Subscribe Sign in

Test environment let anyone access live customer data

1 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1 A3×2 D2×3 D3×5 D4 E3×4 F2×4 all 30 rules
  • Even a temporary staging server needs to be locked down.
  • Today’s tales of woe comes courtesy of Richard Schut, Managing Director & AI Software Researcher at SmartRepl, a company that offers business AI services such as AI receptionists and sales automation.
  • Schut and his team discovered that there was a test environment that was accessible outside the network and connected to a database which had live customer information in it.
  • After Schut and his colleagues discovered the security vulnerability, he at once restricted access to the staging environment.

4 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

There is nothing in this headline a machine can check against the report: no figure, no name and no quotation.

Nothing was measured here, so nothing is claimed. How this is checked

Even a temporary staging server needs to be locked down.

Welcome back to PWNED, the weekly column where we learn life lessons about how we let cybercrims access our data through carelessness. Hopefully, others’ mistakes provide an example of what not to do.

Today’s tales of woe comes courtesy of Richard Schut, Managing Director & AI Software Researcher at SmartRepl, a company that offers business AI services such as AI receptionists and sales automation. In a past job, Schut was working for what he describes as a mid-size company during a security audit whose purpose was to identify any potential problems ahead of moving some local systems to the cloud.

Schut and his team discovered that there was a test environment that was accessible outside the network and connected to a database which had live customer information in it.

The test environment was still running months after it was at first set up.

After Schut and his colleagues discovered the security vulnerability, he at once restricted access to the staging environment. Then he and his team started a review of other development and test environments in the company to make sure none of them was open to exploitation.

Shortened to 1 minute of reading, this version reads 6.8 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 9.4 5 49 -0.1 48.6
Mundane Readneutralized from The Register 7.3 4 49 -0.1 48.6

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works