Another day, another cloud service leaking personal data because of a misconfiguration. And before you jump to any conclusions, no, it’s not a leaky bucket on AWS S3 or a public blob on Microsoft Azure…
The culprit is, once again, GitHub, where an open-source hardware manufacturer has inadvertently left exposed a private-to-public repository that “could have enabled unauthorized access to information about certain user accounts on or before 2019.”
The exposed information involved an auditing data set used for employee training stored on a GitHub repository associated with an inactive former employee’s account. The data set contained some names, email addresses, shipping/billing addresses, and/or whether orders were placed successfully via credit card processor and/or PayPal, as well as details for some orders.
Luckily there were no user passwords or financial informatio