Hacker News new | ask | show | jobs
by kapitanjakc 632 days ago
I found similar vulnerability in Bus State transport facility of government, where you can get list of everyone who did reservation online.

You can get their gender, age, name, mobile number.

I simply reported it to their website's support email and state cyber cell.

This was 7 years ago, that vulnerability still exists.

1 comments

This is why security researchers (threaten to) release this kind of information publicly. Reporting security issues doesn't fix anything until other people learn the details.