqz.com/en/magazine/lufthansa-data-leak-what-a-sin...
- https://fosdem.org/2019/schedule/event/web_extensions_exposi...