15 ms·
Not excusing this is any way, but this app is apparently a fairly junior effort by university students. While it should make every effort to follow good securi
by michaelteter 1y ago
Not excusing this is any way, but this app is apparently a fairly junior effort by university students. While it should make every effort to follow good security (and communication) practices, I'd not be too hard on them considering how some big VC funded "adult" companies behave when presented with similar challenges.
https://georgetownvoice.com/2025/04/06/georgetown-students-create-cerca-a-new-dating-app-that-swipes-right-on-safety/ https://georgetownvoice.com/2025/04/06/georgetown-students-c...
- peterldowns 1y agoI hear you but if you're processing passports and sexual preferences you have to at least respond to the security researcher telling you how you're leaking them to absolutely anyone. This is a total clusterfuck and there are zero excuses for the lack of security here.
- genewitch 1y agoi have an idea, if you don't know anything about app security, don't make an app. "Whataboutism" not-withstanding, this actually made me feel a little ill, and your comment didn't help. I have younger friends that use dating sites and having their information exposed to whoever wants it is gross, and the people who made it should feel bad. They should feel bad about not communicating with the "researcher" after the fact, too. If i had been blown off by a "company" after telling them everything was wide open to the world for the taking, the resulting "blog post" would not be so polite. STOP. MAKING. APPS.
- dylan604 1y agoStop pushing POCs into PROD. There's nothing wrong with making your POC/MVP with all of the cool logic that shows what the app will do. That's usually done to gain funding of some sort, but before releasing. Part of the releasing stage should be a revamped/weaponized version of the POC, and not the damn POC itself. The weaponized version should have security stuff added. That's much better than telling people stop making apps.
- genewitch 1y agoThese "devs" released an app to prod that took passport information and who knows what else. They had no business asking for any of that PII. If all of the developers were named and shamed, would you, as a hiring manager, ever hire them to develop an app for you? Or would you, in fact, tell them to stop making apps? They enabled stalkers. There's no possible way to argue that they didn't, you don't know, and some random person just looked into it because their friends mentioned the app and found all of this. I guarantee if anyone with a modicum of security knowledge looks the platform over there's going to be a lot more issues. It's one thing to be curious and develop something. It's another to seek VC/investments to "build out the service" by collecting PII and not treating it as such. Stop. Making. Apps.
- dylan604 1y agoIf I were ever a hiring manager, hell would have frozen over. But I'm not one for immediately firing someone for making mistakes. Correct the mistake and move on. Some mistakes will never be forgotten, and that dev will forever remember that somethings need extra attention. Also, if we're talking about a company that had a hiring manager in the process of making an app and did not hire employees with security knowledge somewhere in the process, then the entire company is rotten. Let me flip this on its head though with your same logic. If you're the type of person that would be willing to provide an app your passport information. Stop. Using. Apps.
- genewitch 1y agoThese apps are for people who are looking for mates, temporary or otherwise. There may be more nuance than "dummy gave passport info to app"
- dylan604 1y agoNot once ever in my quest of looking for a mate did the potential mate ask to see my passport. There are times when common sense must be used. If an app is asking for invasive data that just feels out of place, just stop. The juice isn't worth the squeeze
- imiric 1y agoYou're shouting into the void. The people making this type of product have zero regard for their users' data, and best engineering or security practices. They're using AI to pump out a product as quickly as possible, and if it doesn't work (i.e. makes them money), they'll do it again with something else. This can only be solved by regulation.
- ghssds 1y agoProgramming should require a gouvernment-emited license reserved to alumni of duly certified schools. Possession of a turing-complete compiler of interpreter without permission should be a felony.
- yamazakiwi 1y agoYou’ve successfully contributed 20 pts to your institutional privilege score; Impressive! You're just one step away from your next badge: "Class Immobility" (95% of users unlock this without trying!) How to unlock: Be denied access to an accredited education. Work twice as hard for half the recognition. Watch opportunities pass you by while gatekeepers congratulate themselves!
- pixl97 1y agoWhile previous is an over reactions, the wild west free for all we have is also a problem. At the end of the day the masses will finally get tired of the fuckery of programmers doing whatever they want and start putting laws in place, and the laws will be passed by the stupidest people among us. Programmers now should start looking into standards of professional behaviors before they are forced on them by law.
- yamazakiwi 1y agoThe problem isn't that anyone has access to programming, it's that corporate incentives prioritize profit over quality, security, and ethics. And sure, if your follow-up is "that won’t change," I get it, but that doesn’t mean the open nature of programming is the problem. >At the end of the day the masses will finally get tired of the fuckery of programmers doing whatever they want and start putting laws in place, and the laws will be passed by the stupidest people among us. I agree laws will pass eventually but it won't start from the people. They rarely even think or hear about software security as something other than an amorphous boogie man, and there are no repercussions so any voices are easily forgotten. Eventually, it will be some big tech corp executive or politician moving into government convincing them to create a security auditing authority to extract money from these companies and/or shut them down. I'm sure we can find some holier than thou types to fill chairs with security auditors for the new "SSC" once it's greenlit.
