Whoops: FlightAware Exposes Sensitive Personal Data Of Millions Of Users, Pilots, And Plane Owners

from the another-day,-another-scandal dept

Popular flight tracking app FlightAware says that they accidentally leaked the personal data of its 10,000 aircraft operators and 12 million users. According to an announcement by the company sent to users, “a configuration error” resulted in the company exposing user usernames, passwords, email addresses, names, billing addresses, telephone numbers, birth dates, aircraft ownership records, user data, and more.

The company is requesting that users reset their account passwords:

FlightAware values your privacy and deeply regrets that this incident occurred. Once we discovered the exposure, we immediately remedied the configuration error. Out of an abundance of caution, we are also requiring all potentially impacted users to reset their password.

In other words, almost all of the data users entered into the website was accidentally left freely available on the open internet. The company didn’t specify whether this data was externally accessed; likely because they don’t know.

As we’ve noted repeatedly, such mistakes are increasingly commonplace in a country that’s simply too corrupt to pass a meaningful privacy law for the internet era. Trading in user data is simply too lucrative, Congress has repeatedly declared, to impose any sort of guard rails on companies (and executives specifically) that over-collect your data, hyper-monetize it, yet fail to adequately secure it.

They do that because the tiny regulatory fines and penalties (if there are any) are viewed as a near-irrelevant cost of business compared to the costs they’d incur from respecting consumer privacy and implementing tough security standards. Nothing changes until those penalties are dramatically reformed and expanded; especially for individual executives.

Flight data, of course, creates a particularly sensitive national security risk. And while Congress did recently pass a privacy law related to flight data privacy, it was simply to protect rich Americans worried about being scolded for their environmentally harmful excessive private jet use.

Filed Under: , , ,
Companies: flightaware

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Whoops: FlightAware Exposes Sensitive Personal Data Of Millions Of Users, Pilots, And Plane Owners”

Subscribe: RSS Leave a comment
11 Comments
Anonymous Coward says:

Re: You get what you pay for.

While I agree, you know what?

Newly minted CS grads are cheaper to hire than 15 year veteran programmers. 15 year veteran programmers are cheaper to hire than 20 year programmers who have trained and practiced in security (and have made many of those mistakes already).

If the job goes to the lowest bidder…

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Subscribe to Our Newsletter

Get all our posts in your inbox with the Techdirt Daily Newsletter!

We don’t spam. Read our privacy policy for more info.

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...