Look,musee eroticism paris we get it. Cybersecurity is hard. But maybe, just maybe, a conference dedicated to computer security and encryption should know better than to leave attendee information exposed via its conference mobile app.
And yet.
SEE ALSO: Tech conferences like RSA still have a diversity problemAs the RSA Conference winds down today in San Francisco organizers have been forced to acknowledge that all has not been right with their own house. Specifically, a security engineer looking into the RSA Conference Mobile App discovered that at least some user information was exposed to anyone who knew where to look.
This Tweet is currently unavailable. It might be loading or has been removed.
"[It] was the API from http://eventbase.com that was used by the RSA conference app," the researcher, who goes by svbl, explained over Twitter direct message. "[The] vulnerability was on eventbase' side."
Svbl tweeted out the steps he took to access the information and alerted organizers to what might generously be called an oversight.
This Tweet is currently unavailable. It might be loading or has been removed.
The RSA Conference responded and quickly resolved the vulnerability, but, shall we say, the response didn't really cop to the fact that organizers baked a vulnerability into their app.
"Our initial investigation shows that 114 first and last names of RSA Conference Mobile App users were improperly accessed," read a statement. "No other personal information was accessed, and we have every indication that the incident has been contained."
This Tweet is currently unavailable. It might be loading or has been removed.
That only 114 first and last names were accessed isn't because of some magic cybersecurity protections. Rather, it's because svbl limited his probing to just a peek — merely to confirm the vulnerability — before reporting it.
This Tweet is currently unavailable. It might be loading or has been removed.
Notably, this isn't the first time the RSA Conference has blundered with its conference app.
"This isn’t surprising," tweeted the engineer and hacker Ming Chow. "Let me remind you of the RSA Conference 2014 app that downloaded all attendees’ names into SQLite DB."
This Tweet is currently unavailable. It might be loading or has been removed.
And, to make matters worse, this wasn't the only problem members of the cybersecurity community had with the conference app. Specifically, the permissions the app required raised a lot of eyebrows.
This Tweet is currently unavailable. It might be loading or has been removed.
Thankfully for attendees, svbl appears to have had no ill intentions.
"[I] only pulled a sample of data (~100 records) before i reported it to RSA directly and as you saw they fixed it very quick (which is awesome)," the researcher wrote to us.
And while a fast response is great, still, come on. Security professionals like those at the RSA Conference shouldn't count on the goodwill of third-party researchers to keep attendee data secure. But somehow, though, that's exactly where we are.
Topics Cybersecurity
This resistance group is sending Trump notes on toilet paperTom Hardy reads another bedtime story, breaks the internet againCraig David's cover of Justin Bieber song is definitely better than the originalHong Kong elects its first female leader and makes her the butt of a rude joke'Glitter booty' is the latest bizarre beauty trend you've secretly always wanted'Star Wars Rebels' finale: Watch Thrawn throw downMelissa McCarthy reveals how her perfect Sean Spicer impression came into being'The Melbourne Jacket' is kinda crazy, but so is Melbourne's weatherFeast your eyes on NASA's stunning 'farewell to Pluto' photoAaron Sorkin is just now discovering there's a diversity problem in HollywoodLittle hedgehog rolls off a pink pillow to save your MondayChris Rock and Dave Chappelle surprised New Orleans fans with spontaneous standSingapore's big plans for nationwide bikeAre Passwords Dead? What Are Passkeys, and Why Everyone's Talking About ThemInfowars apologizes for spreading #Pizzagate conspiracyOne Direction's Liam Payne is officially a fatherGoogle now offers a free Android app every weekThis week in apps: Mario 'runs' onto Android, Uber for teens and a Google search redesignFrom Buzzfeed to Watcher, how Ryan Bergara built a career on ghostsThe trailer for Harry Styles' solo debut has everyone freaking out Need a Story for Your Commute? Look to the Vending Machine I Thought My Dad Had No More Secrets to Tell, But... Moebius and the Key of Dreams: On Jean Giraud's Astonishing Multiverse In Sixteenth Young Artists: No Social Media Following? Just Buy One. Elliot Paul’s “The Last Time I Saw Paris” (1942) W. Eugene Smith’s Obsessive, Quixotic Documentary Work The Lights Dim at La Pagode, One of Paris’s Best Cinemas Portable People: Short Fiction by the Late Paul West The Lumpy, Crowded Graveyard: On Necrotopology and Memory You Could Own Edith Wharton’s Sterling Silver Baby Rattle The Certainty of Documentary Uncertainty. The Altars in Mitla: Visiting Mexico on Dia de los Muertos 100 Years Ago, Cinema Saw Its First Nude Floating Capital: A Tour of Levitating Businessmen in Literature The History of the Yew Tree, “The Tree of the Dead” Gothic Horror and the Odd Appeal of “Melmoth the Wanderer” Ragnar Kjartansson Uses Clichés to Destroy Western Culture Some Are More Human Than Others: Stevie Smith’s Sketches At Tokyo’s Book and Bed, Readers Are Encouraged to Doze Off
3.6516s , 10195.78125 kb
Copyright © 2025 Powered by 【musee eroticism paris】,Exquisite Information Network