30 ms·
Hacking Grindr Accounts with Copy and Paste
- vmception 6y agofuck "responsible disclosure" the outcome of this runaround was that grindr stated they will create a bug bounty program proving once again that the "market based bug bounty program" has better aligned incentives and results in solving the same thing, vulnerabilities that should have been fixed to begin with were fixed.
- yolomusk 6y agoGives new meaning to backdooring on Grindr.
- sebmellen 6y agoWow, password reset tokens returned directly in-browser; that's hard to believe. I wonder how long this had been going on?
- trhway 6y agosomeone designed and implemented it. Would be interesting to know the rationale and their train of thought leading to that.
- rickyc091 6y agoIf I had to guess, the developer used that to debug the reset token to QA if the flow worked; then it was forgotten and skipped past Code Review since the team just left a LGTM without actually looking at the code OR there were to many changes to the PR.
- WD-42 6y agoThis sounds extremely likely, because it sounds like something I would have done.
- hn_throwaway_99 6y agoI mean, I don't think it's that hard to surmise how something like this could have happened. Yes, the bug is egregiously bad, but I don't think it's likely the developer purposely designed it to work like that. Some simple possibilities: (a) perhaps the page was originally intended only to be accessible from a user hitting from a private link sent to their email address (i.e. how normal password resets work, or (b) The API in use was designed to only be accessed server-side, but it was inadvertently proxied through to a client-side call. Again, yes, the bug is very bad. Software is complex, and humans are humans, and it's not difficult to imagine how these bugs occur.
- hiharryhere 6y agoThat’s why doing pen tests on the regular is necessary. We shouldn’t rely on humans getting it right every time, or strangers on the internet reporting it.
- deleted 6y ago[deleted]
- kbenson 6y agoI don't think the developer designed it to work that way either, but something like this only happens when the person creating it, or the people touching it after either don't know how important this interaction flow is or don't take it seriously enough. Whatever API this is using, there's zero reason to show any information about the request other than "we didn't die, so it should succeed". Beyond even showing it, there's zero reason for a password reset API to respond to the request with the secret at all. If it needs to return anything identifying about the request, it should be some identifier that is NOT the secret, which can be used to pull up general info about the request later if needed (time generated, whether it was used, is it expired, etc). Extra points if the access credentials to any back-end API the request page uses can't even request the secret key from a request. A sane API makes it very hard for something like this to happen. Often that takes an inversion of thinking, so instead of making an API as useful as possible and return as much data as efficiently as possible, you make to make it as secure as possible, which means returning as little data as possible to satisfy the specific needs of the use case, and different locked down credentials for specific use cases.
- djaque 6y ago"It's friday and I want to go home" :) But seriously, I'm sure it was made by people that just didn't stop to think about security and "it works, so we're done here" Then, as a business you're not going to try and fix it if the software already works. That would be pure cost.
- Nextgrid 6y agoFrom experience I noticed that a lot of developers don't look at the big picture and don't have a full understanding of how the system works, what's the rationale behind how the feature achieved its objective and how it might be abused by a malicious user. The #1 thing that I think about when I'm looking at some code or feature (and recommend others do the same) is how malformed or intentionally malicious input would break it, but it seems like their developers clearly didn't do so. This is also compounded by the drive to artificially complicate software stacks (microservices, etc) and "silo" developers into their own little bubble where they only work on a small aspect of the system and never have a need (nor the mental capacity - due to intentionally complicated stacks with dozens of microservices in various languages) to look at the big picture.
- jonplackett 6y agoMental thought process of programmer: Sooo... what's the one thing we need this token to be. Secret. OK, let's just return it to the one person in the whole world we don't want to have it. Mmmm is it lunchtime...?
- yyx 6y agoMore like this: Issue #2141 - implement password reset: After answering secret question user should see password reset link. Issue #2534 - send email with password reset link. Issue #2743 - remove password reset link from web page Issue #3892 - replace secret question with email address input
- megous 6y agoIt makes automated testing of pw reset flow easier. Otherwise you'd need some out of band method to get the token.
