4 ms·
I understand this might be a security issue, and I guess Checkmarx gets their name out. You can tell if someone swipped left or right on someone. However how i
by throwaway_45 9y ago
I understand this might be a security issue, and I guess Checkmarx gets their name out. You can tell if someone swipped left or right on someone. However how is this information useful for someone?
- cmg 9y agoI can imagine ways that a stalker/abuser would find this "useful" information and use it to harm, taunt, threaten, scare or harm their target.
- theEXTORTCIST 9y agoThere is the issue of the TLS connection of images fetched in the app (other things too?) being tied to a domain without a valid cert. In other words, you could MITM the TLS session between the wifi user and the Tindr servers for AT LEAST photos within the app, perhaps more (authentication? other app behavior?). Because the app isn't strictly enforcing the validation of the cert of the photos domain it's trying to reach to pull photos, your MITM server is free to serve to the app as if it was the server on the Internet.
- deadmetheny 9y agoPersonally, I'm resisting the urge to MITM a coffee shop wireless AP and replacing all profile image requests with a request for a random picture of Donald Trump.
- arbitrage 9y agoThe article says that it looks like profile images can be downloaded insecurely. So now you can snoop on what people are looking at. And liking. Opportunities for blackmail, doxxing, griefing, etc., abound. Also, attacks don't have to exist in a vacuum. As part of a larger suite of attacks, it appears to be a useful tool that can help build up a profile of somebody. The answer when it comes to hacking is almost never "why". Rather, it's usually "why not".
- zethraeus 9y agodisclaimer: let's have https everywhere and all that. That said, you've described the 'why not'. All of the attacks you've identified are targeted and require significant investment. This opening doesn't allow for economically profitable mass-collection and exploitation (like say, grabbing credit cards or hacking into email accounts).
- dullgiulio 9y agoThat's a bad line of thinking. Privacy doesn't work this way: there are a lot of things that you do every day and keep private even though they cannot easily be exploited. It's human nature.