By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release

This New Dungeons & Dragons Starter Set Helps Beginners Explore the Realms of D&D

News Room News Room 8 August 2025
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data
News

A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data

News Room
Last updated: 8 August 2025 18:16
By News Room 4 Min Read
Share
SHARE

Top streaming services like Netflix and Disney+ have made sustained investments over the years to lock their content down. Whenever they can, they prevent users from accessing videos without a subscription or watching region-blocked content. New findings presented today at the Defcon security conference in Las Vegas, though, indicate that streaming platforms used for things like internal corporate broadcasts and sports livestreams can contain basic design flaws that allow anyone to access a vast swath of content without logging in.

Independent researcher Farzan Karimi first realized years ago that misconfigurations in application programming interfaces, or APIs, exposed streaming content to unauthorized access. In 2020 he disclosed a set of such flaws to Vimeo that could have allowed him to access close to 2,000 internal company meetings along with other types of livestreams. The company quickly fixed the issue at the time, but the finding left Karimi with concerns that similar problems could be lurking in other platforms.

Years later, he realized that by refining a technique for mapping how APIs retrieve data and interact, he could look for other vulnerable platforms. At Defcon, Karimi is presenting findings about current exposures in one mainstream sports streaming platform—he is not naming the site because the issues are not yet resolved—and releasing a tool to help others identify the problem in additional sites.

“For a company all hands or other sensitive meeting, there might be key internal information being shared—CEOs or other executives talking about layoffs or sensitive intellectual property,” Karimi told WIRED ahead of his conference talk. “You can see a bad pattern emerge in how easily you can circumvent authentication to access streams, but this class of issue was previously dismissed as requiring deep knowledge of a given business to identify.”

APIs are services that fetch and return data to whoever requests it. Karimi gives the example that you can search for the movie Fight Club on a streaming platform, and the stream for the movie may come back with information about the length of the movie, trailers, actors in the movie, and other metadata. Multiple APIs work together to assemble all of this information with each fetching certain types of data. Similarly, if you search for Brad Pitt, a set of APIs will interact to deliver Fight Club along with other movies he’s starred in like Troy and Seven. Some of these APIs are designed to require proof of authentication before they will return results, but if a system hasn’t been scrutinized deeply, it is common for other APIs to blindly return data without requiring proof of authorization on the assumption that only an authenticated requestor will be in a position to send queries.

“Often there are basically four, five, some number of APIs that have all this metadata, and if you know how to trace through them, you can unlock paywalled content for free,” Karimi says. “It’s a ‘security through obscurity’ model where they would never think that someone would be able to manually connect the dots between these APIs. The automation I’m introducing, though, helps find these authorization flaws quickly at scale.”

Karimi emphasizes that top streaming services are largely locked down and either corrected such API misconfigurations long ago or avoided them from the start. But he emphasizes that more utilitarian platforms for corporate streaming and other live events—including always-on cameras in sports arenas and other venues that are meant to only be accessible at certain times—are likely vulnerable and exposing video that is thought to be protected.

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

A decade later, Windows is still bringing Control Panel features to the Settings app

News Room News Room 8 August 2025
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

The Best Over-the-Counter Hearing Aids

If you’re spending hundreds or thousands of dollars buying an OTC hearing aid, make sure…

8 August 2025

Instagram’s Map is here, and this is how you can turn your location off

Responses have ranged from being mildly annoyed that Instagram is ripping off Snapchat’s Snap Maps…

8 August 2025

Marathon expected to launch “within this fiscal year” following indefinite delay, says Sony

Sony has addressed concerns regarding the release of Marathon following its indefinite delay back in…

8 August 2025
News

Join Our Next Livestream: What GPT-5 Means for ChatGPT Users

Few recent software releases have been as hyped as OpenAI’s launch of its GPT-5 model. “GPT-5 is the first time that it really feels like talking to an expert in…

News Room 8 August 2025

Your may also like!

Mobile

Samsung Unveils AI-Driven Voice Phishing Scam Detection on One UI 8 Smartphones

News Room 8 August 2025
News

Mini Ikea stores will be opening inside some Best Buys this year

News Room 8 August 2025
Gaming

Take-Two Boss Strauss Zelnick Says Borderlands Chief Randy Pitchford ‘Can Be Controversial at Times — Sometimes Intentionally, Sometimes Unintentionally,’ but ‘I Still Love Him to Death’

News Room 8 August 2025
Mobile

Realme P4 Series Teased to Launch in India Soon; Could Debut With Realme P4 Pro 5G

News Room 8 August 2025

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?