App flaw let anyone access UK Conservative politicians’ data

The UK Conservative party is learning a hard lesson about the importance of basic security measures in mobile apps. Users have discovered that you could log into the party’s conference app using only an attendee’s email address, providing access to all kinds of sensitive data. And when many of the conference participants are politicians who registered with their email addresses at Parliament… you can guess what happened next.

Users entered the email addresses of major politicians, including Michael Gove and Boris Johnson, and promptly discovered info like mobile phone numbers. In some cases, people started messing with that data. One person changed Johnson’s photo to a porn image, while another altered Gove’s portrait to that of his former boss Rupert Murdoch. It was harder to obtain info for people who weren’t politicians, but they too were vulnerable if you could obtain their email addresses.

CrowdComms, the Australian company behind the app, removed the login feature through an update to curb further abuse. The Conservatives, meanwhile, said they were “investigating the issue further.” While it’s not certain just who decided on the password-free sign-ins, many have criticized the party for a lack of oversight that might have caught such a glaring oversight before the app went live. This was easily avoidable, and may have had lasting consequences beyond the conference.

Source: Dawn Foster (Twitter), Guardian

Post Author: martin

Martin is an enthusiastic programmer, a webdeveloper and a young entrepreneur. He is intereted into computers for a long time. In the age of 10 he has programmed his first website and since then he has been working on web technologies until now. He is the Founder and Editor-in-Chief of BriefNews.eu and PCHealthBoost.info Online Magazines. His colleagues appreciate him as a passionate workhorse, a fan of new technologies, an eternal optimist and a dreamer, but especially the soul of the team for whom he can do anything in the world.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.