DooKey
[H]F Junkie
- Joined
- Apr 25, 2001
- Messages
- 12,708
According to KrebsonSecurity, LocationSmart has been leaking real-time location data for mobile carrier customers on their web site to anyone that wanted to get it because of a bug. Apparently, this data was free for the taking without any form of authentication required. LocationSmart claims that they don't release this type of information without consent and have removed the offending service from the site. However, the simple fact of the matter is due to their failure to properly protect the data they put many people in jeopardy of stalking or worse. The major carriers need to screen their third party customers better.
But these assurances may ring hollow to anyone with a cell phone who’s concerned about having their physical location revealed at any time. The component of LocationSmart’s Web site that can be abused to look up mobile location data at will is an insecure “application programming interface” or API — an interactive feature designed to display data in response to specific queries by Web site visitors.
But these assurances may ring hollow to anyone with a cell phone who’s concerned about having their physical location revealed at any time. The component of LocationSmart’s Web site that can be abused to look up mobile location data at will is an insecure “application programming interface” or API — an interactive feature designed to display data in response to specific queries by Web site visitors.