Live data from Hacker News

Hacking Grindr Accounts with Copy and Paste

troyhunt.com

81–90 of 202 posts

Re: Hacking Grindr Accounts with Copy and Paste

#81

That 'bug' is so stupid and elementary that I'm disinclined to think it's a bug. If they had any security people, it'd never have existed. So ... they just don't give a shit . Surprise?

"Security people" spend most of their time dealing with dubious compliance requirements that rarely improve security (in most cases they annoy users and force them to use even less secure workarounds) than actual security like reviewing code to catch things like this and implement policies to make sure unreviewed code doesn't make it to production.

In some cases, mandatory compliance measures even worsen security with rules such as requiring some kinds of characters in a password for instance.

Re: Hacking Grindr Accounts with Copy and Paste

#82
post #11

OK, I know it’s easy to say “well of course it’s not safe, don’t send nudes and don’t go on sketchy hookups”. But, to paraphrase Drag Race: men are rotted gila monsters. (I’m a gay male, I can say that. Also I speak from experience. I've seen things you people wouldn't believe.) So, as a thought exercise, how do you make an app like this more secure? Harm reduction is the name of the game. What are the best practices…

Unfortunately, a large part of it can only really be solved by making the world and the laws of the world safer for the LGBTQ community.

I do what I can in terms of promoting certain ideas, creating informational resources, etc. But I am just one person and yadda.

As long as it is okay to jail or kill people merely for being gay, no amount of security will ever really make it safe.

In the meantime, perhaps someone should blog about "dating security best practices for the LGBTQ crowd" or something like that. (It won't be me. I'm just tossing the idea out there.)

Re: Hacking Grindr Accounts with Copy and Paste

#83
post #5

I guess the good news is that it requires knowledge of the user's email address to execute. You can't just run it on random people (emails aren't disclosed) and even if you know someone on the app in real life, chances are good that they use a personal address that you won't have. Still a pretty bad vulnerability and pretty awful that grindr was ignoring it.

Imagine someone running their contact list through this. You could find everyone you know on Grindr right away, and snoop on their conversations and read their personal info... Not only that, but emails are very easy to find these days with tools like apollo.io.

Social engineering trick: "Hey can you take our picture, my phone is dead, so can you just email it to me?"

Re: Hacking Grindr Accounts with Copy and Paste

#84
This issue is incredibly strange and severe.

One thing I did notice, though: The timestamps on the Twitter DMs, which were used as evidence to assert that they're unresponsive in DMs, cover a time period of 90 minutes. The language the twitter client is set to is also not english (maybe French? the original discovery was made by someone who lives in France. I don't know), which introduces the possibility that it wasn't even daytime in the US when those were sent.

I'm all for publicly announcing these things (in a responsible way) and forcing a quicker response from the company, and its also likely that Troy tried to reach out on his own, but I just think that screenshot is a bad example of a company not responding to DMs. If it had been 48 hours to a week, then I'd be in the concerned camp.

Re: Hacking Grindr Accounts with Copy and Paste

#85
post #53

If your company is being actively targeted by nation states (and rest assured, Grindr is), you should have a serious security team where this sort of stuff shouldn't have seen the light of day. I'm not exaggerating when I say this bug may have gotten people locked up, or been the lever for corporate/government espionage.

I don't mean to downplay the issue, but why would LGBT-hostile nation-states target Grindr's infrastructure when it's much easier to detect users at the network level based on TLS SNI (since encrypted SNI is still not a thing thanks to corporate influence)?

[deleted]

Re: Hacking Grindr Accounts with Copy and Paste

#87
post #84

This issue is incredibly strange and severe. One thing I did notice, though: The timestamps on the Twitter DMs, which were used as evidence to assert that they're unresponsive in DMs, cover a time period of 90 minutes. The language the twitter client is set to is also not english (maybe French? the original discovery was made by someone who lives in France. I don't know), which introduces the possibility that it wasn…

The Twitter DMs are timestamped on September 23. Troy sent his public tweet on October 1.

Re: Hacking Grindr Accounts with Copy and Paste

#89
post #88

One reason why generating random email address for each registered account is a good practice if you care about security, and can sometimes save you.

This is why I love sign up with Apple. Even though developers don’t like it, it’s good for users privacy and security.

Re: Hacking Grindr Accounts with Copy and Paste

#90
post #73

Earlier quoted context omitted.

$50 says they're not. This is something every organization has to say for PR reasons, but saying "we believe" is very fishy wording. It could well be this bug has been around for months before it was discovered, and used by many black/grey-hat hackers.

Governments. It was likely used by governments. Bi men who live straight lives with a wife and family are ridiculously common. The ability to blackmail those people is extremely valuable to certain state organizations.

I've never been gay or bi, and I've never used Grindr, but I have held government security clearances for almost 40 years. It's a lot different today than it was back then. Early on, I knew several people who had "experimented" in college, and they were denied clearances. (Actually the government never officially denied them because that would require an explanation of the criteria used for the denial. Instead, it was perpetually "pending".) Anyway, the basis for their denial was the potential for blackmail, which is a serious national security threat. Sometime within the past 25-30 years, they seem to have revised their policies so gay/bi people can get cleared, as long as they are open about it.
Post reply on HN