The Asian Age

Microsoft data mistakenly exposed

-

San Francisco, Aug. 24: Some 38 million records stored on a Microsoft service, including private informatio­n, were mistakenly left exposed this year, security firm UpGuard said Monday.

The data, including names, addresses, financial informatio­n and Covid-19 vaccinatio­n statuses, was made vulnerable — but not compromise­d — before the problem was resolved, according to the digital security company’s investigat­ion.

Among the 47 affected organizati­ons were American Airlines, Ford, JB Hunt and public agencies such as the Maryland

Department of Health and New York City's public transit system.

They all used a Microsoft product called Power Apps, which allows for the creation of websites and mobile apps to interact with the public.

The service's default software configurat­ion setting meant the data of the affected organisati­ons was left without protection up until June 2021, according to UpGuard.

“As a result of this research project, Microsoft has since made changes to Power Apps portals,” the report said.

Microsoft said it had let clients know when potential security risks were uncovered so that they could fix the problems themselves.

“We take security and privacy seriously, and we encourage our customers to use best practices when configurin­g products in ways that best meet their privacy needs,” a spokespers­on said.

But UpGuard said it would have been better to change the way the software works at the source, and based on how customers use it, rather than “to label systemic loss of data confidenti­ality an end user misconfigu­ration, allowing the problem to persist.”

 ??  ?? Microsoft logo adorns a building in Chevy Chase, Maryland. Some 38 million records stored on a Microsoft service, including private informatio­n, were mistakenly left exposed this year, security firm UpGuard said.
Microsoft logo adorns a building in Chevy Chase, Maryland. Some 38 million records stored on a Microsoft service, including private informatio­n, were mistakenly left exposed this year, security firm UpGuard said.

Newspapers in English

Newspapers from India