Slashdot Mirror


Blippy Exposes Credit Card Numbers Through Simple Google Search

An anonymous reader writes "In an unfortunate data breach, social media site Blippy has left credit card numbers in clear text, searchable via a simple Google query. The results show the amount spent on a transaction, the location, and the full card number. As of this submission, the issue still hasn't been resolved." The company's co-founder, Philip Kaplan, told the NY Times, "... when people link their credit cards to Blippy, merchants pass along their raw transaction data – including some credit card numbers – and the site scrubs that information to present just the merchant and the dollar amount spent. But several months ago, when Blippy was being publicly tested, that raw transaction data was present in the site's HTML code, where it was retrieved by Google. Mr. Kaplan said that early on, Blippy started disguising the raw transaction data behind the scenes, but it did not know about the breach until today."

3 of 95 comments (clear)

  1. Looks bad... for 4 people by alain94040 · · Score: 5, Informative

    As of this submission, the issue still hasn't been resolved

    Not true. If I read the explanation carefully, what really happened is that some credit card companies sometimes add the CC number to the description of the purchased item. Bad! Which also means that on your printed statement for instance, your full CC number will appear. During beta testing of Blippy, they were not aware of that "feature", so they let through the full CC number of 4 beta testers. Once they figured it out, they easily added a filter.

    If you were a beta tester for a service like Blippy, you can't be too shocked that this might happen. A better discussion would be what is Blippy really good for? I can see why I might like to browse other people's purchases once in a while, but why would I want to broadcast mine?

    --
    better than an internship in a startup: become a founder!

    1. Re:Looks bad... for 4 people by Anonymous Coward · · Score: 5, Funny

      Offtopic, I know, but do any of you know of any sites better than slashdot? Or does (mostly) intelligent discussion just not exist on the internet..

      You might try here

  2. Nothing to hide by Sir+Holo · · Score: 5, Funny

    If you have nothing to hide, then why not?

    /sarcasm (see NYT article)