• AutoTL;DR@lemmings.worldB
    link
    fedilink
    arrow-up
    2
    ·
    3 days ago

    This is the best summary I could come up with:


    A prominent identity verification firm that has contracted with TikTok, Uber, X, and other large platforms, left a set of administrative login credentials exposed to the internet for more than a year, according to a report from 404 Media.

    The credentials could have allowed a bad actor to access sensitive user information, including images of Americans’ driver’s licenses, the outlet writes.

    At the time, Elon Musk was rolling out a number of new, controversial features, including optional user verification for Blue subscriber accounts.

    To verify users on sites like X, AU10TIX asks for a number of identifying data points, including selfies and pictures of government-issued IDs.

    404 Media writes that the debacle started because an AU10TIX staffer’s login credentials were harvested by malware in 2022 and later posted to a Telegram channel.

    According to AU10TIX’s website, it has partnered with many other large, prominent platforms and brands, including PayPal, LinkedIn, Coinbase, eToro, and UpWork, among others.


    The original article contains 428 words, the summary contains 156 words. Saved 64%. I’m a bot and I’m open source!