Earlier quoted context omitted.
someone designed and implemented it. Would be interesting to know the rationale and their train of thought leading to that.
I mean, I don't think it's that hard to surmise how something like this could have happened. Yes, the bug is egregiously bad, but I don't think it's likely the developer purposely designed it to work like that. Some simple possibilities: (a) perhaps the page was originally intended only to be accessible from a user hitting from a private link sent to their email address (i.e. how normal password resets work, or (b) T…
Hacking Grindr Accounts with Copy and Paste
31–40 of 202 posts
Re: Hacking Grindr Accounts with Copy and Paste
#32I'm so glad I've gone social media free, all the big players in this space have shown repeatedly they don't care about the safety of their users. Grindr was already caught sharing HIV status information with 3rd parties. Eventually these horrible companies will be regulated, but tons of people are going to be harmed before that happens.
Re: Hacking Grindr Accounts with Copy and Paste
#33Re: Hacking Grindr Accounts with Copy and Paste
#34Re: Hacking Grindr Accounts with Copy and Paste
#35> we believe we addressed the issue before it was exploited by any malicious parties I wonder how they are sure of this. In their logs, there would be no difference between a legitimate password reset and a malicious one, given that even a legitimate flow would result in an initial request from some IP address, then when the user receives the email with the reset link they will most likely click on that from the same…
You might also have a few emails from users...
Re: Hacking Grindr Accounts with Copy and Paste
#36> we believe we addressed the issue before it was exploited by any malicious parties I wonder how they are sure of this. In their logs, there would be no difference between a legitimate password reset and a malicious one, given that even a legitimate flow would result in an initial request from some IP address, then when the user receives the email with the reset link they will most likely click on that from the same…
Not saying they did, but couldn't you make an estimate by looking at frequency of resets by single accounts? If someone took over an active account presumably that person would reset the password to get back in (and have a weird email). ASSUMING Grindr logs the person out of the app when the password is reset. You might also have a few emails from users...
Furthermore, for dormant accounts (where the user is no longer using the app - potentially because they are now in a relationship) the user will not notice anything either, and the notification email is likely to get lost in the endless newsletter spam the non-technical majority has in their inbox.
Re: Hacking Grindr Accounts with Copy and Paste
#37Re: Hacking Grindr Accounts with Copy and Paste
#38> Lol
I can understand this is most probably a private lol by a surprised. But how about we at least stop making these are you gay? Lol! a public moment worth screenshooting?
An Ashley Madison data leak is a national embarrassment whereas a Grindr one, a "national security threat" [1]. Being on AM is just a vaudevillian indiscretion, being on Grindr is bro lol that feeds hate and wrecks lives.
[1] https://www.theverge.com/interface/2019/3/28/18285274/grindr...
Re: Hacking Grindr Accounts with Copy and Paste
#39Re: Hacking Grindr Accounts with Copy and Paste
#40Earlier quoted context omitted.
> even if you knkw someone on the app, chances are good that they use a personal address that you won't have I doubt that; I bet most users use whatever Gmail/etc personal address they use for other non-work accounts.
Extremely anecdotally: it’s [person_name]@gmail.com I know of very few friends who go through the process of creating a burner email account to sign up for Grindr. Now, maybe that’s different in other countries, but at least in the States, I would bet good money you can guess their Gmail address.