Stories
Slash Boxes
Comments

SoylentNews is people

posted by mrpg on Wednesday December 20 2017, @07:30PM   Printer-friendly
from the forecast-cloudy dept.

Submitted via IRC for AndyTheAbsurd

An Amazon Web Services (AWS) S3 cloud storage bucket containing information from data analytics firm Alteryx has been found publicly exposed, comprising the personal information of 123 million US households.

[...] The 36 GB data file titled "ConsumerView_10_2013" contained over 123 million rows, each one signifying a different American household. A similar file was seen by UpGuard when the personal details of 198 million American voters, compiled in a dataset by a data firm used by the Republican National Committee, were exposed.

[...] Default security settings for S3 buckets usually allow only authorised users to access the contents; however, UpGuard reports the bucket was configured via permission settings to allow any AWS "Authenticated Users" to download its stored data.

Authenticated users are any user that has an AWS account.

[...] Alteryx took ownership for the bucket after it had secured it, UpGuard said, with an Alteryx spokesperson playing down the leak to Forbes.

"Specifically, this file held marketing data, including aggregated and de-identified information based on models and estimations provided by a third-party content provider, and was made available to our customers who purchased and used this data for analytic purposes," the spokesperson is quoted by Forbes as saying. "The information in the file does not pose a risk of identity theft to any consumers."

Source: Alteryx S3 leak leaves 123m American households exposed


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by fishybell on Thursday December 21 2017, @01:32AM

    by fishybell (3156) on Thursday December 21 2017, @01:32AM (#612664)

    S3 is a data storage service provided by Amazon.

    It has a medium-sized list of recommended security best-practices, then an almost infinite list of security options for users and services. It is easy to misconfigure.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2