- ativzzz 6y agoYou should be able to get the token from your database, unless you're doing black box testing, which I am not a fan of for reasons such as this.
- megous 6y agoI'm not justifying it. Just saying that this might have been one reason for such data to be returned. You may not have access to the database if you're doing frontend testing using headless browser.
- developer2 6y agoThis is frighteningly standard across most companies with no serious planning phase for new features, and no code review process. Fact is, some developer was told to create a REST API for password resets, and to return the secret token so that the (internal to the company!) client can send the email containing that token. This developer did their job correctly. At some point, a different developer was told to consume this endpoint, send the related email, and tell the end user (browser client) that the email was sent. This second developer is not part of the "senior services team" who designed the above API, which is perfectly valid. Instead, this is a junior developer taking on their first task at the company. "Take this password reset API endpoint, and integrate it". In addition to queuing the password reset email with the token embedded within it, they also accidentally proxy the password reset service's payload to the browser. No intermediate or senior develop reviewed this new employee's PR; if they did bother to look at it, they only checked for coding standard violations (eg. indentation), without taking the effort to understand the logic of the code. This is actually extremely common, unfortunately. The server-side layer that directly interacts with clients (ie. browsers) is generally delegated to the most junior developers, because it's menial and uninteresting work to connect the backend services to the browser. The current senior developers spent years working on that kind of garbage already, and they'd rather work on the "more interesting/advanced" backend work. Thus, the junior developers whose skills aren't yet honed are stuck–typically unsupervised–working on the front-facing components. Also, this routinely happens at companies which rush every feature out the door with modern "agile" practices. The sprint is almost over! Quick, deliver all features by tomorrow to keep up our velocity and avoid a sprint review with negative feedback! Just merge it and push to prod without QA on a Friday at 4pm! If only the above was a comedy routine, rather than what it truly is: the genuine reality at a large number of companies.
- goguy 6y agoI'd expect even a junior to at a minimum test and view the response payload, see the token and think "bad idea".
- lol768 6y agoAgreed, this is far too basic for the "oh yeah, a junior developer might not have noticed it" excuse. Hacker News seems to assume juniors are useless, from the comments I've seen to date - but they should be able to _think_ and solve problems, even if they're less experienced at interacting with stakeholders, designing system architecture etc.
- frequentnapper 6y agoI wonder how many bootcamps that promise to make you a "fullstack developer" in X weeks even cover the basics of security.
- wilsonrocks 6y agoMine didn't in any great detail.
- djaque 6y agoI guess the good news is that it requires knowledge of the user's email address to execute. You can't just run it on random people (emails aren't disclosed) and even if you know someone on the app in real life, chances are good that they use a personal address that you won't have. Still a pretty bad vulnerability and pretty awful that grindr was ignoring it.
- jdminhbg 6y ago> even if you knkw someone on the app, chances are good that they use a personal address that you won't have I doubt that; I bet most users use whatever Gmail/etc personal address they use for other non-work accounts.
- perardi 6y agoExtremely anecdotally: it’s [person_name]@gmail.com I know of very few friends who go through the process of creating a burner email account to sign up for Grindr. Now, maybe that’s different in other countries, but at least in the States, I would bet good money you can guess their Gmail address.
- sebmellen 6y agoImagine someone running their contact list through this. You could find everyone you know on Grindr right away, and snoop on their conversations and read their personal info... Not only that, but emails are very easy to find these days with tools like apollo.io.
- perardi 6y agoOK, I know it’s easy to say “well of course it’s not safe, don’t send nudes and don’t go on sketchy hookups”. But, to paraphrase Drag Race: men are rotted gila monsters. (I’m a gay male, I can say that. Also I speak from experience. I've seen things you people wouldn't believe.) So, as a thought exercise, how do you make an app like this more secure? Harm reduction is the name of the game. What are the best practices for this? Is it 2FA? Is it encryption keys linked to one device? Is it copying principles from Signal? Is it just having competent developers?
