26 ms·
Group sex app leaks locations, pics and personal details
- maximente 7y agoall of this makes me wonder when - not if - there's going to be House of Cards style blackmail + intrigue when it comes to leveraging data leaks like these over politicians or influential people. "vote for this or we expose your $recent_embarrassing_breach data" is quite a powerful ultimatum, no? and the only way to win is not to play (e.g. never download + use a potentially embarrassing app), and we know that many aren't so digitally savvy, so this seems like a gold mine for nefarious uses. i dunno, maybe it's too tin foily but it feels inevitable.
- Rebelgecko 7y agoIt's entirely possible that this has already happened but no one knows other than the blackmailer and victim know.
- redleggedfrog 7y agoAfter this latest spiral down in the degradation of politics I feel like that kind of information would nearly be a badge of honor. When your highest seat of the government does pr0n stars, well, the bar is pretty low.
- ultrarunner 7y agoMaybe for the type of person that ‘rises’ to political office, but regular people probably still care quite a bit.
- traderjane 7y agoDo regular people care with their words or with their votes? Because if it just words then how much care is there? As Mitch McConnell's office has stated recently, "Boys will be boys." Isn't that an informal assessment of American culture?
- imesh 7y agoCertainly not of corporate culture. People get fired for stuff like that all the time. Johnah Friedland said the n-word and had to step down from Netflix and he didn't even use it in a racist context. He only said the word as he listed offensive words. Weird sex stuff can certainly be used to affect people in powerful corporate positions.
- deleted 7y ago[deleted]
- gd1 7y ago'Mitch McConnell's office has stated recently, "Boys will be boys." ' No they fucking didn't. https://www.washingtonexaminer.com/opinion/somehow-we-just-got-a-whole-news-cycle-about-something-mitch-mcconnell-never-said https://www.washingtonexaminer.com/opinion/somehow-we-just-g...
- BarkMore 7y agoMcConnell’s office did not state that. Search the web for “mcconnell fake quote” for info.
- Terr_ 7y ago> "You know the cream rises to the top!" > "So does the scum," said Vimes automatically -- Snuff by Terry Pratchett
- Marsymars 7y agoMy only real regret from reading Discworld was not keeping a set of notes of memorable quotes/thoughts.
- BillyWilly 7y agoHell yea, take me back to when I could cheat on my wife in office!
- RaceWon 7y ago> When your highest seat of the government does pr0n stars, well, the bar is pretty low. So by that logic JFK and MLK were also pretty low? Oh wait--I'm not sure they were doing actual porn stars.
- redleggedfrog 7y agoNo, not much different. Not sure what it is about politics and/or power that somehow makes it so difficult to keep it in your pants.
- krapp 7y ago>Not sure what it is about politics and/or power that somehow makes it so difficult to keep it in your pants. Sexual aggression has been a virtue signal of male power and status since the days when kings compared the size of their slave harems. Modern men have been taught through all forms of commercial media that their value as people is directly proportional to the amount of casual sex they have. Culturally, power and sex have always been linked. When Trump said he could just grab women by the pussy and get away with it, of course, he was right. At that level of privilege one often doesn't need to keep it in their pants. Propriety and chastity are for lesser men to whom legal and social consequences can be applied.
- redleggedfrog 7y agoYes, the badge of honor I mentioned earlier. Still disappointing. You'd think we'd be better than this, by now.
- krapp 7y agoTwo steps forward, one step back, unfortunately. It's difficult to make progress when rape culture is a billion dollar industry and we're in the midst of an anti-progressive social backlash. At least every now and then a Bill Cosby or Harvey Weinstein gets raked over the coals. Maybe it's simply due to the existence of social media and an actual positive effect of "outrage culture" but a few decades ago such people would have been all but untouchable.
- acdha 7y agoI think most people who are concerned are bothered by the non-consensual activity. The people most likely to make public complaints about marital infidelity only do so for their political opponents and and voted for him by something like 90%.
- allthecybers 7y agoI don't think you're far off. Plus, who knows how long the bad guys had to harvest this stuff prior to the good guys finding it. Or I wouldn't put it past some foreign hacker agency or even the NSA from scooping it up for a rainy day.
- duxup 7y agoIt seems like something obvious enough that I would be surprised if it wasn't already done. The sheer volume of data and highly motivated state actors who are outside any legal risk both seem pretty high.
