Feeds

Dutch news agency goof leaks VIP phone numbers

Low security in the Low Countries

High performance access to file storage

Security shortcomings by Dutch press agency GPD exposed the private telephone numbers of politicians and other public figures to prying eyes until earlier this week.

Former telephone numbers of controversial anti-immigration MP Geert Wilders and an old (now disconnected) mobile, formerly belonging to prime minister Jan Peter Balkenende, were left exposed by the leak. Current phone numbers exposed by the snafu included those of TV presenters Mart Smeets, Jort Kelder and Felix Meurders, as well as those of hundreds of other celebrities and media figures in The Netherlands.

The exposed numbers were held on a communal database maintained by reporters at the agency. Technology site Tweakers discovered that the database was only protected by an easily-guessed password. Confidential telephone and other information was left open to anyone with enough nous to construct an appropriate Google search.

GPD has acknowledged the error and padlocked its database to protect sensitive information, Dutchnews reports.

Expatica adds that GPD is blaming a configuration error for the snafu, which exposed what ought to have been an internal intranet-only application to the great unwashed.

Dutch news outlet NOS has a story that contains a screen shot from Google returning the prime minister's mobile number (cropped out) here. And there's more on the story (for Dutch speakers) at nu.nl here.

The incident is not the first time GPD has made the news itself as a result of information security shortcomings. In November 2007, two officials from the Ministry of Social Affairs were caught lifting information from the GPD database using the credentials of a former employee. ®

Bootnote

Thanks to Dutch reader Edwin for the tip on this story.

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.