6 ms·
Yo App Allegedly Hacked By College Students
- sillysaurus3 12y agoIs it wise to advertise that you've hacked any app in this social climate? Theoretically, could the founder of Yo have pressed charges against the student? (This would, of course, be complete suicide for any startup. But companies aren't always rational actors.)
- deleted 12y ago[deleted]
- onuryavuz 12y agoNope, they are white hat. Hacking a product/app/website and not talking about it, not warning the founder is the problem. In fact, what those guys are doing increases the collective conscious and improves the system to be able to develop better/safer products.
- sillysaurus3 12y agoI don't think the US court system agrees, which is what I'm asking about here. In fact, it seems straightforward to make a case against the student's activities. From the Computer Fraud and Abuse Act: (2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains— ... (C) information from any protected computer; The phone numbers are probably information from a protected computer. Young people are pretty often cavalier about jeopardizing their futures. I'm just checking whether there is, in fact, a chance that this young person could have.
- kachnuv_ocasek 12y agoThe computer was obviously not protected.
- sillysaurus3 12y agoProtected computers: In practice, any ordinary computer has come under the jurisdiction of the law, including cellphones, due to the inter-state nature of most internet communication. (See the case history, below). http://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act http://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
- danielweber 12y agoI don't get to hack stuff just because I say "white hat." If it's not yours, don't mess with it.
- _ikke_ 12y agoAnd leave security holes open for people with less good intent and actually harm users?
- danielweber 12y agoThere are plenty of companies who will pay you for your services, and under contract so it's completely legal, too.
- stackcollision 12y agoI recall a case where the courts did not agree with you. I can't remember names or many details, but the gist was that some guy realized that one of the pages was taking an fdat argument that was his userid, and by simply incrementing that number he could retrieve the data of any user he wanted. He presented his findings to the company (something major, like AT&T maybe), and they immediately sued him. He fought in court saying he wasn't malicious and was "white hat" as you say, but I believe he was convicted. Does anyone remember this case?
- danielweber 12y agoWeev. Search HN, there are hundreds of conversations about that case.
- sillysaurus3 12y agoIndeed, he was sent to prison.
- jacquesm 12y agoApp now sends 'Ya!'.
- zedadex 12y ago"Oy!"
- jyz 12y agoGeorgia tech alum here. Whoever did this, I may have a job offer for you! Awesome!
- deleted 12y ago[deleted]
- mantraxC 12y agoQuick! Give those students one million dollars in VC funding! Just think about it. We have more and more flash-in-the-pan shoddily written apps in mobile. And because they're flash-in-the-pan, for a time, they're popular. And because they're shoddily written, they're easily exploited at the peak of their popularity, so you can amass a ton of personal information from the app users and abuse it any way you want. Hacking crappy mobile apps may soon become the new "my WordPress blog got hacked". Think of the potential, it can be a whole new industry. Not to mention all the fake diplomas, mortgages, Russian brides and Cialis pills that'll get sold in there.
- Spearchucker 12y agoI have little sympathy for Yo - it's indicative of the cavalier (arrogant?) attitude many seem to have towards security these days. There's this prevalent minimum viable product attitude lately that seems to make app developers think security is something you can think about later. It isn't. You have an obligation to your users and the personal data they entrust you with. Build it in. Today. And know that you can't write secure code as part of an agile process. Security means sitting down and working out a threat model before you jump into code, user needs and backlogs. In other words, choose design up front, or have a contingency ready because you're going to get hacked.
- DanBC 12y agoWhat's the worst that could happen? I'm not trying to minimise the severity of their fail; I am genuinely curious if they could have pushed something malicious to user phones?
- neilkimmett 12y agoThey are asking for users phone numbers: very sensitive data. Apparently that data is not being handled securely.
- Spearchucker 12y agoRespectfully (I mean no offence), your comment is typical of one that trivialises security. Information disclosure is one of only six threats (spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege). Threats (individually, or within a threat tree) lead to exploits, which if not mitigated, have consequences. They in turn have an impact. The impact for Yo is not the degree of sensitivity of the data - that's semantic. The real impact is reputational. Trust is easily obtained, but very difficult to regain once lost.
- munin 12y ago> Trust is easily obtained, but very difficult to regain once lost. I don't believe you. People still shop at Target, people still use Heartland payment processing systems, people still use Comodo and Verisign as digital certificate authorities. Stratfor still has customers, people still use Firefox, Internet Explorer and Chrome, and so on. In this thread you ask people to care about security because of the harm it will bring to their reputation, but really you are the only person who considers the security reputation of a company, service, or product before using it. No-one else does. People in the world consider hackers and security problems to be a bit like tornadoes - what could you have done differently to avoid being hit by one? And really, the track record for making secure software is very bad. Matasano is the premier application security consulting company in the world. Their blog got hacked. Microsoft is the premier software development company in the world, they invest billions comma billions of dollars in the security of their software, from paying internal red teams to giving grants to leading academics for groundbreaking research. Their software still gets hacked. So what's your secret to making software secure? Is it more quotes from the CISSP handbook?
- irfan 12y agoThe app uses parse.com API for all communication (and probably for all data storage) and I haven't seen it communicating with anything other than parse, getsentry and flurry services. Does hacking the app means hacking parse.com?
- fredsted 12y agoMaybe the hackers found their API keys in the app binary.
- infinite_snoop 12y agoProbably, I took it apart and had a quick look but couldn't find the key. I only had a quick scan of the Application and Activity classes though and did a search for Parse.initialize (where the key is passed in)
- deleted 12y ago[deleted]
- infinite_snoop 12y agoOk, I took another look and all the Parse keys are in a very obvious place!
- infinite_snoop 12y agoI'm interested in how you can conceal these API keys in Android, there does not seem to be any recommended approach. Obscure methods like wrapping them up in C native code get mentioned. I'm assuming Proguard does not help?
- fmax30 12y agoWhile i was messing around with another app , what i saw was that parse apps leak their clientkeys but not the application Id. I did look more into it . parse does some sort of hashing to make an iid which is sent with each request . I am pretty sure that the iid is made from the app key and the client key. I did mess around a lot with an app using parse with charles web proxy and a number of decompilation tools i plan to write about it soon. ( as soon as i get something concrete)
- DigitalSea 12y agoThe Yo joke keeps on getting funnier. First 1.2 million dollars of funding for an app that allows you to send, "yo" to your friends and now this hack. What the hell was the money spent on? It certainly wasn't security. I'd imagine the developers threw a massive party with kegs and thousands of pizzas with the funding money because lets be honest: Yo is an MVP product that is not refined nor innovative and could be built by a 14 year old with a Udemy course on Objective-C. The fact it supposedly took 8 hours to build and started off as an April Fools Day joke says it all, right? I like stupid apps and things like this, but the fact this received funding just reminds me of 1999. Apps like this shouldn't take funding, they're short-lived hype apps, they're not the next Twitter or Facebook. Can the bubble just pop already please? Save the VC funding for startup ideas that actually deserve it. This is the pet rock of mobile apps. At least Mike Judge has a plot he can adopt for season two of Silicon Valley though.
- madeofpalk 12y agoMaybe they haven't spent the 1.2 million dollars? Maybe they and their investors know a little bit more than we do and have something up their sleeves. What we do know is they sure have recieved a lot of attention they wouldn't have otherwise.
- hnha 12y agoThe funding came from the CEO himself, it's just a marketing scheme...
- 12y ago
- paul9290 12y agoGreat marketing, everyone is talking about the app now. Just heard it on the FM radio. The title of the article even hints to this be marketing.. "allegedly." I don't believe much of anything I see on the Internet. I think you shouldn't either!
- uptown 12y agoExactly. Whether it's true or not, it extends the idiocy for another day or two.
- joekrill 12y agoWell if you scroll down to the "Update" portion you'll see it's been confirmed. Alas, that's by the CEO, so I guess theoretically this could all be one big scheme. But they were getting quite a bit of hype before this security issue(s) arose.
- uptown 12y agoAnd suddenly 'Yo' has a path to monetization ... litigation!
- jwheeler79 12y ago'bringing on a specialist security team' (i.e. better programmers who know what the fuck theyre doing)
- ulfw 12y agoThose students have done a better jop than the original app developers and deserve a million dollar more than funding for a 'Yo' app. Please. Let's be serious.
- isaiahturner 12y agoI came here to talk a little about Yo. I was one of the original people to "hack" the app and updated the message to say "Tweet #YoBeenHacked" at about 3AM EST on June 20th. This is the hashtag that has sense been used. Approximately 15 minutes after doing this, I received a call from Or, the founder and CEO of Yo. Or, Chris, and I talked for about an hour and fixed a few issues then. From that point on, the message could not be updated. The issues with Yo were not entirely Or's fault. As he put it, the app was intended as a "prototype" and had it not blown up so fast, this would not have been an issue. A common claim is "You have 1 million dollars, hire someone to fix this!" which Or had already done. A meeting with the parse team had already been scheduled long before today and had everyone tried to hack the app today, the attempts would fail. During this meeting Parse's Security team, Or and I fixed the security issues. I would be happy to answer any other questions, post below. During the conversation Chris and I were both offered freelance jobs. Chris declined, I accepted. I currently am working on a feature for Yo to update your username.
- isaiahturner 12y agoAdditionally, securing Parse requires setting an ACL. This is not a huge deal but many apps do not. If you use Parse, please check your ACL.
- jsinghdreams 12y agoHow was the Yo app hacked to play sounds('rick roll') that weren't originally in the app binary?
- isaiahturner 12y agoOr came to the conclusion those people changed the binary and that they were on jailbroken devices. Those videos were faked so to say.
- jsinghdreams 12y agoGotcha. The binary only has two .mp3 files; yo.mp3 and yoyo.mp3.