Dating Apps Exposed 845GB of Explicit Photos, Chats, and More (wired.com) 43
Lily Hay Newman writes via Wired: Security researchers Noam Rotem and Ran Locar were scanning the open internet on May 24 when they stumbled upon a collection of publicly accessible Amazon Web Services "buckets." Each contained a trove of data from a different specialized dating app, including 3somes, Cougary, Gay Daddy Bear, Xpal, BBW Dating, Casualx, SugarD, Herpes Dating, and GHunt. In all, the researchers found 845 gigabytes and close to 2.5 million records, likely representing data from hundreds of thousands of users. They are publishing their findings today with vpnMentor.
The information was particularly sensitive and included sexually explicit photos and audio recordings. The researchers also found screenshots of private chats from other platforms and receipts for payments, sent between users within the app as part of the relationships they were building. And though the exposed data included limited "personally identifying information," like real names, birthdays, or email addresses, the researchers warn that a motivated hacker could have used the photos and other miscellaneous information available to identify many users. The data may not have actually been breached, but the potential was there. "The researchers don't know whether anyone else discovered the exposed trove before they did," the report adds. "If you use one of the affected apps there's not a lot you can do to protect against the possibility that the data was stolen before the researchers found it. There wasn't a specific trove of passwords in the exposed data, so changing your password likely won't do much."
All you can really do is hope the developer locks down the cloud infrastructure before anyone grabs the information.
The information was particularly sensitive and included sexually explicit photos and audio recordings. The researchers also found screenshots of private chats from other platforms and receipts for payments, sent between users within the app as part of the relationships they were building. And though the exposed data included limited "personally identifying information," like real names, birthdays, or email addresses, the researchers warn that a motivated hacker could have used the photos and other miscellaneous information available to identify many users. The data may not have actually been breached, but the potential was there. "The researchers don't know whether anyone else discovered the exposed trove before they did," the report adds. "If you use one of the affected apps there's not a lot you can do to protect against the possibility that the data was stolen before the researchers found it. There wasn't a specific trove of passwords in the exposed data, so changing your password likely won't do much."
All you can really do is hope the developer locks down the cloud infrastructure before anyone grabs the information.
I am releived (Score:3, Funny)
Sad fact (Score:2)
Re: (Score:2)
Re: Sad fact (Score:2)
I disagree. If I was a bachelor looking for a special kind of lay, I wouldn't mind having my app data be exposed to all. I control what data I give them, and I believe that to get laid you don't need to give data that are too private.
Re: (Score:3)
Actually, no. It is non-experts relying on a technical product actually being created and maintained by competent engineers. Like if you buy an electrical stove, you can rely on it not catching fire or electrocuting you, or if you buy a car, you can rely on the brakes working.
Unfortunately, there still is this utter idiocy of software not being regarded as technology that needs to be done by competent and qualified engineers. It is pretty easy connecting some resistance wires to electricity to heat somethin
Re: (Score:2)
High IQ/Low IQ. You are probably going to have the urge to have Sex. That is why Dating Sites, and Porn Sites do so well. We kinda want to have sex. Our High IQ who that this site that tailors to your particular kink is going to have a battle of our Advance brains which are only a few million years old, compared to our billion year old sex drive.
Besides if you so smart to judge the security of a web app, you probably aren't going to like any web-app. Heck you shouldn't be on Slashdot, because I am sure
"just put everything in the cloud" (Score:2)
Re: (Score:2)
Because the execs don't give a fuck. When you're raking in cash so fast you can literally make a year's salary in seconds, you get detached from reality.
They need to come back down to Earth.
Re: "just put everything in the cloud" (Score:2)
Re: (Score:3)
I laughed, but Herpes Dating and many of these are of interest if you're looking for some low grade blackmail material or just something embarrassing to hurt some one with.
Re: (Score:2)
Indeed. That needs to come in via liability and personal punishment on negligence. I mean, negligence does not get any more gross than not securing a cloud container. That is not a simple mistake. That requires a complete amateur having done it and then nobody ever checking it at all. Hence the gross negligence is on the management side here and that should come with personal liability.
Re: (Score:2)
Pamela Anderson private tape with her husband was locked in safe. It was stolen by an electrician looking for glory. It was put online. Paris Hilton’s sex tape was leaked.
The difference is now Is two fold. First, there is no barrier to publication. No one is going to
Meanwhile.... (Score:5, Funny)
Beavis (Score:2)
> "We were amazed by the size and how sensitive the data was," Locar says.
Lots of Copyrighted Content... (Score:1)
Whew (Score:2)
I guess ZooOrgy and CaveBanginHippos are safe then.
Perhaps this connects to the latest spam wave (Score:2)
That's really to bad (Score:3)
That's ratuer unfortunate.
All those nudes just out there, and it's all from Gay Daddy Bear, BBW Dating, Herpes Dating, etc. :(
Let me know when there is a leak from ThatHottieYouLikedInHighSchool.com
I changed my mind (Score:4, Funny)
It just occurred to me that the hotties I liked in high school arw now old ladies with four grown kids, most about 150 pounds heavier. They're still great people. I think I'll stick to their fully-clothed Facebook pics, now that I think about it.
Re: (Score:3)
ThatHottieYouLikedInHighSchoolsDaughter.com
Re: (Score:3)
ThatHottieYouLikedInHighSchoolsDaughterWhoJustTurned18.com
-1 Pedant
Re: (Score:2)
It's called Facebook, Ray.
Except these days they're posting pictures of their lunch or - if you're lucky - their latest boob job and/or beachwear.
Re: (Score:2)
Herpes Dating sounds like a really bad idea. Presumably it's for people with herpes to date other people with herpes, theory being they can't get herpes twice... But they can. Same with HIV positive dating and porn.
Re: (Score:2)
I suppose if you have herpes, and many people do, it's probably safer be with the someone else who has it than someone who does not.
It's also probably - how do I say this? If you have herpes, and of course you're honest with your partner, somebody in the same boat may have less likely to run away.
The quality of comments has gotten so good /s (Score:2)
Re: (Score:2)
Even complete morons can get online now. One of the downsides of technological advances. And the one thing the human race has in endless supply are morons, as the comments nicely show.
Re: (Score:2)
Re: (Score:1)
thank you for the summary - i'm from the future, and it's the same up there.
Alrighty, right, right (Score:2)
Re: (Score:2)
Well, I imagine that telling a date that you have herpes would tend to be a major turn off for most. Meeting someone who also already has herpes would remove that stigma.
Mine the data for the US Election (Score:2)
Chinese government company? (Score:2, Informative)
Re: (Score:2)
Most people don't think about where their data goes, or who has access, they don't care. Which is kind of sad. I think seeing the development or admin side of one of these services would be quite eye opening for most people.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Requiring certified engineers for designing/building significant infrastructure seems like how we handle getting minimum competence and a throat to choke in other areas-- I wonder why that's never gotten a foothold.
Re: (Score:2)
You deserve it (Score:1)
If you downloaded something called "Gay Daddy Bear" on your phone, you deserve to get ALL your info leaked, everywhere.
PS: Am I the only one that started laughing uncontrollably after finding out that's a real thing?