时间:2024-11-22 03:51:32 来源:网络整理编辑:熱點
It's a bad day for would-be tech watchdogs and gossips.The tech industry whistleblower and survey si
It's a bad day for would-be tech watchdogs and gossips.
The tech industry whistleblower and survey site Blind temporarily exposed user data when it left a server functioning without password protection. That's according to TechCrunch, whose new report not only uncovered the server lapse, but also called into question Blind's claims of privacy and complete user anonymity.
SEE ALSO:Blind: The hot app where all the best Silicon Valley gossip is read right nowA South Korean company, Blind is a site that allows tech industry employees to anonymously discuss their companies with colleagues. It also regularly produces surveys about sensitive topics like workplace harassment and diversity that it then distributes to the press. Blind gained prominence when discussions on the platform exposed sexual harassment at Uber. According to TechCrunch, it just secured $10 million in a new round of funding.
Central to Blind's functioning are its claims of privacy and user anonymity. Without this assurance, employees would likely feel uncomfortable discussing their employers.
The unprotected server reportedly showed logins, messages, and interactions,"allowing anyone to read private comments and posts."
Blind responded to the report saying that the unprotected server was an isolated incident that affected users who logged in between Nov. 1 and Dec. 19. Blind said it sent a push notification to affected users within the app.
“While developing an internal tool to improve our service for our users, we became aware of an error that exposed user data,” Blind reportedly wrote.
In addition to account activity, Blind protects its users by disassociating work email addresses from accounts. Blind says that it does not store email addresses, and only creates unique tokens from emails once you sign up.
"Email verification is safe, as our patented infrastructure is set up so that all user account and activity information is completely disconnected from the email verification process," a Blind FAQ reads. "It is impossible to match your user activity to any profile or email information provided upon sign up."
Despite these claims, TechCrunch was able to view emails of Blind users who had not yet posted. The server also contained pairings of these accounts with their unique member IDs, which could reportedly allow for identification if they did post in the future. The report also showed potentially shoddy encryption work for passwords and user tokens.
The server lapse is a potentially huge breach of trust for Blind users. Blind has the potential to be an important whistle-blowing tool for an industry that certainly needs oversight. But without confidence in its security, its users, and its power, could vanish.
CORRECTION: Dec. 21, 2018, 5:16 p.m. PST
A previous version of this article stated that Blind emailed users about the breach. Blind did not email users. It sent a push notification to affected users within the Blind app.
TopicsCybersecurity
Samsung Galaxy Note7 teardown reveals the magic behind the phone's iris scanner2024-11-22 03:31
“華為小公主”的一支舞,暴露娛樂圈多少明星的尷尬2024-11-22 03:25
原創古裝探案短劇《捕快姐姐郝可愛》開機,女捕快一馬當先破奇案2024-11-22 03:21
王一博摔車事件後續 :胡通明發聲明回應 ,我們的事故是一個意外2024-11-22 03:10
Fake news reports from the Newseum are infinitely better than actual news2024-11-22 02:54
安以軒挺二胎巨肚連辦兩場派對,向太夫婦、陳喬恩蕭敬騰等出席2024-11-22 02:30
聚劃算99晚會收視太火爆,網友:亮點多到數不過來2024-11-22 02:17
中國輪滑協會正式授予王一博 “中國滑板運動推廣大使”稱號2024-11-22 02:16
5 people Tim Cook calls for advice on running the biggest company in the world2024-11-22 02:10
聚劃算99晚會收視太火爆,網友 :亮點多到數不過來2024-11-22 02:10
Wikipedia co2024-11-22 02:58
短視頻為電影宣發賦能 ,抖音花式“玩法”助力春節檔電影票房大賣2024-11-22 02:46
專業造型“抖”起來 ,《抖音巨星化妝間》攜明星造型師打造彩妝知識陣地2024-11-22 02:44
[完片服務] 落地上海科技影都影視金融平台—太保攜拍片保助力2024-11-22 02:39
These glasses hide a fitness tracker on your face2024-11-22 02:30
你見過在過山車上塗口紅的神奇操作嗎?這檔節目真是活久見2024-11-22 02:08
救命 ,寧靜能放棄她的可怕審美麽?2024-11-22 01:48
2021天津衛視德雲社相聲春晚演員陣容官宣 酷狗音樂將同步播出獨家音頻2024-11-22 01:47
Richard Branson 'thought he was going to die' in bike accident2024-11-22 01:46
《向往》曬中國風概念海報,透露下一季開播時間 ,觀眾不淡定了 !2024-11-22 01:44