3 ms·
A London startup, Rentify, were trying to replace every photo returned by the Tinder API over their network with their CEO's face when they discovered a secret
by mendez 10y ago
A London startup, Rentify, were trying to replace every photo returned by the Tinder API over their network with their CEO's face when they discovered a secret value showing the success rate of a user's photo.
Full marks for fun office hack originality.
0 marks for Tinder for not using https for their photos.
A friend of mine also discovered Tinder was returning dates of birth to calculate age client side, so was able to predict other user's star signs: https://medium.com/haralds-notebook/tinder-should-probably-fix-this-8f5628046626 https://medium.com/haralds-notebook/tinder-should-probably-f...
It proved fairly effective at getting a reply, as you might imagine. Thankfully he had the decency to explain how he guessed.
- georgespencer 10y agoThis was us! Thanks for linking. The terrifying bit is the sheer volume of data Tinder is leaking -- I would assume accidentally. The swipe % on the images for referrer and referee are pretty bad, but DOB and number of FB friends is enough data that you could trivially locate the person on Facebook.
- mendez 10y agoNice work! Agree, basic stuff as well - calculating an age from DateTime on the server is coding 101.