Oljestaten Qatar satsade på en app för att spåra, kartlägga och försöka kontrollera smittan av Corona. Nu har personlig information och positionsdata om hundratusentals användare läckt ut på nätet.
Appen har varit ett krav från myndigheterna, medborgare har varit tvingade att ladda ned appen. Nu har Amnesty hittat allvarliga säkerhetsbrister i appen och tjänsten. Hundratusentals användares ID, personliga information och positionsdata har läckt ut på nätet.
Claudio Guarnieri, a senior technologist at Amnesty International and head of its Security Lab, told BuzzFeed News that his organization found the flaw that could have compromised people’s data.
“The app downloaded the QR code from the server by performing a particular request providing the national ID the user provided at registration,” he said. “However, anyone with the sufficient technical know-how to analyze the inner workings of the apps would have been able to reconstruct the network protocol and notice that because the server only expected an ID number to return the QR code, one could request it for any other ID instead.”
A hacker could have used a brute-force attack to generate all possible combinations of the ID numbers, retrieving their data.
https://twitter.com/botherder/status/1265251369784684545?s=20
0 kommentarer