Just Wanted to Be a Driver, Ended Up Discovering a Time Capsule
用户尝试注册东南亚某打车应用时,发现自己的手机号已被占用,并显示了一个旧的Yahoo邮箱账户。这表明该平台可能存在数据管理问题和用户信息泄露风险。 2025-7-5 02:46:44 Author: infosecwriteups.com(查看原文) 阅读量:17 收藏

Erkan Kavas

I just wanted to hustle and make some side cash. Instead, I unearthed a digital fossil from the Yahoo era.

While casually trying to register as a driver on a very famous Southeast Asian super-app (let’s call it HohoJEk™ for legal reasons), I used my own phone number — a number I’ve owned for years.

image @ thehackernews.com

The app politely told me: “This number is already registered.”

Which is weird, because:

  • I’ve never signed up as a driver.
  • I don’t own a motorbike.
  • I barely drive a shopping cart straight.

Even better — it showed me part of the previous driver’s data: their first name and a Yahoo email alias.

Yes, in the year of our Lord 2025. Yahoo. Like it’s still 2007.

Upon entering my phone number during registration, the app tried to be helpful by saying something like:

"Hi Alibaba! We found an existing driver account with this number."
Email: a***@yahoo.com

I know I’m not Ali or Alibaba. And I sure as hell don’t use Yahoo. So how do they still have this?


文章来源: https://infosecwriteups.com/just-wanted-to-be-a-driver-ended-up-discovering-a-time-capsule-085808a4baa8?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh