1/13 So, this week I discovered my first #serious #security #vulnerability in a public system.
In the past I've found #problems in #software, problems with #websites, with bureaucratic processes, some of which were significant, but they all pale in comparison to this one.
It starts with a #chain of #pharmacies.
13/13 This isn't a mom-and-pop operation; it's a very large company. Somehow, this #design got through #meetings and #proposals and #committees and #design and #implementation and #review and #testing, without anyone pointing out this #flaw?
Or, more likely, low-level employees or contractors tasked with building it did see the problem, and maybe even said something, but #management #ignored it.
I will post updates when I have them.
If you can believe it, it gets #worse.
Being privacy-conscious, when I created the account, I turned off all email notification settings (and phone/text settings).
Today, I made a refill request through the website. And then, because of a problem with my insurance company, the system sent me a cleartext email containing the prescription information, including the drug name and dosage, as well as the reason the email was sent.
In unencrypted email. #JFC
I have sent a second #complaint.