Live data from Hacker News

Swipe Left: Privacy Practices of Online Dating Apps

royapakzad.co

11–20 of 36 posts

Re: Swipe Left: Privacy Practices of Online Dating Apps

#11
Privacy practices of "Swipe Left: Privacy Practices of Online Dating Apps":

After clicking on this article, Google, Facebook and LinkedIn will know that you are interested in the privacy practices of online dating apps.

Privacy Policy and Terms of Use:

  Facebook collects user data to create profiles that...

  Google...

  LinkedIn...

Data Retention:

  Facebook...
  .
  .
--Sending HTTP requests to Facebook, Google, and LinkedIn results in the collection of this metadata and possibly data by your national and possibly foreign government surveillance organizations...

---Data retention by your national surveillance organization...:

Re: Swipe Left: Privacy Practices of Online Dating Apps

#12
post #11

Privacy practices of "Swipe Left: Privacy Practices of Online Dating Apps": After clicking on this article, Google, Facebook and LinkedIn will know that you are interested in the privacy practices of online dating apps. Privacy Policy and Terms of Use: Facebook collects user data to create profiles that... Google... LinkedIn... Data Retention: Facebook... . . --Sending HTTP requests to Facebook, Google, and LinkedIn…

How will Facebook know I viewed a page which has no FB tracking on it? I didn't see a Like button.

Re: Swipe Left: Privacy Practices of Online Dating Apps

#13
post #12
post #11

Privacy practices of "Swipe Left: Privacy Practices of Online Dating Apps": After clicking on this article, Google, Facebook and LinkedIn will know that you are interested in the privacy practices of online dating apps. Privacy Policy and Terms of Use: Facebook collects user data to create profiles that... Google... LinkedIn... Data Retention: Facebook... . . --Sending HTTP requests to Facebook, Google, and LinkedIn…

How will Facebook know I viewed a page which has no FB tracking on it? I didn't see a Like button.

The website is sending out a request to connect.facebook.net

As a rough estimate, maybe 90% of the top 10,000 websites will send out (multiple) HTTP(S) requests to Google and Facebook from your browser.

Re: Swipe Left: Privacy Practices of Online Dating Apps

#15

Sigh, being paranoid bout this stuff makes it really hard to get laid :/ "Screw [dating app] lets meet with this cryptographically anonymous app instead" seems like a tough sell for most women tho.

> "Screw [dating app] lets meet with this cryptographically anonymous app instead" seems like a tough sell for most women tho.

"Sure, but please prepare a cryptographically signed recent lab report showing you've tested negative for all STDs. It would be best if the report was on blockchain."

Re: Swipe Left: Privacy Practices of Online Dating Apps

#16
Our app has a somewhat Tinder-like feel, though it's paid (escorts). I don't want to go overboard plugging, so see my profile for details. For fun, here's how we score on the article's items:

1. No scammers. We require providers to be vetted in some way (references). Clients are going to need to provide screening to see providers.

2-A. We use our custom login system. Verifying your social media account is just a read-once thing we do; we don't ever have access to post. In fact, it is unlikely we'd even get approved for an API key on most platforms.

2-B. For launch we're pretty exclusionary :(. Focusing on cishet couplings, female provider. We're going to address that as soon as possible. Queer sex workers face additional challenges for sure.

3. Data safety. Due to our company's legal status (extrajurisdictional), we have to deeply hide all data. Our servers don't have persistent storage, RAM only. (At boot, it's a manual restore from something like Tarsnap.) Only a few people have root or raw DB access. This does not include most devops people - they go through a change approval process. Real access is limited to core members heavily vested in the company with a need-to-know. More at [1], please ignore the clickbait title.

Another key point: connectivity is heavily restricted. App servers only have inbound socket from their hidden service, plus outbound to the DB layer hidden service. DB layer only has that inbound socket. DB requests are rate limited globally plus per user.

4. We'll wipe your data shortly after deactivation if there are no abuse reports on your account. In which case we keep a photo ID and birthdate so you can't sign up again and get a clean record. This is needed to protect user's safety. But at least a photo is not so readily searchable. Maybe Facebook can do it, but if we were to somehow

1: https://medium.com/@PinkApp/pink-app-trading-latency-for-ano...

Re: Swipe Left: Privacy Practices of Online Dating Apps

#17
post #16

Our app has a somewhat Tinder-like feel, though it's paid (escorts). I don't want to go overboard plugging, so see my profile for details. For fun, here's how we score on the article's items: 1. No scammers. We require providers to be vetted in some way (references). Clients are going to need to provide screening to see providers. 2-A. We use our custom login system. Verifying your social media account is just a read…

Uh- That is a really cool article you shared. Very impressive stuff.

Would love to read a write up on:

> Our servers don't have persistent storage, RAM only. (At boot, it's a manual restore from something like Tarsnap.)

Re: Swipe Left: Privacy Practices of Online Dating Apps

#20
post #11

Privacy practices of "Swipe Left: Privacy Practices of Online Dating Apps": After clicking on this article, Google, Facebook and LinkedIn will know that you are interested in the privacy practices of online dating apps. Privacy Policy and Terms of Use: Facebook collects user data to create profiles that... Google... LinkedIn... Data Retention: Facebook... . . --Sending HTTP requests to Facebook, Google, and LinkedIn…

I'm sure this is true, but what if you leverage something like PiHole and browser extensions like Privacy badger or uBlock? Surely, these offer some tangible protection against this kind of sharing?
Post reply on HN