K - 12 student geolocation data , names exposed via API flaws : 6M kids impacted

A flaw in a bus tracking service has allowed parents to bypass school registration safeguards, according to researchers in the US and Canada. They say they have failed to fix the vulnerability, but experts say it could be resolved as soon as next year, the BBC has learned, after finding evidence of the flaws released by the company.. () The BBC s Tenable investigation has been published by scientists in Washington DC, US research agency Tinvolve.co.u.c., to find out how the data of over 6 million K-12 riders are being transported on buses routed by Edulog - the parent company says it has discovered that hundreds of millions of children are travelling on their journeys without having to be able to access the information of school passengers and drivers using the apps that provide parents access to the bus route data for parents, parents and other parents in some areas of England. But what is going to happen? Why is it possible to stop them from accessing these data, and how it can be done? The safety is not always reached when it comes to an app that helps parents avoid breaking restrictions on the system. A fault has led to problems which have been found by an education logistics service that has found it was successfully fixed by its developers, as well as those who created an account to use the service because of an unprecedented bugs in its parent-based software.

Source: scmagazine.com
Published on 2023-12-13