In October 2023, an independent security firm tested the mWater platform for World Vision Ethiopia. The firm found no high-risk or critical vulnerabilities. It reported one medium-risk finding (withdrawn), two low-risk findings and two informational findings.
The firm later withdrew the medium-risk finding after we explained how mWater login tokens work. The other four findings concern how long login sessions last and standard web security headers. None of them exposed data. This article lists each finding and what we did about it.
World Vision Ethiopia requires a penetration test before staff store potentially sensitive data in a new software platform. A penetration test is an authorized attempt to break into a system to find weaknesses before attackers do.
The security firm Theos carried out the test over five business days in October 2023, with mWater's authorization. It was a gray-box test of the mWater Portal web application at portal.mwater.co. In a gray-box test, the testers have ordinary user accounts but no access to the source code.
World Vision Ethiopia set up admin, manager and viewer accounts in its own mWater organization for the testers. This let them try to reach data beyond what each role and organization allows. The firm rated each finding as critical, high, medium, low or informational. World Vision Ethiopia shared the report with us on 30 October 2023.
mWater did not pay for or direct the test. We answered the findings in writing on 31 October 2023.
None of the findings allowed the testers to see data they were not authorized to see.
Status: withdrawn by the firm. The test used a valid login token, so no data was exposed. The explanation is below.
Status: accepted. A login session lasts until the user logs out or changes their password. This is deliberate. Field staff often work offline for long periods, and an expired session would lock them out until they reach a connection.
The API accepts only encrypted HTTPS connections. This header also tells browsers to refuse unencrypted connections in advance.
These headers stop a shared computer's browser from keeping copies of pages after logout.
The X-Content-Type-Options: nosniff header stops browsers from guessing file types.
The firm reported that a user's email address could be read through the API with that user's client ID. That is true, and it is how logging in works.
A client ID is a secret token the server issues when a user logs in with a correct password. The browser or app then sends it with each request. Holding someone's client ID is the same as being logged in as them, so it is equivalent to knowing their password.
The server creates each client ID from 128 random bits. It cannot be guessed, and other users never see it. Without a valid client ID, the API shows only a user's name and username. These are public so that people can share surveys and data with each other. A private dashboard stays private to its authorized viewers, however someone calls the API.
As with any login token, keep yours private. Do not share links that contain client= in the address. Changing your password signs out all your other sessions.
An insecure direct object reference (IDOR) exists when changing an identifier in a request returns another user's data without authorization. Here, the identifier was the session token itself, so no authorization check was bypassed. The API checks every request against the permissions of the user who owns the token before it returns data.
mWater has added security features since the test, including email two-factor authentication (2FA) and organization 2FA policies. Admins can choose to be notified when a member has no 2FA, or require it for every member. See Two-factor authentication.
For how we protect data more generally, see Data security.