5 ms·
It's really sad to see so many findings, especially the ones that are exactly the same as issues that tinder had _years_ ago. Did they do no research? Did they
by hyperhopper 5y ago
It's really sad to see so many findings, especially the ones that are exactly the same as issues that tinder had _years_ ago. Did they do no research? Did they just not care?
Example, the exact same triangulation issue that allows tracking users happened 6 years ago:
https://www.google.com/amp/s/time.com/8604/tinder-app-user-location-security-flaw/%3famp=true https://www.google.com/amp/s/time.com/8604/tinder-app-user-l...
- IncludeSecurity 5y agoMy team found the tinder vuln, there are still plenty of location based apps that have that vuln...plenty. :(
- markwillis82 5y agoOut of curiosity, what would be the best way of displaying a rough distance for location on these style apps? (Round to nearest mile? Show a town name?)
- g_p 5y agoOne approach I've been thinking about in the past (at least as a rough concept) is for the back-end to round both users' location to an "area" (probably city level or similar), then compute the distance between the centroids of those areas. That way moving around your own city wouldn't change the returned distance, nor would the other person's moving around their own city. Even spoofing API requests wouldn't help much, as you'd only be able to triangulate which particular area centroid the distance is being measured to, and that is probably something the user is already disclosing on their profile anyway. This could even be done in a relatively private way by only reporting the area level location to the server (not that I imagine many services would want to give up valuable raw location data!), as the server wouldn't need anything more granular. Obviously there's challenges in more rural areas where population and premises density are lower - how big is the "area" in that case, and is the distance reported that meaningful in these situations?
- raverbashing 5y agoRound it to a given precision and maybe fuzz it?
- correct_horse 5y agoThe way tinder dealt with it, as I understand, is by dividing the world into a coarse grid. Users were placed in the grid, then distances calculated from the centers of the grid squares. Basically rounding of position, not rounding of distance. They tried rounding distance (calculated from exact positions) but one can exploit that by exploring for the boundary where the distance changes from one integer to another.
- vmception 5y agoI would lean toward not care It doesn't affect anything Users still pay, and they were focusing on becoming publicly traded and now are
- hyperhopper 5y agoBut not caring implies some kind of tradeoff. If you don't care, just don't add the feature! Obviously they do care if they knew that their almost identical competitor did it and put was an issue, but decided to add the feature anyway.
- rootsudo 5y agoThis also worked until recently on telegram, it's so novel to me, what was a huge deal with the cell phone AMPS/TDMA days and how Kevin Mitnick was caught, is possible now, with someone bored and a day to kill with a waymark and working backwards to try to isolate. I just find it so fascinating, what was only possible by telecom/nation states now the average poweruser can do if they really pleased. Then again, API walk, race attacks and such, aren't the average power user, right?
- enedil 5y agoHuh? On telegram you had to explicitly opt in, and there were warnings when you tried to enable this.
- ryanlol 5y ago>triangulation Multilateration, not triangulation :)
- magnostherobot 5y agogrindr's pretty old at this point, and shows you distances to other people _to the metre_.
- notsureaboutpg 5y agoAren't they the same company? Aren't all of these owned by Match.com? At least the creator of Bumble originally worked at Tinder. Not surprising they are largely the same underneath the marketing
- fatnoah 5y agoThe Bumble issues feels so much worse, IMHO. All of the "hacks" clearly demonstrate that little of the security, limits, etc. are enforced by the server.