Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

... and the BlueToad blog post. Nothing of substance, mostly just a "sorry" and "we've fixed it".

http://blog.bluetoad.com/2012/09/10/statement-from-bluetoad-...



I wish they also said they were not collecting "other personal data as, full names, cell numbers, addresses, zipcodes", which the pastebin posters claimed was in the original file.

Unfortunately, BlueToad's statement leaves some wiggle room.

"BlueToad does not collect, nor have we ever collected, highly sensitive personal information like credit cards, social security numbers or medical information. The illegally obtained information primarily consisted of Apple device names and UDIDs – information that was reported and stored pursuant to commercial industry development practices."

Edit: The "98% correlation" leads me to believe the publicly posted info is the full extent of the leak.


Why? If 98% of the posted UDIDs are in their database then I could see them say "98% correlation"


Good to see they don't forget the obligatory, "we take information security very seriously," line.


They always seem to say that in retrospect, even though the evidence shows they obviously don't take their security very seriously. Otherwise, they wouldn't of had such a leak.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: