Publisher: City & State New York
Date Published: June 27, 2024
Relevant To: Government data security research
Verification Status: Verified
Notes: The NYPD’s public-facing officer disciplinary database (launched after 2020 repeal of NY’s 50-a law shielding police records) had an access-control flaw allowing anyone to reach an unauthenticated developer back-end and add, modify, or delete officer profile records, including uploading malicious files via an exposed Azure storage key. Discovered by independent researcher Jason Parker; NYPD says it was fixed and no data was compromised, but couldn’t confirm how long the flaw existed. Separately, ProPublica found the database’s disciplinary records fluctuated unreliably day to day. Relevant precedent for evaluating the security posture of any BPA-tracked accountability/transparency database, not just vendor ALPR systems.