Lego fixes dangerous API vuln in BrickLink service | TechTarget
Summary
Substantial sums of money change hands through the eBay style service, with desirable kits, such as the Hogwarts Express from Lego’s Harry Potter series often selling for close to their original retail price. The second vulnerability existed in BrickLink’s “Upload to Wanted List” page – which lets users add Lego sets they have their eye on to a watchlist. “Today, nearly all business sectors have increased their usage of APIs to enable new functionality and streamline the connection between consumers and vital data and services,” said Yaniv Balmas, vice-president of research at Salt Security. The growth trend has seen an increasing number of high-profile incidents linked to API traffic this year, including the recent attack on Australian telco Optus, which saw names, addresses, dates of birth, phone numbers, email addresses, and driving licence and passport data relating to 11 million customers stolen and held to ransom – an incident so serious in its scope that the Australian government is now planning to amend its telecoms security regulations. In this case, Salt’s research team disclosed the vulnerabilities through a coordinated disclosure, and the issues have now been remediated and should pose no further threat to hordes of excited builders over the holidays.