Kickstarter Bug Exposes Private Project Info to Public

On Friday, a Kickstarter engineer discovered a small bug in Kickstarter’s private API.  The bug allowed a user’s private project data to be accessed via the API.  No financial data was compromised, but users with private projects may have had some of their information leaked.  Kickstarter reports that 48 projects were accessed during the weeks where the bug was live, but there’s no telling whether those were authorized by the original project owners or not.

In emerging social networks, and especially in networks like Kickstarter that involve financial transactions, security is critical to users’ willingness to participate.

AW+

WORK SMARTER - LEARN, GROW AND BE INSPIRED.

Subscribe today!

To Read the Full Story Become an Adweek+ Subscriber

View Subscription Options

Already a member? Sign in