Canadian Vaccine Passport App Exposes Data

Canadian Vaccine Passport App Exposes Data

Canadian vaccine passport app PORTpass may have exposed personal information belonging to hundreds of thousands of users. 

According to a report by CBC News, the app’s operators left data, including names, identification documents, and email addresses, on an unsecured website. The personal information was allegedly stored in plain text and could be accessed by the public. 

Following a tipoff received on Monday, the news source investigated the security of the PORTpass website. CBC News said it was able to verify that app user’s information, among others: “Email addresses, names, blood types, phone numbers, birthdays, as well as photos of identification like driver’s licenses and passports can easily be viewed by reviewing dozens of users’ profiles.”

In an article published September 28, the news source wrote: “CBC is not sharing how to access those profiles, in order to protect users’ personal information.”

CBC added: “The information was not encrypted and could be viewed in plain text.”

The team behind the app is based in Calgary and led by Chief Executive Officer Zakir Hussein. In response to concerns over the app’s security, Hussein reportedly denied that PORTpass was experiencing any verification or security issues.

However, the app’s website has been taken offline, and visitors to the site are currently met with the message, “We are updating. Stay tuned.”

PORTpass is described on Google Play as “a secure and contactless way for a member of the public to gain access to a building, site, or ticketed event using their secure MapleCode.”

Hussein reportedly said the app has more than 650,000 registered users across Canada. 

Trevor Morgan, product manager with data security experts comforte AG, commented: “Unless the app vendor goes to great lengths to apply data-centric security such as format-preserving encryption or tokenization to protect sensitive data by obfuscating sensitive data elements, situations like this one will happen again and again, and people will hesitate to adopt such tools. 

“Any time an organization collects and processes peoples’ health information, it has the ultimate responsibility to protect that data and ensure it is never presented in readable format to unauthorized users.” 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Mulls Cyber-attack Reporting Mandate

US Mulls Cyber-attack Reporting Mandate

Legislation requiring critical infrastructure companies to report cyber-attacks to the federal government has been introduced in the United States Senate.

Leaders of the Senate Homeland Security and Governmental Affairs Committee put forward the new cyber-incident reporting bill yesterday. If enacted, critical infrastructure owners and operators would have to report cyber-attacks to the government within 72 hours. 

The proposed bill echoes the defense authorization bill passed by the House of Representatives that requires critical infrastructure owners and operators to report significant cybersecurity incidents within a 72-hour time frame.

Included in the new legislation is a proposal to create a Cyber-Incident Review Office within the Cybersecurity and Infrastructure Security Agency (CISA). The role of the office would be to receive, aggregate, and analyze reported incidents.

The new bill would also make it mandatory for organizations, including businesses with more than 50 employees, nonprofits, and state and local governments, to inform CISA of any ransomware payments they make. Organizations infected with ransomware would be required by law to consider recovery tactics other than paying their attackers. 

CISA would be empowered under the new legislation to subpoena entities that flout the incident-reporting and ransomware-payment requirements. Potential penalties for those that do not comply include referral to the Department of Justice and being banned from federal contracting. 

Under the legislation, participants from federal agencies would create a Joint Ransomware Task Force “to coordinate an ongoing, nationwide campaign against ransomware attacks, and identify and pursue opportunities for international cooperation.”

Homeland Security and Governmental Affairs chairman Gary Peters, who introduced the bill, said it could help to limit the impact of cyber-assaults.

“When entities, such as critical infrastructure owners and operators, fall victim to network breaches or pay hackers to unlock their systems, they must notify the federal government so we can warn others, prepare for the potential impacts, and help prevent other widespread attacks,” said Peters in a statement.

Earlier this month, Peters said that the Federal Information Security Modernization Act – which was last updated over six years ago – did not go far enough to protect federal networks. He then called for cyber-attack reports to be shared by the federal government in a timely manner.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains