The Wiert Corner – irregular stream of stuff

Jeroen W. Pluimers on .NET, C#, Delphi, databases, and personal interests

  • My badges

  • Twitter Updates

  • My Flickr Stream

  • Pages

  • All categories

  • Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 1,860 other subscribers

Reminder to self: re-check the Dotpe API Security Breach — bool.dev

Posted by jpluimers on 2025/03/04

Still public merchant information

Still public merchant information

It looks like some store and merchang APIs were not protected back when [Wayback/Archive] Dotpe API Security Breach — bool.dev was published.

Reminder to self: check their status now as I can’t believe their “human error” got fixed properly.

History (reverse chronological order):

  1. [Wayback/Archive] How DotPe’s ‘Human Error’ Exposed Confidential Customer API Data
  2. [Wayback/Archive] Deedy on X: “Today, Google-backed DotPe locked down their APIs by rate-limiting by IP on /external/merchant and blocking others. They sent a legal notice to the author before fixing it and haven’t publicly acknowledged the issue at all. Companies must be held accountable for poor security.…”

    [Wayback/Archive] Tweet JSON: [Wayback/Archive] GYSlTthakAEoojp.png:orig (2346×1838)

  3. Now protected private API

    Now protected private API

    [Wayback/Archive] Deedy on X: “6 hours later, the API is still very much public! …”

    [Wayback/Archive] Tweet JSON: [Wayback/Archive] GYK38dXbkAEEEs_.jpg:orig (1358×1798)

  1. [Wayback/Archive] pea bee on X: “Sorry guys – have taken the post down due to a legal notice from Dotpe. I could fight them because I didn’t access anything that wasn’t already public. But it’s not worth the hassle. The legal process in this country is in itself a punishment. 🙏”

    [WaybackSave/Archive] pea bee on X: “Only wrote about open APIs that anyone scanning their QR codes can view. Sales numbers were literally calculated from looking at their public menu webpage API calls. I didn’t access any backend APIs or internal documents.”

  2. [Wayback/Archive] What’s inside the QR code menu at this cafe? – by peabee (now returns a HTTP 404, but the archives are OK)

Related:

Queries:

--jeroen


PS

Back when scheduling this, these APIs were still not protected (I did not test rate-limiting):

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.