3 ms·
What's interesting to me is how the passage of time seems to have affected how Snapchat responded to this. About twelve months ago I found a very similar vulne
by objclxt 13y ago
What's interesting to me is how the passage of time seems to have affected how Snapchat responded to this.
About twelve months ago I found a very similar vulnerability in SnapChat that could be used to provide a cellphone number for any given username (it was probably slightly more serious than what Gibson found, it was far easier to exploit).
Anyway, I ended up guessing Evan Spiegel's e-mail address along with a few other SnapChat staff and got in touch with them. They responded in twenty four hours, patched it, and we had a brief chat about how I ended up finding it in the first place. This was back when the API was still running on Google App Engine (...maybe it still is, although that would be surprising). I got the impression it was held together with string, but they engaged with me and it got fixed.
I would be interested to know how GibSec engaged with Snapchat, because their experience seems very different to mine, and yet the vulnerabilities are very, very similar.
- argonaut 13y agoAccording to my interview with them a few months ago, they're still running a Java stack on Google App Engine. It bears noting that GAE is good enough for Khan Academy too.
- objclxt 13y agoOh, I'm sure technically it's good enough, it just seemed surprising from a cost perspective. It seems at the scale they're at it would be cheaper to run their own. But then again, perhaps given the money going in cost isn't something Snapchat have to worry about.
- a_olt 13y agoGibSec say in their disclosure that SnapChat still uses GAE, and argue that this will make attacks easier/faster due to the server being unlikely to bottleneck.