Well,Sister Emanuelle this is certainly not great: An unprotected database of more than a billion users' records from across the internet — including "social media accounts, email addresses, and phone numbers" — was discovered on an unidentified Elasticsearch server that could be accessed by anyone with the server's web address.
What's even weirder is, according to Bloomberg, no one is exactly sure how it got there.
The discovery was made in October by cybersecurity experts Bob Diachenko and Vinny Troia; the 4 terabytes of data they found also included Facebook, Twitter, and LinkedIn profile information. All told, the server contained information on four billion user accounts and 650 million unique email addresses, affecting 1.2 billion people.
As WIREDpoints out, though, it's important to keep in mind what the data does notinclude: things like passwords and credit card numbers. So at least there's that! Troia also told WIREDthat the server is no longer online and that he reported its presence to the FBI.
While it's unknown how the data got to be on this server, there are a few things Troia was able to uncover. First, it seems like the data came from multiple datasets, some of it from data broker People Data Labs (PDL), which provides "data enrichment." (TL;DR: It provides data points on internet users so brands can create more specific content with which to target these users.)
Second, the server the information was found on did not belong to PDL. Troia reports that PDL "appears to use Amazon Web Services" for their servers, while the mystery data-laden server was residing — again, unprotected — on Google's Cloud Services. Neither the server or the data were controlled by Google.
Troia and Sean Thorne, co-founder of People Data Labs (PDL), both indicated to WIREDthat the data probably wasn't obtained via a breach of PDL, but may have been obtained legitimately by a customer who bought the data for data enrichment purposes and left it unprotected.
Said Thorne, “The owner of this server likely used one of our enrichment products, along with a number of other data enrichment or licensing services. Once a customer receives data from us, or any other data providers, the data is on their servers and the security is their responsibility."
To compare the data he found with what PDL had, Troia created a free account, which includes 1,000 searches per month, and cross-checked dozens of people from the PDL search with the data from the unprotected server. He found a nearly complete match, supporting his theory that PDL was the source of much of the data. Only users' education information was left out of the found data.
Troia also told WIREDit's possible that some of the data came from another data broker, Oxydata, which denied that any sort of breach of their data had occurred — which means it, too, could have been obtained completely legitimately.
SEE ALSO: Adobe exposed nearly 7.5 million Creative Cloud accounts to the publicIn one more act of public service, Troia supplied the data to breach clearinghouse HaveIBeenPwned, which allows users to see if their accounts have been compromised.
The scariest thing, as Troia points out, is that if this really is just gross mismanagement of legitimately obtained data, there's little to be done in terms of holding anyone accountable for the breach.
"Because of obvious privacy concerns, cloud providers will not share any information on their customers, making this a dead end," Troia writes. "Agencies like the FBI can request this information through legal process (a type of official Government request), but they have no authority to force the identified organization to disclose the breach."
We've reached out to Google for comment, but it's doubtful they can say anything that'll make us feel better about this whole thing.
Topics Cybersecurity
Google promises to stop digging through your email inbox to target ads (which it was totally doing)Netflix embraces wrestling with wonderful 'GLOW'What's coming to Netflix in July 2017Russia tried to hack election systems in nearly half the U.S.'Jurassic World' has a dumb new title and a really familiar taglineRon Howard is a solid choice for Han Solo director. Here's why.What's coming to Netflix in July 2017Game of Thrones trailer: 10 clues you missed in the new Season 7 promo'Echo Arena' is the first VR game that made me forget I was realMLB wants you to sit through an entire baseball game in VRJ.K. Rowling revealed there are two Harry Potters'Echo Arena' is the first VR game that made me forget I was realTalking to your car is better than ever, thanks to Nuance's voice assistantThese definitely real leaked emails show exactly why the Han Solo spinRon Howard is a solid choice for Han Solo director. Here's why.'Game of Thrones' Season 7 posters are hereHow to get a job at: Getty ImagesWhat's coming to Hulu in July 2017Watch Roborace's self'Star Wars' concert series lets you feel the force Apple isn't safe from Sen. Elizabeth Warren's plan to break up Big Tech Elon Musk says Autopilot prices will revert to normal on Monday The 'Dark Knight' trilogy returns to theaters for a 70mm IMAX tour 12 remote places to unplug from this suffocating election campaign Philadelphia just banned cashless stores. Good. Vivo Apex 2019: No holes, all screen Lady Gaga mocks pregnancy rumors with a truly A+ tweet Jordan Peele's 'Us' is a force to be reckoned with: Review Ian McShane and Orlando Jones can't save 'American Gods' from itself. Mark Zuckerberg's former mentor says privacy manifesto is a PR stunt Toyota says selling full Tesla says it'll keep more stores open and raise car prices Elon Musk slams SEC 'overreach,' says he cut his Tesla Comedy 'genius' and prolific 'web prankster' dies in tragic hit and run Tesla called out for sneaky math on Model 3 pricing Disney's 'DuckTales' features an amazing nod to the classic NES game Inventor of the web says the web needs to be fixed, and fast Donald Trump's first major newspaper endorsement is not exactly a shocker About 100,000 devices helped take down the internet via a cyberattack 'Grown
2.4897s , 10132.515625 kb
Copyright © 2025 Powered by 【Sister Emanuelle】,Charm Information Network