19 votes

Unsecured database of millions of SMS text messages exposed password resets and two-factor codes

4 comments

  1. [3]
    Soptik
    Link
    People underestimate how much is out there, unsecured, free to take. I've seen reddit post about people not only making their .env files publicly accessible, but even making them somehow indexed...

    People underestimate how much is out there, unsecured, free to take. I've seen reddit post about people not only making their .env files publicly accessible, but even making them somehow indexed by search engines. I've seen devcon talk about security cameras. They are often available on the internet, with no or default password, and some of them even have RCE vulnerabilities. It was very interesting talk - today if you want to get into something, you don't need to actually hack it; most of the time it's enough to just google it.

    6 votes
    1. [2]
      Octofox
      Link Parent
      I guess one upside is there is so much unsecured stuff on the internet that if you just do the minimum to secure a system it likely won't ever be targeted because attackers spend their time on the...

      I guess one upside is there is so much unsecured stuff on the internet that if you just do the minimum to secure a system it likely won't ever be targeted because attackers spend their time on the endless easy targets.

      2 votes
      1. nothis
        Link Parent
        It's kinda Darwinian, but sometimes I think the same. I think all the big, headlining viruses in recent years didn't affect people who had the latest Windows updates, for example.

        It's kinda Darwinian, but sometimes I think the same. I think all the big, headlining viruses in recent years didn't affect people who had the latest Windows updates, for example.

  2. Alfred
    Link
    If there ever was a reason to be using encrypted SMS where you could it's this, wow. I'm at the point where when my family texts me I'll respond in WhatsApp and just praying that Facebook won't...

    If there ever was a reason to be using encrypted SMS where you could it's this, wow.

    I'm at the point where when my family texts me I'll respond in WhatsApp and just praying that Facebook won't have a scandal where they say it's not encrypted

    3 votes