A researcher bought noreply.net. Companies started sending him secrets.

A critical infrastructure vulnerability exists where organizations are inadvertently sending sensitive data—including credentials, personal information, and proprietary details—to publicly registered domains like noreply.net and noreply.us that were purchased by security researchers. This widespread misconfiguration affects over 6,200 root domains and exposes the dangerous practice of relying on placeholder email addresses without proper validation, representing a significant data breach risk that currently depends on researchers' ethical stewardship rather than secure system design. The issue reveals systemic gaps in IT governance, configuration management, and email system auditing that could expose organizations to compliance violations, intellectual property theft, and regulatory penalties if these domains fell into malicious hands.

Matt Burgess, wired.comArs Technica2 min read
Read full article
A researcher bought noreply.net. Companies started sending him secrets.

Read the full story at Ars Technica →