Privacy

Hack Alert: Cupid Media Found In Breach Of Privacy Laws

Privacy
  • Friday, July 18 2014 @ 07:05 am
  • Contributed by:
  • Views: 1,493

Bad news for Cupid Media and more than 200,000 of its Australian users: the online dating company has been found in breach of privacy laws.

Cupid operates more than 35 niche dating websites, including ChristianCupid, MilitaryCupid, SingleParentLove and other sites based on ethnicity, religion and location. Australian Privacy Commissioner Timothy Pilgrim found Cupid Media breached the Privacy Act by failing to take reasonable steps to secure data held on its websites. As a result of Cupid’s lax approach to security, hackers gained access to the company’s webservers in January of last year and stole the personal information of about 245,000 users. The information included full name, date of birth, email addresses and passwords.

At the root of the security breach is Cupid’s failure to have a password encryption process in place. "Password encryption is a basic security strategy that may prevent unauthorised access to user accounts," said Commissioner Pilgrim. "Cupid insecurely stored passwords in plain text, and I found that to be a failure to take reasonable security steps as required under the Privacy Act."

The commissioner added that the Cupid Media fiasco illustrates the importance of correctly handling personal information that is no longer needed, either by securely destroying or de-identifying it. “Holding onto old personal information that is no longer needed does not comply with the Privacy Act and needlessly places individuals at risk," he explained. "Legally, organisations must identify out-of-date or unrequired personal information and have a system in place for securely disposing with it.”

While online dating companies certainly do need to fiercely protect the massive amounts of personal data they gather, it’s also up to the daters themselves to take the most secure approach possible to dating online. Anyone using an online dating site should regularly update their privacy settings and change their password. It’s also important to remain vigilant about limiting the personal information you share. Only the bare minimums required should be posted online, or you risk becoming the victim of identity theft or a scam.

Commissioner Pilgrim noted that, on the plus side, "Cupid's vulnerability-testing processes did allow it to identify the hack and respond quickly." The company has addressed the security concerns and the investigation is now closed, but the commissioner warns against future attacks: “Hacks are a continuing threat these days, and businesses need to account for that threat when considering their obligation to keep personal information secure."

Should Your Salary Be A Secret When You’re Online Dating?

Privacy
  • Saturday, July 12 2014 @ 10:10 am
  • Contributed by:
  • Views: 1,287

I like to think we live in a world where income is unimportant compared to connection, but let’s get real: the world is nowhere even close to that. Like it or not, dating and finances are inextricably intertwined, and that probably isn’t changing any time soon.

The problem becomes even more apparent when you’re dating online, where many profiles include a section for salary. Is it really anyone’s business to know that information before you’ve even met in person? And what are the repercussions, if they do?

If you make significantly less than someone you’re interested in, will you feel inadequate? Will they think you’re only involved with them for their money?

Is Privacy a Thing of the Past When it Comes to Online Dating?

Privacy
  • Wednesday, April 23 2014 @ 07:08 am
  • Contributed by:
  • Views: 1,442

We’ve been warned of scandals when it comes to online dating. Some people post fake profiles and create stories of financial hardship to extract money or financial information from other users, hoping to cash in on someone’s vulnerability or desire for love. This can compromise our security, but it’s within our control to not respond or to report the abuse. But what about the information we voluntarily offer without even knowing how it will be used?

Mobile dating and location-based apps operate and match you with others according to where you physically are, which means they need to collect data from you, usually through your phone’s GPS. But then what happens to the information? Is it used only for matching purposes to benefit the users of the site, or are companies using this valuable information in other ways?

New legislation aims to protect users from themselves and the online dating sites who collect location and other personal information. Senator Al Franken is leading the charge, advocating for more privacy for users.

"This stuff is advancing at a faster and faster rate, and we've got to try and catch up," Franken tells USA Today. "This is about Americans' right to privacy and one of the most private things is your location."

Considering how many people have used online dating sites – a recent Pew report indicated 38% of singles – it makes sense that companies offering services for daters operate with security and privacy in mind. Unfortunately, most people don’t realize how much information they are voluntarily sharing when they sign up and post photos on their phone.

Members also might not realize what information a dating website or app is collecting about them and their social media networks, say if a Facebook login is used to sign up. Though most companies will outline what information they can collect about you and your friends, the fine print is often overlooked by users just trying to download and check out a new app.

A few states require online dating sites to disclose whether they conduct criminal background checks on members, including Illinois, New York, New Jersey and Texas. eHarmony, Match, and Sparks Networks signed an agreement with the California District Attorney’s office in 2012 to check subscribers against national sex offender registries and provide a rapid abuse reporting system for members. Security precautions are being taken to protect users, but legislators like Al Franken and privacy advocates don’t think it’s enough.

Rainey Reitman of the San Francisco, Calif.-based Electronic Frontier Foundation, a nonprofit that advocates for user privacy amid technology development, told USA Today: "People don't realize how much information they're exposing even by doing something as slight as uploading a photograph. Many online apps are very cavalier about collecting that information and perhaps exposing it in a way that would make you uncomfortable."

Use Tinder? Your Exact Location May Have Been Exposed

Privacy
  • Friday, March 28 2014 @ 07:43 am
  • Contributed by:
  • Views: 1,766

Bad news for Tinder fans: all those creepy people you've been avoiding on the app may now know exactly where you are.

It turns out the dating app suffered from a bug for most of last year that would've allowed hackers to determine the exact location of its users. And Tinder chose to cover it up until just a few weeks ago. The information security firm Include Security exposed the security vulnerability in mid-February, saying that anyone with the right kind of knowledge could "get the exact latitude and longitude coordinates for any Tinder user" provided that the app was running.

