AI girlfriend review site's secrets were exposed to the world for three weeks
Even testing and staging sites need protection from prying eyes
Welcome back to PWNED, where we delve into the world of security blunders. This time, we're examining a test site that inadvertently exposed sensitive information. If you have a story of a network left vulnerable, send it to pwned@sitpub.com. Our source this week comes from Mia Morin, Editor & AI Quality Analyst at Intimeros, a platform that reviews and rates AI companions.
The issue began during a redesign. One of Morin’s colleagues was testing a version of the site and forgot to re-enable password protection. The security lapse persisted for three weeks before anyone noticed. Then, a Google search indexed the test site, revealing unpublished reviews, pricing, and private notes on Intimeros's AI companions. This was possible because the test site directly linked to the production database.
The editorial content was safe, but competitors could see Intimeros’s work and potentially understand their strategy. Morin swiftly secured the test site, re-enabling password protection, blocking search engines, and changing system access keys. From this, we learn the importance of securing test versions of websites. They should require logins and block search and AI crawling. A private server with VPN access is even better.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.