TechCrunch News 01月31日
AngelSense exposed location data and personal information of tracked users
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

AngelSense公司的用户个人信息及位置数据被暴露在互联网上。安全公司UpGuard发现后通知该公司,一周多后其secured服务器。数据库暴露诸多信息,包括用户姓名、地址等,影响情况不明,公司称在调查是否通知用户。

🎈AngelSense用户个人信息及位置数据被暴露在网上,无密码保护。

💻UpGuard发现后通知AngelSense,该公司起初误认邮件为垃圾,接到电话后才重视。

❓数据库暴露时间及受影响用户数量不明,公司称在调查是否通知用户。

AngelSense, an assistive technology company that provides location monitoring devices for people with disabilities, was spilling the personally identifiable information and precise location data of its users to the open internet, TechCrunch has learned.

The company secured the exposed server on Monday, more than a week after it was alerted to the data leak by researchers at security firm UpGuard.

UpGuard shared details of the exposure exclusively with TechCrunch after AngelSense resolved the lapse. UpGuard has since published a blog post on the incident. 

The New Jersey-based AngelSense provides GPS trackers and location monitoring to thousands of customers, according to its mobile app listing, and is touted by law enforcement and police departments across the United States.

According to UpGuard’s researchers, AngelSense left an internal database exposed to the internet without a password, allowing anyone to access the data inside using only a web browser and knowledge of the database’s public IP address. The database was storing real-time updating logs from an AngelSense system, which included the personal information of AngelSense customers, as well as technical logs about the company’s systems.

UpGuard said it found customers’ personal data, like names, postal addresses, and phone numbers in the exposed database. The researchers said they also found GPS coordinates of individuals being monitored — including associated health information about the tracked person, which included conditions like autism and dementia. The researchers also found email addresses, passwords, and authentication tokens for accessing customer accounts, as well as partial credit card information — all of which was visible in plaintext, UpGuard said. 

It’s not known exactly how long the database was exposed nor how many customers were affected. According to the database’s listing on Shodan, a search engine of internet-facing devices and systems, AngelSense’s exposed logging database was first spotted online on January 14, though it may have been exposed some time earlier.

AngelSense chief executive Doron Somer confirmed to TechCrunch that the company took the exposed server offline after initially identifying UpGuard’s first email as spam.

“It was only when UpGuard phoned us that the issue was raised to our attention,” Somer said. “Upon its discovery, we acted promptly to validate the information provided to us and to remedy the vulnerability.”

“We note that other than UpGuard, we have no information suggesting that any data on the logging system potentially was accessed. Nor do we have any evidence or indication that the data has been misused or is under threat of misuse,” Somer told TechCrunch, claiming that the data “was not sensitive personal information.” 

Somer would not say if the company has the technical means to determine if there was any access to the unprotected server prior to UpGuard’s discovery.

When asked if the company planned to notify affected customers and individuals whose data was exposed, Somer said the company was still investigating.

“If notice to regulators or persons is warranted, we will of course provide it,” Somer said.

Somer did not respond to a follow-up inquiry by press time.

Database exposures are often the result of misconfigurations caused by human error, rather than malicious intent, and have become an increasingly common occurrence in recent years. Similar security lapses of exposed databases have resulted in the spill of sensitive U.S. military emails, the real-time leak of text messages containing two-factor codes, and chat histories from AI chatbots.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

AngelSense 信息泄露 用户安全
相关文章