MoviePass user records exposed on public server


San Francisco, Aug 21 (IANS): American subscription-based movie ticketing service MoviePass, Inc. has exposed thousands of unencrypted customer card numbers and personal credit cards because a critical server was not protected with a password.

The database was massive, containing 161 million records at the time of writing and growing in real time. Many of the records were normal computer-generated logging messages used to ensure the running of the service - but many also included sensitive user information, such as MoviePass customer card numbers, TechCrunch reported on Wednesday.

A cybersecurity expert named Mossab Hussain, from a Dubai-based firm named SpiderSilk, discovered the unprotected server and shared sample data sets with TechCrunch to confirm that MoviePass was in fact leaving the data unencrypted and accessible to anyone.

There is no information whether MoviePass' customer information was ever collected or disseminated by a malicious third party.

However, Hussain's findings about the state of MoviePass' security are deeply troubling. Given the mountain of controversies MoviePass has faced in the past, it's easy to see how cybersecurity could fall by the wayside, according to The Verge.

  

Top Stories


Leave a Comment

Title: MoviePass user records exposed on public server



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.