6 ms·
Donald Daters, a dating app for Trump supporters, leaked its users’ data
- bentona 8y agoPolitics aside, is the person who found this exploit really a "security researcher" if they sent the data to a news publisher instead of responsibly disclosing the issue?
- jshowa1 8y agoNot sure how this is much different than posting a blog post about it.
- bhhaskin 8y agoI would say the difference is they sent the data to a 3rd party.
- bentona 8y agoTelling the operators first creates a situation where there is a reasonable chance that no one malicious will obtain the data. Publishing a public blog post greatly increases the chance the entire dataset will be leaked to the public.
- jshowa1 8y agoNearly all security vulnerabilities are published in blog posts at some point because most companies deny a problem even exists or needs to be fixed. Sometimes they just don't even respond and the person who discovered the vulnerability publishes anyways as a sort of "punishment" for the companies lack of response.
- kevinmchugh 8y agoThe researcher can only change the likelihood the data isn't obtained by a malicious actor if a malicious actor hasn't already obtained the data. The researcher usually has no way of telling if a malicious actor has the data. Optimizing for the worst-case scenario, which is yes, a black-hat hacker has already gotten there, it makes sense to prioritize notification of users by all available means so they can attempt to remediate the data loss.
- sp332 8y agoYes. This way the users know to protect themselves as quickly as possible. It's not like they made the app easier to hack with the information in the article, anyone who looks at the app will see the data.
- bhhaskin 8y agoI don't agree. Maybe if they just reported it instead of sending the data. That implies malicious intent.
- Dylan16807 8y agoHow does sending data to a journalist imply malicious intent? That doesn't make any sense at all.
- sp332 8y agoDownloading the data is always harder to defend than just discovering it. But unless and until they do something malicious, or sell the data to the highest bidder, I'm going to say it's fair game. Really we don't know how many independent copies were made while the data was live, and however much blame I assign to the hacker has got to be tiny compared to the responsibility of the app maker.
- bentona 8y agoBy definition (https://en.wikipedia.org/wiki/Responsible_disclosure https://en.wikipedia.org/wiki/Responsible_disclosure) this is not "Responsible", but I don't believe it's little-r responsible either. They should have at least told the operators and TC simultaneously, and not (according to the article) relied on TC to tell the operators.
- tptacek 8y ago"Responsible disclosure" is an Orwellian term coined by vendors to coerce researchers. The accepted term among professional researchers is "coordinated disclosure". This wasn't coordinated disclosure, but not all disclosure has to be. https://hn.algolia.com/?query=author:tptacek%20responsible%20disclosure&sort=byDate&prefix&page=0&dateRange=all&type=comment https://hn.algolia.com/?query=author:tptacek%20responsible%2...
- monksy 8y agoMinimal Viable Products strike again.
- huebomont 8y agoAnyone with half a brain could tell this was a bare-minimum effort that you shouldn't trust with your information.
- jdoliner 8y agoNot calling this app Covfefe Meets Bagel seems like a bit of a missed opportunity to me. Not making the Firebase instance private seems like a bigger missed opportunity though.
- protomyth 8y agoI suppose this could be an interesting attack vector on folks. Pick a group you hate, create a website specifically targeted at that group, get their personal information, and then have a "data breach". Just being part of some groups could seriously impact people in certain circles. Its not like there is much risk for the website owners given past breaches. At worst you fold the company and even that isn't very certain since TOS seems to be king.
- pbarnes_1 8y ago"Emily Moreno, the app’s founder and a former aide to Sen. Marco Rubio" Seems unlikely in this case.
- protomyth 8y agoSen. Marco Rubio is not a Trump fan (now that is an understatement), so I'm not sure that makes it less likely. I have doubts in this case and chalk it up to crappy developers unless something more comes of it. It still seems like an attack vector that has a really good risk / reward ratio. Thinking about it, it also seems like an interesting way to feed an election campaigns big data.
- AnarchoYeasty 8y agoFairly sure you just described a honey pot. It's often times fake petitions and email groups, but this is a common tactic among anti-fascists (and fascists too for that matter). Removing the element of anonymity of your opponent is a hugely powerful weapon.
- 0x8BADF00D 8y agoWhy does everyone seem to make the same mistake? DO NOT roll your own crypto.
- trhway 8y agowhile i suspect a couple layers/points, i can't zero in on the major specific point of your sarcasm/humor. "The data was accessible from a public and exposed Firebase data repository, which was hardcoded in the app."
- stevenwoo 8y agoThe article mentions it was because their Firebase database was unsecured - meaning anyone who knew the url could get access to all the data. That was the default for a long time, and Firebase will send you email reminders if you keep it unsecured. The developer ignored the best practices mentioned in the Firebase documentation and the email reminders that come out once a week (I think).
- olliej 8y agoCrypto wasn’t involved - this was just a publicly available database of all their users. The crypto version of this I guess would be to store the plaintext copy of the encrypted content as metadata on the “encrypted” content? No amount of correct encryption or (in this case) API access policies saves you if you just publish all the data publicly
- jv22222 8y agoDonald Daters huh. Wow, that's a lot of people dating Donald Trump.
- blackflame7000 8y agoBoth the people that use the app and attack the app need to reevaluate what's important in life
- YuriGrinshteyn 8y agoThe best people.