In certain areas, getting security right can seem to be very easy. But, hmm, let’s look at this: Poorly anonymized logs reveal NYC cab drivers’ detailed whereabouts. They used MD5 to anonymize the license plate numbers of the taxi drivers â€“ and they did not use any salt. So, it is fairly easy to run all the license plates through MD5 and get the right links. Nothing new, isn’t it? Well, no but most attacks are actually not newâ€¦.
- Improperly anonymized taxi logs reveal drivers’ identity, movements (net-security.org)
- Poorly anonymized logs reveal NYC cab drivers’ detailed whereabouts (arstechnica.com)
- Lessons from NYC’s improperly anonymized taxi logs (medium.com)