- sebmellen 6y agoUh... One part of it is not returning password reset tokens in the browser. If you know remotely anything about web security this is the most glaring security flaw you could ever encounter. Other steps are nice to think about, but ensuring basic security measures would preempt 99% of data breaches and "hacks".
- perardi 6y agoYeah, in this particular case, they were just glaringly stupid. Just gaming out ideas in my head. I have friends from rather more repressive countries, namely China, where being gay is still a grey area in terms of legality and acceptance, and I’m just thinking of better ways to structure a system.
- thaumasiotes 6y ago> rather more repressive countries, namely China, where being gay is still a grey area in terms of legality and acceptance ...what?
- ghostbrainalpha 6y agoCould you explain why that's bad for someone who knows nothing about security? Where should the password reset token be?
- dewey 6y ago
- 3pt14159 6y agoDidn't ytcracker work for Grinder? It's a hard thing to Google, but I follow him on Twitter and I thought that was the case. If so, this is a hilarious event for some other rapper to dunk on.
- Nextgrid 6y ago> we believe we addressed the issue before it was exploited by any malicious parties I wonder how they are sure of this. In their logs, there would be no difference between a legitimate password reset and a malicious one, given that even a legitimate flow would result in an initial request from some IP address, then when the user receives the email with the reset link they will most likely click on that from the same computer, thus the same IP address showing up on the logs. In case of a malicious attempt the same pattern would be seen - there is no way for them to know whether the user obtained the reset token from the e-mail (as they should) or directly from the password reset endpoint itself.
- sebmellen 6y ago$50 says they're not. This is something every organization has to say for PR reasons, but saying "we believe" is very fishy wording. It could well be this bug has been around for months before it was discovered, and used by many black/grey-hat hackers.
- sneak 6y agoGovernments. It was likely used by governments. Bi men who live straight lives with a wife and family are ridiculously common. The ability to blackmail those people is extremely valuable to certain state organizations.
- on_and_off 6y agoI wonder why you are getting downvoted so much. I don't know how common bi-men are (probably more than bi erasure makes us believe) but it feels like a least a portion of them are not ready to come out as bi.
- thaumasiotes 6y ago> I don't know how common bi-men are (probably more than bi erasure makes us believe) They're not that common. The literature shows a bimodal straight/gay distribution of homosexual tendency in men and a more Gaussian distribution in women.
- hiharryhere 6y agoThat’s appalling Bug bounties are are well and good, but a basic pen test would have picked that up. They aren’t that expensive and for a business trading in data that can get you killed in some parts of the world, should be mandatory.
- HenryBemis 6y agoIt's not a bug. It is either a backdoor placed there from the design/implementation or super lazy programming. I don't want to think it's done on purpose (Hanlon's razor).
- chki 6y agoIf that's an intentional backdoor it's a very weird backdoor. Wouldn't you at least obfuscate things a little bit? Simply mixing up the characters in that string in some pre-planned order would be enough.
- wyattpeak 6y agoWhile I doubt it's an intentional backdoor, I wouldn't assume that backdoors would be obfuscated. You can't deny knowledge of an obfuscated backdoor, while an obvious one could plausibly be a simple mistake.
- joosters 6y agoIf you stick with that logic, you’ll think every mistake is a backdoor !
- BHSPitMonkey 6y agoIf it were a malicious backdoor, it wouldn't have been "hidden" in the response to the _actual_ password reset request form.
- franga2000 6y agoA full account takeover is a really shitty backdoor. Just make a separate "test" endpoint that's exactly the same as the main API but requires no authentication so anyone can read anything. Perfectly deniable as just a bug and entirely undetectable from a target's POV.