Hello, major privacy violation!

The company confirmed that "anyone with rudimentary programming skills could query the Tinder API directly and pull down the coordinates of any user." From that API data, it is then possible to triangulate the exact location of the user with a very high degree of accuracy. We're talking within 100 feet. And remember that part where they said "rudimentary programming skills?" So not only can creeps get incredibly close to you, they don't even have to be smart creeps in order to do it.

So much for the fun of all that mindless swiping.

It’s a bad bug, for sure, but before you go cursing the day Tinder hit the app-mosphere, Include Security also noted in an FAQ on its disclosure blog post that these flaws can be "common place in the mobile app space" and will “continue to remain common if developers don't handle location information more sensitively." Is that more comforting or less comforting? I'm not actually sure…

What I am sure of is that Tinder should not have failed to disclose the vulnerability when it was privately reported. Users deserved to know that the security of their location data was potentially compromised, even though the bug was fixed sometime between December and January.

Your questions now are probably "Has anyone actually exploited this?” and “Can I tell if someone has tracked me using this privacy vulnerability?" According to Include Security’s post, “there is no simple way to determine if this attack was used against a specific Tinder user." In other words, nope – you have no way of knowing if that slightly unbalanced-looking person you just rejected is about to come knocking at your door.

Good luck sleeping (or swiping) with that on your mind.

See a demo of the Tinder vulnerability at work:

Live Video Chats Gaining Popularity among Online Daters

Privacy
  • Friday, March 21 2014 @ 07:15 am
  • Contributed by:
  • Views: 1,312

Users of online dating sites sometimes get frustrated and overwhelmed with all the lengthy profiles and messaging back and forth before they ever get to a date with a potential match. A simple solution: why not test the chemistry first by video chatting with each other before meeting for drinks or coffee?

Enter a new crop of online dating apps focused on video interaction. Among those making headlines in this growing field are Date.fm, Flikdate, Video Date and two new apps launched last fall -- View N Me and Instamour.

Developers of these apps saw an opportunity when they noticed how Skype and Facetime are fast becoming typical platforms for people to communicate. They figured singles would want to see if there's chemistry before spending the time and money and effort to meet a date in person. And why not do that from your laptop or mobile phone?

While it sounds great to meet a potential date through a video chat, some people aren't so convinced. Not everyone is a movie director or cinematographer who can figure out good lighting to highlight someone's most attractive features. All too often, poor lighting and strange camera angles can interfere with making a good first impression. View N Me offers tips for looking your best on video to address this problem.

Safety is another concern, and different app developers deal with it in different ways. For example, Video Date does not use phone numbers or e-mails for people to communicate through the service, and messages delete after 24 hours. View N Me offers a strict no tolerance policy for any type of inappropriate behavior on its site. Once someone is reported they conduct a review and terminate the subscription if the user's behavior is deemed inappropriate.

But the most important question for daters is: how easy is the service to use?

Date.fm works a bit like a video-enabled Tinder app. It is simple to use - the service provides general information like age and location along with photos of matches, and you can like or dislike them. If you both like each other, you are sent a notification and then can start video chatting from within the app. FlikDate touts itself as "the fastest date in the world." You simply connect with your Facebook account and play a type of video roulette, where you can chat with someone instantly, see if you click, and accept or reject your match on the spot.

It's no surprise that video dating is becoming more and more popular. People are looking for quick ways to get to know each other. But the real test for love still takes time and effort.

Online Dating Safety Tips from Zoosk

Privacy
  • Sunday, March 09 2014 @ 10:48 am
  • Contributed by:
  • Views: 1,759

According to recent research, online dating is now the most popular way to meet prospective romantic partners. If you're considering joining a dating site but aren't sure what to do or what to expect, it's a good idea to proceed with both an open mind for meeting people and a little precaution.

Online dating safety is a concern, and the U.S. Attorney General's office has taken a stand to encourage people to exercise caution when searching for a relationship online because of the recent dating scams, especially when online daters misrepresent themselves in order to extract financial favors.

Zoosk, which markets itself as the number one dating app, has put together a few quick tips for online dating safety, so keep them in mind when you begin your own search:

Create an Alias - Create a new username and use a different email account from your main email when signing up for a dating site to protect your privacy.

Stay Online - Don't give out your personal cell phone number right away, especially if you are feeling pressured. Keep your messages and chats online through the dating site until you meet in-person.

Keep Personal Info Private - Do not share sensitive personal or financial information with someone whom you haven't met. This includes your last name, address, home or work phone numbers in addition to any financial information.

Go Out in Public - Always choose a public venue for your first few in-person dates, such as a restaurant or coffee shop. Never meet for the first time at your/their home, and don't arrange to have your date pick you up. Plan to meet each other at a restaurant or other public location instead.

Tell a Friend - Always let a friend or family member know who, when and where you're meeting for an in-person date with someone you met online.

Here are a few more things to keep in mind when you're online dating:

Meet sooner rather than later. Many problems for daters occur because they form a virtual relationship with their online match and become emotionally invested before they've seen each other face-to-face. Before you get intimate through emails and phone calls, plan to meet each other for coffee in person. Often, a scammer will try to avoid in-person meetings and keep things going online. If your date keeps making excuses for why he can't get together, then move on.

Keep drinking to a minimum. Some people like to have a glass of wine to loosen up on a date. Keep in mind your tolerance levels. If you get tipsy after a drink or two, you might want to consider not drinking at all. Don't make yourself vulnerable to your online dates, especially when you don't know them.

Page navigation