Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Peloton's Leaky API Let Anyone Grab Riders' Private Account Data

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Peloton's Leaky API Let Anyone Grab Riders' Private Account Data


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: it.slashdot.org

Zack Whittaker, reporting for TechCrunch: Halfway through my Monday afternoon workout last week, I got a message from a security researcher with a screenshot of my Peloton account data. My Peloton profile is set to private and my friend's list is deliberately zero, so nobody can view my profile, age, city, or workout history. But a bug allowed anyone to pull users' private account data directly from Peloton's servers, even with their profile set to private. Peloton, the at-home fitness brand synonymous with its indoor stationary bike and beleaguered treadmills, has more than three million subscribers. Even President Biden is said to own one. The exercise bike alone costs upwards of $1,800, but anyone can sign up for a monthly subscription to join a broad variety of classes. As Biden was inaugurated (and his Peloton moved to the White House -- assuming the Secret Service let him), Jan Masters, a security researcher at Pen Test Partners, found he could make unauthenticated requests to Peloton's API for user account data without it checking to make sure the person was allowed to request it. (An API allows two things to talk to each other over the internet, like a Peloton bike and the company's servers storing user data.) But the exposed API let him -- and anyone else on the internet -- access a Peloton user's age, gender, city, weight, workout statistics and, if it was the user's birthday, details that are hidden when users' profile pages are set to private. Masters reported the leaky API to Peloton on January 20 with a 90-day deadline to fix the bug, the standard window time that security researchers give to companies to fix bugs before details are made public. But that deadline came and went, the bug wasn't fixed and Masters hadn't heard back from the company, aside from an initial email acknowledging receipt of the bug report. In some other Peloton news: Peloton recalls all treadmills after reported injuries, death.

Read more of this story at Slashdot.

...



๐Ÿ“Œ Peloton's Leaky API Let Anyone Grab Riders' Private Account Data


๐Ÿ“ˆ 111.34 Punkte

๐Ÿ“Œ Pelotonโ€™s Leaky API Spilled Ridersโ€™ Private Data


๐Ÿ“ˆ 73.44 Punkte

๐Ÿ“Œ Pelotonโ€™s Leaky API Potentially Exposed Ridersโ€™ Personal Information


๐Ÿ“ˆ 62.3 Punkte

๐Ÿ“Œ MYXfitness bike beats Peloton on weight capacity. Too bad that's where support for larger riders ends


๐Ÿ“ˆ 37.94 Punkte

๐Ÿ“Œ Peloton Row: What you need to know about Peloton's first rowing machine


๐Ÿ“ˆ 34.13 Punkte

๐Ÿ“Œ Bluetooth Security Flaw Could Let Nearby Attacker Grab Your Private Data


๐Ÿ“ˆ 31.66 Punkte

๐Ÿ“Œ Millions of Apps Leak Private User Data Via Leaky Ad SDKs


๐Ÿ“ˆ 29.24 Punkte

๐Ÿ“Œ Hi, Jack'd: A little PSA for anyone using this dating-hook-up app... Anyone can slurp your private, public snaps


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ Let's Encrypt plugs hole that let miscreants grab HTTPS web certs for strangers' domains


๐Ÿ“ˆ 28.64 Punkte

๐Ÿ“Œ T-Mobile Alerts 2.3 Million Customers of Data Breach Tied to Leaky API


๐Ÿ“ˆ 27.71 Punkte

๐Ÿ“Œ How Spoutibleโ€™s Leaky API Spurted out a Deluge of Personal Data


๐Ÿ“ˆ 27.71 Punkte

๐Ÿ“Œ T-Mobile Bug Let Anyone See Any Customer's Account Details


๐Ÿ“ˆ 25.49 Punkte

๐Ÿ“Œ Critical 'Sign in with Apple' Bug Could Have Let Attackers Hijack Anyone's Account


๐Ÿ“ˆ 25.49 Punkte

๐Ÿ“Œ Critical 'Sign in with Apple' Bug Could Have Let Attackers Hijack Anyone's Account


๐Ÿ“ˆ 25.49 Punkte

๐Ÿ“Œ TIBCO FTP Community Edition up to 6.5.0 on Windows Server/C API/Golang API/Java API/.Net API access control


๐Ÿ“ˆ 25.03 Punkte

๐Ÿ“Œ From Monolith to Microservices at Grab (aka Go for Grab)


๐Ÿ“ˆ 24.81 Punkte

๐Ÿ“Œ Instagram's leaky API exposed celebrities' contact details


๐Ÿ“ˆ 24.36 Punkte

๐Ÿ“Œ Intel: Let's talk about SGX, baby. Let's talk about 2U and me. Let's talk about all the good things, and the bad...


๐Ÿ“ˆ 24.36 Punkte

๐Ÿ“Œ Intel: Let's talk about SGX, baby. Let's talk about 2U and me. Let's talk about all the good things, and the bad...


๐Ÿ“ˆ 24.36 Punkte

๐Ÿ“Œ *taps on glass* Hellooo, IRS? Anyone in? Anyone guarding taxpayers' data from crooks? Hellooo?


๐Ÿ“ˆ 24.26 Punkte

๐Ÿ“Œ does anyone have any evidence that new reddit collects more data? has anyone tested yet and found out?


๐Ÿ“ˆ 24.26 Punkte

๐Ÿ“Œ does anyone have any evidence that new reddit collects more data? has anyone tested yet and found out?


๐Ÿ“ˆ 24.26 Punkte

๐Ÿ“Œ Uber Settles Complaint Over Data Protection for Riders, Drivers


๐Ÿ“ˆ 24.23 Punkte

๐Ÿ“Œ Uber sues LA in bid to protect scooter ridersโ€™ geolocation data


๐Ÿ“ˆ 24.23 Punkte

๐Ÿ“Œ Mammoth grab of GP patient data in the UK set to benefit private-sector market access as rules remain unchanged


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Peloton API Bug: Expert Commentary


๐Ÿ“ˆ 23.32 Punkte

๐Ÿ“Œ Peloton: Schwachstelle in der API des Unternehmens erlaubte Zugriff auf sensible Daten der Nutzer


๐Ÿ“ˆ 23.32 Punkte

๐Ÿ“Œ Symantec API Flaws reportedly let attackers steal Private SSL Keys and Certificates


๐Ÿ“ˆ 22.17 Punkte

๐Ÿ“Œ Account Take over Vulnerability in EA Origin Game Client Let Hackers Hijack the 300 Million Gamers Account


๐Ÿ“ˆ 21.95 Punkte

๐Ÿ“Œ Leaky WWE Database Exposes Personal Data of 3M Wrestling Fans


๐Ÿ“ˆ 21.45 Punkte

๐Ÿ“Œ CENTCOM Says Massive Data Cache Found on Leaky Server is Benign


๐Ÿ“ˆ 21.45 Punkte











matomo