Article 5846W Private Data Gone Public: Razer Leaks 100,000+ Gamers’ Personal Info

Private Data Gone Public: Razer Leaks 100,000+ Gamers’ Personal Info

by
Fnord666
from SoylentNews on (#5846W)

Freeman writes:

https://arstechnica.com/information-technology/2020/09/100000-razer-users-data-leaked-due-to-misconf

In August, security researcher Volodymyr Diachenko discovered a misconfigured Elasticsearch cluster, owned by gaming hardware vendor Razer, exposing customers' PII (Personal Identifiable Information).

The cluster contained records of customer orders and included information such as item purchased, customer email, customer (physical) address, phone number, and so forth-basically, everything you'd expect to see from a credit card transaction, although not the credit card numbers themselves. The Elasticseach cluster was not only exposed to the public, it was indexed by public search engines.

Link to the tweet from the security researcher.

[...] One of the things Razer is well-known for-aside from their hardware itself-is requiring a cloud login for just about anything related to that hardware.

[...] Over the last year, Razer awarded a single HackerOne user, s3cr3tsdn, 28 separate bounties.

We applaud Razer for offering and paying bug bounties, of course, but it's difficult to forget that those vulnerabilities wouldn't have been there (and globally exploitable), if Razer hadn't tied their device functionality so thoroughly to the cloud in the first place.

Reap those cloud benefits.

Original Submission

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments