Calgary third-party vaccination verification app pulls web portal after users' data left unsecured
A third-party vaccine verification app that was initially endorsed by the Calgary Flames' ownership group left some users' data unsecured and available to be viewed by the public, CTV News has confirmed.
The website app of Calgary-made PORTpass was pulled offline late Monday and its website now says "we are updating" on its landing page.
A news tip sent to CTV News and other media outlets on Monday evening pointed out the security flaw that allowed anyone to access profile information of PORTpass users.
The pages displayed the name, email address, blood type, postal code, date of birth and phone number of registered PORTpass users. The page also contained a link to the photo identification submitted by a user, including their driver's licence or passport.
FLAMES FANS: BRING HARD COPIES
Calgary Sports and Entertainment Corporation (CSEC) -- the group that owns the Flames, Stampeders, Roughnecks and Hitmen -- had initially encouraged fans to download PORTpass to provide easier entry into the Saddledome.
CSEC is now saying fans should bring hard copies of their vaccination records to future games.
"CSEC is reviewing issues that have arisen with respect to the use of the PORTpass app and will release further information as appropriate," a statement on the Flames' website reads.
PORTpass CEO Zakir Hussein says he ordered his team to take down their web portal Monday after he found out that user information was publicly available online.
"I'm waiting to hear back from our audit teams here to make sure... where are we going wrong? Where are these holes? What needs to get fixed?" Hussein said Tuesday.
He added that he has two companies auditing the PORTpass security and privacy systems and he is unsure of how many user profiles were affected by the breach.
"Personally, I don't know. I don't yet, but it was definitely not in the hundreds of thousands or thousands or five hundred," he said.
CTV News is unable to verify how many user profiles were affected and for how long their personal information would have been available publicly online.
"We are working on figuring out exactly what happened here and obviously we're going to make this better," Hussein said.
Alberta's Office of the Information and Privacy Commissioner of Alberta said it is contacting PORTpass to remind them about reporting its privacy breach.
"Under Alberta’s Personal Information Protection Act (private sector privacy law), if an organization experiences a breach and determines that there is a real risk of significant harm to affected individuals, it must report the incident to the Commissioner and notify affected individuals," reads a statement from the province's privacy commissioner.
CTVNews.ca Top Stories
'It could be catastrophic': Woman says natural supplement contained hidden painkiller drug
A Manitoba woman thought she found a miracle natural supplement, but said a hidden ingredient wreaked havoc on her health.
After hearing thousands of last words, this hospital chaplain has advice for the living
Hospital chaplain J.S. Park opens up about death, grief and hearing thousands of last words, and shares his advice for the living.
WHO likely to issue wider alert on contaminated cough syrup
The World Health Organization is likely to issue a wider warning about contaminated Johnson and Johnson-made children's cough syrup found in Nigeria last week, it said in an email.
WATCH Video shows dramatic police takedown of carjacking suspects chased through parking lot north of Toronto
Police have released video footage of a dramatic takedown of a group of teens wanted in connection with an attempted carjacking in Markham earlier this month.
Canada, G7 urge 'all parties' to de-escalate in growing Mideast conflict
Canada called for 'all parties' to de-escalate rising tensions in the Mideast following an apparent Israeli drone attack against Iran overnight.
'It was all my savings': Ontario woman loses $15K to fake Walmart job scam
A woman who recently moved to Canada from India was searching for a job when she got caught in an online job scam and lost $15,000.
Families to receive Canada Child Benefit payment on Friday
More money will land in the pockets of some Canadian families on Friday for the latest Canada Child Benefit installment.
After COVID, WHO defines disease spread 'through air'
The World Health Organization and around 500 experts have agreed for the first time on what it means for a disease to spread through the air, in a bid to avoid the confusion early in the COVID-19 pandemic that some scientists have said cost lives.
American millionaire Jonathan Lehrer denied bail after being charged with killing Canadian couple
American millionaire Jonathan Lehrer, one of two men charged in the killings of a Canadian couple in Dominica, has been denied bail.