- offtop5 6y agoConsidering Egypt is using apps like this to persecute LGBT people, this is absolutely horrifying. I'm so glad I've gone social media free, all the big players in this space have shown repeatedly they don't care about the safety of their users. Grindr was already caught sharing HIV status information with 3rd parties. Eventually these horrible companies will be regulated, but tons of people are going to be harmed before that happens.
- bufferoverflow 6y agoWell, it's not like this vulnerability would stop Egyptian theocrats from figuring out who uses the app. All it takes is creating an account and arranging dozens (or hundreds) of dates.
- ve55 6y agoIt would be nice if this level of negligence and incompetence was somehow punished so that it stopped happening so often
- brundolf 6y agoThis will continue to happen as long as companies aren't given any reason to care. The incentives simply don't work out, and I highly doubt the market will ever change that at this point.
- 8bitsrule 6y agoThat 'bug' is so stupid and elementary that I'm disinclined to think it's a bug. If they had any security people, it'd never have existed. So ... they just don't give a shit. Surprise?
- Nextgrid 6y ago"Security people" spend most of their time dealing with dubious compliance requirements that rarely improve security (in most cases they annoy users and force them to use even less secure workarounds) than actual security like reviewing code to catch things like this and implement policies to make sure unreviewed code doesn't make it to production.
- Eikon 6y agoIn some cases, mandatory compliance measures even worsen security with rules such as requiring some kinds of characters in a password for instance.
- isbvhodnvemrwvn 6y agoAnd the standards for getting into security vary, a lot. I've worked with extremely knowledgeable security researchers, and people who were promoted from helpdesk (typically in areas like compliance), with very little knowledge outside of some certificates. With the latter I often had to explain pretty basic stuff, like how digital signatures work and why the client needs to know the public key.
- ojosilva 6y ago> Hey, do you have a Grindr account? > Lol I can understand this is most probably a private lol by a surprised. But how about we at least stop making these are you gay? Lol! a public moment worth screenshooting? An Ashley Madison data leak is a national embarrassment whereas a Grindr one, a "national security threat" [1]. Being on AM is just a vaudevillian indiscretion, being on Grindr is bro lol that feeds hate and wrecks lives. [1] https://www.theverge.com/interface/2019/3/28/18285274/grindr-national-security-cfius-china-kunlun-military https://www.theverge.com/interface/2019/3/28/18285274/grindr...
- adatavizguy 6y agoIn places they are using Grindr and other apps to target and arrest people. [0] Worse than what the phrase 'wrecks lives' connotes. [0] https://www.independent.co.uk/news/world/middle-east/egypt-lgbt-gay-facebook-grindr-jail-torture-police-hrw-b742231.html https://www.independent.co.uk/news/world/middle-east/egypt-l...
- WD-42 6y agoIsn't Grindr a hookup app? It's not like all gay people use it. It'd be like me asking a straight married friend if they used Tinder. Would "lol" be offensive in that context?
- foldr 6y agoThe photo used for the account is also kind of mildly offensive in the same vein. (To non-gay readers: this is not actually how gay men pose for their grindr pics.) Update: I decided to make the same point in the comments on his post and he responded in about the douchiest low-key homophobic way imaginable: http://disq.us/p/2c9pnno http://disq.us/p/2c9pnno Tech has a long way to go on homophobia :(
- rini17 6y agoI am gay and don't find it offensive or homophobic* at all , just a bit cringey. To non-gay readers: yes actually some gays do pose with grimaces. * I'm even inclined to say you are kind of abusing these Big Words, but not care to start argument.
- deleted 6y ago[deleted]
- darepublic 6y agoA startup I worked for had this exact same security issue. I brought it up to the tech lead/CEO but they were in denial about it. Handrolled password reset by dummies basically
- WD-42 6y agoWhy people are still hand rolling common stuff like this is baffling to me. I'm treading on offensive waters here, but I'd guess this is from a nodejs backend, for some reason it seems to be more common to hand roll stuff like this in node than pretty much any other web language/framework I've worked with.
- darepublic 6y agoI have handrolled a pass reset in node but I didn't give up the key back to the client. In this case it was actually spring framework
- the_af 6y ago> Why people are still hand rolling common stuff like this is baffling to me Don't most systems hand roll their own password reset? Using any backend tech, I mean. This isn't crypto, where hand rolling your own solution is almost always a mistake.
- the_af 6y agoCouldn't you just demonstrate the exploit by resetting any password? (by a willing participant, so as not to be considered as doing something illegal). I wonder how your tech lead could deny that.
- KeepFlying 6y ago"Eh that required too much work, no one will try that in real life" "Oh you were smart enough to open the dev tools and see that, that won't happen irl" "oh users don't have important enough info stored on this account so it won't hurt to have someone access it" (<- literally a reasoning used by a site I used in defense of poor security. "the attacker only gets access to your last name and the last 4 digits of your credit card, that's not bad enough to need more security") Don't put it past an incompetent/lazy/underfunded tech lead to dismiss even a one-click account takeover script.
- erichurkman 6y agoBack when I reported a Grindr security flaw (2016), I couldn't find them on any of the bounty sites, security@grindr.com bounced, and support failed to route it correctly. Reaching out to their CTO, who I found on LinkedIn, and firstname.lastname@grindr.com got a reply in 8 minutes. Sad to see they still haven't upped their security game.
- DevX101 6y agoIf your company is being actively targeted by nation states (and rest assured, Grindr is), you should have a serious security team where this sort of stuff shouldn't have seen the light of day. I'm not exaggerating when I say this bug may have gotten people locked up, or been the lever for corporate/government espionage.
- Nextgrid 6y agoI don't mean to downplay the issue, but why would LGBT-hostile nation-states target Grindr's infrastructure when it's much easier to detect users at the network level based on TLS SNI (since encrypted SNI is still not a thing thanks to corporate influence)?
- DevX101 6y agoI'm sure a government could detect that a citizen visited grindr.com, but it'd be harder to guarantee that they actually had intent to commit "crimes" without access to unencrypted internal messages. I'm also concerned about antagonist nation state that gets the personal emails of top officials at Department of Defense. Goes through a targeted list in an attempt to find out who's a member. And if a match found, then engage in a blackmail scheme for secret information.
- JetSpiegel 6y ago> I'm sure a government could detect that a citizen visited grindr.com, but it'd be harder to guarantee that they actually had intent to commit "crimes" without access to unencrypted internal messages. Why would that hypothetical government care about that? Just lock everyone up!
- WD-42 6y agoYou're assuming the attackers are that sophisticated. With an attack this simple it could be exploited by a group of thugs a local police station (with maybe a "computer savvy friend") logging into local accounts to see if they can find anyone they recognize.
- 6y ago
- homero 6y agoA lot of these "bugs" are just backdoors that countries might force them to include. When caught they call it a bug.
- 013a 6y agoThis issue is incredibly strange and severe. One thing I did notice, though: The timestamps on the Twitter DMs, which were used as evidence to assert that they're unresponsive in DMs, cover a time period of 90 minutes. The language the twitter client is set to is also not english (maybe French? the original discovery was made by someone who lives in France. I don't know), which introduces the possibility that it wasn't even daytime in the US when those were sent. I'm all for publicly announcing these things (in a responsible way) and forcing a quicker response from the company, and its also likely that Troy tried to reach out on his own, but I just think that screenshot is a bad example of a company not responding to DMs. If it had been 48 hours to a week, then I'd be in the concerned camp.
- Arcuru 6y agoThe Twitter DMs are timestamped on September 23. Troy sent his public tweet on October 1.
- thaumasiotes 6y ago> This issue is incredibly strange and severe. Severe, yes. It doesn't seem that strange. You could have a flow like: Reset page receives email address and passes it to some backend functionality. The backend checks whether the email address corresponds to an account on the site. It does, so the backend generates a reset token and emails it to the address on the affected account. All of that is supposed to happen. What's also happening is that the reset token is being returned to the reset page, where the person requesting the reset can see it. This is very bad, but it seems likely to have come from some sort of automatic connect-your-frontend-pages-to-backend-services framework solution.