- noobermin 7y agoTo be fair, the users could just be staff or interns. I don't believe anyone is suggesting Trump or Boris Johnson are using 3fun.
- techntoke 7y agoAll it takes is staff or interns to compromise an entire political campaign. Just because they aren't the primary candidate doesn't mean they don't have access via blackmail to the information someone is looking for. It really is a huge security nightmare with people that have a candidate's calendar or even access to a candidate's email. Also, in terms of Trump possibly being compromised. Google Jeffrey Epstein.
- noobermin 7y agoTo be clear, I do not have any illusory perception of the personal morality of Trump, it's just that location data isn't enough to really tie anyone to any official or important person. You can just claim it was an intern even if it was the politician was the user and fire the intern. My point is it's not as potentially damaging as say actual evidence of scandalous behavior is. For example, there was the comedic Ted Cruz twitter scandal in which his account liked a pornhub video featuring incest play. He claimed it was a staff mistake and moved on.
- techntoke 7y agoIf only all the people being paid to automate regular jobs could automate the government instead using open source software.
- userbinator 7y agoAs pointed out in the article, it could be someone having a bit of cheap fun with a spoofed GPS.
- namirez 7y agoIt'a plausible but not very probable, at least as far as policy positions are concerned. With the current campaign financing laws, there are legal ways to coerce politicians into voting a certain way. It's more risky to blackmail them.
- toasterlovin 7y agoBut money only goes so far. Some things cannot be bought, but they can be coerced.
- corndoge 7y agoLike what?
- dhosek 7y agoCompare Lindsay Graham re: Trump in 2015 vs. 2017
- corndoge 7y agoWhat?
- whamlastxmas 7y agoHe was very anti Trump and then later pro Trump. Though it's not clear it's a result of coercion or anything other than Graham capitulating to work to get stuff done
- mandeepj 7y agoHe's a republican. The approach he used - if you can't beat them then join them. Not sure if T has any dirt on him. Along the lines - Chris Christie was also very anti T before T got the nomination.
- gameswithgo 7y agowhen? right now!
- jessaustin 7y agoThis is the best explanation available for why the "black budget" grows ever larger. Who would dare vote against that? Maybe an angel? Maybe someone so obviously corrupt and disgusting that additional proof of those qualities wouldn't surprise any voter.... hmmmm.
- TrumpDaddy 7y agoHave fun thinking about Trump daddy til 2024.
- tempguy9999 7y agoSex with more than one person at a time is corrupt and disgusting, apparently. May I be allowed a different opinion?
- pbhjpbhj 7y agoIsn't the problem hypocrisy rather than group sex? You can perfectly legally have group sex in the UK (if all participants are legally consenting), the people most likely to object are those who think they're in a trusting monogamous/monoandrous relationship with one of the participants. The primary reasons people can be blackmailed seem to be because they've not been forthright, or, they themselves perceive it as wrong.
- tempguy9999 7y agoI'd extend that to hypocrisy and/or dishonesty, and yes those are valid objections (IMO the only ones), but my problem is the apparent view that the act alone is socially reprehensible, not the secondary issues of being two-faced, or going behind your partner's back without their knowledge. So yes I completely agree with you, once those 2 issues have been teased apart. The GP comment with "obviously corrupt and disgusting" was objectionable. TBF looking at other comments I see little or none of that.
- jessaustin 7y agoSomehow you've completely misunderstood the comment above.
- salty_biscuits 7y agoyou can also win by presenting a public persona that is slightly degenerate/shambolic, so such an embarrassment will only add to your appeal in your support base...
- jacobush 7y agoSlightly??
- throwaway-571 7y agoThe Trump / Johnson play.
- jacobush 7y agoI figured as much, and these are not slightly shambolic. (I can not say for Johnson, don't know enough about him.)
- keithnz 7y agowell, black mirror ( the TV series ) has played with this topic. It has already played out in some ways where there's been stories of people being manipulated because they get compromising video by hijacking peoples cams then they leverage that to get more. So, there is a good possibility it's playing out involving people of influence
- chubot 7y agoUh didn't this just happen with Bezos? Although I heard they targeted a personal phone, I don't think it makes that much difference. Computers are insecure in all sorts of ways, whether it's your own phone or somebody's servers. In that case they were trying to blackmail him into making some public statement, with pretty high stakes as far as I remember. Kudos to him for not capitulating!
