Vietnam.vn - Nền tảng quảng bá Việt Nam

Data from 2.6 million Duolingo users was leaked publicly.

Báo Thanh niênBáo Thanh niên24/08/2023


Duolingo is the world's largest language learning website and app, with over 74 million monthly users. According to Bleeping Computer, the leak of Duolingo users' personal data could allow hackers to carry out targeted phishing attacks.

In January 2023, an account on a hacker forum sold data collected from 2.6 million Duolingo users for $1,500; the forum has since ceased operations.

This data includes login information, real names, as well as non-public information, including email addresses and internal information related to Duolingo's service. While Duolingo user profiles publicly display real names and login names, email addresses are kept private.

Dữ liệu 2,6 triệu người dùng Duolingo bị phát tán công khai - Ảnh 1.

The advertisement offered to sell 2.6 million Duolingo user data records for $1,500.

Duolingo confirmed to TheRecord that the data collected and sold was taken from public profiles, and the service is investigating whether it should take preventative measures. However, Duolingo did not mention the fact that email addresses were also listed in the data.

You may also like
China surpasses the US to possess the world's most powerful supercomputer.
China surpasses the US to possess the world's most powerful supercomputer.The LineShine supercomputer was built entirely using microprocessors designed in China, instead of using US-made chips that power most of the world's leading systems.
The proposal for the "right to request data deletion": A shield for consumers in the digital age.
The proposal for the "right to request data deletion": A shield for consumers in the digital age.VHO - The proposal to add the "right to request data deletion" for consumers in the draft amended Postal Law is considered a notable step forward in strengthening the protection of people's privacy in the digital age.
Why can't RAM prices stop rising?
Why can't RAM prices stop rising?The global shortage of memory chips is driving up the prices of consumer technology devices, but finding a short-term solution seems impossible.

Data from 2.6 million users was released yesterday on a new version of the hacker forum for just $2.13. This data was collected using a publicly shared application programming interface (API) since March 2023.

This Duolingo API allows people to submit access to users' public profile information. However, it's also possible to provide an email address to the API and verify whether that address is linked to a Duolingo account.

BleepingComputer stated that this API remained publicly available even after its misuse was reported to Duolingo in January.

It's conceivable that the hacker fed millions of email addresses—possibly leaked in previous data breaches—into the API to see if they belonged to Duolingo accounts. These email addresses were then used to create a dataset containing both public and non-public information.

Dữ liệu 2,6 triệu người dùng Duolingo bị phát tán công khai - Ảnh 2.

Hackers re-uploaded the data of 2.6 million Duolingo users for a very low price.

You may also like
The Prime Minister requested that a breakthrough mechanism for science and technology budgeting be submitted soon.
The Prime Minister requested that a breakthrough mechanism for science and technology budgeting be submitted soon.DNVN - Prime Minister Le Minh Hung has requested ministries to urgently propose breakthrough mechanisms for budget allocation and decentralization of authority to promote the development of science and technology, innovation, and digital transformation.
A department head in Phu Tho province was demoted for playing golf during working hours.
A department head in Phu Tho province was demoted for playing golf during working hours.Following a citizen's complaint, authorities in Phu Tho province have investigated the misconduct of a department-level official who arbitrarily left the office to play golf during working hours.
Chromium vulnerability threatens Chrome, Edge, and Opera: Users are advised to update immediately.
Chromium vulnerability threatens Chrome, Edge, and Opera: Users are advised to update immediately.A serious security vulnerability in the Chromium platform—the framework behind Google Chrome, Microsoft Edge, Opera, and many other popular browsers—is raising concerns about the risk of widespread data theft.

Companies tend to discard collected data, as most of it is already publicly available. However, when publicly available data is mixed with private data such as phone numbers and email addresses, it makes the information leak more risky and potentially violates data protection laws.

In 2021, Facebook suffered a massive data leak after its "Add Friend" API was misused to link phone numbers to the Facebook accounts of 533 million users. The Irish Data Protection Commission (DPC) fined Facebook €265 million ($275.5 million) for causing this data leak. More recently, a flaw in Twitter's API was used to access publicly available data and email addresses of millions of users, leading to a DPC investigation. Duolingo has yet to explain why it left this API publicly accessible despite reports of misuse.



Source link

Trending by Category

Most Read

Google Trends

Same author

Heritage

Figure

Enterprise

News

Political System

Destination

Product

Happy Vietnam
SPRING DATE

SPRING DATE

Springtime colors of the border region

Springtime colors of the border region

The peaceful countryside

The peaceful countryside