The email mostly makes it sound like what’s in the user account table, though last 4 of credit card I didn’t think was in it. And mentioning passwords, not salted/hashed passwords, makes me think it was more.
I’m wondering if this is an Apache or Apache Rivet issue that possibly intercepted everything you sent to the server, which could then be your actual password if you logged in during the timeframe or even credit card if you bought something.
Also Rivet was full of footguns. IIRC, variables would exist for the life of the Apache child, so you had to clear them out or the next request had access to them, so if someone deleted or didn’t run the huge “delete all variables we probably set” proc, and someone was able to get an “info var” output, they’d see everything set in the previous request or further back if nothing overrode it. Like user info, which was just stored in a big global “user” array
The blog mentions recently moving away from TCL. Could it have been related to that?
Do you have an idea why the emails arrive as a drip, spread over days?
Also, Raytheon doesn't ever talk to the public. Most of the work is classified so yea, crisis communication involving the general public, internally, they are clueless.
Tcl and Rivet to me says the code is from the 1990s or 2000s. Does FlightAware go back that far? Otherwise I am surprised at those choices for anything newer.
Frontend code would vary with whatever flavor a developer liked at the time, but the backend was still always going through Rivet/TCL.
ICs would complain about it but the founders cashed out to the tune of 9 figures in the end, so it worked out for them.
I’ll agree that TCL isn’t inherently insecure, but you aren’t getting any libraries or frameworks with it either to make your life easier or safer.
They seem to use some email delivery service that can't handle sending an email to all users within an hour.
Got the same prompt when I logged in - no email despite their insistence they sent it.