TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tell HN: Royal Mail Data Leak

85 pointsby pmxover 2 years ago
Royal Mail (the UK's postal service) has a product called click and drop that allows businesses to pay for and print shipping labels online. It has some value-add features like order-syncing to make buying labels easier. Today when loading pages on click and drop it will show you details from some random account each page load. We saw details of other businesses orders and customer addresses before we logged out and called them about it. We asked another business if they noticed the same and they confirmed that they had.

9 comments

gliffieover 2 years ago
A similar event occured on the Steam Store in 2015 due to a caching problem: <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;gaming&#x2F;2015&#x2F;12&#x2F;valve-explains-ddos-induced-caching-problem-led-to-xmas-day-steam-data-leaks-and-downtime&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;gaming&#x2F;2015&#x2F;12&#x2F;valve-explains-ddos-i...</a>
rrwoover 2 years ago
It seems like good practice is to check data retrieved from the cache is what is expected, e.g. the user id from the cache matches the logged-in user id.<p>Unfortunately, most devs don&#x27;t think there is ever a need to check that until it fails.
评论 #33422155 未加载
okasakiover 2 years ago
One time years ago I visited Youtube and for a few minutes I was logged in as a different user (some guy from North Europe). I could look at their Google profile, etc.<p>It was crazy. I don&#x27;t think I&#x27;ve ever told anyone (how would it come up?) but this reminded me of it.
andrelaszloover 2 years ago
Ouch. I&#x27;ve seen this happen (luckily never in production) when caches doesn&#x27;t get keyed properly.
评论 #33421414 未加载
PuffinBlueover 2 years ago
Now currently down for planned maintenance.<p>EDIT: <a href="https:&#x2F;&#x2F;clickanddrop.statuspage.io&#x2F;incidents&#x2F;8cd3bf2qyz5h" rel="nofollow">https:&#x2F;&#x2F;clickanddrop.statuspage.io&#x2F;incidents&#x2F;8cd3bf2qyz5h</a>
评论 #33420692 未加载
ratg13over 2 years ago
Problem with their cache (redis &#x2F; elasticsearch &#x2F; etc.)<p>Happens even to the best companies.
评论 #33421050 未加载
评论 #33422194 未加载
whywhywhywhyover 2 years ago
Anyone else believe royal mail parcel details are getting siphoned off at some point and sold to scammers.<p>Every time I get a parcel through them I get a phishing sms about the parcel.
评论 #33422333 未加载
rowidover 2 years ago
When I created Amazon account I had some French delivery address and some card. I tried to use it, but they asked for CVV. So I deleted it. And added new one.<p>The account was new and I never used Amazon before.<p>I did received the book thou.
cr3ativeover 2 years ago
Sounds like caching issues resulting in a leak, not an explicit breach.
评论 #33421298 未加载
评论 #33421889 未加载
评论 #33425161 未加载