时间:2026-03-13 17:34:04 来源:网络整理编辑:熱點
It's a bad day for would-be tech watchdogs and gossips.The tech industry whistleblower and survey si
It's a bad day for would-be tech watchdogs and gossips.
The tech industry whistleblower and survey site Blind temporarily exposed user data when it left a server functioning without password protection. That's according to TechCrunch, whose new report not only uncovered the server lapse, but also called into question Blind's claims of privacy and complete user anonymity.
SEE ALSO:Blind: The hot app where all the best Silicon Valley gossip is read right nowA South Korean company, Blind is a site that allows tech industry employees to anonymously discuss their companies with colleagues. It also regularly produces surveys about sensitive topics like workplace harassment and diversity that it then distributes to the press. Blind gained prominence when discussions on the platform exposed sexual harassment at Uber. According to TechCrunch, it just secured $10 million in a new round of funding.
Central to Blind's functioning are its claims of privacy and user anonymity. Without this assurance, employees would likely feel uncomfortable discussing their employers.

The unprotected server reportedly showed logins, messages, and interactions,"allowing anyone to read private comments and posts."
Blind responded to the report saying that the unprotected server was an isolated incident that affected users who logged in between Nov. 1 and Dec. 19. Blind said it sent a push notification to affected users within the app.
“While developing an internal tool to improve our service for our users, we became aware of an error that exposed user data,” Blind reportedly wrote.
In addition to account activity, Blind protects its users by disassociating work email addresses from accounts. Blind says that it does not store email addresses, and only creates unique tokens from emails once you sign up.
"Email verification is safe, as our patented infrastructure is set up so that all user account and activity information is completely disconnected from the email verification process," a Blind FAQ reads. "It is impossible to match your user activity to any profile or email information provided upon sign up."
Despite these claims, TechCrunch was able to view emails of Blind users who had not yet posted. The server also contained pairings of these accounts with their unique member IDs, which could reportedly allow for identification if they did post in the future. The report also showed potentially shoddy encryption work for passwords and user tokens.
The server lapse is a potentially huge breach of trust for Blind users. Blind has the potential to be an important whistle-blowing tool for an industry that certainly needs oversight. But without confidence in its security, its users, and its power, could vanish.
CORRECTION: Dec. 21, 2018, 5:16 p.m. PST
A previous version of this article stated that Blind emailed users about the breach. Blind did not email users. It sent a push notification to affected users within the Blind app.
TopicsCybersecurity
Singapore rolls out video2026-03-13 17:06
國足預計首發:劉洋或成奇兵 戴偉浚角色存玄機2026-03-13 16:35
卡納瓦羅 :將俄羅斯驅逐出世界杯是一個正確決定2026-03-13 16:21
青島海牛力爭三年完成衝超目標 球隊新外援即將到位2026-03-13 16:01
You will love/hate Cards Against Humanity's new fortune cookies2026-03-13 15:46
卡納瓦羅 :將俄羅斯驅逐出世界杯是一個正確決定2026-03-13 15:41
曝巴薩並未放棄引進哈蘭德 盼用宏偉規劃說服球員2026-03-13 15:39
烏克蘭國腳:不需要受惠直通世界杯 我們會自己爭取2026-03-13 15:09
U.S. pole vaulter skids to a halt for national anthem2026-03-13 14:59
名記 :內馬爾已基本不訓練 甚至醉醺醺來訓練場2026-03-13 14:47
What brands need to know about virtual reality2026-03-13 17:14
李霄鵬鼓勵國腳:別人可以瞧不起你 但你自己絕對不能放棄2026-03-13 17:13
獨臂球員美國女足聯賽貢獻助攻 生涯112場攻入6球2026-03-13 16:56
徐新:全隊都是比較積極的狀態 爭取有所突破有所進步2026-03-13 16:49
Mall builds real2026-03-13 16:43
徐新 :全隊都是比較積極的狀態 爭取有所突破有所進步2026-03-13 16:27
大快人心 ?曼聯今夏將清洗馬奎爾 國米有意卡瓦尼2026-03-13 16:07
西漢姆欲出售賴斯標價1.5億 曼聯有意簽他替博格巴2026-03-13 15:58
Aly Raisman catches Simone Biles napping on a plane like a champion2026-03-13 15:56
英超速度榜:薩拉赫隻並列第二 第一第四竟是中衛2026-03-13 15:24