1/13 So, this week I discovered my first #serious #security #vulnerability in a public system.
In the past I've found #problems in #software, problems with #websites, with bureaucratic processes, some of which were significant, but they all pale in comparison to this one.
It starts with a #chain of #pharmacies.
9/13 So an attacker can find out exactly what #medications you're taking, what #dose you're taking, and how often you're taking it.
They can see when I last picked up each prescription, and what date it is next available for refill.
They can see exactly which doctor prescribed it.
That is a *lot* of #sensitive #medical information to just give out with essentially no #authentication of the #patient.
Even better, you can order refills, or turn auto-refill on or off.