The ANPR camera system's internal management dashboard could be accessed by simply entering its IP address into a web browser. No login details or authentication of any sort was needed to view and search the live system
Number-Plate Cam Site Had No Password, Spills 8.6 Million Logs of UK Road Journeys
I keep seeing this kind of nonsense every other day. Millions of records exposed here, millions of private pieces of data exposed there... Always without any "hacking" taking place. They just have no passwords. Just keep it all open to the world.
How is this possible?
The thing is, I actually did the same thing myself, BUT I was a single loser, early 20s, at home, in a deep psychosis, running a database which I believed had been secured (I misinterpreted the very misleading and weird documentation)... with no other person involved and a massive "ego" in that I believed myself to be a computer expert.
These leaks you hear about, on the other hand, are huge corporations or governments which obviously must have hired some kind of expert/professional to implement these things, yet they still do what I did at home for my personal project?
How is it possible? I truly do not get it. Unless it's done on purpose, over and over again. Do they not have any kind of "investigation" into these things? Do they never read the news and learn from others' mistake? Do they truly not care about their friends and family and their own records being leaked to the world? How can they not care?
How do you get some kind of security certification if you set up a database with NO AUTHENTICATION WHATSOEVER?