Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good job!

I’d be interested to know how you’re coming to the conclusion that the amount of affected users is likely higher. From the looks of it, I’d suspect that at least some of the sites you mention (gambling, lead carrot) to be littered with fake account data.



When manually reviewing a lot of these sites it was not identifying PII that were in non-english since the automated scanner checks the variable name for known data types (e.g phone) but that would only work for English sites.


We confirmed that the gambling site is not fake data, I dont know about the lead one.

Why we are saying its more is there is likely other services not in our scan list that could be vulnerable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: