Live data from Hacker News

Hacking Grindr Accounts with Copy and Paste

troyhunt.com

31–40 of 202 posts

Re: Hacking Grindr Accounts with Copy and Paste

#31
post #10

Earlier quoted context omitted.

someone designed and implemented it. Would be interesting to know the rationale and their train of thought leading to that.

I mean, I don't think it's that hard to surmise how something like this could have happened. Yes, the bug is egregiously bad, but I don't think it's likely the developer purposely designed it to work like that. Some simple possibilities: (a) perhaps the page was originally intended only to be accessible from a user hitting from a private link sent to their email address (i.e. how normal password resets work, or (b) T…

[deleted]

Re: Hacking Grindr Accounts with Copy and Paste

#32
Considering Egypt is using apps like this to persecute LGBT people, this is absolutely horrifying.

I'm so glad I've gone social media free, all the big players in this space have shown repeatedly they don't care about the safety of their users. Grindr was already caught sharing HIV status information with 3rd parties. Eventually these horrible companies will be regulated, but tons of people are going to be harmed before that happens.

Re: Hacking Grindr Accounts with Copy and Paste

#35

> we believe we addressed the issue before it was exploited by any malicious parties I wonder how they are sure of this. In their logs, there would be no difference between a legitimate password reset and a malicious one, given that even a legitimate flow would result in an initial request from some IP address, then when the user receives the email with the reset link they will most likely click on that from the same…

Not saying they did, but couldn't you make an estimate by looking at frequency of resets by single accounts? If someone took over an active account presumably that person would reset the password to get back in (and have a weird email). ASSUMING Grindr logs the person out of the app when the password is reset.

You might also have a few emails from users...

Re: Hacking Grindr Accounts with Copy and Paste

#36

> we believe we addressed the issue before it was exploited by any malicious parties I wonder how they are sure of this. In their logs, there would be no difference between a legitimate password reset and a malicious one, given that even a legitimate flow would result in an initial request from some IP address, then when the user receives the email with the reset link they will most likely click on that from the same…

Not saying they did, but couldn't you make an estimate by looking at frequency of resets by single accounts? If someone took over an active account presumably that person would reset the password to get back in (and have a weird email). ASSUMING Grindr logs the person out of the app when the password is reset. You might also have a few emails from users...

This would detect a large-scale attack, but wouldn't detect small-scale, targeted attacks as they would just get lost in the noise of legitimate password resets.

Furthermore, for dormant accounts (where the user is no longer using the app - potentially because they are now in a relationship) the user will not notice anything either, and the notification email is likely to get lost in the endless newsletter spam the non-technical majority has in their inbox.

Re: Hacking Grindr Accounts with Copy and Paste

#38
> Hey, do you have a Grindr account?

> Lol

I can understand this is most probably a private lol by a surprised. But how about we at least stop making these are you gay? Lol! a public moment worth screenshooting?

An Ashley Madison data leak is a national embarrassment whereas a Grindr one, a "national security threat" [1]. Being on AM is just a vaudevillian indiscretion, being on Grindr is bro lol that feeds hate and wrecks lives.

[1] https://www.theverge.com/interface/2019/3/28/18285274/grindr...

Re: Hacking Grindr Accounts with Copy and Paste

#40
post #15
post #6

Earlier quoted context omitted.

> even if you knkw someone on the app, chances are good that they use a personal address that you won't have I doubt that; I bet most users use whatever Gmail/etc personal address they use for other non-work accounts.

Extremely anecdotally: it’s [person_name]@gmail.com I know of very few friends who go through the process of creating a burner email account to sign up for Grindr. Now, maybe that’s different in other countries, but at least in the States, I would bet good money you can guess their Gmail address.

In the case of gmail accounts you could simply prepend +grindr or any other name to the user part of the email address to get something (relatively) unguessable.
Post reply on HN