this post was submitted on 28 Dec 2024
189 points (98.5% liked)

Privacy

32173 readers
1054 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

On their website, go to the sign in screen and click “Need help signing in”. Go through the prompts and watch the person’s username, and the legal name of all their employers (who have ever used ADP) appear on the screen.

Note: Whether or not you select “my current employer uses ADP”, it will still show you the full list of both current and previous employers (who use ADP).

From there, it is remarkably easy to gain access to paycheck information if you are ~~a grocer, a landlord, a retailer, or anyone of the 2737429193 entities who may~~ have a little extra data on them.

Edit: To address some of the comments, I feel I need to clear something up. I’m not saying this is some authoritarian configuration error ADP messed up on. It’s a standard login that works conveniently for ADP and also happens to be negligent in privacy protection. And it’s most likely completely legal for most people in the U.S.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 36 points 3 days ago (1 children)

Depends on how the parties behaved in the past. There are a bunch of government entities which called police on me in the past when trying to work with them about discovered issues and as result also will just get anonymous 0-day drops in public forums for future issues.

[–] [email protected] 4 points 3 days ago (1 children)

If you really regularly disclosed vulnerabilities you’d know that for entities that don’t have vulnerability disclosure programs you can always report through CISA or ENISA.

[–] [email protected] 11 points 3 days ago (1 children)

I expect the responsible person listed for some specific application to react to an email about it to fix it, and not send me police. Why would I want to jump through hoops for doing them a favour?

Same applies also if there's no easy way to send a mail to someone responsible.

[–] [email protected] -5 points 2 days ago

Ok bro.

Same applies also if there's no easy way to send a mail to someone responsible.

Yeah I’m pressing x for doubt you’ve ever disclosed anything. You got any CVE’s to your name?