- yibg 1y agoEnd of the day it's an ROI analysis (using the term loosely here, more of a gut feel). What is the cost and benefits of making an app more secure vs pushing out an insecure version faster. Unfortunately in today's business and funding climate, the latter has better pay off (for most things anyways). Until the balance of incentives changes, I don't see any meaningful change in behavior unfortunately.
- rs186 1y agoThere is a point to your comment, but I am afraid you are shouting at the wrong thing. Instead, I think this is the fair approach: anyone is free to make a website/app/VR world whatever, but if it stores any kind of PII, you had better know what you are doing. The problem is not security. The problem is PII. If someone's AWS key got hacked, leaked and used by others, well it's bad, but that's different from my personal information getting leaked and someone applying for a credit card on my behalf.
- voytec 1y agoI've also hit this link trying to get any info on "Cerca". It's from April 2025 and praises app created two months earlier. It looks like a LLM-hallucinated garbage. OP's entry mentions contacting Cerca team in February. So either this entry is about a flaw detected at launch date or some weird scheme. Nonetheless: "two months old vulnerability" and "two months old students-made app/service".
- michaelteter 1y agoAh that's a shame. It's hard to tell these days what is real. Linkedin shows 2024 founded, and 2-10 employees. And that same Linkedin page has a post which directly links to this blurb: https://www.readfeedme.com/p/three-college-seniors-solved-the https://www.readfeedme.com/p/three-college-seniors-solved-th... The date of this article is May 2025, and it references an interview with the founders.
- bearsyankees 1y agoI think the date there is March 25
- imiric 1y agoThat sounds like you're excusing them. You know what else was an app built by university students? The Facebook. We're all familiar with the "dumb fucks" quote, with Meta's long history of abusing their users' PII, and their poor security practices that allowed other companies to abuse it. So, no. This type of behavior must not be excused, and should ideally be strongly regulated and fined appropriately, regardless of the age or experience of the founders.
- deleted 1y ago[deleted]
- barbazoo 1y agoHow is one supposed to know that it's just a bunch of script kiddies we shouldn't be too hard on if their apps get released under "Cerca Applications, LLC".
- tmtvl 1y agoI vehemently disagree. 'Well, they didn't know what they were doing, so we shouldn't judge them too harshly' is a silly thing to say. They didn't know what they were doing _and still went through with it_. That's an aggravating, not extenuating, factor in my book. Kind of like if a driver kills someone in an accident and then turns out not to have a license.
- dmitrygr 1y ago+1: if you cannot do security, you have no business making dating apps. The kind of data those collect can ruin lives overnight. This is not a theory, here is a recent example: https://www.bbc.com/news/articles/c74nlgyv7r4o https://www.bbc.com/news/articles/c74nlgyv7r4o
- satanfirst 1y agoThe claim that it should have come up in a government vetting process seems to be proof that one should publish one's own dating information before entrusting it to a site that might have lost it or worse might provide it to a government specifically.
- burnt-resistor 1y agoIf you cannot do security, you have no business making any app people use in significant numbers containing Personally Identifiable Information (PII). Perhaps, like GDPR, HIPAA, and similar, any (web|platform)apps that contain login details and/or PII must thoroughly distance themselves from haphazard, organic, unprofessional, and (bad) amateurish processes and technologies and conform to trusted, proven patterns, processes, and technologies that are tested, audited, and preferably formally proven for correctness. Without formalization and professional standards, there are no standards and these preventable, reinvent-the-wheel-badly hacks will continue doing the same thing and expecting a different result™. Massive hacks, circumvention, scary bugs, other attacks will continue. And, I think this means a proper amount of accreditation, routine auditing, and (the scary word, but smartly) regulation to drag the industry (kicking-and-screaming if need by by showing using appropriate leadership on the government/NGO-SGE side) from an under-structured wild west™ into professionalism.
- yard2010 1y agoThese guys should probably study something else.
- selcuka 1y agoFair point, but come on. Not returning the OTP (which is supposed to be a secret) in the response payload is common sense, whether you are a seasoned developer or a high school student. It is also a commercial product, not something they made for fun: In-App Purchases - Cerca App $9.99 - Cerca App 3 month $9.99 - 10 Swipes $2.99 - 3 Swipes $0.99 - 5 swipes $1.99 - 3 Searches $1.99 - 10 Searches $3.99 - 5 Searches $2.99
- root_axis 1y agoSadly, it's not common sense. I've worked with dozens of people who just throw arbitrary state into front-end response payloads because they're lazy and just push to the front-end whatever comes from the service API.
- selcuka 1y ago> because they're lazy Exactly my point. The reason is not being a university student. It's laziness, or not taking your job seriously.
- cAtte_ 1y agothis stops applying when your cute little app starts storing people's passports
- mbs159 1y agoAlthough I do agree with the sentiment, you should handle sensitive information if you are not capable of properly doing so.