TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

RSA leaked conference attendees' personal details via unsecured APIs

39 pointsby lnguyenabout 7 years ago

3 comments

Maxiousabout 7 years ago
This was also reported in the 2014 conference app so perhaps they just don&#x27;t care? <a href="http:&#x2F;&#x2F;blog.ioactive.com&#x2F;2014&#x2F;02&#x2F;beware-your-rsa-mobile-app-download.html" rel="nofollow">http:&#x2F;&#x2F;blog.ioactive.com&#x2F;2014&#x2F;02&#x2F;beware-your-rsa-mobile-app-...</a>
thaumaturgyabout 7 years ago
Of course they did.<p>I&#x27;m sure one of the 10,000 &quot;cybersecurity&quot; vendors pimping out their latest SaaS could&#x27;ve prevented all this, if only RSAC had paid the annual enterprise-class subscription fee. Any of the cutting-edge, leading security companies that were there -- like McAfee -- would have protected them if only RSAC were a paying customer.<p>More seriously: there really isn&#x27;t a way to fix this, is there? I mean, in the bigger picture. On the one hand, you&#x27;ve got data being offered wholesale to companies whose homepage pitch is &quot;uses data to change audience behavior&quot;; on the other, you&#x27;ve got the US government, Equifax, and 166 others just in my bookmarks that have all given data away for free out of sheer ineptitude, and had ... pretty much zero consequences for it.<p>So RSAC is a mediocre commercial event, complete with &quot;booth babes&quot; in one vendor&#x27;s case (really? In 2018? WTF is wrong with them anyway?), but they&#x27;re still trying to pretend to be a huge security conference, and if they can&#x27;t get this stuff right either, then I guess we might as well just give up and start talking about life in a post-privacy world.<p>I&#x27;ve read a fair bit of dystopian cyberpunk for dessert reading. I don&#x27;t recall any of the authors being visionary enough to foresee the trading value of personal information.
reilly3000about 7 years ago
Automated pentesting should be a thing that is ubiquitous and free for all developers, like WC3 validation attempted to be for the early web. Mistakes like this and hundreds of others are too easy to make.<p>Also lol rekt. This is sublime irony.<p>It isn’t that conference attendance data is devastating PII, it’s proof that the security industry needs to shrink and become a commodity. That or industry must accept software should be developed slower with greater expense.