- caperfee 6y agoThere is additional information in the post indicating that there was no adequate response to the original report even after 5 days: The person who forwarded this vulnerability ... provided full details ... on September 24. ... after 5 days of waiting and not receiving a response, contacted me. He also shared a screenshot of his attempt to reach Grindr via Twitter DM
- megous 6y agoOne reason why generating random email address for each registered account is a good practice if you care about security, and can sometimes save you.
- ed25519FUUU 6y agoThis is why I love sign up with Apple. Even though developers don’t like it, it’s good for users privacy and security.
- SebastianKra 6y agoIn theory, yes. But since it itself has had significant security flaws, since it's so difficult to log in without apple devices, and since you cant trust Apple to be neutral (they recently deleted all Sign-In-With-Apple Accounts from Epic, even though that has very little to do with their dispute and will hurt customers more than Epic), I'd rather reuse my email a couple of times than sell even more of my soul to this volatile company.
- 333c 6y agoThey didn't actually remove Epic's access. Epic just claimed that they would with no corroboration. https://www.imore.com/apple-reverses-course-will-still-allow-sign-apple-fortnite https://www.imore.com/apple-reverses-course-will-still-allow...
- helios_invictus 6y agoAs far as I can tell Grindr has had crappy security and a willful negligent response to security concerns for its entire existence. Don't forget that location tracking in real time of people with Grindr. Don't use Grindr.
- willio58 6y agoI'm not a user of Grindr, but isn't the real time location tracking a feature that users actually like?
- kbos87 6y agoThe real-time location tracking is very central to the app. It’s a grid of people organized by distance.
- thisrod 6y agoYes. "Who else in my structural engineering tute is gay?" was one of the killer apps for GPS on mobile phones.
- Saint_Genet 6y agoIt’s how you try to find out if the hot guy across the bar might be up for it.
- Havoc 6y agoTroy is obviously a good guy but I think he may be stepping into murky waters here with the switch from logging pwns to actively investigating. Think he'll do a legit job either way but it seems like a gamble to me. Investigative stuff is well...more murky
- kbos87 6y agoI’m not an engineer, but I can say that for a very long time Grindr felt like it was basic, poorly built, and generally unreliable. A couple of years ago it felt like there was a serious wave of investment in the app - the UI got better, it stopped dropping messages and having random outages - but clearly the DNA of the company hasn’t really changed.
- peter303 6y agoGrinder was owned by a Chinese video game company from 2016 to 2020. Under pressure from from the US government it was sold to a southern california company.
- maybeanewone 6y agoMy understanding - Grindr doesn't store your chat history, so logging in on a new device won't show your old chat messages. Phew. Grindr is particularly bad at security. It was fairly easy to triangulate users locations until fairly recently and some users were being harassed, and grindr ignored their reports for a long time. It was also fairly easy to use fake locations until fairly recently which was also causing problems for non-users. Grindr regularly shuts down accounts with no process. It's very easy to lose your contacts. Grindr lies about what information they retain. They claim to hold very little information, which they provide when your account is shut down. However they must retain a list of your blocks and favorites in order to function. They lie and say they don't retain this info. Because of the nature of their service, they should be on top of all this stuff, but they are really bad at it.
- maybeanewone 6y agoThey lie and say they don't* retain this info.
- caymanjim 6y agoYou can edit your own recent post.
- tiku 6y agoMust be some framework that has this behaviour as default. Else it would be really really bad.
- mskec 6y agoWhat would be the use case for a framework that returns password reset token to random user requesting password reset of another account. Token must only be available to account owner. A framework like this should not be used.
- woutr_be 6y agoThis seems to be fairly deliberate, the QR code might probably give you some clues. They needed to generate a QR code so the user could just scan it and reset their password.
