The private data of millions of European Internet users have been accessible for several weeks on various pornographic sites.
Private data that we consent to leave on the sites we visit and use are sometimes sensitive data, especially when it comes to adult sites. After the 3Fun affair, which had already paid attention to the almost daily chronicle of data leaks, today is a network of Spanish “camgirls” sites that is making headlines.
Several popular sites exposed millions of sex workers and users after the company managing the sites left an unprotected database. The sites, managed by VTS Media, based in Barcelona, include amateur.tv, webcampornoxxx.net, and placercams.com. Most site users are based in Spain and Europe, although according to our colleagues from TechCrunch, there would be users around the world, sex does not really borders.
The database, which contains months of daily recordings of site activities, was left without a password for weeks. The logs included detailed records of when users logged in, including usernames and sometimes their IP addresses. Newspapers also included users’ private messages to each other, as well as promotional e-mails they received from various sites. The logs even included failed login attempts, storing usernames and passwords in clear text.
The exposed data also revealed which videos users viewed and praised, exposing private sexual preferences. The logs were detailed enough to see which users were logging in, where, and often their email addresses or other identifiable information – that in some cases we could match real identities.
User data and camgirls exposed
Not only were the users affected, but the “camgirls” – who broadcast live sex content via webcam to viewers who subscribed to these sites – also saw some of their account information on display.
The database was closed last week. This is not a small deal because according to the Alexa ranking of traffic, amateur.tv is one of the most popular sites in Spain.
According to researchers at Condition: Black, a cybersecurity and Internet freedom company, “This is a serious technical and compliance failure. After reviewing the data privacy policy and site terms and conditions, it is clear that users probably had no idea that their activities were being monitored at this level of detail. Users should always consider the implications of their data leaks, but especially where they could impact people’s lives. “
Data exposure – where companies inadvertently leave their own systems open to all – has become increasingly common in recent years. Dating sites are among those that contain the most sensitive data. These security vulnerabilities can be extremely detrimental to their users, exposing private sexual encounters and known preferences only by the users themselves.
As with the exhibition of the 3Fun dating service database, camgirl site exposure is not just a potential security risk. Listening habits could be used to blackmail people who fear that their sexual preferences will be revealed. A problem all the more worrying when we know that victims of this kind of failure or abuse rarely complain because they do not wish to reveal their intimate activity on the internet.