{"id":175,"date":"2021-11-20T09:08:29","date_gmt":"2021-11-20T09:08:29","guid":{"rendered":"https:\/\/anthonyparkes.co.uk\/?p=175"},"modified":"2021-11-20T12:07:14","modified_gmt":"2021-11-20T12:07:14","slug":"175","status":"publish","type":"post","link":"https:\/\/anthonyparkes.co.uk\/?p=175","title":{"rendered":"Dynotag SuperAlertID"},"content":{"rendered":"\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>After seeing this in a random shop for 50p I thought I\u2019d get it and see how it works. The idea looks good.<\/p>\n\n\n\n<p>Boy was i wrong\u2026<br>The tag itself is nothing but a QR code that takes you to a website with the information you enter when activating it. No NFC, it looks like something made in the \u201990s.<\/p>\n\n\n\n<p>But that can\u2019t be too bad, right?<br>Wrong!<br>After testing a tag with fake info i was shocked. The QR code only contains a URL with a 7-digit number in the URL.<\/p>\n\n\n\n<p>Surely not? You all know where this is going.<\/p>\n\n\n\n<p>What happens if I change that code? If you thought the personal and medical details for someone else. Well done you get a gold star.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"766\" height=\"1024\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-766x1024.jpg\" alt=\"\" class=\"wp-image-177\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-766x1024.jpg 766w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-224x300.jpg 224w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-768x1027.jpg 768w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-rotated.jpg 857w\" sizes=\"auto, (max-width: 766px) 100vw, 766px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<p>So what sort of information do people upload to this thing?<br>A scary amount of data. Almost every tag I checked had a Name, Date of birth, address, and email address on it.<br>But wait for it&#8230; A large amount also had Medical info, Medication Doctor&#8217;s details.<\/p>\n\n\n\n<p>So not the big question. Can we automate a download of all this data, Afterall all we need is a 7 digit number and from the one I bought I know my number. What if we download 100, 100, or even 100000 at a time.<br>You guessed it. Yes, we can. And even worse. The site has no limit or rate-limiting per IP address.<\/p>\n\n\n\n<p>I&#8217;m not going to help anyone get the information but as simple as it is I&#8217;m not going to be able to stop anyone. For this reason, I&#8217;m not going to give the URL for the QR code. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Lets look at the data.<\/h2>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>Each tag can have different data. Almost all have Names, addresses, and Email addresses but many have loads more info.<\/p>\n\n\n\n<p>I&#8217;ll be blocking out identifiable info as this is a real person I randomly picked.<\/p>\n\n\n\n<p>This person Gives us a Full street address (click it on the site for a google map).<\/p>\n\n\n\n<p>Cell phone and work numbers.<\/p>\n\n\n\n<p>Date of Birth<\/p>\n\n\n\n<p>Gender, Height, Weight, Hair Colour, Eye colour, and Spoken Languages.<\/p>\n\n\n\n<p>That alone is a scary about of information but keep reading.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/basic-info.png\" alt=\"\" class=\"wp-image-182\" width=\"361\" height=\"554\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/basic-info.png 445w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/basic-info-195x300.png 195w\" sizes=\"auto, (max-width: 361px) 100vw, 361px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>Next up we have the Conditions section<\/p>\n\n\n\n<p>This gives details of any medical conditions the person has listed.<\/p>\n\n\n\n<p>After all this is sold as a Magic medical device.<\/p>\n\n\n\n<p><\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/conditions.png\" alt=\"\" class=\"wp-image-183\" width=\"187\" height=\"367\"\/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>This is the notes section. <\/p>\n\n\n\n<p>A free area to give away any personal information you like that Dynotag didn&#8217;t think scammers would need. <\/p>\n\n\n\n<p>Use this to tell everyone your deepest secrets.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/notes.png\" alt=\"\" class=\"wp-image-184\" width=\"255\" height=\"481\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/notes.png 505w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/notes-159x300.png 159w\" sizes=\"auto, (max-width: 255px) 100vw, 255px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>The Contacts Section<\/p>\n\n\n\n<p>This lets you share other people&#8217;s personal data. Likely without them even knowing. <\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/contacts.png\" alt=\"\" class=\"wp-image-185\" width=\"245\" height=\"252\"\/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"216\" height=\"224\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/Supplements.png\" alt=\"\" class=\"wp-image-187\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"338\" height=\"224\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/Physicians-1.png\" alt=\"\" class=\"wp-image-189\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/Physicians-1.png 338w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/Physicians-1-300x199.png 300w\" sizes=\"auto, (max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/medications.png\" alt=\"\" class=\"wp-image-186\" width=\"222\" height=\"608\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/medications.png 302w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/medications-110x300.png 110w\" sizes=\"auto, (max-width: 222px) 100vw, 222px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>And now we get to the ultra scary bit.<\/p>\n\n\n\n<p>The Policies and Files area<\/p>\n\n\n\n<p>The policy contains details of insurance etc including a pdf scan uploaded by the user.<\/p>\n\n\n\n<p>The Files also have uploaded scans on this one even including a scan of the person&#8217;s Drivers Licence.<\/p>\n\n\n\n<p><\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"292\" height=\"151\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/Insurance.png\" alt=\"\" class=\"wp-image-190\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"323\" height=\"554\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/files.png\" alt=\"\" class=\"wp-image-191\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/files.png 323w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/files-175x300.png 175w\" sizes=\"auto, (max-width: 323px) 100vw, 323px\" \/><\/figure>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">So what do we think<\/h2>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>I think SuperAlertID.com By Dynotag has messed this up beyond any kind of excuse. They have created a public database of personal and medical data with the added bonus of copies of official government IDs that can be accessed by anyone.<\/p>\n\n\n\n<p>Never before has identity theft been so easy. No more going through bins to look for copies of letters. Now all you need to do is enter a 7 digit number and with the help of a poor person that brought a SmartID with no idea of the lacking security, you have everything you need.<\/p>\n\n\n\n<p>If you have one of them get your data deleted from the site RIGHT NOW. it may however be too late. With SuperAlertID being around since 2019 the time someone has had to mine the data has long passed. <\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"469\" height=\"673\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/t1-1.jpg\" alt=\"\" class=\"wp-image-193\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/t1-1.jpg 469w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/t1-1-209x300.jpg 209w\" sizes=\"auto, (max-width: 469px) 100vw, 469px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/t2-1.jpg\" alt=\"\" class=\"wp-image-192\" width=\"231\" height=\"420\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/t2-1.jpg 411w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/t2-1-165x300.jpg 165w\" sizes=\"auto, (max-width: 231px) 100vw, 231px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"766\" height=\"1024\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-766x1024.jpg\" alt=\"\" class=\"wp-image-177\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-766x1024.jpg 766w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-224x300.jpg 224w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-768x1027.jpg 768w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p2-rotated.jpg 857w\" sizes=\"auto, (max-width: 766px) 100vw, 766px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"564\" height=\"854\" src=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p1-1.jpg\" alt=\"\" class=\"wp-image-194\" srcset=\"https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p1-1.jpg 564w, https:\/\/anthonyparkes.co.uk\/wp-content\/uploads\/2021\/11\/p1-1-198x300.jpg 198w\" sizes=\"auto, (max-width: 564px) 100vw, 564px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>After seeing this in a random shop for 50p I thought I\u2019d get it and see how it works. The idea looks good. Boy was<\/p>\n","protected":false},"author":2,"featured_media":193,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"template-centered.php","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-175","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=175"}],"version-history":[{"count":5,"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/175\/revisions"}],"predecessor-version":[{"id":201,"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/175\/revisions\/201"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=\/wp\/v2\/media\/193"}],"wp:attachment":[{"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/anthonyparkes.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}