Tuesday, March 21, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Configuration error leads to data leak in Mastodon

Kiratas by Kiratas
March 18, 2023
in World
Reading Time: 1 min read
0
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

The cause of a data leak at Mastodon was not an external intrusion, but an insufficient configuration of the Mastodon server for storing user data. This made it theoretically possible for every user of the service to view the data uploaded to files.mastodon.social. Mastodon discovered the bug on February 24th and closed it within 30 minutes. However, the leak had existed since the beginning of February because the infrastructure had been upgraded at the time, the provider writes in an e-mail.

Data exports public

Mastodon normally protects access to files with long, randomly generated file names, among other things, so that only those who know the link can access the files. However, this mechanism could be circumvented in the course of the upgrade. Much of the data accessible in this way is publicly available anyway.

However, this does not apply to the data exports downloaded by users, which also contain non-publicly shared posts, direct messages and attachments. In a statement, Mastodon stated that this archive data was immediately deleted to prevent further access to it. However, it was not possible to prevent access that had already taken place.

The temporarily public data exports contain the public profile, your own favorites and bookmarks as well as posts and media attachments. Mastodon assured that neither e-mail addresses nor other personal identification data were included. No further action is required from users.

(uk)

To home page

Tags: configurationdataData keyerrorfile serverleadsLeakMastodonSecurityVulnerabilities

Related Posts

World

Tamames makes Yolanda Díaz ugly that she uses the motion for a long hour to campaign for ‘Sumar’

by Kiratas
March 21, 2023
World

Lies at the push of a button: GPT-4 apparently more susceptible to false information

by Kiratas
March 21, 2023
World

Java 20 extends concurrency with scoped values

by Kiratas
March 21, 2023
World

OKDIARIO finds ‘El Mediador’ exclusively in Madrid

by Kiratas
March 21, 2023
World

Combustion engine dispute: proposal by the EU Commission to end the debate

by Kiratas
March 21, 2023
Next Post

What happens in the field...

Piqué reveals that a former referee offered Negreira's son for the Kings League

"Negreira and some Barcelona employees set up the scam for years"

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.
Contact Us:
[email protected]

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence Bank Barcelona business ChatGPT Check Cybercrime data data protection day Energy EU euros Facebook February Google government health iOS iPhone law League Life Linux and Open Source live Mac Madrid March Microsoft million online price result Security Smartphone Spain Spanish Sánchez Test time today Vulnerabilities year years

Recent Posts

  • Tamames makes Yolanda Díaz ugly that she uses the motion for a long hour to campaign for ‘Sumar’
  • Lies at the push of a button: GPT-4 apparently more susceptible to false information
  • Java 20 extends concurrency with scoped values
  • DMCA
  • Home

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Kiratas 2023. All Rights Reserved.