> The developers stored users IDs (driver license images) in an unprotected directory.
Worse than that. They stored the private data they claimed to be erasing on an open website. No effort to hack, no protection from accidental exposure, no clear intention of protecting the data because they made no effort to do so.
I don’t even think it was due to “vibe coding”, looks like a toy prototype deployed without any consideration.
!!!!!
The losers they hired to write that code laughed all the way to the bank.