

Check your permissions: default settings in Microsoft tool exposes 38 million us...
source link: https://www.theverge.com/2021/8/24/22639106/microsoft-power-apps-default-permissions-settings-user-records-exposed-38-million-upgard
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Check your permissions: default settings in Microsoft tool exposes 38 million user records online
Thankfully, there’s no evidence the data has been exploited
Illustration by Alex Castro / The Verge
Default permissions settings in an app-building tool from Microsoft have been blamed for exposing the data of 38 million people online. Information including names, email addresses, phone numbers, social security numbers, and COVID-19 vaccination appointments was inadvertently made publicly accessible by 47 different companies and government entities using Microsoft’s Power Apps platform. There’s no evidence of the data being exploited, though, and the underlying issue has now been fixed by Microsoft.
The problem was originally discovered in May by security research team UpGuard. In a recent blog post from UpGuard and report from Wired, the company explains how organizations using Power Apps created apps with improper data permissions.
“We found one of these [apps] that was misconfigured to expose data and we thought, we’ve never heard of this, is this a one-off thing or is this a systemic issue?” UpGuard’s vice president of cyber research Greg Pollock told Wired. “Because of the way the Power Apps portals product works, it’s very easy to quickly do a survey. And we discovered there are tons of these exposed. It was wild.”
Power Apps allows companies to build simple apps and websites without formal coding experience. Organizations implicated in the breach — including Ford, American Airlines, J.B. Hunt, and state agencies in Maryland, New York City, and Indiana — were using the site to collect data for various purposes, including organizing vaccination efforts. Power Apps offers tools for quickly collating the sort of data needed in these projects, but, by default, leaves this information publicly accessible. This is the exposure UpGuard discovered.
The mechanism of this particular ‘breach’ is interesting, as it blurs the line between what is a software vulnerability and what is merely poor choice in user interface design. UpGuard says Microsoft’s position is that this was not a vulnerability as it was users’ fault for not properly configuring the apps’ permissions. But, arguably, if you are making an app designed to be used by people with little coding experience, then making things as safe as possible by default would seem to be the smart move. As reported by Wired, Microsoft has now changed the default permissions settings responsible for the exposure.
Recommend
-
6
AdvertisementWordPress released Gutenberg 11.6, the latest version of the block-based website editing experience. This new release features useful enhancements and a number of bug fixes as well. Perhaps the most int...
-
5
Executive Summary Varonis researchers enumerated a list of 812 subdomains and found 689 accessible Jira instances. We found 3,774 public dashboards, 244 projects, and 75,629 issues containing email addresses, URLs, a...
-
8
WordPress Security Plugin Exposes +1 Million WebsitesWPS Hide Login WordPress Plugin exposed the location of the hidden login page, defeating the purpose of the plugin / 3 hours ago / 3 min read
-
14
Catastrophic Log4j Security Fail Threatens Enterprise Systems & Web Apps WorldwideA serious code execution vulnerability in Log4j has security experts warning of potentially catastrophic consequences for enterprise organizations...
-
9
This is the seventh and final part of a series of blog posts related to Azure AD best practices. They are all related to a talk I gave at Tech Days Finland as well as in the Microsoft Identity Developer Community Office Hours. For the...
-
7
Data breach at Nelnet exposes 2.5 million student loan records ...
-
4
Twitter API security breach exposes 5.4 million users’ data
-
2
Microsoft to Improve Default App Settings in Windows 11
-
3
Removing automapping and resetting default mailbox permissions in Exchange Online Corrupted mailbox permissions and automapping settings are not that uncommon scenario and many Exchange admins hav...
-
11
Ransomware Attack On US Dental Insurance Giant Exposes Data of 9 Million Patients
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK