PolyWolf on Security

The Missouri Govenor Said Something Really Dumb; Remember This Debacle?

Posted on 2021-10-14: https://twitter.com/govparsonmo/status/1448697768311132160

Govenor (at the time) Mike Parson:

Through a multi-step process, an individual took the records of at least three educators, decoded the HTML source code, and viewed the SSN of those specific educators.

We notified the Cole County prosecutor and the Highway Patrol’s Digital Forensic Unit will investigate.

Somehow, this never got taken down, despite literally everyone with a basic understanding of computers pointing out just how BS it was.

The “individual” he’s referring to was a cybersecurity professor, who didn’t even exploit any bugs, just looked at data embedded in the website being served. Which, for some inane reason, included sensitive SSNs. He even notified the website operators and gave them time to fix the vulnerability!

See these pieces by Ars Technica: