API Misuse: Hacker Leaks 2.6M Duolingo Users' Emails & Names

111@zerobytes.monster to Technology@beehaw.org – 64 points –
API Misuse: Hacker Leaks 2.6M Duolingo Users' Emails & Names
hackread.com
8

There is no such thing as "api misuse". You provide the api and people use it according to the conditions you provide. Tighten your shit. Don't blame your own failures on other people.

Oh no, my email and name! /s

Very useful for the people who send out phishing scam emails

Which is why I am happy to have email aliases. Alias gets leaked? No problem. I'll just delete that one and make a new one for that service. Scammers and spammers have a useless email address and I still have my clean inbox.

Providing a name is optional so for many users its just an email address.

Why is this news? duome.eu has scraped this data and a lot more since forever.