{"id":31864,"date":"2020-09-14T09:35:52","date_gmt":"2020-09-14T13:35:52","guid":{"rendered":"http:\/\/pappp.net\/?guid=af30cfb89e3e80a93a3c1dbc984cb477"},"modified":"2020-09-14T09:35:52","modified_gmt":"2020-09-14T13:35:52","slug":"private-data-gone-public-razer-leaks-100000-gamers-personal-info","status":"publish","type":"post","link":"https:\/\/pappp.net\/?p=31864","title":{"rendered":"Private data gone public: Razer leaks 100,000+ gamers\u2019 personal info"},"content":{"rendered":"<p class=\"syndicated-attribution\">Source: <a href=\"https:\/\/arstechnica.com\/?p=1705755\">Ars Technica<\/a><\/p>\n<div style=\"background-color : #fff7d5;\n\t\t\tborder-width : 1px; padding : 5px; border-style : dashed; border-color : #e7d796;margin-bottom : 1em; color : #9a8c59;\">Article note: We really need a regulatory infrastructure that makes it prohibitively expensive to collect and silo data unless there is an extremely compelling reason. \r\nAlso, there is _no reason_ for a hardware configuration utility to connect to the Internet.<\/div><div>\n<figure><img src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2020\/09\/razer-data-leak-800x185.jpg\" alt=\"This redacted sample record from the leaked Elasticsearch data shows someone's June 24 purchase of a $2,600 gaming laptop.\" referrerpolicy=\"no-referrer\"\/><p><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2020\/09\/razer-data-leak.jpg\" rel=\"noopener noreferrer\">Enlarge<\/a> <span>\/<\/span> This redacted sample record from the leaked Elasticsearch data shows someone's June 24 purchase of a $2,600 gaming laptop. (credit: <a rel=\"noopener noreferrer\" href=\"https:\/\/www.linkedin.com\/pulse\/thousands-razer-customers-order-shipping-details-web-diachenko\/\">Volodymyr Dianchenko<\/a>)<\/p>  <\/figure><div><a name=\"page-1\"><\/a><\/div>\n<p>In August, security researcher Volodymyr Diachenko discovered a misconfigured Elasticsearch cluster, owned by gaming hardware vendor Razer, exposing customers' PII (Personal Identifiable Information).<\/p>\n<p>The cluster contained records of customer orders and included information such as item purchased, customer email, customer (physical) address, phone number, and so forth&mdash;basically, everything you'd expect to see from a credit card transaction, although not the credit card numbers themselves.&nbsp;The Elasticseach cluster was not only exposed to the public, it was indexed by public search engines.<\/p>\n<blockquote>\n<p dir=\"ltr\" lang=\"en\">I must say I really enjoyed my conversations with different reps of <a href=\"https:\/\/twitter.com\/Razer?ref_src=twsrc%5Etfw\" rel=\"noopener noreferrer\">@Razer<\/a> support team via email for the last couple of week, but it did not bring us closer to securing the data breach in their systems. <a href=\"https:\/\/t.co\/Z6YZ5wvejl\" rel=\"noopener noreferrer\">pic.twitter.com\/Z6YZ5wvejl<\/a><\/p>\n<p>&mdash; Bob Diachenko (@MayhemDayOne) <a href=\"https:\/\/twitter.com\/MayhemDayOne\/status\/1300811914050707456?ref_src=twsrc%5Etfw\" rel=\"noopener noreferrer\">September 1, 2020<\/a><\/p><\/blockquote>\n<p>Diachenko reported the misconfigured cluster&mdash;which contained roughly 100,000 users' data&mdash;to Razer immediately, but the report bounced from support rep to support rep for over three weeks before being fixed.<\/p><\/div><p><a href=\"https:\/\/arstechnica.com\/?p=1705755#p3\" rel=\"noopener noreferrer\">Read 12 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1705755&amp;comments=1\" rel=\"noopener noreferrer\">Comments<\/a><\/p><div>\n<a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=3Bsb1MKNaIE:c75SzvSSisU:V_sGLiPBpWU\" rel=\"noopener noreferrer\"><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?i=3Bsb1MKNaIE:c75SzvSSisU:V_sGLiPBpWU\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=3Bsb1MKNaIE:c75SzvSSisU:F7zBnMyn0Lo\" rel=\"noopener noreferrer\"><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?i=3Bsb1MKNaIE:c75SzvSSisU:F7zBnMyn0Lo\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=3Bsb1MKNaIE:c75SzvSSisU:qj6IDK7rITs\" rel=\"noopener noreferrer\"><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?d=qj6IDK7rITs\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=3Bsb1MKNaIE:c75SzvSSisU:yIl2AUoC8zA\" rel=\"noopener noreferrer\"><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?d=yIl2AUoC8zA\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Enlarge \/ This redacted sample record from the leaked Elasticsearch data shows someone&#8217;s June 24 p&#8230;<\/p>\n<p> <a href=\"https:\/\/pappp.net\/?p=31864\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[226],"tags":[],"class_list":["post-31864","post","type-post","status-publish","format-standard","hentry","category-news-2"],"_links":{"self":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts\/31864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=31864"}],"version-history":[{"count":0,"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts\/31864\/revisions"}],"wp:attachment":[{"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=31864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=31864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=31864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}