Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Nevilledog

(51,137 posts)
Tue Feb 8, 2022, 08:31 PM Feb 2022

Donation site for Ottawa truckers' 'Freedom Convoy' protest exposed donors' data



Tweet text:

Zack Whittaker
@zackwhittaker
New: GiveSendGo, the donation site used by the Ottawa trucker's "Freedom Convoy" protest after its GoFundMe campaign was frozen last month, left an S3 bucket open that exposed donors' passports and driver's licenses.

techcrunch.com
Donation site for Ottawa truckers’ ‘Freedom Convoy’ protest exposed donors’ data
GiveSendGo exposed passports and driver's licenses used to validate the payments of donors.
3:03 PM · Feb 8, 2022



https://techcrunch.com/2022/02/08/ottawa-trucker-freedom-convoy-exposed-donation/


*snip*

TechCrunch was tipped off to the data lapse after a person working in the security space found an exposed Amazon-hosted S3 bucket containing over 50 gigabytes of files, including passports and driver licenses that were collected during the donation process.

The researcher said they found the web address for the exposed bucket by viewing the source code of the Freedom Convoy’s webpage on GiveSendGo.

S3 buckets are used for storing files, documents or even entire websites in Amazon’s cloud but are set to private by default, and require a multi-step process before a bucket’s contents can be made public for anyone to access.

The exposed bucket had over a thousand photos and scans of passports and driver licenses uploaded since February 4, when the Freedom Convoy’s page was first set up on GiveSendGo. The filenames suggest that the identity documents were uploaded during the payments process, which some financial institutions require before they can process a person’s payment or donation.

*snip*



8 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Donation site for Ottawa truckers' 'Freedom Convoy' protest exposed donors' data (Original Post) Nevilledog Feb 2022 OP
Oh, so when they call themselves the #1 free Christian crowdfunding site, tanyev Feb 2022 #1
This message was self-deleted by its author Chin music Feb 2022 #2
Rt TY.. Cha Feb 2022 #3
Not sure why a passport would be needed to donate money. Or even be on a computer Maraya1969 Feb 2022 #4
I don't have one. Never cared for travel. 634-5789 Feb 2022 #5
Same Here! ProfessorGAC Feb 2022 #6
Identity theft coming to bunch of freedom loving idiots. Pobeka Feb 2022 #7
It's a real shame. Nevilledog Feb 2022 #8

tanyev

(42,578 posts)
1. Oh, so when they call themselves the #1 free Christian crowdfunding site,
Tue Feb 8, 2022, 08:40 PM
Feb 2022

they mean if you give them money they’ll give away all your information for free.

Response to Nevilledog (Original post)

Maraya1969

(22,486 posts)
4. Not sure why a passport would be needed to donate money. Or even be on a computer
Tue Feb 8, 2022, 08:50 PM
Feb 2022

Mine is locked in a safe and no information is digitized.

ProfessorGAC

(65,085 posts)
6. Same Here!
Tue Feb 8, 2022, 08:53 PM
Feb 2022

Like you, passports are in the fire safe.
And, I agree it seems odd to need a passport to donate money.
Perhaps a Canadian law to monitor foreign transactions to fight money laundering?

Latest Discussions»General Discussion»Donation site for Ottawa ...