Technology Today

Rallyhood says it &private and secure.& But for some time, it wasn''t.The social network designed to help groups communicate and coordinate left one of its cloud storage buckets containing user data open and exposed.
The bucket, hosted on Amazon Web Services (AWS), was not protected with a password, allowing anyone who knew the easily-guessable web address access to a decade worth of user files.Rallyhood boasts users from Girl Scout and Boy Scout troops, and Komen, Habitat for Humanities, and YMCA factions.
The company also hosts thousands of smaller groups, like local bands, sports teams, art clubs, and organizing committees.
Many flocked to the site after Rallyhood said it would help migrate users from Yahoo Groups, after Verizon (which also owns TechCrunch) said it would shut down the discussion forum site last year.The bucket contained group data as far back to 2011 up to and including last month.
In total, the bucket contained 4.1 terabytes of uploaded files, representing millions of users& files.Some of the files we reviewed contained sensitive data, like shared password lists and contracts or other permission slips and agreements.
The documents also included non-disclosure agreements and other files that were not intended to be public.Where we could identify contact information of users whose information was exposed, TechCrunch reached out to verify the authenticity of the data.A security researcher who goes by the handle Timeless found the exposed bucket and informed TechCrunch, so that the bucket and its files could be secured.When reached, Rallyhood chief technology officer Chris Alderson initially claimed that the bucket was for ''testing& and that all user data was stored &in a highly secured bucket,& but later admitted that during a migration project, ''there was a brief period when permissions were mistakenly left open.It not known if Rallyhood plans to warn its users and customers of the security lapse.
At the time of writing, Rallyhood has made no statement on its website or any of its social media profiles of the incident.Stop saying, ‘We take your privacy and security seriously





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Everyone using Amazon issued with an urgent 'don't click' warning this week


Sky is dishing out free TV channel upgrades, and here's how to watch it


Apple fans rushing for ₤ 35 iPhone 16 Pro Max as Sky uses payday deal


'I visited Chinese city which is like sci-fi movie with robots and noiseless trains'


Top Tech: Amazon's best early Prime Day deals including Ring, Tefal and Nespresso


Brits now 'obsessed' with health tracking and say it's key to motivation


Virgin Media is distributing complimentary wise TVs in surprise seven-day sale


O2 confirms UK network switch off and the exact date your phone might quit working


Samsung and Google have a new Android competitor that's like Nothing you've seen before


'Spectacular' Samsung Galaxy S25 Ultra gets £10 a month price cut


Sky users given 48-hour cost alert and your costs could increase tomorrow


Never ever miss your favourite television series when on vacation with basic travel hack


Amazon may offer big reason to ditch your Fire TV Stick next week and try something new


Samsung and Google smartphone deals consist of free earbuds and smartwatches


Everyone using Google Chrome must restart their browser now - don't ignore new alert


iPhone users surprised after finding 'concealed' hack to organise home screen


Sky dishes out brand-new iPhone 16 at 'lowest ever' rate, not surprising that it's offering fast


Argos shoppers can get a free 40-inch Hisense TV by doing one thing


Immediate alert for everyone with a Gmail account - do not overlook 6 important brand-new rules


BBC iPlayer is rivalling Sky TV with a vital free upgrade - check your settings now