15 comments

  • pants2 4 hours ago ago

    So did you disclose this responsibly? Posting about it publicly first is asking for that sensitive data to be leaked. Might as well hack and repost that PII yourself.

    • g48ywsJk6w48 3 hours ago ago

      This is not a data leakage. They deliberately included 999 of their customers' email addresses in publicly accessible JavaScript code in order to test certain features on them.

  • shoo 12 hours ago ago

    Are the patient emails real patients or could they be test accounts?

    • KomoD 4 hours ago ago

      The emails are definitely real, I checked a few and they appear in HIBP.

    • g48ywsJk6w48 8 hours ago ago

      They look like real people's email addresses. I checked a few. They belong to real people.

  • thom-gtdp 4 hours ago ago

    How do you find such data leaks? Do you manually check all websites you visit?

    • g48ywsJk6w48 3 hours ago ago

      I was curious to know which service provider they use. So I went to look at the source code of their websites.

  • speedgoose 16 hours ago ago

    Looks like you used a LLM to write your post, or am I wrong?

    • thom-gtdp 9 hours ago ago

      Totally agree Check the Wikipedia page "Signs of AI writing", found 2 of them in this post (overuse of em dash and negative parallelism) Also quickly checked Medvi, their JavaScript looks good...

      • g48ywsJk6w48 8 hours ago ago

        Would you like me to show you specific JavaScript files right here?

        • thom-gtdp 7 hours ago ago

          Yes please, I only checked the ones from homepage, I probably missed some if the other pages includes other scripts

          • g48ywsJk6w48 5 hours ago ago

            Just open app.medvi.org and search in DevTools gmail/yahoo/icloud and you will see js bundle with emails.

            or seasonhealth/openloophealth to find another js bundle with staff emails.

            • thom-gtdp 4 hours ago ago

              Mamma Mia I see them! Crazy 1018 customer mails addresses at first sight

              • g48ywsJk6w48 3 hours ago ago

                Yes, and it's a company that makes hundreds of millions of dollars a year.

    • g48ywsJk6w48 8 hours ago ago

      Yes, LLM assisted.