Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Bob LeFridge  :tinoflag:
Bob LeFridge :tinoflag:
@BobLefridge@mastodon.nz  ·  activity timestamp 2 weeks ago

Keith Ng at the Herald has a good summary of what's known and where we're at.

"MMH has confirmed that only a single stolen user account was used in the attack. Posing as a normal user, the hackers were able to trick the application interface into providing the files for 127,000 other users. The control mechanisms meant to stop one user from accessing other users’ files had failed, or did not exist."

It sounds like they accessed one person's files, then trimmed the URL to move up a directory or two where they found paydirt.

So less of a hack, more of a problem with poor or non-existent security.

https://archive.md/EXu2y#selection-4127.0-4127.331

#ManageMyHealth

  • Copy link
  • Flag this post
  • Block
Angela Antunovic
Angela Antunovic
@AngelaAntunovic@mastodon.nz replied  ·  activity timestamp 2 weeks ago

@BobLefridge The CEO should be fired. Betcha staff have been pointing out the deficiencies for years.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct