8 ms·
Find Friends Abuse
- teaneedz 13y agoA 322 word blog post, no apology and 6 instances of the word 'abuse'. The PR message that Snapchat just sent is not a good one. Their target demographic may not care much, but at the end of the day, this brand just dropped a big ball and lost an opportunity to build something better.
- xSwag 13y agoThere is an easier way to solve this issue: Bug Bounty. It worked for Google, it worked for Facebook and its working for Yahoo! Infact, it worked so well for Google that they recently increased the rewards. A venture-backed startup like Snapchat that stores private pictures (even temporarily) should have no trouble paying out $5k a few times for vulnerabities.
- awhitty 13y agoThey were aware of the vulnerability for months. They chose not to adequately address it. A bug bounty wouldn't solve that problem.
- octatone2 13y agoThe problem is they did not see it as a vulnerability, they touted it as a feature, and even made a blog post outlining how you could exploit it. That was the most WTF event in following this story.
- pkfrank 13y agoI really feel like SnapChat is fumbling this whole thing. They ignored the security warning, and now seem to be blaming the security group for the leak of info: >On Christmas Eve, that same group publicly documented our API, making it easier for individuals to abuse our service and violate our Terms of Use. The funny thing is that folks on HN and in the tech community generally will fault SnapChat for their callous attitude to security and pitiful response. But 99.9% of their users won't know or care, and investors will consider this a "lesson learned" and move on without a second thought. Once the 24/hr news-cycle moves past the hyperbolic "SnapChat Hacked!" headlines, this ordeal and their pathetic response will slip into the forgotten-ether of low-impact data leaks.
- nkvl 13y agoIf only it would go away so easily. The PR strategy they have going on, if taken at face value, is a sure way to have stuff like this happen again; and every time they'll be the losers. Pissing off the same people who are trying to help you is childish at best.
- superuser2 13y ago>callous attitude to security and pitiful response How would you have designed this functionality in a way that isn't vulnerable to the same attack? Rate-limiting can slow you down, but you could run the script for months if you wanted. Fundamentally Snapchat is using user-supplied data, and users can lie. Maybe we can check if they are lying by querying a database of people who have verified that they know each other? Oh wait, that's Facebook. HN would be boycotting on principle and screaming about violation of privacy.
- thirsteh 13y ago> Rate-limiting can slow you down, but you could run the script for months if you wanted. Fundamentally Snapchat is using user-supplied data, and users can lie. You can make the same argument about employing exponential backoff on a login screen. It's still very effective deterrence.
- superuser2 13y agoThere is a good chance that a failed password attempt is an indication of something shady going on, so exponential delays are appropriate. How are you going to tell the difference between an API hit for the phone number of someone you know vs. a phone number you made up? Or are you going to increase the delay after every query? If you do that, then the "find friends" feature will just break down for people with sufficiently large contact lists. Maybe don't reveal the username unless that user has your phone number in their contacts? Sounds good. But how are you going to check? Snapchat would need to store every user's contact list, which HN also considers unacceptable. Hashing is not an effective mitigator here because it's so easy to bruteforce the space of 10-digit numbers.
- octatone2 13y agoWhy is user info presented in the clear to anyone who asks for it via their api? Here's a more sane approach I imagine: Allow sending snaps to a phone number (rather than to a username - since you would not know it the time), and attach a "friend request" as part of delivery. When the person at that phone number retrieves the snap they have the additional option of accepting the friend request which then (and only then) exposes their user info to the originating party.
- daurnimator 13y agovia MMS? that would be quite a bit of business AND development effort... (which must be redone for each country of operation)
- octatone2 13y agoNo, via snapchat's delivery system; they obviously can map a phone number to username, therefor they can implement sending snaps to phone numbers (as a proxy) in place of a username.
- tantalor 13y agoSnapchat doesn't use MMS.
- daurnimator 13y agoThat was sort of my point
- maxerickson 13y agoThat would be horribly abused (people sending things other people don't much want to look at). Allowing the friend based on phone numbers might be ok (but you still have to somehow make sure people don't get a bunch of garbage requests).
- octatone2 13y agoLeave out the snap sending part, just make it a friend request. Don't expose to the sender whether the number is not attached to account, it is accepted or rejected. User can or can not send snaps then.
- deleted 13y ago[deleted]
- chris_wot 13y agoOn Christmas Eve, that same group publicly documented our API, making it easier for individuals to abuse our service and violate our Terms of Use. Security through obscurity? Great way of protecting your users. It's pathetic that they believe that others haven't already worked out their protocol and were using it. Funny how they have had to quickly backtrack from this blog post: http://blog.snapchat.com/post/71353347590/finding-friends-with-phone-numbers http://blog.snapchat.com/post/71353347590/finding-friends-wi...
- smackfu 13y agoDid they not have a max phonebook size? Rate limiting doesn't matter if one API call can do it all.
- notlisted 13y agoWow. Talk about a non-reaction. As if bad code resulting in the disclosure of 4.6MM numbers and IDs is a non-issue. Posted something about this on FB, achieved zero reactions which really surprised me, until I realized that some think it's only for sexting... and thus nobody is willing to admit they've installed it (it's useful for other stuff as well, I'm my own emoticon). Several of my friends are in the list (known nicks match known numbers, showing exactly what's the problem here). Maybe I should post something on their wall? :-)
- deleted 13y ago[deleted]
- notlisted 13y agoEDIT: hey' where's the response I was responding to? Obviously (obviously!) I don't use it for sex pix. Never trusted the "no screenshot possible" aspect, nor does my wife... Anyhow, I dismissed it as useless for that exact same reason, but I have a bunch of friends that I send silly messages to and like I said, it works quite well if you use your own face as an emoticon. We also like the paint-over the picture feature. It's easy to add odd picture annotations (stick figure skiers in the snow, cowboys and indians) and then send cartoons back and forth. It also has practical uses, because you can save the picture before sending. The other day I was in the market for window shades -- I know, so very Burbistan -- so I took a shot of each window in my home, marked up every picture with the dimensions and saved it to my phone (my friends have no interest in 18 sets of window dimensions) Best of all, all this nonsense doesn't take up any space on my phone.
- hindsightbias 13y ago> zero reactions Brave new world. The kids don't care about security, and they don't read their FB.
- notlisted 13y agoNot a kid, nor are most of my friends (many are 29.99999999)
- dannsfw 13y ago"We want to make sure that security experts can get ahold of us when they discover new ways to abuse our service so that we can respond quickly to address those concerns." "Quickly" is a relative term here, I guess.
- Systemic33 13y agoSo in a nutshell they are saying that some of their users are risky enough to use a feature that discloses their phone number to them, and they consider this information as non-sensitive data. Snapchat is and will always just be a fad, it's the current social network flavour of the time, and when something more interesting comes along, I will bet that the 4.6M users will be inactive in no time. This is also why their users aren't concerned with this leak, because the premise in snapchat is a sort of leaking of your good and bad moments, with no filter. But i'd be pretty sure that if it turns out they save the images and videos, it would be much bigger of a deal, because it ruins this premise.
- dsl 13y agoI implemented a "find friends" server side functionality for a mobile app (due to a similar business requirement of allowing new users to locate friends). After prompting the user for the ok, the mobile app would upload the entire address book to the server. I would check for matches and return a maximum of 25% of total contacts as being valid (randomly so you wouldn't know which numbers really didn't exist). If there were more hits they would be placed into a queue and sent periodically as "your friend has joined!" notices which also increased engagement. Subsequent checks were done by again uploading the entire address book, however I would check against the previously stored phonebook (numbers only hashed with a per user salt) and limit the number of valid hits returned based on the delta of the address book. So if you kept sending 1000 new numbers every time, you wouldn't get any new matches. It was also rate limited per account (which required a verified phone number). All the logic took less than a few hours to think up and implement. Here you go Snapchat, now fix your shit.
- ch4ch4 13y agoAt least you ask the user for permission- Snapchat doesn't even alert the user before uploading the ENTIRE address book! I take issue with this new generation of developers who seem to have no moral or ethical boundaries on the invasion of privacy. The whole "viral/social marketing" trend is also to blame, in addition to the way that startup valuation puts so much emphasis on "traction" rather than the actual tech or even a viable business model!
- jluxenberg 13y agoNot true; they prompt and clearly describe what they will do with your address book during onboarding. Can't find a screenshot of it now, and maybe it has changed since they first launched.
- thaumaturgy 13y ago> I take issue with this new generation of developers who seem to have no moral or ethical boundaries on the invasion of privacy. I do too, but I'm beginning to become convinced that most people really don't care and really aren't bothered by it. We've had numerous clients -- maybe most of them -- request or expect us to keep track of the passwords for their online accounts for them. Privacy erosions and violations by various businesses really haven't been that big of a deal outside of tech circles. Just an hour or so ago, while on an errand, an NPR guest was mentioning something similar, that her Facebook account had been compromised but it didn't change the way she used the service. It wasn't really anything more than a temporary inconvenience for her. Earlier today, a client's personal Hotmail account was compromised. It was being used to spam people on his contacts list. We got in touch with him to give him the heads-up on it. His response was, "it's not a big deal, I don't really care about that, I'm not even going to change the password on it." We had one business client that supposedly took security very seriously. Government funded and all that. They would routinely ask us to put new procedures and safeguards in place, only to then turn around and immediately try to work around them for convenience's sake. This has been a tough thing to accept, but I really don't believe any more that most people care at all about privacy or security. What they mostly want is convenience. And SnapChat is very convenient.
- Gurrewe 13y agoI tried to send a snap ( via http://kittenbot.gustav.tv/ http://kittenbot.gustav.tv/ ) to all the leaked users. Turns out the app crashes a lot after around 10k friends. :D
- nostromo 13y agoIt's hard for me to get too worked up over this. I mean, do phonebooks still exist? They used to list everyone's numbers and their names and addresses and then leave them on everyone's doorstep. This is just a (partial) phone number and username. About the worst abuse I can think of is that you have someone's username from another service, and you can maybe find their phone number. This seems mild compared to, say, Facebook allowing you to search by email and find a user's facebook profile.
- dudurocha 13y agoThat is one of the worst 'apologies' from I startup I've ever read. There is none " We fucked up, sorry, we're fixing it". They speak of the leak as simple 'hack' like someone who was capable of finding all your friends using facebook and random luck. I hope they fix this right, and be more apologetic the next time.
- gibsonsecurity 13y agoWe're going to be releasing a statement shortly. Here: https://gist.github.com/anonymous/8231005 https://gist.github.com/anonymous/8231005
- schappim 13y ago>"$10 to whoever shows me where the apology is in this. Still looking…" - carpeaqua So true!
- wfraser 13y ago"How dare they tell people about the insecure API we wrote and how it works!"