Technical Issues

Grindr Security Flaw Exposes Users’ Restricted Profiles And Location Data

Technical Issues
  • Friday, April 13 2018 @ 09:22 am
  • Contributed by:
  • Views: 1,676
Grindr Security Flaw

The dating app world has once again been hit with a privacy scandal. DC-based developer Trevor Faden revealed a sweeping security flaw in Grindr’s code, a glitch he says has the potential to expose sensitive information of more than 3 million daily users.

According to Faden, Grindr attaches a list of restricted profiles to each user’s account to prevent the app from displaying a profile after the user has blocked them. The list would normally remain invisible, but a loophole makes it possible to retrieve the list from Grindr’s code, thereby granting someone access to the names of every account that has blocked them.

Faden launched a website tool called C*ckBlocked that allowed users to retrieve their blocked lists by entering their Grindr username and password. Nearly 50,000 signed up, and once they did so, Faden was able to gain access to a cache of other personal information that is not publicly available on Grindr profiles, including unread messages, email addresses, deleted photos, and location data -- even for users who opted out of making their location public.

Could Hackers Spy on Your Tinder Account?

Technical Issues
  • Friday, February 16 2018 @ 08:25 am
  • Contributed by:
  • Views: 1,786
Tinder Security
Image: wired

The next time you swipe right on a Tinder match when you’re sitting at a bar, consider that hackers might be taking notes.

Website MarketWatch reported that vulnerabilities were found in the popular app, exposing users to hackers. The vulnerability stems from Tinder not using encryption on users’ photos. Instead, they use a basic HTTP, an unsecure older protocol, rather than HTTPS. This means when you swipe, hackers have the ability to see not only profiles, but the actions you take with swiping, super-liking, and rejecting photos as well. Think of it as someone looking over your shoulder as you’re swiping.

Tech Times reported that users aren’t at risk of spies seeing their actions when they are swiping at home over a private Internet connection, but they are when using public WiFi networks.

Ashley Madison Is In Trouble Again, This Time For Exposing Users’ Private Pics

Technical Issues
  • Thursday, December 28 2017 @ 09:48 am
  • Contributed by:
  • Views: 2,994
Ashley Madison

Life’s short, have an affair. But for the love of two-timing tricksters everywhere, don’t do it on Ashley Madison.

Following the catastrophic hack that hit the company in 2015, the dating site for extramarital action is in hot water again - this time for exposing a large portion of its cheating clientele’s private photos.

A team of security researchers has revealed that “poor technical and logical implementations” has left many images from Ashley Madison users vulnerable to exposure online. Due to these flaws, they wrote in a report, approximately 64% of the site’s private (and often explicit) pictures are accessible.

Adult FriendFinder Hack Exposes 412 Million User Accounts

Technical Issues
  • Tuesday, December 06 2016 @ 10:25 am
  • Contributed by:
  • Views: 3,195

A hack against popular adult dating and entertainment company FriendFinder Networks has exposed personal data linked to more than 412 million user accounts. The breach is one of the largest in history, and marks the second such incident at the company in two years.

Nearly 340 million accounts from the company’s flagship site, Adult FriendFinder, were compromised according to a report from LeakedSource. The hack also targeted other sites owned by FriendFinder Network, including Cams.com, and records from Penthouse.com, which was sold in February.

The Adult FriendFinder data stretched back 20 years. Information such as usernames, emails, and join dates was stolen, along with account passwords (the majority of which featured unsecured protections or none at all) and membership data like VIP status and browser information. The cache also appears to include 15 million email addresses from deleted accounts.

Tinder App Crashes, Removes Matches

Technical Issues
  • Saturday, September 03 2016 @ 06:55 am
  • Contributed by:
  • Views: 1,784
 Tinder App Crashes

Popular dating app Tinder crashed on Thursday night, ahead of a long holiday weekend in the United States.

The International Business Times reported that Tinder had crashed around 10:00pm Eastern time, and users were having problems retrieving their messages, contacting their matches and even logging in. Some users reported losing their matches as well. Users on the Dating Sites Reviews Forum also had issues with Tinder

Angry Tinder users voiced their frustration over social media, making jokes about Tinder failing just when they got some matches, were trying to contact their dates to meet, or downloaded the latest version of the app.

One user joked:

“Tinder crashes before it opens which also describes my love life ‪#tinder”

Fling.com Hack Exposes Passwords (And More) Of 40 Million Users

Technical Issues
  • Wednesday, June 22 2016 @ 06:52 am
  • Contributed by:
  • Views: 6,474
Password Security

Fresh off the news that BeautifulPeople.com had been hacked comes another tale of privacy violation. This time, Fling.com is the victim of the breach.

International Business Times reports that tens of millions of credentials were stolen from the adult dating website and put up for sale on the dark web. The information allegedly includes usernames, plain text passwords, email addresses, IP addresses, gender, sexual preferences, and date of birth records. It appears that some of the accounts belong to Fling administrators.

According to the hacker responsible for the breach - who goes by the pseudonym ‘peace_of_mind’ - the data dump contains more than 40 million Fling.com records. It’s currently on sale for 0.8874 bitcoins, which is worth approximately $411 at the time of writing.

Vice Motherboard obtained a sample of the data from the hacker. The individual to whom the Fling.com domain is registered then confirmed its legitimacy.

“We take internet security very seriously,” he wrote in an email to Motherboard. “Our site is free to join and we do not store any credit card information. We've investigated the sample data and it is from a breach that happened in 2011.”

Motherboard also shared the sample data with security researcher Troy Hunt, proprietor of the breach notification website “Have I Been Pwned?” Using HIBP, Hunt discovered and contacted two victims of the Fling breach. One confirmed their full password in the sample. The second claimed they had no recollection of joining the site, but said the beginning of the password was something they have used in the past.

On the bright side, some of the email addresses in the sample did not appear to belong to any Fling accounts. Motherboard tested 101 addresses and found that only 61 were already in use.

Additionally, some of the accounts included in the data may have been disabled prior to the breach. “Accounts in the sample were also flagged with settings such as ‘admin_disabled,’ ‘user_disabled,’ or “active,’” writes Motherboard. “However, these flags seemed to have no bearing on whether an email address was already in use or not on Fling.”

Continued investigation provided further reason to believe that not all the accounts for sale are valid. Motherboard found that accounts can be created on Fling without clicking a verification link sent to an email address. They also found that Fling passwords are required to include numbers, though many passwords in the sample data only contained letters.

To be on the safe side, anyone who has used Fling.com should change their password - particularly if it has been used for more valuable services, like an email account or bank account.

Page navigation