Kickstarter Bug Exposed Unreleased Projects, but Mostly to The Wall Street Journal
For the last three weeks, Kickstarter had a security hole that allowed viewing of unreleased project proposals — but no account or financial info — through its API. The Wall Street Journal, which discovered the problem, downloaded 77,000 projects and drafts from the site. But aside from that, Kickstarter said in a blog post, only 48 unlaunched projects were accessed while the bug was live, some of them by Kickstarter’s engineers working on its API.