Telefonica Spain has inadvertently exposed the personal details of customers of its Movistar division. Names, addresses, fixed and mobile line numbers, email addresses and the call breakdown of Movistar customers were all exposed because of basic programming errors in Movistar’s online customer portal. Anyone with a Movistar …

  1. Zippy's Sausage Factory

    I can remember showing a vendor a fail like this on a system, years ago.

    "But nobody's ever going to do that," they said. "Don't worry about it."

    You'll be unsurprised to know we didn't buy their crap product.

    1. BillG

      Nobody is going to do that!

      @Zippy, I saw the same thing.

      I explained to a former employer how a similar issue could hack the corporate website and even bring it down. I got a very angry response of "Nobody is going to do that!" All traces of my complaint were erased.

  2. Anonymous Coward
    Anonymous Coward

    What class of Movistar customers were exposed?

    Prepaid Sim or Billpay or Home Bundle, or all of the above???

  3. amanfromMars 1 Silver badge

    IT's a Novel Virtualised Utility for AI Application in Future Productions

    This type of flaw is technically known as a Insecure Direct Object Reference (IDOR), a basic problem on poorly designed web applications that has been known about for many years but still crops up more than occasionally.

    1. David 132 Silver badge

      Re: IT's a Novel Virtualised Utility for AI Application in Future Productions

      Sssh. The grown-ups are talking.

  4. Anonymous Coward
    Anonymous Coward

    Any GDPR fine coming?

    "This type of flaw is technically known as a IDOR, a basic problem on poorly designed web applications that has been known about for many years but still crops up more than occasionally."

    The complacency shown is criminal. Until lawyers start bringing cases, I don't see things improving. Its not my problem attitude,except it fucking is!

    1. EnviableOne

      Re: Any GDPR fine coming?

      Agree, same with the OWASP top 10.

      Personally I think allowing any of them is grounds for prosecution for negligence