- Traubenfuchs 6y agoI have very little trust in the capabilities and interest of the Grindr team to do anything but making money with overpriced subscriptions. It's riddled with bugs, years old, yet they keep adding new, unnecessary features like video chat to justify their insanely priced "unlimited" subscription. This year there have been a few months where your own profile data would not load, making you think you'd lost your profile data and having to create it all again. Yet all you needed to do was to restart the app ~10 times to get it to load. Sometimes messages just... get lost in the ether. The "online now" notification is flaky. Grindr Online (web browser) is a whole new mess. I haven't used it in a long while, but the first months it felt as "professional" as an interns side project. Also you need to keep Grindr open on the phone while using it, kind of beating the purpose. The setting to use the metric system still resets to imperial regularly. The app is full of fakers, yet they still have no identity validation feature.
- ruiseal 6y agoWhy was it necessary for Troy to create an account on behalf of someone else?
- progre 6y agoHe didn't, his friend created the account. It's usefull to have someone else, on a diffrent device, and IP block to create the account to confirm that it's possible to take over an account that you have no previous connection to.
- tialaramex 6y agoIf the target has halfway competent security response, you just say "Look at this obvious bug in your design" and they fix it. The first part of Troy's post makes it clear that Grindr did not have halfway competent security response. When you're dealing with a target that doesn't have halfway competent security response the only option is to actually have an equivocal demo that there's a hole which means you need to break into somebody else's account. Anything else they'll most likely gaslight you and their users. "No, there was no hole, Troy just accessed his own account, nothing to see, fake news".
- londons_explore 6y agoGetting in touch with "the right people" seems to be hard at a lot of companies for rare issues like this. Imagine another rare issue - say I want to speak to the board of directors to give them a buyout offer... Would I manage that though in-app chat?
- vilifiedtwin 6y agoThe scary thing is that sometimes bad actors don't need to hack anything. They can just buy the service. Imagine if Saudi Arabia bought Grindr.
- beaker52 6y agoI've fixed this exact vulnerability (sans QR code) for a client of mine in the last 2 years. I place the cause for these kinds of issues on the split between "frontend" and "backend" developers, with many frontend developers coming out of code camps able to build client-side rendered single page applications and being very proficient in JavaScript but not having experience with aspects of security-related software design. Back in the olden days, coming through learning PHP which was all server-side, you got a lot more exposure to that. Less so with these React-heavy code camps.
- nefitty 6y agoAny recommended resources to improve on this specific gap? Ie backend security for frontend devs
- tsimionescu 6y agoShouldn't this incur a massive fine under the GDPR? Isn't this gross negligence in data protection?
- progre 6y agoGDPR enforcement against non-EU companies has not been tested yet, but this might be a juicy test case if there are any lawyers out there.
- gentlewater 6y agoI've been on Grindr for years, and I know first hand that their support is as bad as it can get. _Seriously_. I know because they also have a big automated ban problem. In trying to fight their bot issue, they've started auto-banning accounts that trigger their filter in some way or another. I've been banned 4 times without cause. Each time you have to contact support, who seemingly are either unable or not allowed to answer with anything other than canned responses. Three times the support person realized the ban was erroneous and lifted it without further ado. One time the person affirmed it, all while refusing to break from the canned responses or provide any justification. Most frustrating experience I've ever had with a digital service.
- w_t_payne 6y agoAll you need to do is buy a seat on a RTB exchange and you can already collect pretty much all the information you need without having to hack anything. Our digital infrastructure is ludicrously insecure and open to abuse. The stable door is wide open, and has been for over a decade.
- davewritescode 6y agoI’ve worked on these types of features and this is egregiously bad. Where I work, we won’t even tell you the full email address that we’re sending the password reset to.
- a-dub 6y agoI'm not even sure I'd call this a security flaw or bug... It seems like the design was wrong or it just wasn't done right for some reason. A post-mortem on how this ended up in production would be interesting.