User icon
is this illegal
User icon
I successfully obtained the IP addresses, approximate locations, usernames and display names of all 14 blaze users.

edit: I now also have bios, profile websites, profile locations, avatars, ISP, last profile update date, date of last post, all posts, and list of all alts

edit 2: I was also the person who nuked all posts twice because balze didn't use RLS properly

edit 3: kyle thinks blocking me will stop me?
  • User submitted image
Comments
  • User icon
    No, I did not leak any PII, and the information was already made public by Balze so I just archived it.
    • User icon
      while the owner is negligent at securing their data, it is still illegal 😭
    • User icon
      Not illegal for me, illegal for balze violating their own privacy policy. For context, after the db got nuked twice, balze made it so that users can only see their own data, but also made it so that if you're logged out you can see everything for some reason, so by simply requesting everyone's profiles while logged out, we can grab ALL information on user profiles, including IP addresses for some reason.
    • User icon
      I discovered this completely by accident, I noticed that you can't see anyone else's posts when logged in, so I decided to log out, and when looking at the requests, I saw Kyle's IP address and made a very simple python script to fetch all users from Supabase with the IP address field and got all 15 users (until he deleted my account for some reason, like, what lmao, that doesn't stop me?)
    • User icon
      it's illegal to both, blaze for basically failing to secure data in one of the worst way possible and for you still continuing after finding out the issue

      have you at least contacted blaze privately?
    • User icon
      I have no way of contacting them privately since they blocked me everywhere so I got someone else I trust to report it instead
    • User icon
      I also checked again, still not illegal for what I did since this data was accessible without bypassing or breaking into anything, you don't even have to be logged in! You can get everyone's IP addresses with a single request to the Supabase
    • User icon
      well of course you didn't break into anything because blaze is badly checking permissions (if it even check), blaze as a social media is not supposed to make ips accessible to everyone, that's not an intended feature

      even if it is accessible even when not logged, it doesn't make it legal, an open endpoint (that is not intentional) doesn't let you gather everyone data

      Criminal Code, RSC 1985, c C-46 Section 342.1 (1)

      communication aside, ah...
    • User icon
      Under Canadian law maybe, however, under Australian law, I haven't done anything illegal, I would have to actually hack something or break into Balze to violate the law.

      Balze's ToS also says this:

      You are required to comply with all applicable laws, rules, and regulations in your jurisdiction while using Blaze. Any illegal activities or violations of local laws will result in severe consequences, including but not limited to account suspension or termination.

      This implies that only my local laws apply, and not laws in the United States.
    • User icon
      Furthermore, intent matters for you, not for the developer.

      If you intentionally bypass protections → problem
      If the developer accidentally exposes data → their problem

      courts do not criminalise users for a server yelling secrets into the void.
    • User icon
      there's for sure a law just like the one in canada in australia

      like somewhere in

      Criminal Code Act 1995 Part 10.7 from the Australian criminal code
    • User icon
      Section 478.1 – unauthorised access to data

      illegal if you access data without authorisation

      Illegal if you bypass a technical control or circumvent protections

      Section 478.2 – unauthorised modification

      Illegal if you change data or impair a system without permission

      The law focuses on access that you are explicitly not allowed to have. If a server accidentally exposes something publicly, and you access it like a normal user, it’s not unauthorised
    • User icon
      I see. i guess it's legal for you. but is it legal to process personal info data from a badly coded website?
    • User icon
      It does move into grey area there, but let's be real, no regulator is coming after someone who saw a public leak, tried to report it, didn’t share any pii, on a site with 12 real users (6 of which are alt accounts)
    • User icon
      yeah no one would care about us for sure lol

      but I'm just saying that it doesn't put a good image on yourself 😭
    • User icon
      don't get my reputation
  • User icon
    I mean it's basically public domain data at this point with how bad Blaze security is.