Microsoft leaks 6.5TB in Bing search data via unsecured Elastic server. *Insert 'Wow... that much?' joke here*
- Reference: 1600869080
- News link: https://www.theregister.co.uk/2020/09/23/microsoft_leaks_over_65tb_bing/
- Source link:
According [1]to a report from security site WizCase, the server was password-protected until around 10 September, when "the authentication was removed".
WizCase code-prober Ata Hakcil discovered the leak on 12 September. The data appears to be generated by the Bing mobile app, which promises users "Getting rewarded is easy, just search with the Bing," and has been downloaded more than 10 million times from Google's Play Store. The data was growing by up to 200GB per day and included searches from people in more than 70 countries, according to WizCase.
Once the data was unsecured, several things happened. The infosec firm reported the problem to Microsoft on 13 September, and the database was secured by the company's security response centre on 16 September. That left plenty of time for hackers and bots to find the data, and WizCase said the server suffered a [2]Meow attack on two occasions, referring to a bot which deletes unsecured databases and replaces them with new ones including the word "meow". However, data continued to be collected. If the Meow bot found that data, it is likely that other interested parties did as well.
In mitigation, the data did not include personal information such as name, address or email address. A critical question, though, is whether there was enough data included that the individuals could be traced.
In 2006, AOL released what it thought was anonymised search data for research purposes, but journalists soon proved this wrong by identifying some of the searchers. One of the reasons why this was easy was that each searcher was identified by a numeric key, so it was possible to see all the searches made by a particular individual.
It seems Microsoft's leaked data may likewise have privacy implications. WizCase screenshots show that the data includes fields called deviceID, deviceHash, AdID and clientID, all of which are promising in terms of finding all the searches from a particular user. There are also coordinates showing location "within 500 meters", not precise enough to get an address, but helpful to someone trying to identify searchers.
The data also reveals some of the unsavoury things people search for, including illegal content. WizCase suggested that if criminals succeed in deanonymising the data, some individuals could be vulnerable to blackmail or phishing scams as a result.
Statcounter [3]data shows just 2.83 per cent market share for Bing versus Google's 92.05 per cent. That said, it is a small percentage of a very large market, and Statcounter's figures may not reflect searches via the Bing app or those integrated into Windows search.
The incident is unfortunate for Microsoft, which advertises "simplified privacy controls" as one of the benefits of the iOS version of Bing Search.
A Microsoft spokesperson told us: “We’ve fixed a misconfiguration that caused a small amount of search query data to be exposed. After analysis, we’ve determined that the exposed data was limited and de-identified.”
Anybody can make a mistake, but there is an implicit deal with search providers like Microsoft and Google that we get personalisation and improved search results in return for allowing them to collect data on our behaviour. A high level of trust is required, and this kind of incident is damaging to that trust. The data was, apparently, not encrypted. ®
Get our [4]Tech Resources
[1] https://www.wizcase.com/blog/bing-leak-research/
[2] https://www.theregister.com/2020/07/24/meow_database_attack/
[3] https://gs.statcounter.com/search-engine-market-share
[4] https://whitepapers.theregister.com/
Re: Must be all of Bing data?
I think most people just use it to search for google.
Re: Must be all of Bing data?
Oh come on, we know how efficient Microsoft is when it comes to storage space.
That 6.5TB is probably just 20000000 copies of an installer and corresponding DLL files.
How much of it was for Google or Firefox?
What percentage? I'd wager 25%.
Often when using Tor, Google is pretty hostile in terms of "anti-robot" tests.
In that case I alternate between Bing and DuckDuckGo depending on my exit-point and if they work or not.
Usually when the only thing that works is Bing... I just restart Tor to get a different exit point haha!
Slag of Bing...
but a least it doesn't rig image searches when you don't use their own browser.
Hint: Do an image search with a n other browser on Google, then compare with Chrome. Note the lack of filtering options when not using Chrome?
Re: Slag of Bing...
I noticed the lack of everything with javascript disabled. Bye bye google image search.
"simplified privacy controls"
None.
What could be simpler?
"The data was, apparently, not encrypted"
That is just about as damning a sentence as one can write in this kind of case. In what world does a major multinational behemoth create a database of user-identifiable data and not encrypt it ?
There should be a law on that.
That, and the fact that the authentication was removed (why ??) means that I am quite happy to have never used Bing and won't be using it any time soon.
At least not until my aneurysm. After that, no guarantees.
6.5TB is quite a lot of data. I bet the internet bill for those two people is massive.
Had to be done.
Re: I bet the internet bill for those two people is massive.
What those two people would be more concerned about is if their drug-dealing, bomb-making searches have been uncovered.
Must be all of Bing data?
I think I may have been duped into using Bing once or twice on a fresh install of windows, who used it a lot?