Conservative conference App allowed access to ministers’ personal details
The Huffington Post is reporting that the Conservative Conference App allowed access to ministers’ personal details and the ability to alter them.
The tech company behind the Conservative Party conference app has accepted responsibility for a major flaw which… allowed anyone to log in as a politician, delegate or journalist attending the Birmingham event simply using their email address….
Jacobin’s Dawn Foster tweeted screenshots showing how she could log into Boris Johnson’s account without being asked for a password or provide confirmation.
Once in, Johnson’s personal details which he’d provided to sign up to the app were freely available.
All profiles could also be edited by anyone – Michael Gove’s picture was replaced with one of Rupert Murdoch and Johnson’s “position” was changed to …
The app, created by an Australian firm called Crown Comms, was updated and the login function removed after concerns were raised with the party….
A statement from CrowdComms said: “An error meant that a third party in possession of a conference attendee’s email address was able, without further authentication, to potentially see data which the attendee had not wished to share – name, email address, phone number, job title and photo. The error was rectified within 30 minutes…
“We will also be reporting this to the ICO and reviewing and amending our Data Policies. We apologise unreservedly to the Conservative Party and their delegates.”
Read more at Tory Conference App Security Blunder Exposes Ministers’ Personal Details
