// data security

All signals tagged with this topic

Flock's Roadside Cameras Store Vast Tracking Data, Hacker Dump Shows

Flock Safety's license plate readers, deployed across thousands of US neighborhoods as a "public safety" tool, accumulate months of movement records on every vehicle that passes, creating a de facto surveillance database accessible to local police without traditional warrant requirements. The physical vulnerability of these devices and the unencrypted data they contain expose a gap between consumer assumptions about surveillance (limited, purposeful) and the reality: continuous, indiscriminate tracking infrastructure that treats movement as a permanent record. Demand for surveillance transparency laws is likely to increase, and consumer skepticism toward "smart city" hardware marketed as crime-fighting will likely harden as the monitoring capabilities become clearer.

SafePal breach exposes customer data while wallets stay secure

SafePal's hack shows hardware wallet security functions as designed, but customer databases remain exposed. The vulnerability for mainstream adoption isn't the vault—it's the personal information tied to ownership, which creates legal and privacy risks that deter ordinary consumers. As crypto companies scale, their security posture only equals their least-protected system, and customer data breaches inflict more reputational damage than technical wallet compromises.

Companies' Careless Email Defaults Expose Private Data at Scale

Security researchers bought abandoned domains like noreply.net and deleteduser.com and received years of misdirected sensitive data—passwords, medical records, financial statements—that companies automatically sent to these addresses. Automation and default email practices have created a system where corporate negligence, not sophisticated hacking, is the primary vector for mass data exposure. For consumers, privacy is threatened not by malicious actors alone but by the routine operational negligence of every company you've interacted with.

Exposed Passport Database Highlights ID Verification Infrastructure Gaps

A misconfigured cloud storage bucket exposed nearly a million identity documents. The incident reflects a broader problem: biometric and identity verification vendors operating at the infrastructure layer of digital onboarding often treat security as secondary to deployment speed. Companies handling government-issued credentials apply less rigor than financial services would demand, even as digital identity becomes the gating layer for financial services, hiring platforms, and government access globally. The vulnerability isn't encryption or hacking—it's the proliferation of unvetted third-party identity platforms that enterprises trust without understanding their security posture.

Hotel check-in system exposed a million travel documents to the internet

A misconfigured cloud storage bucket—the most common form of data exposure in hospitality—shows that routine operational infrastructure (hotel registration systems) now holds identity verification data that criminals actively harvest for fraud. The system was public by default, meaning the vulnerability required zero technical skill to exploit and likely persisted for months before discovery. Hotels appear to lack basic audit practices for third-party vendors handling biometric and document data.