Friday, April 1, 2016

50 GB of Verizon customer - Accessible through MongoDB client and the IP address (no password needed)


Company response-  it is test data.
Really?


50 GB of Verizon customer data has been discovered, completely unprotected by any password or authentication.

Yet, even after a back-and-forth with Verizon’s director of cybersecurity, Jim Matteo, Verizon did little to fix the issue.

The Verizon PR team claimed that the MongoDB was only a test environment with fictitious customer data, non-sensitive reference material, unique encryption keys and solely used passwords specific to that test environment. 


For more info:

No comments:

Post a Comment