- diogenescynic 7y agoAnd it appears Jeffrey Epstein may have been using compromising information as blackmail the rich and powerful then laundered the money through a fraudulent hedge fund operation.
- pasquinelli 7y agoThis is a tangent but is that what it appears to be? Some people must really like associating with their blackmailers if that's the case.
- goatinaboat 7y agoMaybe Epstein never actually needed to blackmail anyone? Maybe they were just happy to be sold tickets on the Lolita Express? I’m sure he kept some blackmail material regardless, which will soon be revealed.
- ceejayoz 7y ago> Some people must really like associating with their blackmailers if that's the case. Or their blackmailers require the social engagements and outwardly positive attitude as part of the blackmail.
- luckylion 7y agoIIRC, the brother of Bezos' girlfriend sold the texts to the media. The good old way of getting the goods, just pay somebody close to it ;)
- mturmon 7y agoIt’s well known that the FBI had dossiers on political opponents that were used to silence them, or attempt to silence them (Daniel Ellsberg, Martin Luther King). What you’re proposing would merely be the same concept with a different leverage mechanism. I’m sure private interests would also have the same ideas.
- 0x8BADF00D 7y agoIt is a lot easier to collect this kind of data as well.
- mturmon 7y agoYou're right, and that's where the parallel I offered kind of breaks down: the digital-domain hacks can scale much more readily than the older ones could, and even at the targeted level, digital information-gathering may be less risky.
- ScottFree 7y agoWhat makes you think it hasn't already been done, exposed and dismissed as conspiracy theory?
- shostack 7y agoI actually worry more about the other threat implied by your use of dynamically inserting kompromat in a message. Imagine sending emails like that at scale in key voting districts. Sure it would get shut down. Substantial, irrevocable damage could still be done in the form of voter suppression.
- luckylion 7y ago> Sure it would get shut down. You mean it would get shut down if done officially? Otherwise, I don't really see an option of shutting it down once the emails are underway. I doubt that providers will manually kill emails from their users' mailboxes, even if they were allowed to.
- rjf72 7y agoIf there's anybody that actually thinks that conspiratorial, consider two mutually exclusive options, one of which must be true: 1) Companies collecting massive amounts of data will only use the data in a lawful and ethical fashion, even in cases where they perceive there to be a potential for significant gain in misuse. 2) Companies collecting massive amounts of data will, sooner or later, use that data in an unlawful or unethical fashion to exploit others in a way that stands to potentially significantly boost their power/influence/wealth. I'm going a far step above beyond and suggesting the exploitation will come, not from leaks, but directly from the data harvesting companies. The reason is simple. Again, the two scenarios above are mutually exclusive and one must be true. So what would you place the probability weighting as? I think most of everybody would agree that the probability of #2 is very near 100%. It's also possible that it is literally 100%, in that it has already happened but we don't know about it. Truly effective blackmail would obviously not be headline news.
- narrator 7y ago#2 Already happened: "Hundreds of Bounty Hunters Had Access to AT&T, T-Mobile, and Sprint Customer Location Data for Years" https://www.vice.com/en_us/article/43z3dn/hundreds-bounty-hunters-att-tmobile-sprint-customer-location-data-years https://www.vice.com/en_us/article/43z3dn/hundreds-bounty-hu...
- tempguy9999 7y agoIt wouldn't matter if we weren't so uptight about sex (thanks, christianity!) Granted what goes on behind your doors may not be what I want to see, but it should not cost you much more than a red face and some banter down the pub if it comes out. And perhaps not even that. Sex is sex, let's chill out about it.
- rossdavidh 7y agoIt would be somewhat surprising to me if this hadn't already happened.
- brandonmenc 7y agoI would be shocked if this isn't happening all the time.
- davinic 7y agoOne thing rarely discussed with a Gmail hack is that it isn't just email, it's location history, search history, backed-up photos, app store history (on Android) AND browsing history. With that data almost anyone could be a blackmail target.
- mywittyname 7y agoAt some point, I think the public will just stop caring. American society has already reached that level in some ways. I can't imagine the President's supporters caring about anything bad he's ever done.
- Scoundreller 7y agoPenetration testing a group sex app. I'm surprised it hasn't been done before.
- taneq 7y agoOf course they found multiple ways in.
- Scoundreller 7y agoThey had partners to assist.
- deleted 7y ago[deleted]
- lysp 7y agoCareful of any leaks
- tamaharbor 7y agoMaybe there is a backdoor.
