Data security – week 2
Microsoft Data Breach
Microsoft is one of the most popular companies that everyone
uses day to day, but did you know Microsoft had a data breach in July 2021. That
Microsoft PowerApps data breach exposed 38 million records containing personal identifiable
information PII. The data breach caused 47 major companies across multiple industries
including the government and the public health agencies to be impacted and this
data breach. The breach exposed personal identifiable information that includes
names, COVID-19 contact tracking information, vaccination appointments, Social
Security numbers call mom employee IDs and email address. Analysts discovered
the open data protocol API for an organisation’s that power apps portable that
contain an anonymously accessible list lists of data.
Microsoft Power Apps is a cloud-hosted suite of services
that allows organizations to create business intelligence applications. Power
Apps portals allow both internal and external users to securely access data
through a public website. Users can store data, create forms for users to enter
data, and use APIs to retrieve data from other applications.
The service also allows users to enable OData APIs, which
permit organizations to publicly display Power Apps lists. A design mishap left
organizations that did not enable certain permissions vulnerable.
If this would happen again the credibility of Microsoft reputation
would be at stake. Microsoft is normally a trustworthy company with hundreds of
millions of people using their products on a daily basis. for this not to
happen again I think the company will need to look at their design and have
more beta testing before they launch it to the market. just so they can be sure
that their customers day arts are as protected as possible.
Comments
Post a Comment