Calgary third-party vaccination verification app pulls web portal after users' data left unsecured
A third-party vaccine verification app that was initially endorsed by the Calgary Flames' ownership group left some users' data unsecured and available to be viewed by the public, CTV News has confirmed.
The website app of Calgary-made PORTpass was pulled offline late Monday and its website now says "we are updating" on its landing page.
A news tip sent to CTV News and other media outlets on Monday evening pointed out the security flaw that allowed anyone to access profile information of PORTpass users.
The pages displayed the name, email address, blood type, postal code, date of birth and phone number of registered PORTpass users. The page also contained a link to the photo identification submitted by a user, including their driver's licence or passport.
FLAMES FANS: BRING HARD COPIES
Calgary Sports and Entertainment Corporation (CSEC) -- the group that owns the Flames, Stampeders, Roughnecks and Hitmen -- had initially encouraged fans to download PORTpass to provide easier entry into the Saddledome.
CSEC is now saying fans should bring hard copies of their vaccination records to future games.
"CSEC is reviewing issues that have arisen with respect to the use of the PORTpass app and will release further information as appropriate," a statement on the Flames' website reads.
PORTpass CEO Zakir Hussein says he ordered his team to take down their web portal Monday after he found out that user information was publicly available online.
"I'm waiting to hear back from our audit teams here to make sure... where are we going wrong? Where are these holes? What needs to get fixed?" Hussein said Tuesday.
He added that he has two companies auditing the PORTpass security and privacy systems and he is unsure of how many user profiles were affected by the breach.
"Personally, I don't know. I don't yet, but it was definitely not in the hundreds of thousands or thousands or five hundred," he said.
CTV News is unable to verify how many user profiles were affected and for how long their personal information would have been available publicly online.
"We are working on figuring out exactly what happened here and obviously we're going to make this better," Hussein said.
Alberta's Office of the Information and Privacy Commissioner of Alberta said it is contacting PORTpass to remind them about reporting its privacy breach.
"Under Alberta’s Personal Information Protection Act (private sector privacy law), if an organization experiences a breach and determines that there is a real risk of significant harm to affected individuals, it must report the incident to the Commissioner and notify affected individuals," reads a statement from the province's privacy commissioner.
CTVNews.ca Top Stories
Poilievre will do 'anything to win,' must condemn Alex Jones endorsement: Trudeau
Prime Minister Justin Trudeau is ramping up his attacks on Conservative Leader Pierre Poilievre as he promotes his government's federal budget.
'My stomach dropped': Winnipeg man speaks out after being criminally harassed following single online date
A Winnipeg man said a single date gone wrong led to years of criminal harassment, false arrests, stress and depression.
New evidence challenges the Pentagon's account of a horrific attack as the U.S. withdrew from Afghanistan: CNN exclusive
New video evidence uncovered by CNN significantly undermines two Pentagon investigations into an ISIS-K suicide attack outside Kabul airport, during the American withdrawal from Afghanistan in 2021.
'One of the single most terrifying things ever': Ontario couple among passengers on sinking tour boat in Dominican Republic
A Toronto couple are speaking out about their 'extremely dangerous' experience on board a sinking tour boat in the Dominican Republic last week.
All Alberta wildfires to date in 2024 believed to be human-caused: province
There are 63 wildfires burning in Alberta's forest protection area as of Wednesday morning and seven mutual aid fires, including one in the Municipal District of Peace.
Suspects waving weapons, smashing glass in Toronto jewelry store robbery caught on video
Arrests have been made after five men were captured on video rampaging through a jewelry store in Toronto, waving weapons and smashing glass display cases.
Pilot proposes to flight attendant girlfriend in front of passengers
A Polish pilot proposed to his flight attendant girlfriend during a flight from Warsaw to Krakow, and she said yes.
Ottawa injects another $36M into fund for those seriously injured or killed by vaccines
The federal government has added $36.4 million to a program designed to support people who have been seriously injured or killed by vaccines since the end of 2020.
Ex-SNC executive sentenced to prison term in bridge bribery case
The RCMP says a former SNC-Lavalin executive has been sentenced to three and a half years in prison in connection with a bribery scheme for a bridge repair contract in Montreal.