- gafferongames 7y agoAustralians only: somebody definitely got rooted.
- larkinrichards 7y agoI’ve reported a bug like this in an application that deals with a similarly sensitive topic— They managed to call me back in 30 minutes (I never gave them my number) and had it fixed in a few hours. I did contact them via every medium I could find, not just email. Obviously, the response these folks got from the company should have told them they were talking to the wrong person, and they should have been more vigilant in attempting to contact the right person.
- jammygit 7y agoHow often do the researchers get paid for doing this sort of work?
- larkinrichards 7y agoAn early stage company doesn’t have much to pay you with, but they’re thankful for the help. From my perspective, protecting the data of 10k users was just as important as— or more important than— protecting the data of 1.5m users. I feel bad when people assume negative intent. I don’t think anyone at this company wanted to violate the privacy of their users— they just didn’t get the message through the right channels.
- comboy 7y ago> protecting the data of 10k users was just as important as— or more important than— protecting the data of 1.5m users care to elaborate on a logic behind that?
- aflag 7y agoOne line of reasoning is that the everyone will know about companies leaking data of millions, so they can take steps to mitigate, whereas probably no one will know about a leak like this and just live unaware
- deleted 7y ago[deleted]
- ghostpepper 7y agoIsn't ~35 days very short for a responsible disclosure timeline? This is extremely sensitive info and from the blog post it sounds like they didn't even warn the company that they were planning to disclose it. edit: didn't notice the article does mention the problem was fixed before publishing, although they don't say how well it was fixed
- rolltiide 7y ago> 3fun took action fairly quickly and resolved the problem, but it’s a real shame that so much very personal data was exposed for so long.
- ghostpepper 7y agoAh thanks I missed that on first scan
- dymk 7y agoNot sure how comfortable I am with them posting unredacted map screenshots of PII...
- userbinator 7y agoI agree that the ineffective privacy setting is broken, but I feel like an app which has as part of its functionality finding users near you, naturally needs to tell others your location, and vice-versa. I assume any app which asks for GPS permissions is going to phone home with your location.
- dymk 7y agoThese apps only display a very rough location - nobody reasonably expects for their precise GPS coords to be disclosed
- ceejayoz 7y ago"There's someone within a mile of you" and "here's their coordinates down to ~30 feet, and their supposedly private photo, and their birthday" are very different bits of info.
- sealthedeal 7y agoTrump secretly on the 3fun train gang
- sersi 7y agoIsn't it irresponsible for pen test partners to publish the maps with the location markers with such details as they did in London? It's a good example of how concerning this is but they should have shown fake data there since this is still user's private data...
- slg 7y agoThat is basically the middle of London. I expect hundreds of thousands of people pass through the area in the screenshot every day. The density of people there is so high that the location really can't be linked to anyone specific. Plus it is real time location so you can't distinguish if this is a person's home, someone at work, someone checking the app while sitting on a bus, etc. This location data would be much more dangerous if it was showing the manually entered addresses of users, a screenshot of an area with a low density of people, or if you had constant access and could identify patterns of locations to identify individuals.
- rurounijones 7y agoTo be devil's advocate, since London is coated with CCTV some bad actor (think state or organisation with access to said CCTV) here could probably combine the location timestampw with CCTV images and identify people. I am sure some civil servent could argue that know if people in "positions of power" were using suchs apps that opened them up bo blackmail and that they should be therefore checked as aprecaution.
- Shoue 7y agoIf you've ever had a crime committed against you in London you'll know just how useless the CCTV can be. The quality is often so bad you can't really get anything useful from it, and in many cases the camera isn't even on/working/recording to anything.
- dharma1 7y agoI had my bike nicked a few weeks ago in London. Turns out the council installed new HD/4K cameras that very morning right where I left it - they managed to ID and arrest the perp, and charge him with multiple other thefts too. So it looks like the crappy cctv is getting an upgrade
- dymk 7y agoI thought “pentestpartners” was writing a self post-morem based on that company description
- jagannathtech 7y agoThank God I'm not alone
- flywithdolp 7y agoThat's a great example for lack of understanding of the sex app between great UX to the risks the user face when all those features are in the app
- oaiey 7y agoWhat reading this it crossed my mind that a part of this is a result of too much frontend code. Here in exposing the location for distance purpose.
