Streaming site Kanopy exposed viewing habits of users, researcher says

cameraImage Credits:

On-demand video-streaming site Kanopy has fixed a leaking server that exposed the detailed viewing habits of its users.

Security researcher Justin Paine discovered the leaking Elasticsearch database last week and warned Kanopy of the exposure. The server was secured two days later, on March 18, a spokesperson told TechCrunch. “We are currently investigating the scope and cause as well as reviewing all of our security protocols.”

Kanopy is like Netflix, but for classic movies and documentaries. The company partners with libraries and universities across the U.S. by allowing library card holders to access films for free.

In a blog post, Paine said the server contained between 25-40 million daily logs, which he said could have identified all the videos searched for and watched from a user’s IP address.

“Depending on the videos being watched — that potentially could be embarrassing information,” he wrote.

The logs also contained geographical information, timestamps and device types, he said. He noted that there was no other personally identifiable information — such as usernames and email addresses — attached to the logs. 

According to a report last year, Kanopy has more than 30,000 movies on its platform.

Comments are disabled for this article.

Luxury air travel startup Aero raises $20M

Aero, a startup backed by Garrett Camp’s startup studio Expa, has raised $20 million in Series A funding — right as CEO Uma Subramanian said demand for air travel is returning “with a v...
A yellow SkyMul drone with a rebar tying tool sitting on top of some rebar

Robotics roundup

I’m excited for any opportunity to talk about soft robotics. There’s something other-worldly abou...

Gillmor Gang: Off The Record

Of all the gin joints etc. etc. Clubhouse continues to confound those who don’t believe in the restorative powers of the Next Big Thing. It doesn’t make sense, they say, that an audio s...