Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Unknown, Unprotected Database Exposes Info on 80 Million US Households
Oldest First  |  Newest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/29/2019 | 10:25:55 PM
Income
The surprising piece in my mind is income....all other info you can typically find on a persons facebook page if they embrace social media or through publically accessible mediums.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/30/2019 | 11:17:04 AM
Is it Microsoft?
I heard this yesterday, is it the one related to Microsoft?
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/30/2019 | 11:20:50 AM
65%?
An unprotected database with information that could affect up to 65% of US households One wonders why there this much information in a database. And what type of database can allow public access without credentials?
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/30/2019 | 11:22:34 AM
40 years
Everyone included in the database appears to be over the age of 40. Interesting. So data gathered is not random obviously.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/30/2019 | 11:25:28 AM
Re: Income
The surprising piece in my mind is income. That makes sense, all this information in one data set would creat value I would think.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/30/2019 | 11:27:22 AM
Owner?
As of this article, the database is still online because the researchers have not been able to identify the owner for notification. That is quite strange. So we have the source but not the owner? Are they not able to trace back to account?
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2019 | 11:00:46 PM
Re: Income
It's amazing how many times single data sets in and of themselves are of no consequence but coupled together that they become valuable.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2019 | 11:02:10 PM
Re: Owner?
They definitely should be able to do so, but many times the demographic information such as data owner and custodian aren't associated. It's definitely best practice to do so and from this you can definitely see why.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2019 | 11:08:13 PM
Re: 40 years
Data is not random or was taken from a specific part of the database. My assumption, that the data is sorted by a certain criteria in the database and that dataset would be age. Just a theory, but otherwise it would be way too coincidental.


Cybersecurity Industry: It's Time to Stop the Victim Blame Game
Jessica Smith, Senior Vice President, The Crypsis Group,  2/25/2020
5 Ways to Up Your Threat Management Game
Wayne Reynolds, Advisory CISO, Kudelski Security,  2/26/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8741
PUBLISHED: 2020-02-28
A denial of service issue was addressed with improved input validation.
CVE-2020-9399
PUBLISHED: 2020-02-28
The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 definitions 200114-0 of Antivirus Pro, Antivirus Pro Plus, and Antivirus for Linux.
CVE-2020-9442
PUBLISHED: 2020-02-28
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.
CVE-2019-3698
PUBLISHED: 2020-02-28
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux...
CVE-2020-9431
PUBLISHED: 2020-02-27
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.