April 9, 2024, 7:36 p.m. | /u/Competed

cybersecurity www.reddit.com

I recently stumbled upon a concerning security issue and promptly reported it to the company responsible. The issue involved an API data exposure that exposed sensitive customer information, including names, addresses, and order history. To my surprise, I was only rewarded with $2.77 worth of "rewards" points.

What's even more concerning is that the same data was accessible on their website without directly accessing the API endpoint. Simply by logging out of my account and navigating to the order history …

addresses api customer customers cybersecurity data data exposure exposed exposure history information issue names order points responsible rewards security sensitive surprise the company

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Sr. Staff Firmware Engineer – Networking & Firewall

@ Axiado | Bengaluru, India

Compliance Architect / Product Security Sr. Engineer/Expert (f/m/d)

@ SAP | Walldorf, DE, 69190

SAP Security Administrator

@ FARO Technologies | EMEA-Portugal