Facebook with Latestnigeriannews  Twieet with latestnigeriannews  RSS Page Feed
Home  |  All Headlines  |  Punch  |  Thisday  |  Daily Sun  |  Vanguard   |  Guardian  |  The Nation  |  Daily Times  |  Daily Trust  |  Daily Independent
World  |  Sports  |  Technology  |  Entertainment  |  Business  |  Politics  |  Tribune  |  Leadership  |  National Mirror  |  BusinessDay  |  More Channels...

Viewing Mode:

Archive:

  1.     Tool Tips    
  2.    Collapsible   
  3.    Collapsed     
Click to view all Entertainment headlines today

Click to view all Sports headlines today

A Website Listing Millions Of Valuables Almost Became A 'Burglar's Shopping List' Because Of A Design Flaw

Published by Business Insider on Wed, 07 Jan 2015


A website listing the valuables of millions of Britons was nearly transformed into a "burglar's shopping list" due to acritical vulnerability in its software, the BBC reportsImmobilise is a UK website which acts as a free register for individuals' and businesses' valuables. It has more than 4 million registered accounts, listing more than 28 million valuables, ranging from computer hardware to bikes to jewellery. It's supported by the British police as it helps combat theft by providing a nationwide database of goods with serial numbers that can be cross-referenced against for "recovered goods or suspected stolen property," its website states.But a vulnerability discovered by security researcher Paul Moore and publicised this week meant hackers were theoretically able to access the entire database of 28 million valuable items, in addition to the addresses they're registered to. It's "quite a nice shopping list for a would-be burglar," Moore writes."They'll know your name, home address, telephone number(s), email address, the make/model of your item, any identifying factors (serial numbers, IMEIs, unique marks etc), and even how much it's worth," the researcher continues. "Sure it'll take some time and you're bound to hit a rate limiter along the way, but even if it takes a day/week/month, it's worth the wait."Each record had a ID number. The way the vulnerability worked was by changing the ID number so that users could gain unauthorised access to any record with no password required. As Security Week notes, this design was actually "a feature that allowed police and insurance companies to verify the authenticity of an ownership certificate based on its ID." In short, the site was "insecure by design."The initial issue was identified more than a year ago and reported to Recipero, the company responsible for Immobilise. While Recipero did take action, a vulnerability allegedly still remained for more than a year'and was patched only after Moore told Recipero his intention to publish.Recipero has maintained that no data was ultimately compromised by the vulnerability. There's"no evidence of any data leakage," a statement says. The company has also apologised to its customers, but not for the fault in its software. Instead, Recipero says it"apologises for any alarm that the BBC report on 6th January concerning Immobilise.com may have caused you."On Twitter, BBC reporter Dave Lee says that Recipero warned him there were "inaccuracies" in Moore's report, but that they wouldn't reveal them unless the BBC "help the article... or alternatively sent them the piece ahead of publication." The BBC chose not to do so, and Recipero has subsequently failed to respond to their enquiries as to the nature of the inaccuracies.Join the conversation about this story
Click here to read full news..

All Channels Nigerian Dailies: Punch  |  Vanguard   |  The Nation  |  Thisday  |  Daily Sun  |  Guardian  |  Daily Times  |  Daily Trust  |  Daily Independent  |   The Herald  |  Tribune  |  Leadership  |  National Mirror  |  BusinessDay  |  New Telegraph  |  Peoples Daily  |  Blueprint  |  Nigerian Pilot  |  Sahara Reporters  |  Premium Times  |  The Cable  |  PM News  |  APO Africa Newsroom

Categories Today: World  |  Sports  |  Technology  |  Entertainment  |  Business  |  Politics  |  Columns  |  All Headlines Today

Entertainment (Local): Linda Ikeji  |  Bella Naija  |  Tori  |  Pulse  |  The NET  |  DailyPost  |  Information Nigeria  |  Gistlover  |  Lailas Blog  |  Miss Petite  |  Olufamous  |  Stella Dimoko Korkus Blog  |  Ynaija  |  All Entertainment News Today

Entertainment (World): TMZ  |  Daily Mail  |  Huffington Post

Sports: Goal  |  African Football  |  Bleacher Report  |  FTBpro  |  Kickoff  |  All Sports Headlines Today

Business & Finance: Nairametrics  |  Nigerian Tenders  |  Business Insider  |  Forbes  |  Entrepreneur  |  The Economist  |  BusinessTech  |  Financial Watch  |  BusinessDay  |  All Business News Headlines Today

Technology (Local): Techpoint  |  TechMoran  |  TechCity  |  Innovation Village  |  IT News Africa  |  Technology Times  |  Technext  |  Techcabal  |  All Technology News Headlines Today

Technology (World): Techcrunch  |  Techmeme  |  Slashdot  |  Wired  |  Hackers News  |  Engadget  |  Pocket Lint  |  The Verge

International Networks:   |  CNN  |  BBC  |  Al Jazeera  |  Yahoo

Forum:   |  Nairaland  |  Naij

Other Links: Home   |  Nigerian Jobs