قالب وردپرس درنا توس
Home https://server7.kproxy.com/servlet/redirect.srv/sruj/smyrwpoii/p2/ Business https://server7.kproxy.com/servlet/redirect.srv/sruj/smyrwpoii/p2/ bank statements, drivers' licenses, SSNs, and tax records / Boing Boing

bank statements, drivers' licenses, SSNs, and tax records / Boing Boing



First American Financial Corp is a Fortune 500 company that insures titles on peoples' property; their insecure website exposed 885,000,000 records for property titles, going back 16 years, including bank accounts (with scanned statements), social security numbers, wire transaction receipts, scanned drivers' licenses, tax records, mortgage records, etc – when notified of the error, the company (which employs 18,000 people and more than $ 5.7B last year) closed the misconfiguration.

It's not clear whether or not records were compromised.

The error was in the company's customer portal, which anyone who ever closed a real-estate purchase mediated by First American would have accessed. All it took to gain access to other peoples' records was to change the customer number in the portal, adding or subtracting one to step through every customer on file, back to 2003.

KrebsOnSecurity confirmed the real estate developer's findings, which indicates that First American's web site exposed approximately 885 million files, the earliest dating back more than 16 years. No authentication was required to read the documents.

Many of the exposed files are records of wire transactions with bank account numbers and other information from home or property buyers and sellers. Ben Shoval, the developer who notified KrebsOnSecurity about the data exposure, said because First American is one of the most widely used companies for real estate title insurance and for closing real estate deals – sign stacks of legal documents.

“Closing agencies are supposed to be the only neutral party that doesn’t represent anyone else's interest,” says Shoval.

First American Financial Corp. Leaked Hundreds of Millions of Title Insurance Records [Brian Krebs/Krebs on Security]

( via The Verge )

<! –

Cory Doctorow

I write books. My latest graphic is called "In Real Life" (with Jen Wang); a nonfiction book about the arts and the internet called information for wanting to be free: Laws for the Internet Age (with introductions by Neil Gaiman and Amanda Palmer) and a YA science fiction novel called Homeland (it's the sequel to Little Brother) . I speak all over the place and I tweet and tumble, too.

->


Source link