Lemonade says website security flaw is ‘by design’
techcrunch.com
techcrunch.com
The user shouldn't then complain if they give the link to everyone on the web via social media.
This exact pattern is also something less legit security researchers do deliberately to try to coerce companies into paying bounties. They deliberately try to leak OAuth tokens, verification URLs, Auth cookies and other secrets into Google search results, and then claim your site is insecure because "anyone with Google can see my private data!"
Any recommendations for a replacement?
"1/ Let’s set things straight up front: What @muddywatersre found were links to 4 insurance quotes shared by Lemonade users themselves. (aka, they loved it so much, they shared ‘em).
That is not a vulnerability, it’s by design!"
"2/ We designed our quotes to be shareable. If someone wants to send their quote to their family, friends, or mortgage bank, they can. Btw, turns out people post their quotes on Pinterest and UX blogs, and these are the ones they stumbled upon"
"3/ Since Google indexes Pinterest and blogs, these links end up being discoverable on Google."
What’s the actual vulnerability here?
The only “vulnerability” is the short seller saying that they were able to log into the users account, but if they were able to log into the users account, why were they only able to access their name and quote, information the users had chosen to share publicly, and were not able to access a whole host of other data that would be available if one were able to log in to a users account.
MW made a video: https://youtu.be/ILcjmnFCID8