It's a bad day for would-be tech watchdogs and Hollywood Archivesgossips.
The tech industry whistleblower and survey site Blind temporarily exposed user data when it left a server functioning without password protection. That's according to TechCrunch, whose new report not only uncovered the server lapse, but also called into question Blind's claims of privacy and complete user anonymity.
SEE ALSO: Blind: The hot app where all the best Silicon Valley gossip is read right nowA South Korean company, Blind is a site that allows tech industry employees to anonymously discuss their companies with colleagues. It also regularly produces surveys about sensitive topics like workplace harassment and diversity that it then distributes to the press. Blind gained prominence when discussions on the platform exposed sexual harassment at Uber. According to TechCrunch, it just secured $10 million in a new round of funding.
Central to Blind's functioning are its claims of privacy and user anonymity. Without this assurance, employees would likely feel uncomfortable discussing their employers.
The unprotected server reportedly showed logins, messages, and interactions,"allowing anyone to read private comments and posts."
Blind responded to the report saying that the unprotected server was an isolated incident that affected users who logged in between Nov. 1 and Dec. 19. Blind said it sent a push notification to affected users within the app.
“While developing an internal tool to improve our service for our users, we became aware of an error that exposed user data,” Blind reportedly wrote.
In addition to account activity, Blind protects its users by disassociating work email addresses from accounts. Blind says that it does not store email addresses, and only creates unique tokens from emails once you sign up.
"Email verification is safe, as our patented infrastructure is set up so that all user account and activity information is completely disconnected from the email verification process," a Blind FAQ reads. "It is impossible to match your user activity to any profile or email information provided upon sign up."
Despite these claims, TechCrunch was able to view emails of Blind users who had not yet posted. The server also contained pairings of these accounts with their unique member IDs, which could reportedly allow for identification if they did post in the future. The report also showed potentially shoddy encryption work for passwords and user tokens.
The server lapse is a potentially huge breach of trust for Blind users. Blind has the potential to be an important whistle-blowing tool for an industry that certainly needs oversight. But without confidence in its security, its users, and its power, could vanish.
CORRECTION: Dec. 21, 2018, 5:16 p.m. PST
A previous version of this article stated that Blind emailed users about the breach. Blind did not email users. It sent a push notification to affected users within the Blind app.
Topics Cybersecurity
Lyft's 'trending destinations' suggests popular locations to riders'The Simpsons' parodied 'Stranger Things' and of course Lisa was ElevenAll the Apple TV+ trailers released so farYes, Hillary Clinton tweeted about the end of Michael Flynn. Yes, it was glorious.Teen becomes talk of the neighborhood when taquito gets confused for cigarVolvo's first allWhy the 'Office Ladies' podcast is worth your timeThe best celebrity hair of the 2010s that inspired who we wanted to be'The Simpsons' parodied 'Stranger Things' and of course Lisa was ElevenAn Aussie airline successfully tested a nonstop NYC–Sydney flightGoogle's selfI waited in the snow for several hours to buy stuff with Kylie Jenner's face on itHow one company is transforming trash into clean energyThis BBC weather presenter just busted out a total mic drop of a punTeen becomes talk of the neighborhood when taquito gets confused for cigarObama's photographer just threw shade at Trump's chaotic security meetingThis flooring sale at Lumber Liquidators means up to 50% off.The Analogue Pocket celebrates the history of mobile gamingDude rolls his valentine an impressive heartWhere the hell did this head More than 1 billion Yahoo users hacked in new security breach, company reveals 'Can I have your meds?' and other questions you shouldn't ask someone with ADHD SMOSH's Anthony Padilla and Ian Hecox talk about their fav 'Ghostmates' co Amazon's drone just accomplished its first real delivery A wild theory about why Trump left Twitter out of his big tech summit This mom did all of her holiday shopping without spending a penny #WakeyLeaks is college football's delightfully absurd spy scandal Photographer explores the public and private personas of your favorite actors Inside the White House's first 5 ways to keep your holiday shopping secret The polar vortex is going to punch you in the face, repeatedly Amazon Prime Video arrives in Australia, but is it even worth it? This line of lipsticks comes in tiny wine Students' catchy long division song will be stuck in your head all day Uber will now offer rides in self Here are the 10 best video games of 2016 IMDb meets Bollywood, launches 'India Spotlight' Young Jedis fight an impressive lightsaber battle in a school cafeteria New site visualises how you rode with Uber in 2016 'What Remains of Edith Finch' tells an artful story about death
2.6214s , 8223.75 kb
Copyright © 2025 Powered by 【Hollywood Archives】,New Knowledge Information Network