https://arstechnica.com/gadgets/2021...e-information/
Peloton is having a rough day. First, the company recalled two treadmill models following the death of a 6-year-old child who was pulled under one of the devices. Now comes word Peloton exposed sensitive user data, even after the company knew about the leak. No wonder the company’s stock price closed down 15 percent on Wednesday.
...
Researchers at security consultancy Pen Test Partners on Wednesday reported that a flaw in Peloton’s online service was making data for all of its users available to anyone anywhere in the world, even when a profile was set to private. All that was required was a little knowledge of the faulty programming interfaces that Peloton uses to transmit data between devices and the company’s servers.
Data exposed included:
Ars agreed to withhold another piece of personal data exposed because Peloton is still working to secure it.
...
Researchers at security consultancy Pen Test Partners on Wednesday reported that a flaw in Peloton’s online service was making data for all of its users available to anyone anywhere in the world, even when a profile was set to private. All that was required was a little knowledge of the faulty programming interfaces that Peloton uses to transmit data between devices and the company’s servers.
Data exposed included:
- User IDs
- Instructor IDs
- Group Membership
- Workout stats
- Gender and age
- Weight
- If they are in the studio or not
Ars agreed to withhold another piece of personal data exposed because Peloton is still working to secure it.
Leave a comment: