Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
Microsoft’s Surface Laptop Is Marked Down by 0

Microsoft’s Surface Laptop Is Marked Down by $350

13 November 2025
DHS Kept Chicago Police Records for Months in Violation of Domestic Espionage Rules

DHS Kept Chicago Police Records for Months in Violation of Domestic Espionage Rules

12 November 2025
A Proposed Federal THC Ban Would ‘Wipe Out’ Hemp Products That Get People High

A Proposed Federal THC Ban Would ‘Wipe Out’ Hemp Products That Get People High

12 November 2025
Facebook X (Twitter) Instagram
Just In
  • Microsoft’s Surface Laptop Is Marked Down by $350
  • DHS Kept Chicago Police Records for Months in Violation of Domestic Espionage Rules
  • A Proposed Federal THC Ban Would ‘Wipe Out’ Hemp Products That Get People High
  • Our Favorite Travel and Outdoor Gear Is on Sale at Huckberry
  • Anthropic’s Claude Takes Control of a Robot Dog
  • Valve Announces Console-Like Steam Machine, Steam Frame VR Headset, And New Steam Controller
  • The AI Boom Is Fueling a Need for Speed in Chip Networking
  • New Planet-Hopping Trailer For The Super Mario Galaxy Movie Shows Returning Cast, Rosalina, Bowser Jr. And More
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data
News

A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data

News RoomBy News Room8 August 20253 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data
Share
Facebook Twitter LinkedIn Pinterest Email

Top streaming services like Netflix and Disney+ have made sustained investments over the years to lock their content down. Whenever they can, they prevent users from accessing videos without a subscription or watching region-blocked content. New findings presented today at the Defcon security conference in Las Vegas, though, indicate that streaming platforms used for things like internal corporate broadcasts and sports livestreams can contain basic design flaws that allow anyone to access a vast swath of content without logging in.

Independent researcher Farzan Karimi first realized years ago that misconfigurations in application programming interfaces, or APIs, exposed streaming content to unauthorized access. In 2020 he disclosed a set of such flaws to Vimeo that could have allowed him to access close to 2,000 internal company meetings along with other types of livestreams. The company quickly fixed the issue at the time, but the finding left Karimi with concerns that similar problems could be lurking in other platforms.

Years later, he realized that by refining a technique for mapping how APIs retrieve data and interact, he could look for other vulnerable platforms. At Defcon, Karimi is presenting findings about current exposures in one mainstream sports streaming platform—he is not naming the site because the issues are not yet resolved—and releasing a tool to help others identify the problem in additional sites.

“For a company all hands or other sensitive meeting, there might be key internal information being shared—CEOs or other executives talking about layoffs or sensitive intellectual property,” Karimi told WIRED ahead of his conference talk. “You can see a bad pattern emerge in how easily you can circumvent authentication to access streams, but this class of issue was previously dismissed as requiring deep knowledge of a given business to identify.”

APIs are services that fetch and return data to whoever requests it. Karimi gives the example that you can search for the movie Fight Club on a streaming platform, and the stream for the movie may come back with information about the length of the movie, trailers, actors in the movie, and other metadata. Multiple APIs work together to assemble all of this information with each fetching certain types of data. Similarly, if you search for Brad Pitt, a set of APIs will interact to deliver Fight Club along with other movies he’s starred in like Troy and Seven. Some of these APIs are designed to require proof of authentication before they will return results, but if a system hasn’t been scrutinized deeply, it is common for other APIs to blindly return data without requiring proof of authorization on the assumption that only an authenticated requestor will be in a position to send queries.

“Often there are basically four, five, some number of APIs that have all this metadata, and if you know how to trace through them, you can unlock paywalled content for free,” Karimi says. “It’s a ‘security through obscurity’ model where they would never think that someone would be able to manually connect the dots between these APIs. The automation I’m introducing, though, helps find these authorization flaws quickly at scale.”

Karimi emphasizes that top streaming services are largely locked down and either corrected such API misconfigurations long ago or avoided them from the start. But he emphasizes that more utilitarian platforms for corporate streaming and other live events—including always-on cameras in sports arenas and other venues that are meant to only be accessible at certain times—are likely vulnerable and exposing video that is thought to be protected.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSamsung Galaxy S26 Edge to Be Thinner than Galaxy S25 Edge Model Despite Larger Battery, Tipster Claims
Next Article Volume, John Wick Hex Studio Bithell Games Loses ‘Majority’ Of Staff To Layoffs

Related Articles

Microsoft’s Surface Laptop Is Marked Down by 0
News

Microsoft’s Surface Laptop Is Marked Down by $350

13 November 2025
DHS Kept Chicago Police Records for Months in Violation of Domestic Espionage Rules
News

DHS Kept Chicago Police Records for Months in Violation of Domestic Espionage Rules

12 November 2025
A Proposed Federal THC Ban Would ‘Wipe Out’ Hemp Products That Get People High
News

A Proposed Federal THC Ban Would ‘Wipe Out’ Hemp Products That Get People High

12 November 2025
Our Favorite Travel and Outdoor Gear Is on Sale at Huckberry
News

Our Favorite Travel and Outdoor Gear Is on Sale at Huckberry

12 November 2025
Anthropic’s Claude Takes Control of a Robot Dog
News

Anthropic’s Claude Takes Control of a Robot Dog

12 November 2025
The AI Boom Is Fueling a Need for Speed in Chip Networking
News

The AI Boom Is Fueling a Need for Speed in Chip Networking

12 November 2025
Demo
Top Articles
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024107 Views
Costco partners with Electric Era to bring back EV charging in the U.S.

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 202494 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Valve Announces Console-Like Steam Machine, Steam Frame VR Headset, And New Steam Controller Gaming

Valve Announces Console-Like Steam Machine, Steam Frame VR Headset, And New Steam Controller

News Room12 November 2025
The AI Boom Is Fueling a Need for Speed in Chip Networking News

The AI Boom Is Fueling a Need for Speed in Chip Networking

News Room12 November 2025
New Planet-Hopping Trailer For The Super Mario Galaxy Movie Shows Returning Cast, Rosalina, Bowser Jr. And More Gaming

New Planet-Hopping Trailer For The Super Mario Galaxy Movie Shows Returning Cast, Rosalina, Bowser Jr. And More

News Room12 November 2025
Most Popular
The Spectacular Burnout of a Solar Panel Salesman

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025135 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024107 Views
Costco partners with Electric Era to bring back EV charging in the U.S.

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks
Our Favorite Travel and Outdoor Gear Is on Sale at Huckberry

Our Favorite Travel and Outdoor Gear Is on Sale at Huckberry

12 November 2025
Anthropic’s Claude Takes Control of a Robot Dog

Anthropic’s Claude Takes Control of a Robot Dog

12 November 2025
Valve Announces Console-Like Steam Machine, Steam Frame VR Headset, And New Steam Controller

Valve Announces Console-Like Steam Machine, Steam Frame VR Headset, And New Steam Controller

12 November 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.