Originally Posted by Golf1echo View Post
Apparently this information was on an unsecured Microsoft Cloud ... seems like they should be included culpability as well.
I'm curious why you think this way. The cloud is infrastructure and virtualized hardware provided to users to do whatever they want to. This is 100% directly the fault of developers who didn't implement per-request authorization on FAF's web site. There are plenty of tools and plenty of consulting firms who specialized in analyzing web sites for security flaws. FAF did not do their due diligence in hardening their site. This exact same scenario would be present had they hosted their site on AWS or cheap web site
