Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I find it unlikely they have a database explicitly for driver names/license plates. Unless it was some flat-file dump compromised. I'm curious how much data was really obtained. If only 50k were truly stolen, it could be a shard too. The lack of technical details is sketchy to me


I also find it unlikely it's just the name and license number. They used to return all of a driver's information (name, phone, address, drivers license, license plate, etc) from the rest endpoint they were using on their website. They closed that hole it after it we disclosed it to them.


Why wouldn't they? I imagine there's some driver signup form that saves to some database table on their site.


Maybe they have query logging turned on and saw what queries the attacker ran?


Definitely plausible, and I hope so --- but there's no clarification of that or technical insight.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: