Look,Watch Sex (1994) Part 1 we get it. Cybersecurity is hard. But maybe, just maybe, a conference dedicated to computer security and encryption should know better than to leave attendee information exposed via its conference mobile app.
And yet.
SEE ALSO: Tech conferences like RSA still have a diversity problemAs the RSA Conference winds down today in San Francisco organizers have been forced to acknowledge that all has not been right with their own house. Specifically, a security engineer looking into the RSA Conference Mobile App discovered that at least some user information was exposed to anyone who knew where to look.
This Tweet is currently unavailable. It might be loading or has been removed.
"[It] was the API from http://eventbase.com that was used by the RSA conference app," the researcher, who goes by svbl, explained over Twitter direct message. "[The] vulnerability was on eventbase' side."
Svbl tweeted out the steps he took to access the information and alerted organizers to what might generously be called an oversight.
This Tweet is currently unavailable. It might be loading or has been removed.
The RSA Conference responded and quickly resolved the vulnerability, but, shall we say, the response didn't really cop to the fact that organizers baked a vulnerability into their app.
"Our initial investigation shows that 114 first and last names of RSA Conference Mobile App users were improperly accessed," read a statement. "No other personal information was accessed, and we have every indication that the incident has been contained."
This Tweet is currently unavailable. It might be loading or has been removed.
That only 114 first and last names were accessed isn't because of some magic cybersecurity protections. Rather, it's because svbl limited his probing to just a peek — merely to confirm the vulnerability — before reporting it.
This Tweet is currently unavailable. It might be loading or has been removed.
Notably, this isn't the first time the RSA Conference has blundered with its conference app.
"This isn’t surprising," tweeted the engineer and hacker Ming Chow. "Let me remind you of the RSA Conference 2014 app that downloaded all attendees’ names into SQLite DB."
This Tweet is currently unavailable. It might be loading or has been removed.
And, to make matters worse, this wasn't the only problem members of the cybersecurity community had with the conference app. Specifically, the permissions the app required raised a lot of eyebrows.
This Tweet is currently unavailable. It might be loading or has been removed.
Thankfully for attendees, svbl appears to have had no ill intentions.
"[I] only pulled a sample of data (~100 records) before i reported it to RSA directly and as you saw they fixed it very quick (which is awesome)," the researcher wrote to us.
And while a fast response is great, still, come on. Security professionals like those at the RSA Conference shouldn't count on the goodwill of third-party researchers to keep attendee data secure. But somehow, though, that's exactly where we are.
Topics Cybersecurity
Balzac and the Reassembly of France by Jérôme DavidStaff Picks: Moscow, Misunderstandings, and Money Mark by The Paris ReviewThe Ragpicker: Frédéric Pajak’s ‘Uncertain Manifesto’How I Began to Write by Gabriel García MárquezWalter Benjamin in Ibiza by Frédéric PajakStaff Picks: Features, Films, and Flicks by The Paris ReviewSkate Escape: On ‘Minding the Gap’A Mail Carrier Bikes the Wasteland by GébéDressing for Others: Lawrence of Arabia’s Sartorial Statements by Isabella HammadMeet Your New Favorite Poet by Anthony MadridWhiting Awards 2019: Nadia OwusuStaff Picks: Spells, Cephalopods, and Smug Salads by The Paris ReviewThe Genius of Terry Southern by David L. UlinRedux: The StoneBalzac and the Reassembly of France by Jérôme DavidA Tribe Called Quest Is Gone, but HipBeyond the Narrative Arc by Jane AlisonOne Word: Dipshit by Halle ButlerWhiting Awards 2019: Terese Marie Mailhot, NonfictionAmerican Blood: An Interview with Mitchell S. Jackson by Annie DeWitt Starbucks says it's going to block porn on its public WiFi How to use Apple's Live Captions for iPhone, iPad, and Mac devices Neil DeGrasse Tyson being investigated for sexual misconduct Netflix's 'Resident Evil' has 1 moment I still can't get over 'Xenoblade Chronicles 3' review: Persist and ye shall be rewarded Sneaky otter evades capture after feasting on garden's prized koi Tony Hawk sings with 'Tony Hawk's Pro Skater' cover band in London bar Spotify launches Friends Mix, your new personalized playlist with friends Barack Obama's 2022 summer playlist has bangers aplenty Putin and Saudi Crown Prince got real bro Wordle today: Here's the July 25 Wordle answer and hints 20 gifts for people who've been burned by 2018 Jameela Jamil goes viral with her comments about 'why airbrushing should be illegal' Wordle today: Here's the July 27 Wordle answer and hints How to navigate the world of internet pet adoption with your kids Laura Loomer's IRL Twitter protest has become ... a Twitter meme 19 wild headlines from 2018 that sadly aren't from The Onion Big animals had a big week Wordle today: Here's the July 30 Wordle answer and hints Announcer sings 'Mr. Plow' song from 'The Simpsons' during Apple Cup blizzard
2.1643s , 10131.6328125 kb
Copyright © 2025 Powered by 【Watch Sex (1994) Part 1】,Miracle Information Network