{"id":236923,"date":"2024-06-27T01:53:30","date_gmt":"2024-06-27T01:53:30","guid":{"rendered":"https:\/\/michigandigitalnews.com\/index.php\/2024\/06\/27\/an-id-verification-service-that-works-with-tiktok-and-x-left-its-credentials-wide-open-for-a-year\/"},"modified":"2025-06-25T17:16:02","modified_gmt":"2025-06-25T17:16:02","slug":"an-id-verification-service-that-works-with-tiktok-and-x-left-its-credentials-wide-open-for-a-year","status":"publish","type":"post","link":"https:\/\/michigandigitalnews.com\/index.php\/2024\/06\/27\/an-id-verification-service-that-works-with-tiktok-and-x-left-its-credentials-wide-open-for-a-year\/","title":{"rendered":"An ID verification service that works with TikTok and X left its credentials wide open for a year"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p>An ID verification company that works on behalf of TikTok, X and Uber, among others, has left a set of administrative credentials exposed for more than a year, <a data-i13n=\"cpos:1;pos:1\" href=\"https:\/\/www.404media.co\/id-verification-service-for-tiktok-uber-x-exposed-driver-licenses-au10tix\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:as reported by 404 Media;cpos:1;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><em><\/em><\/a>. The Israel-based AU10TIX verifies the identity of users by using pictures of their faces and drivers\u2019 licenses, potentially opening up both to hackers.<\/p>\n<p>\u201cMy personal reading of this situation is that an ID Verification service provider was entrusted with people&#8217;s identities and it failed to implement simple measures to protect people&#8217;s identities and sensitive ID documents,\u201d Mossab Hussein, the chief security officer at cybersecurity firm spiderSilk who originally noticed the exposed credentials, said.<\/p>\n<p>The set of admin credentials that were left exposed led right to a logging platform, which in turn included links to identity documents. There\u2019s even some reason to suspect that bad actors got ahold of these credentials and actually used them.<\/p>\n<p>They appear to have been scooped up by malware in December 2022 and placed on a Telegram channel in March 2023, according to timestamps and messages acquired by <em>404 Media<\/em>. The news organization downloaded the credentials and found a wealth of passwords and authentication tokens linked to someone who lists their role on LinkedIn as a Network Operations Center Manager at AU10TIX.<\/p>\n<p>If hackers got ahold of customer data, it would include a user\u2019s name, date of birth, nationality, ID number and images of uploaded documents. It\u2019s pretty much all an internet gollum would need to steal an identity. All they would have to do is snatch up the credentials, log in and start wreaking havoc. Yikes.<\/p>\n<p>AU10TIX has issued a statement on the matter, writing that the \u201cdata was potentially accessible\u201d but that it sees \u201cno evidence that such data has been exploited.\u201d The company said that impacted customers have been notified and that it\u2019s decommissioning the current operating system in favor of a new one that focuses more on security.<\/p>\n<p>Some of its partners switched verification companies before this issue popped up. A spokesperson for Upwork said that it has \u201cbeen working with a different service provider for some time now.\u201d X, however, just signed up with AU10TIX <a data-i13n=\"cpos:2;pos:1\" href=\"https:\/\/techcrunch.com\/2023\/09\/15\/x-launches-account-verification-based-on-government-id\/\" data-ylk=\"slk:back in September;cpos:2;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><\/a> and it uses government-issued IDs to <a data-i13n=\"cpos:3;pos:1\" href=\"https:\/\/help.x.com\/en\/rules-and-policies\/verification-policy\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:verify premium users;cpos:3;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \">verify premium users<\/a>. Others, like Fiverr and Coinbase have said they aren\u2019t aware of any data exposure, though they still work with AU10TIX.<\/p>\n<p>Dumping customer data on Telegram or on the dark web has become the most popular way for hackers to do their thing. Back in late March, over 73 million AT&amp;T passwords <a data-i13n=\"cpos:4;pos:1\" href=\"https:\/\/www.engadget.com\/att-resets-millions-of-customers-passcodes-after-account-info-was-leaked-on-the-dark-web-160842651.html\" data-ylk=\"slk:were leaked onto the dark web;cpos:4;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><\/a>. LoanDepot <a data-i13n=\"cpos:5;pos:1\" href=\"https:\/\/www.engadget.com\/loandepot-discloses-that-hackers-breached-personal-data-of-16-million-customers-172702402.html\" data-ylk=\"slk:experienced a similar issue this year;cpos:5;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><\/a>, as did the <a data-i13n=\"cpos:6;pos:1\" href=\"https:\/\/www.engadget.com\/defense-department-alerts-over-20000-employees-about-email-data-breach-164528056.html\" data-ylk=\"slk:US Department of Defense;cpos:6;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><\/a>.<\/p>\n<\/div>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/www.engadget.com\/an-id-verification-service-that-works-with-tiktok-and-x-left-its-credentials-wide-open-for-a-year-171258438.html?src=rss\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] An ID verification company that works on behalf of TikTok, X and Uber, among others, has left a set of administrative credentials exposed for<\/p>\n","protected":false},"author":1,"featured_media":236924,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[159],"tags":[],"_links":{"self":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/236923"}],"collection":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/comments?post=236923"}],"version-history":[{"count":0,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/236923\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media\/236924"}],"wp:attachment":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media?parent=236923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/categories?post=236923"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/tags?post=236923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}