2025-02-24

New Zealand Company’s ‘Impossible-to-Hack’ Security Turns Out to Be No Security at All

A New Zealand-based compliance software company, Teammate App, had a major security breach exposing over 2.9 million records including sensitive user data, despite claiming 'impossible-to-hack' security. When notified about the vulnerability, the CEO dismissed the security concerns and accused the researcher of harassment, while the exposed database contained user credentials, employee information, and accessible company documents.

Original archive.is archive.ph web.archive.org

Log in to get one-click access to archived versions of this article.

read comments on news aggregators:

Related articles

POLL: Trust in Firefox and Mozilla is Gone - Let's Talk Alternatives

Mozilla's recent source code changes removing the 'we don't sell your data' promise have severely damaged user trust, with a survey showing 90% of Firefox users either distrusting or doubting the organization. Multiple privacy-focused browser alternatives exist, including Librewolf, Waterfox, and emerging projects like Ladybird, offering users various options for secure browsing.

Teslas Monitor Everything—Including You | WIRED

Modern Tesla vehicles are equipped with extensive surveillance capabilities, including multiple cameras and sensors that collect significant amounts of data about the car's surroundings and occupants. While Tesla claims to protect user privacy through data anonymization and limited collection practices, investigations have revealed concerning privacy breaches and employee misuse of customer data. Privacy experts express skepticism about Tesla's data protection measures and policy transparency.

Martin Escardo (@MartinEscardo@mathstodon.xyz)

Recent concerns emerge about potential US government interference with academic platforms like arXiv, GitHub, and university IT systems, particularly regarding DEI policies and federal funding. ArXiv's cloud-based infrastructure and dependence on federal funding through Cornell University raise questions about its vulnerability, though bulk download options exist for data preservation.

DOGE as a National Cyberattack - Schneier on Security

A new Department of Government Efficiency (DOGE) has gained unprecedented access to critical US government systems, including Treasury, USAID, and OPM, bypassing essential security protocols and potentially exposing sensitive data. The breach involves uncleared personnel making system modifications while dismantling security measures, creating vulnerabilities that could be exploited by foreign adversaries.