Categories: News

Target Wish List App Vulnerable To Data Hijacking

Data leaks are becoming more common all over the world in recent times. When personal information is leaked, however, things take a turn for the worst. Target’s wish list application is not safe from harm by the look of things, as a fair amount of customer details have been made public. As a result, part of the app’s features have been suspended for the time being.

Also read: Can Companies Simplify The Conversion From Bitcoin To Fiat Currency?

Target Wish List App Is Not That Safe

What makes wish list applications so interesting is how consumers can put together an overview of items they would like to receive during the year. With the holiday season almost upon us, finding that perfect gift for loved one can prove to be quite a challenge. Thanks to Target’s wish list app, that job has become slightly easier.

Unfortunately, the Target wish list application is not keeping customer information safe, which can be attributed to some sloppy coding along the way. In fact, Avast security researchers noted how the app database is storing the information in such a way that it becomes publicly accessible once you figure out the app’s programming interface. To make matters even worse, that programming interface is publicly available.

In fact, obtaining the information stored in this database can be achieved by using the API, which only requires a “question” as a condition to return information. Once an assailant figures out how the user’s ID is generated, they have access to names, addresses, and email addresses. Not the kind of information one wants out in the open.

Target has not officially responded to this discovery, although one of their spokeswomen stated how certain elements of the application have been disabled for the time being. Engineers and developers are looking at the application’s source code, and a security update will be released in the near future.

Related Post

There is always a certain tradeoff to be made in these types of applications, as some will require a lot of unnecessary permissions whereas others are making information too accessible to the public. Companies really have to step up their game if they want to develop proper applications that are not invading user privacy while still protecting customer data at the same time.

No Financial Information Has Been Stolen So Far

One positive thing to note is how no financial data has been stolen from Target users. Even though the wish list app stores a lot of sensitive information, financial details are not among them [♦as far as we know]. While this is somewhat of a relief, it doesn’t change the fact that Target’s app is leaking on all sides.

This is why Bitcoin is a far more superior method of payment, as there is no vital information that can be leaked at any time. In the worst case scenario, the user’s Bitcoin wallet address is obtained, but an attacker can’t do anything with that unless they obtained the private key associated with that wallet.

Source: Ars Technica

Images credit 1,2,3

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Starknet Introduces STRK20 To Bring Built-In Privacy To ERC-20 Tokens

The team behind Starknet has introduced a new token standard aimed at solving one of…

2 days ago

Meta Acquires Moltbook, A Social Network Built For AI Agents To Interact And Coordinate

In a move that highlights the growing race to build infrastructure for autonomous artificial intelligence,…

2 days ago

Polymarket Partners With Palantir To Develop AI Platform For Sports Betting Integrity

Prediction market platform Polymarket has entered a new partnership with Palantir Technologies and artificial intelligence…

2 days ago

Ethereum Foundation Begins Staking Treasury ETH Using Bitwise Infrastructure

The Ethereum Foundation has begun staking part of its treasury, marking a significant step in…

3 days ago

Cyberconnect And SurfAI Founder Reportedly Under Investigation In China

Fresh reports circulating in the crypto space suggest that Wei Jiequan, better known as Wilson…

3 days ago

Virtuals And dAI Launch ERC-8183 To Enable Trustless Agentic Commerce On Ethereum

The infrastructure powering autonomous AI agents on Ethereum is slowly coming together. Payments, trust layers,…

3 days ago