Data Security

Test website exposes unpublished reviews and strategy

As reported by The Register, a test website for an AI companion review site, Intimeros, was inadvertently left accessible to the public for three weeks, exposing unpublished content and strategic information.

During a website redesign, a staff member at Intimeros disabled password protection on a test version of the site to demonstrate progress to a client. This protection remained off for three weeks, and the site was also not excluded from search engine indexing via a robots.txt file. Consequently, unpublished reviews, pricing details, and private product notes related to AI companion services became visible on Google. The test site was connected to the live production database, though no user data was exposed as it was purely editorial content. This oversight could have allowed competitors to gain insight into Intimeros' editorial strategy.

The issue was rectified by restoring password protection, blocking search engines, and changing system access keys. The company now secures all test sites similarly to their official website and conducts weekly automated scans.

Source: The Register

You can skip this ad in 5 seconds