Live data from Hacker News

Hacking Grindr Accounts with Copy and Paste

troyhunt.com

61–70 of 202 posts

Re: Hacking Grindr Accounts with Copy and Paste

#61

A startup I worked for had this exact same security issue. I brought it up to the tech lead/CEO but they were in denial about it. Handrolled password reset by dummies basically

Why people are still hand rolling common stuff like this is baffling to me. I'm treading on offensive waters here, but I'd guess this is from a nodejs backend, for some reason it seems to be more common to hand roll stuff like this in node than pretty much any other web language/framework I've worked with.

Re: Hacking Grindr Accounts with Copy and Paste

#62
post #53

If your company is being actively targeted by nation states (and rest assured, Grindr is), you should have a serious security team where this sort of stuff shouldn't have seen the light of day. I'm not exaggerating when I say this bug may have gotten people locked up, or been the lever for corporate/government espionage.

I don't mean to downplay the issue, but why would LGBT-hostile nation-states target Grindr's infrastructure when it's much easier to detect users at the network level based on TLS SNI (since encrypted SNI is still not a thing thanks to corporate influence)?

I'm sure a government could detect that a citizen visited grindr.com, but it'd be harder to guarantee that they actually had intent to commit "crimes" without access to unencrypted internal messages.

I'm also concerned about antagonist nation state that gets the personal emails of top officials at Department of Defense. Goes through a targeted list in an attempt to find out who's a member. And if a match found, then engage in a blackmail scheme for secret information.

Re: Hacking Grindr Accounts with Copy and Paste

#63
post #53

If your company is being actively targeted by nation states (and rest assured, Grindr is), you should have a serious security team where this sort of stuff shouldn't have seen the light of day. I'm not exaggerating when I say this bug may have gotten people locked up, or been the lever for corporate/government espionage.

I don't mean to downplay the issue, but why would LGBT-hostile nation-states target Grindr's infrastructure when it's much easier to detect users at the network level based on TLS SNI (since encrypted SNI is still not a thing thanks to corporate influence)?

You're assuming the attackers are that sophisticated. With an attack this simple it could be exploited by a group of thugs a local police station (with maybe a "computer savvy friend") logging into local accounts to see if they can find anyone they recognize.

Re: Hacking Grindr Accounts with Copy and Paste

#64
post #53

If your company is being actively targeted by nation states (and rest assured, Grindr is), you should have a serious security team where this sort of stuff shouldn't have seen the light of day. I'm not exaggerating when I say this bug may have gotten people locked up, or been the lever for corporate/government espionage.

I don't mean to downplay the issue, but why would LGBT-hostile nation-states target Grindr's infrastructure when it's much easier to detect users at the network level based on TLS SNI (since encrypted SNI is still not a thing thanks to corporate influence)?

Because at the application level, you get so much more data. Who they're talking to, who they're meeting. HIV status, photos, etc.

Re: Hacking Grindr Accounts with Copy and Paste

#65

> Hey, do you have a Grindr account? > Lol I can understand this is most probably a private lol by a surprised. But how about we at least stop making these are you gay? Lol! a public moment worth screenshooting? An Ashley Madison data leak is a national embarrassment whereas a Grindr one, a "national security threat" [1]. Being on AM is just a vaudevillian indiscretion, being on Grindr is bro lol that feeds hate and…

Isn't Grindr a hookup app? It's not like all gay people use it. It'd be like me asking a straight married friend if they used Tinder. Would "lol" be offensive in that context?

Re: Hacking Grindr Accounts with Copy and Paste

#66

Earlier quoted context omitted.

A good password reset page would not disclose such a fact (it would return a successful response with a message "if this email exists, we'll email you" regardless of whether it actually exists) however attempting to create an account would disclose that fact by rejecting an account creation attempt with an existing email, unless they use emails purely as communication channels and accounts are uniquely identified by…

>however attempting to create an account would disclose that fact by rejecting an account creation attempt with an existing email, unless they use emails purely as communication channels They can tell the user to await an e-mail from them with the confirmation link. Then if the e-mail address is already in use, send an e-mail saying, "somebody, probably you, tried to register as on but we have you down as already". O…

This is a very good idea I haven't thought about, thanks!

Re: Hacking Grindr Accounts with Copy and Paste

#67

Earlier quoted context omitted.

Since when do beliefs require evidence? They don’t mention any, so this is the most positive sounding but still truthful position they can take. Best I can think of is geolocating IPs of the reset requests and then seeing if the real owner (near original location) does a second reset later to take the account back, but that’s not convincing especially if you know where the account you’re targeting lives and went thro…

It's still pretty misleading. They are supposed to be the experts (in the eyes of non-technical people) and if you don't have the skills to understand how the attack works it's reasonable (or at least used to be reasonable) to consider that the risk is minimal if "experts" do not believe it's bad. This response lures their users into a false sense of security.

> This response lures their users into a false sense of security.

That's the entire point of their response though. If all you ever had to do was tell people the truth, PR wouldn't be a thing.

Re: Hacking Grindr Accounts with Copy and Paste

#68

That’s appalling Bug bounties are are well and good, but a basic pen test would have picked that up. They aren’t that expensive and for a business trading in data that can get you killed in some parts of the world, should be mandatory.

It's not a bug. It is either a backdoor placed there from the design/implementation or super lazy programming. I don't want to think it's done on purpose (Hanlon's razor).

If that's an intentional backdoor it's a very weird backdoor. Wouldn't you at least obfuscate things a little bit? Simply mixing up the characters in that string in some pre-planned order would be enough.

Re: Hacking Grindr Accounts with Copy and Paste

#69

Earlier quoted context omitted.

This would detect a large-scale attack, but wouldn't detect small-scale, targeted attacks as they would just get lost in the noise of legitimate password resets. Furthermore, for dormant accounts (where the user is no longer using the app - potentially because they are now in a relationship) the user will not notice anything either, and the notification email is likely to get lost in the endless newsletter spam the n…

I think this is a good point. I'll admit that I'm naive about web and security (not my area). Are multiple password resets within a small time frame common? I would not expect this to be common, but user behavior has often defied my expectation. If it is uncommon I think you could create a correlation and get an estimate, if it is common then I completely agree that it would be lost in the noise. And yeah I agree tha…

I've at times done a string of password resets when unusually designed sign up pages cause a password not to be captured by my password manager.

This seems to happen most when it's a multi page setup process. I often use a plain text scratchpad document to prevent the loss of data but sometimes circumstances happen.

I'm using LastPass for what it's worth. If anyone has better experiences with competitive products I'd be happy to hear about it.

Re: Hacking Grindr Accounts with Copy and Paste

#70
post #11

OK, I know it’s easy to say “well of course it’s not safe, don’t send nudes and don’t go on sketchy hookups”. But, to paraphrase Drag Race: men are rotted gila monsters. (I’m a gay male, I can say that. Also I speak from experience. I've seen things you people wouldn't believe.) So, as a thought exercise, how do you make an app like this more secure? Harm reduction is the name of the game. What are the best practices…

> But, to paraphrase Drag Race: men are rotted gila monsters. (I’m a gay male, I can say that. Also I speak from experience. I've seen things you people wouldn't believe.) No dude, being gay does not give you the license to be disrespectful towards all men.

Instead of trying to make this about yourself, maybe take the context and infer it as bringing some humor into their comment on a pretty serious topic
Post reply on HN