Slashdot Mirror


Kickstarter Leaves Project Ideas Exposed

netbuzz writes "Crowd-funding startup Kickstarter is taking a public-relations hit today after it was reported that some 70,000 not-yet-public project ideas were left exposed on the company's Web site for more than two weeks. Kickstarter insists that no financial information was compromised and that only a few dozen of the projects were actually accessed. 'Obviously our users' data is incredibly important to us, the company said in a blog post. 'Even though limited information was made accessible through this bug, it is completely unacceptable.'"

3 of 56 comments (clear)

  1. "Exposed" defined: by Bananatree3 · · Score: 5, Informative
    TFA reads:

    This bug allowed some data from unlaunched projects to be made accessible via the API. It was immediately fixed upon discovering the error. No account or financial data of any kind was made accessible. The bug was introduced when we launched the API in conjunction with our new homepage on April 24, and was live until it was discovered and fixed on Friday, May 11, at 1:42pm. The bug made accessible the project description, goal, duration, rewards, video, image, location, category, and user name for unlaunched projects.

  2. Relatively quick disclosure by Anonymous Coward · · Score: 2, Informative

    Discovered and fixed on Friday, publicly disclosed on their blog on Monday. While it's not good that they had this bug in the first place, it's refreshing to see them take responsibility for it and explain it publicly and promptly.

  3. Re:I so meta... by CastrTroy · · Score: 4, Informative

    Obligatory XKCD.

    --

    Anthropic principle: We see the universe the way it is because if it were different we would not be here to see it.