- edejong 7y agoI’m just waiting for the day when Tinder is down in popularity, security fixes are a bit more lackadaisical and a zero-day exposes a decade of personal preferences of a large share of the population, not unlike a nuclear waste leak. Imagine the awkwardness when a coworker finds out you swiped them left (or right). And no, I am not going to end this with a paternalistic or moralistic statement.
- Kuraj 7y ago> Imagine the awkwardness when a coworker finds out you swiped them left (or right). This really doesn't seem like that big of a deal to me.
- cojxd 7y agoI assume someone who uses a "group sex" app is sunk in such level of degeneracy that they don't care much about their reputation anyway.
- elmo2you 7y agoMaybe I didn't have enough coffee yet today, or maybe I'm just missing something entirely, but.... this whole report talks about how the web API leaks user data, right? Yet all I see in their examples are HTTPS requests. Doesn't that require that somebody already infiltrated either a client device (scope limited to single client), or a central server? How did they man-in-the-middle/decrypt this HTTPS traffic? True, if a web cache (not under exclusive control of the company) can be queried for this data by a 3rd party, it sure is a big problem. But that is rather an operational fuck-up more than it is a fundamental design flaw. How did these pen testers get access to server requests, inside the HTTPS traffic with 3fun's servers? I'm curious how they got access to this info. I'm also curious why nobody else appears to be asking that question. Did I read the article too quickly and miss something that explains how they did that?
- arethuza 7y agoI don't know how this was done, but traffic could presumably be intercepted by using a proxy and installing the certificate for the proxy on the device - you have a secure connection from the app to the proxy and a separate secure connection from the proxy to the servers but the proxy gets to see all traffic in the clear.
- kjaftaedi 7y agoThey're just querying the API. The data they are examining was meant so the app knows how many people are "in your area" .. but instead of just giving you some vague information, it's giving you the exact coordinates of other users, and identifying info about them.
- rossdavidh 7y agoReally, one could argue it's not even "leaking" data about other users, it's just delivering that data to you per your request. "Leak" kind of implies at least disclosing info about other users was not your intention, whereas this seems more like "Delivering".
- hn_throwaway_99 7y ago
- mschuster91 7y agoInteresting, that's the second dating app with a data leak today - Lovoo also has one, though the data is not as fine as here. https://www.heise.de/newsticker/meldung/Dating-App-Lovoo-Nutzer-koennen-leicht-geortet-werden-4492446.html https://www.heise.de/newsticker/meldung/Dating-App-Lovoo-Nut...
- Bostonian 7y agoI doubt it is good for society for such apps to exist in the first place.
- sceptically 7y agoI am curious... Why do you think so?
- qzx_pierri 7y agoThey're probably bitter because they never get any action, so they project disdain onto people whom enjoy their sex lives. It's a mixture of jealousy and frustration.
- Bostonian 7y agoThe app is promoting and is a manifestation of what a National Review essays calls our Our Childless, Childish Culture By MADELEINE KEARNS August 8, 2019 3:34 PM https://www.nationalreview.com/2019/08/our-childless-childish-culture/ https://www.nationalreview.com/2019/08/our-childless-childis... In the Western world and Asia, fertility is below replacement world, and in the Western world, the fraction of children born out of wedlock, who do worse than children of married couples by any measure, is rising. So I think working on something like eHarmony is much more moral than the app discussed in this thread.
- 420codebro 7y agoClutch those pearls buddy - clutch em tight.
- gunshai 7y agoThe assertion being people who want to have threesomes are less likely to have children? I suppose that could be the case, however I am fairly unconvinced that this has any real affect on the population in comparison to the cost of having a child coupled with the rise of understanding the costs involved with having a child.
- ratel 7y agoVery funny: A security issue in a group sex app is reported by penetration test partners. It could have been the name of the app.
- stockkid 7y agoReminds me of a similar submission a while ago: https://news.ycombinator.com/item?id=18029078 https://news.ycombinator.com/item?id=18029078 Shame that they transmit sensitive information like that in a URL param in a plaintext.
- akpakima 7y agoWhat comes after Facebook, Instagram and Snapchat..? Introducing the next generation of social media.. PAGEDIN Pagedin lets you create events to share with friends, book restaurants, attractions and services. iOS users can download the beta version via TestFlight. https://testflight.apple.com/join/IPITLy7T https://testflight.apple.com/join/IPITLy7T For more info, queries and suggestions Email: team@pagedin.co.uk www.pagedin.co.uk
- tossAfterUsing 7y agothere's a group sex app? brilliant!